Windows Computers in SBS2011 Domain are not updating

We have a mix of Windows XP and Windows 7 computers in a SBS2011 domain.
WSUS is not used or configured. Each computer was setup to auto download and install updates. About 2 months ago, this process stopped.

On the Windows 7 Systems, the control Windows/Windows Update section reports that updates are "Managed by your system Administrator"

I tried to run the update manually on one of the Windows 7 PC's  and got Error code 80072ee2.

On one of the Windows XP systems, I checked in the System Properties/Automatic Updates tab and I that the following selection is made and greyed out so it cannot be changed: Notify me but don't automatically download and install them.

Do I have need to change something in a Group Policy?
Who is Participating?
Cris HannaConnect With a Mentor Commented:
Here is the official Repair Guide for WSUS on SBS from Microsoft
Repair Windows Server Update Services
Run gpresult /v > C:\gpresult.txt

on each OS and look through that file for the WSUS setting to find out what policy you need to fix.
Cris HannaCommented:
You'll have to Edit Group Policy on the SBS Server
Specifically the Update Services Client Computer Policy and the Update Services Common Settings Policy

Why aren't you using WSUS?
Train for your Pen Testing Engineer Certification

Enroll today in this bundle of courses to gain experience in the logistics of pen testing, Linux fundamentals, vulnerability assessments, detecting live systems, and more! This series, valued at $3,000, is free for Premium members, Team Accounts, and Qualified Experts.

go to the sbs server and edit the group policy
itplatoonAuthor Commented:
Another system admin might have made use of WSUS, not sure at this point.

I do see an error on the SBS console>Home> Updates  tab that shows " Update services cannot be contacted"

I checked and do see the Update Services service is online and running
Cris HannaCommented:
So is your goal to get WSUS working properly. Or do you want to disable the group policy objects that force workstations to only update through WSUS?
itplatoonAuthor Commented:
If there is no downside to using WSUS, it might make sense to fix and use it. At this point, nothing is getting updated. So what are next steps to fix WSUS?
Sushil SonawaneCommented:
You have to remove configure setting related wsus in group policy. Disable the WSUS configure group policy and run the command gpupdate /force or restart the computer and check if you can do windows update manually.

To disable setting is below :

In Group Policy Object Editor, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then click Windows Update.
In the details pane, click Specify Intranet Microsoft update service location.
Click Enabled and type the HTTP(S) URL of the same WSUS server in the Set the intranet update service for detecting updates box and in the Set the intranet statistics server box. For example, type http(s)://servername in both boxes.
Click OK.

For more info refer below link :
itplatoonAuthor Commented:
I use the repair process steps noted at this link: 

I found the following services not running:
WWW Published
Windows Process Activation and showing "Error: 13 The data is invalid

This led me to:

The culprit was: c:\windows\system32\inetsrv\config\applicationHost.config
I used the backup of the applicationHost.config file in c:\inetpub\history.
copied the file over and now all of the service work as expected.
WSUS seems to be working now as well too.
Cris HannaCommented:
Glad you were able to track this down.  is there anyone besides you that would make changes to IIS that could cause that file to change?
itplatoonAuthor Commented:
Thanks for the expert advice!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.