Windows Update issue - enforecement state unknown
Issue: - Software updates to the any of the servers not going thru.. Whereas software distribution works fine, deployment states report says "Enforcement state unknown"
Error Message: - Below error found in “WUAhandler logs."
Enabling WUA Managed server policy to use server: http://server1.contoso.com:80
waiting for 2 mins for Group Policy to notify of WUA policy change...
Timed out waiting for Group Policy notification.
Group policy settings were overwritten by a higher authority (Domain Controller) to: Server and Policy NOT CONFIGURED
Failed to Add Update Source for WUAgent of type (2) and id ({08250946-C9EB-443F-87A4-6AD5B2E5FB2D}). Error = 0x80040692.
Solution: - Firstly check below GPs details? It can be a gpo conflict:
These three policies mentioned should not be configured from domain level. The SCCM client will apply the policy whenever it is required.
a. Allow signed content from intranet Microsoft update service location.
b. Specify intranet Microsoft update service location
c. Automatic Updates Configuration
See tech net article for more details http://technet.microsoft.com/en-us/library/2acc5240-6223-453f-8409-4c020311a1ae
References:-
1. http://anoopcnair.com/2010/10/27/sccm-wsus-scan-agent-is-not-functoning-scan-failed-with-error-0x8024400a-wuahandler-log-for-windows-2008-core-servers/
2. http://blogs.technet.com/b/sus/archive/2010/11/04/information-on-the-configmgr-2007-client-side-process-for-software-updates.aspx
Error Message: - Below error found in “WUAhandler logs."
Enabling WUA Managed server policy to use server: http://server1.contoso.com:80
waiting for 2 mins for Group Policy to notify of WUA policy change...
Timed out waiting for Group Policy notification.
Group policy settings were overwritten by a higher authority (Domain Controller) to: Server and Policy NOT CONFIGURED
Failed to Add Update Source for WUAgent of type (2) and id ({08250946-C9EB-443F-87A4-6AD5B2E5FB2D}). Error = 0x80040692.
Solution: - Firstly check below GPs details? It can be a gpo conflict:
These three policies mentioned should not be configured from domain level. The SCCM client will apply the policy whenever it is required.
a. Allow signed content from intranet Microsoft update service location.
b. Specify intranet Microsoft update service location
c. Automatic Updates Configuration
See tech net article for more details http://technet.microsoft.com/en-us/library/2acc5240-6223-453f-8409-4c020311a1ae
References:-
1. http://anoopcnair.com/2010/10/27/sccm-wsus-scan-agent-is-not-functoning-scan-failed-with-error-0x8024400a-wuahandler-log-for-windows-2008-core-servers/
2. http://blogs.technet.com/b/sus/archive/2010/11/04/information-on-the-configmgr-2007-client-side-process-for-software-updates.aspx
Comments
Post a Comment