Solved

WSUS clients not reporting after being deleted

Posted on 2014-04-12
8
614 Views
Last Modified: 2016-02-21
Hi all, i have had several hundred machines not report into the WSUS console for a number of months so i have ran the database cleanup and it removed the machines. Unfortunately i cant seem to get them back. I have tried running the following script but they still dont appear. Any ideas?

thanks

%Windir%\system32\gpupdate

%Windir%\system32\net.exe stop bits
%Windir%\system32\net.exe stop wuauserv
%Windir%\system32\net.exe stop cryptsvc
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v LastWaitTimeout /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v DetectionStartTime /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v NextDetectionTime /f
del %WINDIR%\WindowsUpdate.log /S /Q
rd /s /q %windir%\softwareDistribution
%Windir%\system32\net.exe start cryptsvc
%Windir%\system32\net.exe start bits
%Windir%\system32\net.exe start wuauserv


sc sdset wuauserv D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)


sc sdset bits D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)

wuauclt /resetauthorization /detectnow
wuauclt /reportnow
0
Comment
Question by:cwstad2
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39995886
Hi,

Run the RSOP.msc and see if group policy is applied.

also share the windowsupdate.log file under c:\windows from any effected system/client.
0
 
LVL 15

Author Comment

by:cwstad2
ID: 39995966
Hi Santosh, these are in the unassigned computers with no GP applied
0
 
LVL 15

Author Comment

by:cwstad2
ID: 39995999
Hi Santosh, i think i have found the issue the log files shows a different WSUS server. Also when i run the above script and check the windowsupdate.log it shows WSUS SERVER as null. How can i change this so that it points to the new sever. Someone else had set this up before i inherited it. I have about 700 clients and servers that have this issue. Also the script says unable to find the specified registry key value

reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v LastWaitTimeout /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v DetectionStartTime /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v NextDetectionTime /f

thanks
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39996056
As you said " you have hundreds of machines", so i would like to suggest you to do it through Group Policy.

Move these machines to any/new OU and apply the GPO.

http://knowledge.quickstart.com/configure-wsus-to-deploy-updates-using-group-policy/

http://www.grouppolicy.biz/2011/06/best-practices-group-policy-for-wsus/
0
 
LVL 15

Author Comment

by:cwstad2
ID: 39996174
Hi Santosh, GPO is enabled on the root of the client and server OU's but some of the GPO's are blocked. I moved one server and that appeared in the WSUS console. I will investigate the clients as these should not be blocked. Thanks. Its been set up in quite a complicated way with different Tiers from 1 to 4
0
 
LVL 15

Author Comment

by:cwstad2
ID: 39996384
Hi Santosh, is does WSUS look for clients in the AD or does it scan the network? The GPO for clients seems to be OK.
0
 
LVL 13

Accepted Solution

by:
Santosh Gupta earned 500 total points
ID: 39996610
Hi,

Once gpo will appied client will report to wsus.
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 39996892
WSUS knows nothing about active directory.. you use group policy and client side targetting to put the computers in the different groups.  it is a pull vice a push operation
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SpaceMonger Issue 4 34
GPO reset 2 45
Microsoft Qualifications 5 46
Configuring DNS Round Robin in Windows DNS server ? 8 75
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question