Quantcast
Channel: WSUS forum
Viewing all 12874 articles
Browse latest View live

Upstream Server in Diffrent Forest

$
0
0

Hi Experts

According to requirement, we need to install WSUS Upstream Server in one management domain (xyz.com) and need to patch/install updates in Client domains (client1.com) using Downstream Server in autonomous mode.

Do you think this is possible? How authentication will happen between Upstream and Downstream using autonomous mode?


Thanks Cloudy Lynx


WSUS - Download error

$
0
0

Hello Experts,

We have one old windows server 2003 machine, we try to use it as our WSUS server. installation is gone well but it is not downloading updates. updates are struck at 0%. I tried to reboot server, manually start BITS service. But no luck. the event  error are as below:-

Event id 10032:

The server is failing to download some updates.

Event id364

ontent file download failed. Reason: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. (Exception from HRESULT: 0x80070422) Source File: /c/msdownload/update/software/crup/2014/12/kb3024777-amd64_74755ac18f057a456f596da0610abb67ded07b70.exe Destination File: e:\WSUS\WsusContent\70\74755AC18F057A456F596DA0610ABB67DED07B70.exe.

Any advise will be very helpful to resolve the issue i tried all possible ways in last 4 days.

Regards

Aditya

KB2720211 - KB2734608 > WSUS Nightmare

$
0
0

Hello,

We have a 2012R2 Main office WSUS andmultiple replica windows servers 2008 in other offices.

My servers replica doestn work since i installed this updates. With KB2720211i follow this steps and the serverwas working well:


change HKEY_LOCAL_MACHINE\Software\Microsoft\Update Services\Server\Setup\wYukonInstalled from 1 to 0
install update again
reboot
change HKEY_LOCAL_MACHINE\Software\Microsoft\Update Services\Server\Setup\wYukonInstalled from 0 to 1
reboot
install update AGAIN


I say, ok fine. But them i have the problem with Windows 8 and 2012. I read aboutKB2734608 ( that include KB2720211 Update and this other more2530678, 2530709 )

So i decided install to solve the report comunication with Windows 8 and 2012 clients, but during installation i have an error.



Now, i have errors 7042 and 7053 and my wsus not work. Itooktoo much time looking for infomation and i dont know what more can i do to solve the problem.

I try to reinstall KB2720211with the same process, but an error occur with the installation.

I read all this:

https://social.technet.microsoft.com/Forums/windowsserver/en-US/9f6e3665-6b72-4cd3-abdd-b9f551280acc/wsus-on-windows-2008-r2-and-windows-8?forum=winserverwsus

https://social.technet.microsoft.com/Forums/windowsserver/en-US/ac9c4816-c4f3-4e34-ab07-793f46d102e8/an-error-occured-during-installation-of-kb2734608-windows-2003-wsus-sp2?forum=winserverwsus

https://community.spiceworks.com/topic/606668-wsus-broke-after-installing-kb2734608

I also try to re-index the Wsus Database... with this script of script guys. I have not SSL configured.

Any idea with this nightmare ¿?

Many thanks !


Multiple errors when trying to download updates from my 2012 WSUS Server - 8024401F, 801901F4, 8024000C

$
0
0

Clients are having an issue downloading updates from my WSUS machine. WSUS was working fine and now I'm getting errors saying that greater than 25% of the computers are having issues (which is not normal). I'm running Server 2012 in a hyper-V virtual machine. The only product installed on this VM is WSUS version 6.x

Clients are configured to point to the WSUS server for updates. I've confirmed through the command line (gpresult /R with admin rights shows the WSUS GPO is applied) and event viewer that group policy is successfully taking place.

Just to double check, I ran wuauclt /detectnow and then I checked the windowsupdate.log and I noticed that it mentioned my server name as being the configured update server. 

2014-04-2816:15:22:17022419cAU###########  AU: Initializing Automatic Updates  ###########
2014-04-2816:15:22:17322419cAU # WSUS server: http://(Myfileserver):8530
2014-04-2816:15:22:17322419cAU # Detection frequency: 22
2014-04-2816:15:22:17322419cAU # Approval type: Pre-install notify (Policy)
2014-04-2816:15:22:17322419cAU # Auto-install minor updates: No (User preference)

Then to triple check, I looked in the registry to find the keys that pointed to where the client is trying to get updates. (I blanked out the servernames below.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] "WUServer"="http://XXXXXXXXXX""WUStatusServer"="http://XXXXXXXXXXXXX" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update] "AUState"=dword:00000002 "LastWaitTimeout"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]"NoAutoUpdate"=dword:00000000 "AUOptions"=dword:00000004 "ScheduledInstallDay"=dword:00000000 "ScheduledInstallTime"=dword:00000003 "UseWUServer"=dword:00000001

When check for updates, it finds 12 updates are needed. I try to download them and the client keeps getting an error with code 8024401F. "Windows Update Encountered an unknown error"

I pulled logs from windowsupdate.log on a client machine I'm having issues with.

2014-04-2907:54:52:94222413c4DnldMgrBITS job {6BBB01D7-D9AA-4FA4-9CCE-51E76B42E9C9} hit a transient error, updateId = {A33001C7-2446-4984-A987-2F6CFACD5999}.201, error =0x801901F4
2014-04-2907:54:52:94222413c4DnldMgr Will not attempt to resume the job as it has reached the maximum number of attempts.
2014-04-2907:54:52:94222413c4DnldMgrError 0x8024401f occurred while downloading update; notifying dependent calls.
2014-04-2907:54:52:96022419c0DnldMgrError 0x8024401f occurred while downloading update; notifying dependent calls.
2014-04-2907:54:52:9622241e20DnldMgrError 0x8024401f occurred while downloading update; notifying dependent calls.
2014-04-2907:54:52:962224644AUAU checked download status and it changed: Downloading is not paused
2014-04-2907:54:52:962224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:52:963224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:52:96522413c4DnldMgrBITS job {632784E6-6083-42EA-B5E7-C77501BAB46A} hit a transient error, updateId = {B22EFD58-88B3-4B6A-ADC7-0B07BF7EE4FD}.200, error = 0x801901F4
2014-04-2907:54:52:96522413c4DnldMgr Will not attempt to resume the job as it has reached the maximum number of attempts.
2014-04-2907:54:52:96522413c4DnldMgrError 0x8024401f occurred while downloading update; notifying dependent calls.
2014-04-2907:54:52:978224c48ReportREPORT EVENT: {03E56CC5-0F9A-4F25-8108-41113D01177F}2014-04-29 07:54:52:841-04001161101{D048E2EE-4B85-4072-AC35-C4DF948858D1} 2008024401f AutomaticUpdatesWuAppFailureContent DownloadError: Download failed.
2014-04-2907:54:52:978224c48ReportREPORT EVENT: {B7BDB529-533F-4CFB-8713-6E32FE89BCC3}2014-04-29 07:54:52:909-04001161101{BFE2CAC7-2E6F-43B6-B425-94CEE231AEDC} 2018024401f AutomaticUpdatesWuAppFailureContent DownloadError: Download failed.
2014-04-2907:54:52:978224c48ReportREPORT EVENT: {1DA4FB0A-84A9-4B63-BD42-E93F93BD401E}2014-04-29 07:54:52:948-04001161101{4FC4A660-723C-442A-A183-E21509BBDCF0} 2018024401f AutomaticUpdatesWuAppFailureContent DownloadError: Download failed.
2014-04-2907:54:52:988224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:52:988224c48ReportCWERReporter::HandleEvents - WER report upload completed with status 0x8
2014-04-2907:54:52:988224c48ReportWER Report sent: 7.6.7600.256 0x8024401f D048E2EE-4B85-4072-AC35-C4DF948858D1 Download 101 Managed
2014-04-2907:54:52:993224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {5A90133F-1260-4C43-86AB-12B9989E13EC}]
2014-04-2907:54:52:993224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:52:994224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:52:994224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:52:996224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:52:997224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {345B0353-DFC6-48CC-A6B6-A490CA26B503}]
2014-04-2907:54:52:997224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:52:998224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:52:998224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:52:999224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:000224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {4FC4A660-723C-442A-A183-E21509BBDCF0}]
2014-04-2907:54:53:000224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:53:001224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:001224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:53:003224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:003224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {A9EC16AA-04E5-4D92-BEC5-67C836F7D8F0}]
2014-04-2907:54:53:003224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:53:004224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:004224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:53:005224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:006224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {BFE2CAC7-2E6F-43B6-B425-94CEE231AEDC}]
2014-04-2907:54:53:006224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:53:007224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:007224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:53:009224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:010224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {D048E2EE-4B85-4072-AC35-C4DF948858D1}]
2014-04-2907:54:53:010224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:53:011224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:011224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:53:013224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:014224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {A546FDF1-1AE0-4F0C-A8ED-714AF26C6A1D}]
2014-04-2907:54:53:014224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:53:015224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:015224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:53:017224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:019224644AU>>##  RESUMED  ## AU: Download update [UpdateId = {00176CFB-5FDC-448B-BC54-C38B8E475646}]
2014-04-2907:54:53:019224644AU # WARNING: Download failed, error = 0x8024401F
2014-04-2907:54:53:019224644AU#########
2014-04-2907:54:53:019224644AU##  END  ##  AU: Download updates
2014-04-2907:54:53:019224644AU#############
2014-04-2907:54:53:020224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:020224644AUCurrently showing Progress UX client - so not launching any other client
2014-04-2907:54:53:028224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:53:050224c48ReportCWERReporter::HandleEvents - WER report upload completed with status 0x8
2014-04-2907:54:53:050224c48ReportWER Report sent: 7.6.7600.256 0x8024401f BFE2CAC7-2E6F-43B6-B425-94CEE231AEDC Download 101 Managed
2014-04-2907:54:53:076224c48ReportCWERReporter::HandleEvents - WER report upload completed with status 0x8
2014-04-2907:54:53:076224c48ReportWER Report sent: 7.6.7600.256 0x8024401f 4FC4A660-723C-442A-A183-E21509BBDCF0 Download 101 Managed
2014-04-2907:54:53:076224c48ReportCWERReporter finishing event handling. (00000000)
2014-04-2907:54:53:076224c48ReportREPORT EVENT: {CAC35D34-DCCA-4DF1-BE39-CA44C48C01C5}2014-04-29 07:54:52:973-04001161101{00176CFB-5FDC-448B-BC54-C38B8E475646} 2008024401f AutomaticUpdatesWuAppFailureContent DownloadError: Download failed.
2014-04-2907:54:53:131224c48ReportCWERReporter::HandleEvents - WER report upload completed with status 0x8
2014-04-2907:54:53:131224c48ReportWER Report sent: 7.6.7600.256 0x8024401f 00176CFB-5FDC-448B-BC54-C38B8E475646 Download 101 Managed
2014-04-2907:54:53:131224c48ReportCWERReporter finishing event handling. (00000000)
2014-04-2907:54:53:7952241ca4AUBeginInteractiveInstall invoked for Install
2014-04-2907:54:53:7962241ca4AUAuto-approved 0 update(s) for install (for Ux), installType=0
2014-04-2907:54:53:7962241ca4AUWARNING: BeginInteractiveInstall failed, error = 0x8024000C
2014-04-2907:54:54:0042241bb8AUAU received handle event
2014-04-2907:54:54:0042241bb8AUUpdateDownloadProperties: 0 download(s) are still in progress.
2014-04-2907:54:54:0102241bb8AUTriggering Offline detection (non-interactive)
2014-04-2907:54:54:0102241bb8AUAU setting pending client directive to 'Install Complete Ux'
2014-04-2907:54:54:0102241bb8AUWARNING: Pending directive, 'Install Complete Ux', is not applicable
2014-04-2907:54:54:0122241bb8AUSuccessfully wrote event for AU health state:0
2014-04-2907:54:54:0122241bb8AU#############
2014-04-2907:54:54:0122241bb8AU## START ##  AU: Search for updates
2014-04-2907:54:54:0122241bb8AU#########
2014-04-2907:54:54:0142241bb8AU<<## SUBMITTED ## AU: Search for updates [CallId = {AD5BEF1D-016E-43F1-BD14-8F57CD8F77AD}]
2014-04-2907:54:54:014224c48Agent*************
2014-04-2907:54:54:014224c48Agent** START **  Agent: Finding updates [CallerId = AutomaticUpdates]
2014-04-2907:54:54:014224c48Agent*********
2014-04-2907:54:54:014224c48Agent * Online = No; Ignore download priority = No
2014-04-2907:54:54:014224c48Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
2014-04-2907:54:54:014224c48Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2014-04-2907:54:54:014224c48Agent * Search Scope = {Machine}
2014-04-2907:55:06:364224c48Agent * Added update {345B0353-DFC6-48CC-A6B6-A490CA26B503}.201 to search result
2014-04-2907:55:06:364224c48Agent * Added update {00176CFB-5FDC-448B-BC54-C38B8E475646}.200 to search result
2014-04-2907:55:06:364224c48Agent * Added update {A41E7337-1BC4-4B8E-8F15-66615D2D8677}.200 to search result
2014-04-2907:55:06:364224c48Agent * Added update {92AEAB02-F8FC-4527-B285-50FDC8EF3F85}.201 to search result
2014-04-2907:55:06:364224c48Agent * Added update {4FC4A660-723C-442A-A183-E21509BBDCF0}.201 to search result
2014-04-2907:55:06:365224c48Agent * Added update {BFE2CAC7-2E6F-43B6-B425-94CEE231AEDC}.201 to search result
2014-04-2907:55:06:365224c48Agent * Added update {F49A461D-9FA0-484B-9DB5-B14E9A3D9BD3}.203 to search result
2014-04-2907:55:06:365224c48Agent * Added update {D048E2EE-4B85-4072-AC35-C4DF948858D1}.200 to search result
2014-04-2907:55:06:365224c48Agent * Added update {5A90133F-1260-4C43-86AB-12B9989E13EC}.200 to search result
2014-04-2907:55:06:365224c48Agent * Added update {5030EB19-E22B-4968-8EED-C1D3C1280180}.200 to search result
2014-04-2907:55:06:365224c48Agent * Added update {A546FDF1-1AE0-4F0C-A8ED-714AF26C6A1D}.201 to search result
2014-04-2907:55:06:365224c48Agent * Added update {A9EC16AA-04E5-4D92-BEC5-67C836F7D8F0}.200 to search result
2014-04-2907:55:06:365224c48Agent * Found 12 updates and 74 categories in search; evaluated appl. rules of 1013 out of 2304 deployed entities
2014-04-2907:55:06:365224c48Agent*********
2014-04-2907:55:06:365224c48Agent**  END  **  Agent: Finding updates [CallerId = AutomaticUpdates]
2014-04-2907:55:06:365224c48Agent*************
2014-04-2907:55:06:400224644AU>>##  RESUMED  ## AU: Search for updates [CallId = {AD5BEF1D-016E-43F1-BD14-8F57CD8F77AD}]
2014-04-2907:55:06:400224644AU # 12 updates detected
2014-04-2907:55:06:401224644AU#########
2014-04-2907:55:06:401224644AU##  END  ##  AU: Search for updates [CallId = {AD5BEF1D-016E-43F1-BD14-8F57CD8F77AD}]
2014-04-2907:55:06:401224644AU#############
2014-04-2907:55:06:401224644AUFeatured notifications is disabled.
2014-04-2907:55:06:402224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:55:06:402224c48ReportCWERReporter finishing event handling. (00000000)
2014-04-2907:55:06:405224644AUSuccessfully wrote event for AU health state:0
2014-04-2907:55:11:401224c48ReportCWERReporter finishing event handling. (00000000)
2014-04-2908:07:26:270224c48ReportUploading 26 events using cached cookie, reporting URL = http://(Myfileserver):8530/ReportingWebService/ReportingWebService.asmx
2014-04-2908:07:26:289224c48ReportReporter successfully uploaded 26 events.

I've googled the error codes individually but I've been unsuccessful in fixing this issue. Any help would be greatly appreciated.

UPDATE:

On my client machine I can download and install updates when I click "check online for windows updates." So there must be something wrong with my WSUS server.

UPDATE2:

I solved the problem! The updates orignally were downloaded to the C: drive of the server. I've since moved them to the E: drive and for some reason the Content folder in IIS didn't change the file path to the new WSUScontent folder. I edited the virtual directory settings in IIS and was able to put the correct path in.

Almost immediately after that change was made I noticed computers pulling updates and installing them successfully!

This problem was caused by moving the WSUS updates to a different local drive.

Updates needing files: 2, Downloaded 1,332.54 MB of 1,333.05 MB

$
0
0

Hello,

I notice today that the download status is:

Updates needing files: 2

Downloaded 1,332.54 MB of 1,333.05 MB

I've done a few manual syncs and completely opened up the firewall but still the same message. I found in a previous discussion to run BITSADMIN /LIST /ALLUSERS /VERBOSE to find which files it is stuck on. This is the output,

GUID: {5819E53F-F356-4BC6-8738-A6DBD2C386B3} DISPLAY: '816efd9c-30ba-4ebe-9851-a
96c2a7d94a5'
TYPE: DOWNLOAD STATE: TRANSIENT_ERROR OWNER: NT AUTHORITY\NETWORK SERVICE
PRIORITY: HIGH FILES: 0 / 1 BYTES: 0 / UNKNOWN
CREATION TIME: 20/08/2015 13:19:27 MODIFICATION TIME: 20/08/2015 14:09:27
COMPLETION TIME: UNKNOWN ACL FLAGS:
NOTIFY INTERFACE: UNREGISTERED NOTIFICATION FLAGS: 3
RETRY DELAY: 600 NO PROGRESS TIMEOUT: 86400 ERROR COUNT: 6
PROXY USAGE: OVERRIDE PROXY LIST: lntmg1:8080 PROXY BYPASS LIST: <local>
ERROR FILE:    http://wsus.ds.rr1winwusfs04/d/msdownload/update/software/uprl/20
15/08/exefortesting_4f8a4e3533c4524c910d0207f2a8ff041a6b5f03.exe -> D:\WSUS\Wsus
Content\03\4F8A4E3533C4524C910D0207F2A8FF041A6B5F03.exe
ERROR CODE:    0x801901f6
ERROR CONTEXT: 0x00000005
DESCRIPTION: SUSFile
JOB FILES:
        0 / UNKNOWN WORKING http://wsus.ds.rr1winwusfs04/d/msdownload/update/sof
tware/uprl/2015/08/exefortesting_4f8a4e3533c4524c910d0207f2a8ff041a6b5f03.exe ->
 D:\WSUS\WsusContent\03\4F8A4E3533C4524C910D0207F2A8FF041A6B5F03.exe
NOTIFICATION COMMAND LINE: none
owner MIC integrity level: SYSTEM
owner elevated ?           true
This job is read-only to the current CMD window because the job's mandatory
integrity level of SYSTEM is higher than the window's level of HIGH.
Peercaching flags
         Enable download from peers      :false
         Enable serving to peers         :false

CUSTOM HEADERS: NULL

Listed 1 job(s).

Two things look odd. The domain is not valid and the file name starts with exefortesting...

Anyone else with the same issue? or any idea how to fix? (6.3.9600.16384 on Win2012R2)

Regards, Andrew

svchost & trustedinstaller consuming 100% cpu for 15-20 minutes

$
0
0

Hi,

We have approved Augusts updates on monday. Since then all targeted systems CPU is peaking to 100% for 15-20 minutes on every "check for updates" interval... in our case every 2 hours. svchost (wuauserv service) and TrustedInstaller are the culprits.

I can already confirm the issue occurs on virtual machines (vmware), running a perfmon trace on a physical system now.

Anyone experiencing this issue also? Or any idea what might be causing this? I know it is normal behavior Windows checks for updates and the cpu peaks briefly but a peak of 20 minutes every interval doesn't seem normal to me.

Grts. 



Best Practice to clean up WSUS content no longer needed

$
0
0

I have been researching this for days and probably have about 10 hours invested in trying to come to a conclusion and now want some feedback from this group. Below you will find everything I think you might need about my current configuration. I originally installed my first WSUS server in 2006.Over the years I added new products as needed, changed to express files (seems to have been a bad decision), unselected products no longer needed, and when version 3 came out began running the cleanup wizard monthly. I have never declined any updates myself and only approved those showing as needed. I watched my content grow to about 65 GB then decided to migrate to a new server. I followed this procedure which worked very well:

http://exchangeserverpro.com/how-to-move-wsus-30-to-a-new-server

After the migration I tested a round of updates and everything was working fine. Then I added Windows Server 2008 (only have one server with this OS) and SQL Server 2008 R2 (only have one server with this OS) products and was amazed when my content went up to over 100 GB. I decided to remove those two products since only one server needs them and I could update it direct from MS instead thinking it would be easy to recover the space. Was I in for a surprise. No real easy way to do that. From my research these seem to be the options to do a good clean up on all unneeded content. What do you suggest as the best way for me to proceed?

Option 1: uninstall and re-install fresh

Option 2: reset the content following this procedure:

http://blogs.technet.com/b/gborger/archive/2009/02/27/what-to-do-when-your-wsuscontent-folder-grows-too-large.aspx

Option 3: reset the content following this procedure: (I tested this on my old server and steps 1-4 took about 90 minutes)

1. Decline all previously approved updates. (Yes, all of them. Even the ones you want.)
2. Run the cleanup wizard -- this will remove files in the WsusContent folder.
3. Change the approval of all DECLINED updates from declined to "Not Approved" (and apply inheritance).
4. Run the cleanup wizard again -- this will decline all expired updates.
5. Re-approve needed updates. Content will be re-downloaded.

I do plan to remove the express files option first to reduce the amount of space needed for storage. If you see anything else in my config that should be tweaked please let me know. Thanks for any and all feedback. I appreciate you taking the time to read this and respond.

My configuration follows:

1 Gbps switched network infrastructure with 10/10 fiber internet access

WSUS – current environment – 1 physical server also used as a file share server for user files

Windows Server 2008 Enterprise (x86)

Dual Intel Xeon 2.8 Ghz

2 GB Ram

1 Gbps Nic

136 GB hard drive for DB and WSUS Content files (currently DB=1.5 GB, Content = 108 GB)

WSUS Server version: 3.2.7600.226

Using the Windows Internal Database (I do have a SQL Server 2008 R2 server available now)

128 Computers in 13 groups manually assigned but computers are directed to this server via GP

(all Servers and 90% of workstations are current on updates through last month)

3189 Updates installed/NA

139 Updates needed

919 Updates with no status

Configuration options:

Update source – Microsoft

Products – Office 2003, Office 2010, Windows 7, Windows Defender, Windows Server 2003, Windows Server 2008 R2, Windows XP (previously selected but no longer needed: Office 2002/XP, SQL Server 2008 R2, Windows 2000, Windows Server 2008)

Classifications – critical, definition, security, service packs, update rollups, updates

Update files and languages – store locally, download only when approved, download express installation files, English

Automatic approvals – above classifications for test group which includes one computer with each of the following OS’s: Windows 7, Windows Server 2003, Windows Server 2008 R2, Windows XP

After those machines are tested then I approve and install needed updates for the server group (8 machines total) which include Windows Server 2003, Windows Server 2003 R2, Windows Server 2008 R2, Windows XP

After those machines are tested then I approve needed updates for all computers and let the users install them


How to set 10 Home for WSUS? 7 Home, 8.1 Core are good.

$
0
0

How can we configure Windows 10 Home to use our WSUS ver 3.2.7600.274, which runs on Windows 2008R2 on our Domain?

10 Pro is using WSUS fine. And we set all 7 Home & 8.1 Core laptops to use WSUS, with the WSUS Workgroup Client Setting Manager v1.1 tool (wsusworkgroup.codeplex.com); it seems to set the same keys:

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate]
"WUServer"="http://<WSUSserver>"
"WUStatusServer"="http://<WSUSserver>"

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"UseWUServer"=dword:00000001

But 10 Home seems to ignore them. The WSUS server shows no connection by the 10 Home machine since its upgrade from 8.1; the server still shows it as 8.1.

We have very limited Internet bandwidth so it's a critical bandwidth saving for us ongoing. (we are a non-profit in a remote "third world" location). We have stopped 10 Home upgrades for now.

Here's another post, same issue
http://www.tenforums.com/windows-updates-activation/10932-windows-10-home-not-connecting-intranet-wsus.htm

Thank you
Chris


Not able to install KB 2785220; https://technet.microsoft.com/en-us/library/security/ms13-006.aspx

$
0
0

Error : The update is not applicable on your server

OS : Win 2008 R2 SP1

KB3054846 not needed/applicable?

$
0
0

Hi everyone

Update KB3054846 (see https://support.microsoft.com/en-us/kb/3054846) should be available for Office 2010 SP2 as far as I know, however, both WSUS and Microsoft Update say it is not needed on any of our Windows 7 32-bit PCs. Our patch management solution on the other hand indicates that this update is missing and should be installed. This could be a false-positive but I am not sure. Is anyone else seeing this or does anyone have an explanation for this?

There was a similar case a while ago (https://social.technet.microsoft.com/Forums/windows/en-US/1a76d55e-dfad-4cdd-b90f-0ad54165b7ee/kb2881073-not-applicable?forum=winserverwsus) where the update turned out to be only applicable to Office 2010 on Server 2003. I cannot find such information for KB3054846 though. I would like to understand why WSUS or Microsoft Update don't offer this update and would appreciate any advice. Thank you.

Regards, Stefan


KB2881073 not applicable?

$
0
0

Hi everyone

I have a question regarding KB2881073. This update is not missing according to WSUS and Microsoft Update. However, our patch management solution indicates that this update is missing and needs to be installed. I first thought it could be a false-positive but then I manually installed it without a problem. According to the KB article (https://support.microsoft.com/en-us/kb/2881073?wa=wsignin1.0), the prerequisite is Office 2010 SP2, so WSUS and Microsoft Update should offer this update to all our PCs but that's not the case. Any ideas why? Is anyone else seeing this?

Regards

Stefan



Compliance report for WSUS

$
0
0

Hi,
I have deployed WSUS, using which servers are patched every month, I need to generate compliance report for computers which should have analytical data in the form of pie chart or any other graphical representation.

How could i achieve this considering the fact that i am using Windows Internal DB for WSUS instead SQL (So cant run customized query for compliance report)

How to find WSUS server in unknown environment?

$
0
0

I've got what I consider to be an odd task facing me.  In an server environment where I have no knowledge of the infrastructure, I need to find out where the WSUS server is, and how it's configured.  I can't ask questions of those who are in charge of the environment and I need to identify the WSUS environment ASAP.  I've tried running GPresult and I'm getting access denied for most of the GPResult data even though I'm a domain admin in the environment.

I need to find where the console is installed and whether I have access to it. 

 

Windows update shows WSUS Servers value as

$
0
0

I have a WSUS Windows 2008 client that has a GPO that pushes a WUServer and WUStatusServer ip address, the correct settings are visible in Windows registry, the correct settings come up if you do "req query "HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate"", but in WindowsUpdate.log, it still shows the following:

Agent     * WSUS Server: <NULL>

Agent     * WSUS status server: <NULL>

and fails with exit codes 0x800401FD and 0x80240007. In the Windows update GUI, it displays a 8024402C error code

The WSUS server is running on Windows 2012 R2.

What could be causing this?

Paul


Edit - I would like to add that this 2008 server can ping the WSUS no problem, and can access the http://<ip-address>:8530/selfupdate URL no problem

Windows 10 computers incorrectly reported as Windows Vista on WSUS 3.2 SP2

$
0
0

The public, released versions of Windows 10 are being incorrectly reported on Windows Software Update Services (WSUS) 3.2 as "Windows Vista" not "Windows 10" as expected. The version of WSUS 3.2 SP2 I am using is build 3.2.7600.226

I understand this is a currently a known issue, with no released patch to resolve this as of today's date - 22nd August 2015.

Windows 10 clients should still recieve the correct updates from WSUS 3.2, however I am not able to correctly identify which clients are in fact Windows Vista and which are Windows 10 using WSUS.

There is a hack to manually modify the WSUS SQL database to update this, however directly editing the SQL databases is definitely not supported by Microsoft and could lead to significant problems if done incorrectly.
(details here - http://titlerequired.com/2015/07/22/windows-10-on-wsus-shows-as-windows-vista/ )

A similar issue is also occurring on WSUS Server 2012 R2, details here, also with no released patch at this time.
(details here - https://social.technet.microsoft.com/Forums/en-US/03ef4407-a055-49c0-a864-0b805963bb89/windows-10-computers-showing-on-wsus-server-2012-r2-as-windows-vista?forum=winserverwsus )

This issue has previously occurred with the release of Windows 8.1 being reported by WSUS as "Windows 6.3". Microsoft released a patch for WSUS 3.2 to fix this issue (KB2938066) on 8th July 2014, nearly 9 months after the release of Windows 8.1.
(details here - https://social.technet.microsoft.com/Forums/en-US/7d76e71c-af8b-433f-bb96-e7dd020a0978/why-windows-81-in-wsus-327600262-lastest-report-wrong-version-os-63?forum=winserverwsus&prof=required )
(KB Link here: https://support.microsoft.com/en-gb/kb/2938066 )

This time around the problem is greater as the clients are incorrectly reporting as a different version of Windows, not the correct Windows version number, so it is not just a 'cosmetic' issue. It's difficult to manage problem clients if they being put into incorrect groups due to reporting the incorrect version.

More importantly, will we have to wait a further 9 months from the release of Windows 10 for Microsoft to release a patch this time around.. On what date will a patch be released?

I hope this is helpful for anyone experiencing this issue.


Windows is not updating correctly

$
0
0

Recently, windows has been getting an error when updating. The errors are the following:

There were problems installing some updates, but we'll try again later. If you keep seeing this and want to search the web or contact support for information, this may help:

Cumulative Update for Windows 10 for x64-based Systems (KB3081444) - Error 0x80004005

Update for Windows 10 for x64-based Systems (KB3081441) - Error 0x8007000d

I've made attempts to retry the downloads, but they keep spitting out the same errors. Please advise on how to update the computer correctly or where I can go to download the latest windows 10 updates.

Background Intelligent Transfer Service (BITS) fails to start with error 2147942402 (0x80070002)

$
0
0

I am on a Windows 2003 R2 Standard SP2 (32-bit). BITS refuses to start. System Event log has error 7024 "The Background Intelligent Transfer Service service terminated with service-specific error 2147942402 (0x80070002)". I have tried ALL suggestions found online (the are summarized in this article: http://www.itexperience.net/2009/03/01/fix-the-background-intelligent-transfer-service-service-terminated-with-service-specific-error-2147942402-0x80070002/). No luck so I am basically stuck. Any other ideas? Thanks!

How to REMOVE WSUS CLIENT settings

$
0
0
I have a windows server 2008 that was configured to look to a wsus server that is no longer available. I would like to remove this configuration and set it back to look at microsoft update. I don't see how this can be done. Is it even possible?

Very unexpected server restart after automatic updated

$
0
0

We have a Windows 2012 RS server running Hyper-V that last week at 02:07am decided to install lots of Windows Updates then restart! As a result the non-highly available Virtual Machines went offline so not a great situation to be in when your hosting 24x7 services.

Looking in the WindowsUpdate.Log I can see lots of activity at the time.

2015-08-19      02:01:54:030       1612       1688       Agent      * WSUS status server: http://mercury:8530

2015-08-19      02:01:54:030       1612       1688       Agent      * Target group: (Unassigned Computers)

   2015-08-19          02:01:54:030       1612       1688       Agent     * Windows Update access disabled: No

2015-08-19      02:01:54:061       1612       1688       AU          ###########  AU: Initializing Automatic Updates  ###########

2015-08-19      02:01:54:061       1612       1688       AU          AIR Mode is disabled

2015-08-19      02:01:54:061       1612       1688       AU           # Policy Driven Provider: http://mercury:8530

2015-08-19      02:01:54:061       1612       1688       AU           # Detection frequency: 22

2015-08-19      02:01:54:061       1612       1688       AU           # Approval type: Scheduled (User preference)

2015-08-19      02:01:54:061       1612       1688       AU           # Auto-install minor updates: No (Policy)

   2015-08-19          02:01:54:061       1612       1688       AU           # Auto update required (cannot be disabled)

 

2015-08-19      02:01:54:280       1612       d0c         AU          Update {9B29D104-997F-475E-99B1-854C30CB4E88}.201 was auto-approved for forced install

 

Lots of progress then …

2015-08-19   02:05:30:547       1612       d78         Agent    **  END  **  Agent: Installing updates [CallerId = AutomaticUpdates]

2015-08-19   02:05:30:547       1612       c90         AU           # WARNING: Install call completed, reboot required = Yes, error = 0x00000000

2015-08-19   02:05:30:547       1612       d78         Agent    *************

2015-08-19   02:05:30:547       1612       c90         AU          #########

2015-08-19   02:05:30:547       1612       c90         AU          ##  END  ##  AU: Installing updates [CallId = {D49E3A19-EAF6-4FCD-A2D1-0CAC957AC5E6}]

2015-08-19   02:05:30:547       1612       c90         AU          #############

2015-08-19      02:05:30:547       1612       1688       AU          Install complete for all calls, reboot  needed

 

2015-08-19   02:15:30:559       1612       1688       AU          Client has determined it is safe to reboot without warning. Rebooting now...

2015-08-19   02:15:30:559       1612       1688       AU          AU invoking RebootSystem (OnRebootNow)

2015-08-19      02:15:30:559       1612       1688       AU          Allowing auto firmware installs at next shutdown

 

We control WSUS behaviour via Group Policy so I was surprised why this particular server restarted, It’s in the same OU as other servers that did not restart!

Running Group Policy Modelling I can see that the standard (expected) group policies are in place. In addition on the server that restarted I can see no Group Policy event failures so as far as I’m aware the group policy had been applied, in addition there’s no local security polices applied that would have taken precedence over AD GP’s

The AD functional level is Windows 2008 R2 but we have the relevant ADMX files in place for 2012 R2 Group Policy.

Currently we are set to Automatic Update Option 5 0 “Allow the Local administrator to choose” and “No auto-restart with logged on users for scheduled automatic updates installations”

I’ve been reading lots about the new Windows 2012 “Automatic Maintenance” this is set on all servers to run daily at 2am, although the time is close to my event I would expect the remainder of my server estate to have also started updating and rebooting if this was the process that caused the event. 

I’ve spent some time trying to establish the root cause so I can ensure it doesn’t happen again, so far I can see the cause but no means to prevent future occurrences and I’m concerned it could affect further servers.

Any advice welcomed.... Thanks

 

High CPU usage when Windows update service is running

$
0
0

Hi there, 

I have problem here with more than 10 servers . I can not update them as soon as I enable Windows update service the cpu usage goes to 100%. 

It has been more than a month I could n`t touch these servers becasue of high CPU usage ... 

They are all Windows data center servers 2008 R2 SP1

I sow there are hot-fixes for windows server 2003 and xp in the past. I could n`t find any hot fix for his issue on 2008 servers. 

Thanks, 

Viewing all 12874 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>