Problems with WSUS 2016 and Windows Update Agent

R

Redwizard001

We have a WSUS server running on Windows Server 2016. WSUS detects and sends updates to all systems, including the 2012 servers. WSUS will detect but not send updates to any of the 2016 servers.

It shows 0 updates needed, all updates show "installed or not applicable". These are fresh server installs, they have just been installed straight from a disk image created November of last year.

If I run a report on one of the servers and I set the product filter to "Windows Server 2016" I get 31 updates installed or not applicable.

All 31 updates are set to approval "Install". The status for all of them is "Not Applicable" They are all Critical updates and Security Updates.

I have manually gone through the installed updates on one of the servers in question and verified that these "Not Applicable" updates are not installed.

All these servers are fresh installs and they are in an OU that prevents them from restarting themselves after an update install and I am the only one who manually restarts them. Since they have been installed they have gotten 0 updates. I have a hard time believing that there are 0 applicable updates for a fresh Windows Server 2016 install.

I have ensured that BITS and the Windows Update services are running. I have run the wuauclt /reportnow and wuauclt /detectnow. It doesn't seem to do anything. I have run the cleanup wizard to deny and remove all of the superseded updates. I have verified that the machines are in the correct groups in AD and in WSUS. I have verified in the registry on the affected machines that they are pointing to the WSUS server and it can be pinged. The client can be pinged from the WSUS server. There is no firewall or port blocker or anything like that. I created a completely new 2016 server installation with absolutely nothing installed on it; no roles, no firewalls no virus scanner no nothing, just a blank server and tried to force it to connect. WSUS detects that the server exists but that is about it.

Every other OS works fine, it is only the 2016 servers that have this problem. It is definitely a WSUS server problem; if I go into the registry and change it back to Microsofts server it finds updates.

Does anyone have any idea what might be causing the problem and how to fix it?

One proposed solution was to update the Windows Update Agent. We are on version 10.0.14393.0, this is apparently the RTM version. I have not been able to update this. The updates are supposedly part of the server roll up patches which we are installing on the WSUS server, but the Windows Update Agent isn't getting updated.

We are adding more and more 2016 servers and not being able to use WSUS is causing problems for us.

Thanks

Continue reading...
 
Back
Top Bottom