MECM Software Updates / WSUS Config Untrusted Domain

Johno 106 Reputation points
2020-09-07T06:56:45.583+00:00

Hi All,

I've now got my untrusted domain child site system configured and communicating with the primary site server, clients are registering and applications can be deployed, but I've hit a snag with Software Updates. I've followed the below blog post, but the clients are trying to use WSUS on the primary site server.

https://www.systemcenterdudes.com/installing-sccm-dp-mp-sup-untrusted-domain

The WUAHandler logs and the Registry keys on the client, HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, point to the primary site server rather than the child WSUS site system.

Do I need to override these settings with a group policy or should the client detect the site its in and that the WSUS is installed and configured then set them to the appropriate site system?

Cheers,

Johno

Not Monitored
Not Monitored
Tag not monitored by Microsoft.
35,811 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Eswar Koneti 2,196 Reputation points
    2020-09-07T08:07:01.28+00:00

    Check your boundaries and boundary groups configuration for the selection of the SUP?

    0 comments No comments

  2. Jason Sandys 31,151 Reputation points Microsoft Employee
    2020-09-08T00:24:20.4+00:00

    but the clients are trying to use WSUS on the primary site server.

    Why is this an issue? Are you actually accounting for network restrictions (which have nothing to do with AD or AD trusts)?

    Do I need to override these settings with a group policy

    No, that won't work and the client will disable software updates.

    As Eswar notes, clients locate and use SUPs based on boundaries and boundary groups; however, once they get assigned to a SUP, they won't automatically change unless they fail to communicate with the assigned SUP three times. Also, in this case, failure does not include the typical failure/error cause by a firewall blocking traffic.


  3. Amandayou-MSFT 11,046 Reputation points
    2020-09-08T03:25:34.873+00:00

    Hi @Johno
    We could assign software update points which are in untrusted domain child site system to the boundary group so that clients can find and use them.

    23068-981.png


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.