How to repair unhealthy Endpoint Manager SUP role? Clients unable to receive updates

Charlie Dobson 1 Reputation point
2020-10-22T02:09:13.963+00:00

I'm managing an Endpoint Manager Current Branch (2002) environment. I had everything setup so that clients could get updates while on the internal network/VPN. With COVID and work-from-home, my company asked me to setup an external SUP so that users don't have to connect to VPN to get updates.

I setup an external server on our DMZ and confirmed clients could communicate with it over SSL / WSUS port 8531. However, when I added the WSUS feature to the server, I failed to point the update content location to the shared path on the primary SUP server. This ran for a little while until I noticed clients complaining about SOAP issues and getting 0x80244010, 0x80244007, & 0x8023300d (on different endpoints) errors.

After noting my mistake on the external server, I ran WSUSUTIL.EXE movecontent \\primarysup\wsus -skipcopy and the output said it was successful. I've verified my SQL Server 2012 database is showing the correct path by running Select LocalContentCacheLocation from tbConfigurationB. However, my clients are still reporting the above errors and are basically pounding my primary SCCM server with requests causing high CPU usage.

Is there a step I'm missing to fix the endpoints? Or did I hose my database and need to uninstall and re-install SUP roles on all servers?

Microsoft Configuration Manager Updates
Microsoft Configuration Manager Updates
Microsoft Configuration Manager: An integrated solution for for managing large groups of personal computers and servers.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
1,005 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Amandayou-MSFT 11,051 Reputation points
    2020-10-23T06:58:46.923+00:00

    Hi @Charlie Dobson ,

    -->However, when I added the WSUS feature to the server, I failed to point the update content location to the shared path on the primary SUP server.

    It seems that we could install the secondary SUP on the SCCM console instead of adding the WSUS feature to the server.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.