Dear Community Members,
I'm hoping someone can steer me in the right direction with a problem I have with MS Endpoint Protection Definitions (KB2461484) not being installed when presented through WSUS.
The deployment has been working fine for several months and stopped on 9th July for all workstations. Other updates seem to be unaffected as many have been installed after this date.
The WSUS server is running on Windows 2012 R2 and the clients receiving the MS Endpoint Protection Definitions are Windows 7 machines. There is a GPO in place which configures the Endpoint client to check for definition updates every 2hrs. The WSUS server
has been configured with an automatic approval policy to approve all ‘Definition Updates’ for ‘System Centre Endpoint Protection’ which is working fine since the update is set to ‘Install’ for all computers.
The updates can be seen downloaded on WSUS and initially the status remains as ‘No Status’ but once the clients begin detecting the status changes to ‘Installed/Not Applicable’. The update is definitely not installed as the client shows an old definition
and nothing is shown in the Windows Update history.
Communication is fine between the clients and WSUS server and the excerpt below shows the Windows Update log from the client machine. I have deleted the SoftwareDistribution folder and ran wuauclt /resetauthorization, wuauclt /reportnow, wuauclt /detectnow
all to no avail. I have also run the WSUS Server Cleanup Wizard and re-indexed the WSUS DB all to no avail.
Can anyone suggest anything to resolve this issue?
================
Windows Update Log
================
2019-07-25
12:28:30:779 1572 69c COMAPI -------------
2019-07-25
12:28:30:779 1572 69c COMAPI -- START -- COMAPI: Search [ClientId = Microsoft Forefront Endpoint Protection (1F383481-F70E-4E7A-8B69-C4B4A23928E3)]
2019-07-25
12:28:30:779 1572 69c COMAPI ---------
2019-07-25
12:28:30:779 1572 69c COMAPI <<-- SUBMITTED -- COMAPI: Search [ClientId = Microsoft Forefront Endpoint Protection (1F383481-F70E-4E7A-8B69-C4B4A23928E3)]
2019-07-25
12:28:30:779 1004 758 Agent *************
2019-07-25
12:28:30:779 1004 758 Agent ** START ** Agent: Finding updates [CallerId = Microsoft Forefront Endpoint Protection (1F383481-F70E-4E7A-8B69-C4B4A23928E3)]
2019-07-25
12:28:30:779 1004 758 Agent *********
2019-07-25
12:28:30:779 1004 758 Agent * Online = Yes; Ignore download priority = No
2019-07-25
12:28:30:779 1004 758 Agent * Criteria = "(IsInstalled = 0 and IsHidden = 0 and CategoryIDs contains 'a38c835c-2950-4e87-86cc-6911a52c34a3' and CategoryIDs contains 'e0789628-ce08-4437-be74-2495b842f43b')"
2019-07-25
12:28:30:779 1004 758 Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
2019-07-25
12:28:30:779 1004 758 Agent * Search Scope = {Machine}
2019-07-25
12:28:30:935 1004 758 PT +++++++++++
PT: Starting category scan +++++++++++
2019-07-25
12:28:30:935 1004 758 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://WSUS:8530/ClientWebService/client.asmx
2019-07-25
12:28:31:326 1004 758 PT +++++++++++
PT: Synchronizing server updates +++++++++++
2019-07-25
12:28:31:326 1004 758 PT + ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}, Server URL = http://WSUS:8530/ClientWebService/client.asmx
2019-07-25
12:28:31:419 1004 758 Agent * Found 0 updates and 4 categories in search; evaluated appl. rules of 11 out of 13 deployed entities
2019-07-25
12:28:31:950 1004 758 Agent *********
2019-07-25
12:28:31:950 1004 758 Agent ** END ** Agent: Finding updates [CallerId = Microsoft Forefront Endpoint Protection (1F383481-F70E-4E7A-8B69-C4B4A23928E3)]
2019-07-25
12:28:31:950 1004 758 Agent *************
2019-07-25
12:28:31:950 1572 e18 COMAPI >>-- RESUMED -- COMAPI: Search [ClientId = Microsoft Forefront Endpoint Protection (1F383481-F70E-4E7A-8B69-C4B4A23928E3)]
2019-07-25
12:28:31:950 1572 e18 COMAPI - Updates found = 0
2019-07-25
12:28:31:950 1572 e18 COMAPI ---------
2019-07-25
12:28:31:950 1572 e18 COMAPI -- END -- COMAPI: Search [ClientId = Microsoft Forefront Endpoint Protection (1F383481-F70E-4E7A-8B69-C4B4A23928E3)]
2019-07-25
12:28:31:950 1572 e18 COMAPI -------------
2019-07-25
12:28:36:960 1004 758 Report REPORT EVENT: {77AC4476-2CD7-4602-9721-E5875C73FAC7} 2019-07-25 12:28:31:950+0100 1 147 101 {00000000-0000-0000-0000-000000000000} 0 0 Microsoft Forefront Endpoint PrSuccessSoftware Synchronization Windows Update Client successfully detected 0 updates.