locked
Make sure Updates are downloading from Internal WSUS server or Internet. RRS feed

  • Question

  • Hi All,

    Recently there are some updates installed on a client computer but when I login and checked on WSUS, WSUS server got crashed and  it seems IIS server is not functioning well. below is the error message on event viewer with event ID: 12042.

    "The SimpleAuth Web service is not working."

    Once I reset IIS, WSUS console is working back. However, Here I want to get to know my client PC is got installed updates from Internet or WSUS. I have confused here since all settings are in place properly interns of WSUS configurations. 

    Below is a few setting which I refereed,

    GPO Settings:

    WindowsUpdate.log1:

    2020/05/30 10:31:05.1244338 1252  2112  Shared          * END * Service exit Exit code = 0x240001
    2020/05/31 05:48:17.0040650 1252  1996  Agent           WU client version 10.0.14393.3564
    2020/05/31 05:48:17.0045053 1252  1996  Agent           SleepStudyTracker: Machine is non-AOAC. Sleep study tracker disabled.
    2020/05/31 05:48:17.0046047 1252  1996  Agent           Base directory: C:\Windows\SoftwareDistribution
    2020/05/31 05:48:17.0053034 1252  1996  Agent           Datastore directory: C:\Windows\SoftwareDistribution\DataStore\DataStore.edb
    2020/05/31 05:48:17.0462665 1252  1996  Shared          UpdateNetworkState Ipv6, cNetworkInterfaces = 0.
    2020/05/31 05:48:17.0463099 1252  1996  Shared          UpdateNetworkState Ipv4, cNetworkInterfaces = 1.
    2020/05/31 05:48:17.0471887 1252  1996  Shared          Network state: Connected
    2020/05/31 05:48:17.0521744 1252  1996  Misc            LoadHistoryEventFromRegistry completed, hr = 8024000C
    2020/05/31 05:48:17.0579432 1252  1996  Shared          UpdateNetworkState Ipv6, cNetworkInterfaces = 0.
    2020/05/31 05:48:17.0579528 1252  1996  Shared          UpdateNetworkState Ipv4, cNetworkInterfaces = 1.
    2020/05/31 05:48:17.0579624 1252  1996  Shared          Power status changed
    2020/05/31 05:48:17.0594057 1252  1996  Agent               Timer: 29A863E7-8609-4D1E-B7CD-5668F857F1DB, Expires 2020-05-30 23:55:54, not idle-only, not network-only
    2020/05/31 05:48:17.0646937 1252  208   Agent           Initializing global settings cache
    2020/05/31 05:48:17.0646949 1252  208   Agent           WSUS server: http://***WSUS01:8530
    2020/05/31 05:48:17.0646961 1252  208   Agent           WSUS status server: http://***WSUS01:8530
    2020/05/31 05:48:17.0646967 1252  208   Agent           Alternate Download Server: NULL
    2020/05/31 05:48:17.0646973 1252  208   Agent           Fill Empty Content Urls: No
    2020/05/31 05:48:17.0646980 1252  208   Agent           Target group: Servers
    2020/05/31 05:48:17.0646986 1252  208   Agent           Windows Update access disabled: No
    2020/05/31 05:48:17.0676483 1252  1996  Agent           Initializing Windows Update Agent
    2020/05/31 05:48:17.0677766 1252  1996  DownloadManager Download manager restoring 0 downloads
    2020/05/31 05:48:17.0678760 1252  1996  Agent           CPersistentTimeoutScheduler | GetTimer, returned hr = 0x00000000
    2020/05/31 05:48:17.0948976 1252  4680  DownloadManager PurgeExpiredFiles::Found 1 expired files to delete.
    2020/05/31 05:48:17.0949048 1252  4680  DownloadManager PurgeExpiredFiles::Deleting expired file at C:\Windows\SoftwareDistribution\Download\8be86a04c19878b4eae28e71a2ec8cc3a33cffa0.
    2020/05/31 05:48:17.1126803 2288  1408  ComApi          * START *   Init Search ClientId = Windows Defender
    2020/05/31 05:48:17.1126959 2288  1408  ComApi          * START *   Search ClientId = Windows Defender

    WindowsUpdate.log2:

    2020/05/31 05:48:29.3177361 1252  4680  Agent               Bundles 1 updates:
    2020/05/31 05:48:29.3177415 1252  4680  Agent                 1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F.200
    2020/05/31 05:48:29.3177939 1252  4680  DownloadManager No locked revisions found for update 97B6A577-D90D-4A5F-9772-D236364C64D2; locking the user-specified revision.
    2020/05/31 05:48:29.3183137 1252  4680  DownloadManager No locked revisions found for update 1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F; locking the user-specified revision.
    2020/05/31 05:48:29.3188836 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category PerUpdate.
    2020/05/31 05:48:29.3188854 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category Low.
    2020/05/31 05:48:29.3188860 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category Normal.
    2020/05/31 05:48:29.3188872 1252  4680  DownloadManager Regulation: {7971F918-A847-4430-9279-4A52D1EFE18D} - Loaded sequence number 65535 for regulation category High.
    2020/05/31 05:48:29.3480291 1252  4680  DownloadManager Failed to connect to the DO service; (hr = 80040154)
    2020/05/31 05:48:29.3480303 1252  4680  DownloadManager GetDOManager() failed, hr=80246008, hrExtended=80040154
    2020/05/31 05:48:29.3480321 1252  4680  DownloadManager Failed creating DO job with hr 80246008
    2020/05/31 05:48:29.3533394 1252  4680  DownloadManager DO download failed with error 80246008[Extended: 80040154], falling back to BITS and retrying with new Download Job.
    2020/05/31 05:48:29.5259175 1252  4680  DownloadManager BITS job initialized: JobId = {318F9140-221B-46B4-BB21-4A82120C8C08}
    2020/05/31 05:48:29.5325609 1252  4680  DownloadManager Downloading from http://au.download.windowsupdate.com/d/msdownload/update/software/defu/2020/05/am_delta_patch_1.317.212.0_5043713139f26290dbee3ab1ea6cf22eba1cc280.exe to C:\Windows\SoftwareDistribution\Download\a9067bc45ff8dfbf288e566668ed8a0a\5043713139f26290dbee3ab1ea6cf22eba1cc280 (full file)
    2020/05/31 05:48:29.5348323 1252  4680  DownloadManager New download job {318F9140-221B-46B4-BB21-4A82120C8C08} for UpdateId 1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F.200
    2020/05/31 05:48:29.5466632 1252  4680  DownloadManager Download job 318F9140-221B-46B4-BB21-4A82120C8C08 resumed.
    2020/05/31 05:48:29.5869432 1252  4680  Shared          Effective power state: AC
    2020/05/31 05:48:29.5869480 1252  4680  Agent           Released network PDC reference for callId {13DB53CD-EA24-4527-9ABD-5790C2B526BC}; ActivationID: 32
    2020/05/31 05:48:29.5869558 1252  4680  Agent           Obtained a network PDC reference for callID {13DB53CD-EA24-4527-9ABD-5790C2B526BC} with No-Progress-Timeout set to 4294967295; ActivationID: 33.
    2020/05/31 05:48:29.5873883 1252  5044  Agent           WU client calls back to download call {13DB53CD-EA24-4527-9ABD-5790C2B526BC} with code Call progress and error 0
    2020/05/31 05:48:29.6302145 1252  4680  DownloadManager * END * Begin Downloading Updates CallerId = Windows Defender
    2020/05/31 05:48:29.6387559 1252  4680  DownloadManager Download job 318F9140-221B-46B4-BB21-4A82120C8C08 resumed.
    2020/05/31 05:48:47.7733007 1252  3156  DownloadManager BITS job {318F9140-221B-46B4-BB21-4A82120C8C08} completed successfully
    2020/05/31 05:48:47.7791917 1252  3156  DownloadManager CUpdateDownloadJob::GetNetworkCostSwitch() Unrestricted cost used, but current cost is restricted
    2020/05/31 05:48:47.7909756 1252  3156  Misc            Validating signature for C:\Windows\SoftwareDistribution\Download\a9067bc45ff8dfbf288e566668ed8a0a\5043713139f26290dbee3ab1ea6cf22eba1cc280 with dwProvFlags 0x00000080:
    2020/05/31 05:48:47.8186236 1252  3156  Misc             Microsoft signed: Yes
    2020/05/31 05:48:47.8202452 1252  3156  DownloadManager   Download job completion. Progress for update {1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F} - total = 1390008, transferred = 1390008 bytes. Transfer time=13128, connect time=5062 (ms)
    2020/05/31 05:48:47.8601301 1252  4680  SLS             Retrieving SLS response from server using ETAG f2dAyzSAXLAz7XI7tUppQAzeh4mYqtC/h1zNY+Fz0IU=_1440"..."
    2020/05/31 05:48:47.8604168 1252  4680  SLS             Making request with URL HTTPS://sls.update.microsoft.com/SLS/{9482F4B4-E343-43B6-B170-9A65BC822C77}/x64/10.0.14393.0/0?CH=272&L=en-US&P=&PT=0x7&WUA=10.0.14393.3564
    2020/05/31 05:48:48.9710885 1252  4680  Misc            StatusCode for transaction returned from WinHttpQueryHeaders is 304
    2020/05/31 05:48:49.0306649 1252  4680  DownloadManager All files for update {1B85A067-FD82-4EBC-9A2E-09DB7CED0E1F}.200 were already downloaded and are valid.
    2020/05/31 05:48:49.0318106 1252  4680  DownloadManager * END * Download Call Complete Call 2 for caller Windows Defender has completed; signaling completion.
    2020/05/31 05:48:49.0358205 1252  4680  Shared          Effective power state: AC
    2020/05/31 05:48:49.0358259 1252  4680  Agent           Released network PDC reference for callId {13DB53CD-EA24-4527-9ABD-5790C2B526BC}; ActivationID: 33
    2020/05/31 05:48:49.0361060 2288  1492  ComApi          *RESUMED* Download ClientId = Windows Defender
    2020/05/31 05:48:49.0361090 2288  1492  ComApi          Download call complete (succeeded = 1, succeeded with errors = 0, failed = 0, unaccounted = 0)
    2020/05/31 05:48:49.0361144 2288  1492  ComApi          * END *   Download ClientId = Windows Defender

    Thanks in advance,

    Dilan





    • Edited by Dilanmic Sunday, May 31, 2020 4:47 PM correc
    Sunday, May 31, 2020 4:36 PM

Answers

  • Hi Dilamic,

    Thanks for your posting.

    Open Powershell as an administrator and enter the following command to check the client's default update source:
    $MUSM = New-Object -ComObject "Microsoft.Update.ServiceManager"

    $MUSM.Services | select Name, IsDefaultAUService

    Reference picture:



    You could consider enabling the following GPO on the client. If you enable the following Group Policy, the client only gets the updates from the WSUS and does not get the updates from Microsoft Update.

    -[Turn off access to all Windows Update features]Setting No Configured

    (Location: Group Policy Management Editor\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings)


    If you have any updates about this issue, please keep us in touch.

    Regards,
    Rita     


    Please remember to mark as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, June 1, 2020 2:43 AM

All replies

  • Hi Dilamic,

    Thanks for your posting.

    Open Powershell as an administrator and enter the following command to check the client's default update source:
    $MUSM = New-Object -ComObject "Microsoft.Update.ServiceManager"

    $MUSM.Services | select Name, IsDefaultAUService

    Reference picture:



    You could consider enabling the following GPO on the client. If you enable the following Group Policy, the client only gets the updates from the WSUS and does not get the updates from Microsoft Update.

    -[Turn off access to all Windows Update features]Setting No Configured

    (Location: Group Policy Management Editor\Policies\Administrative Templates\System\Internet Communication Management\Internet Communication settings)


    If you have any updates about this issue, please keep us in touch.

    Regards,
    Rita     


    Please remember to mark as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, June 1, 2020 2:43 AM
  • HI,

    Thank you very much, Sorted!

    Regards,

    Dilan

    Monday, June 1, 2020 5:59 AM
  • Hi Dilanmic,
     
    I am honored to assist you in solving the problem! 
     
    If you have any other issues, please keep in touch.
     
    Regards, 
    Rita

    Please remember to mark as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, June 1, 2020 6:57 AM
  • Hi Dilanmic,
     
    Here is a short summary for future follow-up reference:
     
    Issue Symptom
    Provide script to check the client update source
      
    Solution
    Provide scripts to clients
      
    Regards,
    Rita

    "WSUS" forum will be migrating to a new home on Microsoft Q&A!
    We invite you to post new questions in the "WSUS" forum's new home on Microsoft Q&A!
    For more information, please refer to the sticky post.

    Please remember to mark as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, July 16, 2020 3:25 AM