Quantcast
Channel: WSUS forum
Viewing all 12874 articles
Browse latest View live

WSUS Server not UPDATING/Downloading Updates

$
0
0

Hi,

We do have WSUS that works fine in past months until i declined some updates that i think/thought that are not essential anymore. Example (updates for XP machine) which we dont have anymore XP machine and all other.

then i noticed that WSUS server is not updating/downloading any recent Critical and Security Updates. (which are Automatically Approved is set for this type of updates)

then i set another Rule to Approval for - Microsoft Security Essential to approve also - But it's not downloading the latest updates ( so i have to do a manual import then approved those updates)

i am not sure what went wrong or from the above scenario, can anyone tell me what did i missed or any thoughts?

thanks

anthony


Can't Change Selections in Products and Clasifications

$
0
0

I need to change the Products that we want to support updates for on our WSUS server. I have unchecked some of the old Products (Windows XP, Office 2007) and selected some new Products (Office 2013), click OK and it appears to save those settings.  If I go back and check right away, those selections have been saved.  However, if go back to recheck sometime later, all of the Products that were originally selected are selected again and the news ones I selected are now deselected, another words, it went back to the old settings.

What could be causing this to happen?  Tried under various user accounts, all with Domain Admin Level Privileges and it's the same thing.  We are running Windows Server 2012 R2 with WSUS 6.3.9600.16384. Microsoft System Center 2012 R2 is also on this server, but I am not using it, only using the WSUS MMC for WSUS management.  The database is running on a separate SQL 2008 Server.

Any suggestions?

clients connecting to windows update and ignoring WSUS ?

$
0
0

Hi

We installed a wsus server and we applied the policy by GPO using registry , but we are monitoring  and  noticed that computers and connecting to IP's from Microsoft, still consuming bandwidth .

We know that the policy is applied since we see the computers are shown in the WSUS and locally the windows update screen show the message that is managed by the system administrator .

I understand ( if I'm right ) that if the computer connects to the server it shouldn't connect to the microsoft servers to search for updates.


This is the .reg we are applying to the computers :


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] 
"AcceptTrustedPublisherCerts"=dword:00000001 
"ElevateNonAdmins"=dword:00000001 
"TargetGroup"="Corporacion" 
"TargetGroupEnabled"=dword:00000001 
"WUServer"="http://internal-ip"; 
"WUStatusServer"="internal-ip";

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] 
"AUOptions"=dword:00000004 
"AUPowerManagement"=dword:00000001 
"AutoInstallMinorUpdates"=dword:00000001 
"DetectionFrequency"=dword:0000000a 
"DetectionFrequencyEnabled"=dword:00000001 
"IncludeRecommendedUpdates"=dword:00000001 
"NoAUAsDefaultShutdownOption"=dword:00000001 
"NoAUShutdownOption"=dword:00000001 
"NoAutoRebootWithLoggedOnUsers"=dword:00000001 
"NoAutoUpdate"=dword:00000000 
"RebootRelaunchTimeout"=dword:0000000f 
"RebootRelaunchTimeoutEnabled"=dword:00000001 
"RescheduleWaitTime"=dword:0000000a 
"RescheduleWaitTimeEnabled"=dword:00000001 
"ScheduledInstallDay"=dword:00000000 
"ScheduledInstallTime"=dword:00000009 
"UseWUServer"=dword:00000001

WSUS - pre-reqs for updates i approve

$
0
0

If i Approve a set of Critical updates, I'm assuming that any pre-reqs that they have will not be automatically approved for me (unless i do an Automatic Approval rule that approves ALL Critical updates).

Given that assumption, I have 2 questions:

* Do updates of a particular Classification (like Critical) ONLY have pre-reqs that are also Critical, or might the pre-reqs have some other Classification?

* Is there any automated way to find out for a selection of updates what the pre-reqs updates are and approve them en masse?  Or would i need to look at the details of each update individually to discover which are the pre-req updates?

Thank you!

WSUS at multiple sites and one master to approve

$
0
0

Hi Guys , 

If this has been answered, please forgive me and direct me to that. i have multiple sites wsus installed (sites are connected via vpn). at the moment each sites has it own servers of wsus and in GP ,sites OU to report to its own server. What I like to do is have one master at one site and approve the updates at that server. clients download the updates from it own servers. not from other sites. then again that servers on the branch offices will download updates from Microsoft rather than Master server to save the vpn bandwidth. 

how can i approach that 

thanks

I Can't Install Updates on windows server 2012 r2

$
0
0

Hi All,

I Can't install updates from wsus to w2012r2, after downloading updates from wsus and install them after that i got an error msg "We Couldn't complete updates undoing changes" i faced this issue before but in virtual machine i fix it by unchecked Secure boot In UEFI, but now i faced this issue on physical machine a go into bios to check secure boot but is disabled  i use UEFI.

Any Help Please Thanks in advance !  


IT Helpdesk

Missing update in WSUS

$
0
0

Here I've got a WSUS and ~20 Windows 8.1 x64 Client.

I deploy allnecessary update to the client.

I test different clients with Microsoft Update and now they reports the following updates missing:

KB3005628

I approved this update but no client installs it

KB2976978

I didn't find this update in WSUS

Is this behavior normal?

Must I install those updates manually on all clients?

Thanks

Reto Felix

Auto Approve WSUS Updates

$
0
0

Hi

Can anyone recommend if its a good idea to set WSUS to auto approve updates? Specifically security and critical updates. 

Thanks

Shane 


Client not reporting to WSUS server

$
0
0
I have one client server not reporting to WSUS server, patches are not pushed to the server. I have tried reauthorizing the server from client and I also also did windows components reset. Nothing works. I need help to fix this issue.

Error ID 12072 The WSUS content directory is not accessible.

$
0
0

Hi,

I receive the following error log.

The WSUS content directory is not accessible.
System.Net.WebException: The remote server returned an error: (401) Unauthorized.
at System.Net.HttpWebRequest.GetResponse()
at Microsoft.UpdateServices.Internal.HealthMonitoring.HmtWebServices.CheckContentDirWebAccess(EventLoggingType type, HealthEventLogger logger)

Also WSUS server doesn't install any approved update that "Installed/Not Applicable Percentage"column is still 0% and message says,

"This update supersedes another update. Before you decline any superseded update, we recommend that you verify it is no longer needed by any computer. To do so, approve the superseding update first."

Does this have anything to do with error 12072?

Could you please give me some advise?

Thanks,

New WSUS server has errors

$
0
0

Hello,

I have installed WSUS on Server 2012 R2 on a server following these instructions.  https://mizitechinfo.wordpress.com/2013/08/19/step-by-step-installing-configuring-wsus-in-server-2012-r2/

I did all of the steps in this document but noticed that I am not able to download updates to the client.  I am getting these 2 errors:

1.  Your WSUS server currently shows that no computers are registered to receive updates; and

2.  The files for this update have not yet been downloaded.  The update can be approved but will not be available to computers until the download is complete.  Note that I approved the updates already.  Additional note is that this is an offline network so I did an export from a separate SCCM/WSUS server, which is connected to the internet and successfully synchronized the updates on the offline network. 

Any help in getting this working would be greatly appreciated. 

Thanks,

M

Do I still need to download WSUS 3.0 SP2?

$
0
0

Hello,

I am installing WSUS for the first time and am still trying to figure everything out.  On my 2012 R2 server, I added the WSUS roles.  Do I still need to download WSUS 3.0 SP2 as well?  Please advise.  Thanks for any help!

Thanks,

M

Windows\SoftwareDistribution Folder Cleanup Automation

$
0
0

Hi -

I have a number of machines with a bloated Windows\SoftwareDistribution folder.  I usually address this by:

  1. Stopping the Automatic Updates service.
  2. Deleting the Windows\SoftwareDistribution folder.
  3. Restarting the Automatic Updates service.

I'm considering using a computer startup script to perform this task automatically.  Does anyone have a more elegant method of automating this task?

Thanks in advance for your input.

WSUS status still showing downloading files

$
0
0

I have an interesting issue. Around June 9th, 2015 I had an issue where some files were not downloading after approving the June updates. So, I rebooted the WSUS server. This usually repairs most issues. There was a period of time where some of the definition files were not getting downloaded. Yesterday I approved the patches for the test group and this morning they have downloaded along with the definition files. I am still getting this message on the console. The WSUS server is on Windows Server 2008 SP 2. 32bit.



Would anyone know how to clear the Download Status messages? 

Thanks again for your help.


Computers get in and out of WSUS 2012r2 group, never more then 5 at a time in the group

$
0
0
Hello,
I am about to set up a new WSUS on a 2012 R2 Server. We yet use an old W2k3 R2 for WSUS and want to replace it with this new one.
I already configured almost everything, I do apply the WSUS client-side settings via GPO to my Domain Clients and Servers. Therefore I have created two GPO's, one for Servers and one for Client PC's which are more strict. Within my GPO I am also using the "Target Group Name....." feature in order to add computers directly to the right group in WSUS. I also did the according settings at WSUS side.
Everything works fine so far, computers show up in the correct WSUS groups. For testing purposes I only have assigned the GPO to 3 client PC's, but all my servers in charge, which are about 12.
The three PC's show up, but from the 12 servers only 5 in total show up. The interesting is that this varies, the are never more than five. but always different ones. I feel like they are the 5 last ones who contacted WSUS. I know it is weird, but it looks to me like there cannot be more than 5 members at a time and the 6th one pushes one the the existing 5 out of the group. Strange is also that any of my servers is able to get it's updates, that part works fine. It is just, that my WSUS group never contains more than 5 servers. I assume that once I add more then 5 client PC syncing to this WSUS I will have the same issue with them too.

Any idea?
kind regards,
Dieter Tontsch
mobileX AG

Synchronization Error Wsus 3 SP2 Ver 3.2.7600.226

$
0
0


hello need help

i keep getting this error on my server

i have no proxy, internet is good 

it did work for 1 week and stoped


WSUS clients keep reappearing in WSUS

$
0
0

Hi,

I have a WSUS server (the only one in the network) ver.3.2.7600.226 running on Server 2008 Standard.

I have set up a group policy which has been pushed out to all client machines and they are all reporting back. Some are with updates to install, a few updates failed (which we trouble shoot at source) and some lovely green ticks meaning everything is up to date. IIS is set up and the relevant ports are open and communicating.

However, I have a list of old machine in an OU in active directory where the new group policy is not linked to. There machinesdon't exist anymore (most are just hard drives in a draw!). There is no way they can be contacting WSUS so I delete them from WSUS server (not from Active directory). I carry on happily for about 30 minutes then they pop back. What do you think is happening?

I have admin rights on the server, I've emptied/deleted the WSUS cache files, restarted the WSUS server services and reset IIS. My last thought is that there is some sort of MOF file that is bringing the machines back. They only ones I can find are IIS related. This system was set up before my time here as I'm trying to be a mind reader at well!

Any help gratefully recieved.

All the best,

Simon

Windows Patching

$
0
0

Greetings,

The patching of Windows Server(2003, 2008 & 2012) were done using SCCM on Global scale, where as the Japanese sub-organization unit use WSUS to patch the Server environments. As part of the global standardization activity, we are looking to integrate the Server patching to the Global scale model by moving it from local WSUS platform to the Global SCCM platform. However our client is worried that some of the Operating systems run on Native Japanese language platforms (Windows 2003, 2008 & 2012) and they may miss critical Japanese specific patches, if moved to global SCCM Model.

As per my understanding, all the updates are the same irrespective of the language platform and the same patches that are applicable to native English language servers are same and applicable to any other language servers.

Is my understanding correct Or Do the patches vary based on the Operating system native language pack (based on the patches that are released by Microsoft every month).

Thanks in Advance. Appreciate your support.

SCUP 2011 - possible to publish an update to only one WSUS computer group?

$
0
0

Hello,

I´d like to use SCUP 2011 to deploy Adobe Flash Player Updates to our clients. We are using WSUS 3.0 to Publish windows Updates (not SCCM).

In WSUS we have several computer groups in which the computers get sorted in by GPO.

When i now try to publish an Update, there´s no opportunity to say "publish the Update to group "computers"" (for example)

Is there a way to do so or is an SCUP Update always published to every computer which gets it´s updates from this wsus Server?

I also have another Question - how do i "unpublish" an update? Is there only the way to mark the Update as expired?

Thanks!!

Windows update intermittently downloads on computers throughout a domain

$
0
0

What I mean by this is, we deploy windows 7 through an image we have created. We update this image using a Powershell script which downloads Windows updates from our WSUS. We then deploy this image to a new computer.

Theoretically the new computers should be up-to-date with Windows Updates. The problem is, we drop the computers into different OU groups. They then pick up the GPO which links to our WSUS and should see that it's up-to-date. Some computers are fine and no update installs. But some computers start pulling updates from the WSUS and start installing. Which obviously takes a lot of time. These could differ from 70 updates to 170.

Why would one computer not need updates but then another computer in another OU group start installing updates when both of them link to the same WSUS and both are from the same WIM file?

It's a strange one and I can't see any solution online.

Any advice you can give me? Anything I can check. I have permissions to the WSUS but I don't really know what I'm looking at.

Viewing all 12874 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>