Hi,
1. Open dsa.msc on server to check whether problematic clients were added in "SCE Managed Computers" group
2. Run rsop.msc on clients to check whether the GPOs: SCE Managed Computers Group Policy& System Center Essentials All Computers Policy had been applied correctly on clients.
Check that the client is configured to use the SCE server for Windows Updates. The following registry entries should be set to https://<SCEServerFQDN>:8531
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windows\WindowsUpdate\WUServer
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windows\WindowsUpdate\WUStatusServer
3. Check whether the required ports for communication between clients and server had been opened, or disable the firewall as a test.
4. Is there a proxy server in your scenario? If not, please ensure there is no proxy setting in IE and run proxycfg -d (netsh winhttp reset proxy in vista)command on problematic SCE clients.
5. Run wuauclt /detectnow and reportnow on the SCE agents and also check %windir%\windowsupdate.log on client to see if any error prompt.
HTH.
Jie-Feng Ren - MSFT