This issue is making me question everything I know.
So the setup is just this. They have a boundary group for the VPN clients that points to the CMG. I had them remove all the distributed items from the CMG as they are not necessary. I also discovered that the engineer I am working with is not actually making a deployment package in the ADR, but instead selecting "No deployment package. Clients download content from peers or the Microsoft cloud." He told me yesterday he would like all Windows Updates to come from Microsoft for all endpoints whether or not they were in an office and had an assigned DP or using the CMG. They have F5 VPN setup and would like the Check for Updates to run during log in. This is where the issue is. When I select Check for Updates - it spins forever or errors out altogether. When I have setup Windows Updates in the past, I have always setup a deployment package and distributed to the DP's - not the CMG. The endpoints that are in the office grab the updates from the DP and the endpoints not in the office have grabbed the windows updates from Microsoft as directed by the CMG.