Windows update via SCCM (SUP)

Posted on 2011-04-20
Last Modified: 2013-11-21
I have created a brand new wsus server but have not run the configuration wizard because I want sccm to manage the windows updates.

How do I go about configuring SCCM for windows updates?

At the moment I just want to be able to see how up to date the machines are while my old wsus server continues to apply windows updates through a gpo.

If I look at the update services role on the new wsus server only 13 machines are reporting back.  How do I check the updates status on the new wsus server or within scm?
Question by:WNottsC
    LVL 31

    Expert Comment

    As soon as you install a Software Update Point on top of the WSUS Server you have to deploy Updates with SCCM.
    So i there's no possibility to get the Patch State in SCCM while deploying with native WSUS.
    Also as soon as you deploy Updates with SCCM its important that no WSUS Policy is applying.

    Author Comment

    Ok just so I understand it.

    Currently we have a WSUS server wsus1 which synchronises with Microsoft and is pushing out windows updates with all settings set in a GPO.

    I have now created a new WSUS server wsusnew which also synchronises with Microsoft.

    I have SCCM on a seperate server but have installed the SUP role on the remote wsus server wsusnew.

    1. There is now way of seeing the update statuses within the new WSUS server or SCCM while the old WSUS server and GPO are active?

    2. How do I go about switching from native WSUS to using SCCM?

    LVL 31

    Expert Comment

    1. Yes exaclty. You have to enable the SCCM Updates Agent to get the update compliance information. As soon as there's a WSUS Group Policy, the local SCCM Policy will be overwritten. The client just can report to one environment
    2. You build a update deployment structure in SCCM, disable the WSUS Policy and enable the SCCM Updates Agent in your SCCM environment

    Author Comment

    Thanks for these points but I am having trouble configuring the SUP

    Background of the SCCM setup-

    I have a Primary site server with most roles on but not the Software update point.  I have a remote WSUS server which has the SUP role on.  WSUS Seems to be working fine and is synchronising with SCCM with no errors.

    1.  I then installed a secondary site server which has the DP Role, PMP Role and SUP Role.

    If I look at the Compnent Configuration on the PrimarySite Server, the SUP component settings are

    General - Active Software update point on remote server
                     Active server name:  is remote WSUS server
    Sync Settings - is synchronize from Microsoft Update
    other tabs are fairly standard

    If I look at the SUP Component settings on the secondary server I only get two tabs General and Sync settings.

    On the General tab it is set to none
    On the sync settings tab  the first option is greyed out but set as "Synchronize from an upstream update server"

    I thought everything was ok but I am getting SMS_WSUS_CONTROL_MANAGER errors
    message ID  4968
    SMS Site Component manager failed to install this componnet, because it either can't find or configure WSUS

    It is suggested in what I have read that this is because it can not find   "an active software update point on site server"

    Does anyone have any idea about this
    LVL 31

    Accepted Solution

    you need the WSUS Admin console on the Site Server

    Featured Post

    Integrate social media with email signatures

    Is your company active on social media? Do you also use email signatures? Including social media icons in your email signature is a great way to get fans for free. Let all your email users know you’re on social media quickly and easily, in a single click.

    Join & Write a Comment

    Case Summary: In this Article we introduce the new method to configure the default user profile using Automated profile copy with sysprep rather than the old ways such as the manual copy of a configured profile to default user profile Old meth…
    Problem Description: Actually I found the below issue with some customers after migration from SMS 2003 to SCCM 2007 and epically if they change site code, some clients may appear in the console with old site code, plus old sites still appearing …
    Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
    This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

    728 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now