SCCM, CMG, and WIndows Updates

Matt Dillon 1,216 Reputation points
2021-05-13T17:55:27.917+00:00

Need some direction on a situation I am troubleshooting. Users click on Check for Updates in the Windows 10 Settings and it takes at least 10 minutes to complete. SCCM is setup for Windows Updates and as far as I can tell, everything is set up correctly. The updates are being distributed to a CMG (not sure why this is setup this way as the updates get installed from Microsoft) and the client is on a VPN that points to the CMG. None of the SCCM logs really tell me anything and the CBS.log was a dead end as well.

Thoughts?

Microsoft Configuration Manager Updates
Microsoft Configuration Manager Updates
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
1,061 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Matt Dillon 1,216 Reputation points
    2021-05-18T15:02:20.49+00:00

    This issue is making me question everything I know.

    So the setup is just this. They have a boundary group for the VPN clients that points to the CMG. I had them remove all the distributed items from the CMG as they are not necessary. I also discovered that the engineer I am working with is not actually making a deployment package in the ADR, but instead selecting "No deployment package. Clients download content from peers or the Microsoft cloud." He told me yesterday he would like all Windows Updates to come from Microsoft for all endpoints whether or not they were in an office and had an assigned DP or using the CMG. They have F5 VPN setup and would like the Check for Updates to run during log in. This is where the issue is. When I select Check for Updates - it spins forever or errors out altogether. When I have setup Windows Updates in the past, I have always setup a deployment package and distributed to the DP's - not the CMG. The endpoints that are in the office grab the updates from the DP and the endpoints not in the office have grabbed the windows updates from Microsoft as directed by the CMG.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.