SCCM Https Only site ver 2006.
100 Distribution Points.
Windows 10 Build multiple builds.
When performing Task Sequence In-Place Upgrade, multiple clients stays very long by attempting talk to DP via http and naturally gets IIS 403. Cliet certificate is valid and I checked that correct cert is selected by CM client to talk to the SCCM site (by thumbprint).
Still it is mistery, why client tries to talk http to the DP.