Solved

WSUS clients not reporting after being deleted

Posted on 2014-04-12
8
593 Views
Last Modified: 2016-02-21
Hi all, i have had several hundred machines not report into the WSUS console for a number of months so i have ran the database cleanup and it removed the machines. Unfortunately i cant seem to get them back. I have tried running the following script but they still dont appear. Any ideas?

thanks

%Windir%\system32\gpupdate

%Windir%\system32\net.exe stop bits
%Windir%\system32\net.exe stop wuauserv
%Windir%\system32\net.exe stop cryptsvc
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate /v SusClientId /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v LastWaitTimeout /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v DetectionStartTime /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v NextDetectionTime /f
del %WINDIR%\WindowsUpdate.log /S /Q
rd /s /q %windir%\softwareDistribution
%Windir%\system32\net.exe start cryptsvc
%Windir%\system32\net.exe start bits
%Windir%\system32\net.exe start wuauserv


sc sdset wuauserv D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)


sc sdset bits D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;AU)(A;;CCLCSWRPWPDTLOCRRC;;;PU)

wuauclt /resetauthorization /detectnow
wuauclt /reportnow
0
Comment
Question by:cwstad2
  • 4
  • 3
8 Comments
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39995886
Hi,

Run the RSOP.msc and see if group policy is applied.

also share the windowsupdate.log file under c:\windows from any effected system/client.
0
 
LVL 15

Author Comment

by:cwstad2
ID: 39995966
Hi Santosh, these are in the unassigned computers with no GP applied
0
 
LVL 15

Author Comment

by:cwstad2
ID: 39995999
Hi Santosh, i think i have found the issue the log files shows a different WSUS server. Also when i run the above script and check the windowsupdate.log it shows WSUS SERVER as null. How can i change this so that it points to the new sever. Someone else had set this up before i inherited it. I have about 700 clients and servers that have this issue. Also the script says unable to find the specified registry key value

reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v LastWaitTimeout /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v DetectionStartTime /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update" /v NextDetectionTime /f

thanks
0
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39996056
As you said " you have hundreds of machines", so i would like to suggest you to do it through Group Policy.

Move these machines to any/new OU and apply the GPO.

http://knowledge.quickstart.com/configure-wsus-to-deploy-updates-using-group-policy/

http://www.grouppolicy.biz/2011/06/best-practices-group-policy-for-wsus/
0
Can’t get the mobile email signature right?

Not having any luck when trying to create an email signature for mobile devices? Does the formatting keep messing up? Make sure you have great email signatures on all devices by using Exclaimer Cloud - Signatures for Office 365.

 
LVL 15

Author Comment

by:cwstad2
ID: 39996174
Hi Santosh, GPO is enabled on the root of the client and server OU's but some of the GPO's are blocked. I moved one server and that appeared in the WSUS console. I will investigate the clients as these should not be blocked. Thanks. Its been set up in quite a complicated way with different Tiers from 1 to 4
0
 
LVL 15

Author Comment

by:cwstad2
ID: 39996384
Hi Santosh, is does WSUS look for clients in the AD or does it scan the network? The GPO for clients seems to be OK.
0
 
LVL 13

Accepted Solution

by:
Santosh Gupta earned 500 total points
ID: 39996610
Hi,

Once gpo will appied client will report to wsus.
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 39996892
WSUS knows nothing about active directory.. you use group policy and client side targetting to put the computers in the different groups.  it is a pull vice a push operation
0

Featured Post

Being driven mad by email signature updates?

Having to make a change to your users’ email signatures, yet again? Feel like your head is going to explode? Rely on an Exclaimer email signature management solution to make the process simple!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

26 Experts available now in Live!

Get 1:1 Help Now