October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Configuration Manager

SCCM Secondary Site Upgrade Failure in Configuration Manager 1910: Diagnose and Recover

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a Configuration Manager secondary site fails to upgrade after its parent primary site moves from version 1906 to 1910, treat the failure as a symptom—not proof of one universal 1910 bug. The reported errors point to different causes, including SQL communication problems and certificate or permissions failures. Start with the first meaningful error in the setup logs, verify the installed 1910 build and secondary-site prerequisites, then choose a retry or recovery action based on the evidence.

Configuration Manager 1910 is a historical release from 2020. This guide distinguishes the procedure Microsoft documented for that release from the current console’s normal secondary-site upgrade path.

What a secondary-site upgrade failure means

Updating the parent primary site does not automatically update every existing secondary site. Microsoft’s 1910-era guidance said administrators had to update pre-existing secondary sites manually. A primary site can therefore complete its update while a secondary site remains behind or fails during its own setup.

Two reported 1910-era failure patterns illustrate why the first useful log error matters. One administrator reported SQL Native Client communication errors, including 08S01, Winsock error 10054, and “Communication link failure” (reported SQL communication failure). Another reported a certificate and access-denied sequence: a non-exportable certificate, a missing site exchange certificate, failures to set a security descriptor and grant LocalSystem access, and failure to create a SQL Server certificate (reported certificate and permissions failure). These are user reports, not evidence that every 1910 failure shares one cause.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Tripp Lite SRSCREWS Rack Enclosure Server Cabinet Threaded Hole Hardware Kit
  • Threaded hole hardware kit - 50 each #12-24 screws
  • Fastens equipment to threaded hole rack mount rails
  • Compatible with all #12-24 threaded hole racks

The parent primary’s success does not validate the secondary server’s local SQL instance, permissions, certificates, prerequisites, or network path. Diagnose the affected secondary site on its own evidence before retrying setup.

Capture the actual failure before changing anything

Open the affected secondary site’s installation status in the Configuration Manager console, then correlate it with setup and SQL logs. Record the first failure in chronological order; the final setup return code is often less useful than the operation that first failed.

  • On the secondary server: review ConfigMgrSetup.log, ConfigMgrPrereq.log, smsexec.log, sitecomp.log, and hman.log.
  • For local SQL: inspect the SQL Server error log and confirm the relevant SQL services are running.
  • In Windows: check Event Viewer’s Application and System logs, plus Schannel or SQL-related events when connectivity or TLS is implicated.
  • On the primary site: review hman.log for hierarchy/update activity, cmupdate.log for update and database activity, sitecomp.log for component installation, and dmpdownloader.log for update package activity. Check distmgr.log when content distribution is involved.

For update installation guidance and log interpretation, see Microsoft’s Updates and Servicing troubleshooting reference. Microsoft notes that cmupdate.log can help identify a SQL session or program blocking a database upgrade. For the secondary site itself, use the detailed setup sequence to distinguish the cause from the later “setup failed” message.

Verify the 1910 build and whether the secondary site is current

Before comparing the failure with another environment or applying a release-specific fix, record the primary site’s exact Configuration Manager build, update package identity, and installed rollups. Microsoft revised the globally available 1910 release on January 17, 2020; that revision and later 1910 rollups do not establish that a particular secondary-site setup failure was fixed. See Microsoft’s 1910 change summary and 1910 update rollup.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft documented this query for checking whether a secondary site has installed all fixes applied to its parent primary site. Run it against the Configuration Manager site database and replace the example with the actual secondary-site code:

SELECT dbo.fnGetSecondarySiteCMUpdateStatus ('SiteCode_of_secondary_site');
  • 1 means the secondary site is up to date with fixes applied to the primary site.
  • 0 means it has not installed all those fixes; Microsoft’s documented action is to use Recover Secondary Site to update it.

This query is a status check, not a repair command. Do not edit Configuration Manager database tables to force a status change. The query and release-specific guidance appear in Microsoft’s 1910 secondary-site update guidance.

Classify the error and take the matching first action

Evidence in logs or status Likely area First checks
08S01, 10054, or communication-link failure SQL connectivity, service availability, network, or client protocol Check SQL service state, name resolution, firewall and ports, SQL logs, and SQL client/TLS compatibility.
0x80070005 or failure to grant LocalSystem access Permissions or security policy Check the parent primary computer account’s local and SQL rights, LocalSystem SQL rights, and relevant security controls.
Site exchange certificate missing or marked non-exportable Certificate setup, identity, or key access Inspect the certificate stores, private-key access, setup operation, and certificate policy; do not assume non-exportable alone proves the cause.
Failure to create a SQL Server certificate SQL permissions, certificate access, or cryptographic policy Correlate the certificate error with SQL rights, Windows security controls, and the preceding setup events.
Prerequisite checker reports a failure Incomplete or unsupported server configuration Correct each reported prerequisite, then rerun the checker.
Console reports failure but the site version and logs show completion Possibly stale console status Open Show Install Status and verify the Version column before deciding to retry or recover.
Status query returns 0 Secondary site has not received all parent-site fixes Follow Microsoft’s documented secondary-site recovery/update path.

Check SQL connectivity and the local SQL installation

For communication errors, establish whether the secondary server can reach and use its SQL instance before rerunning Configuration Manager setup. A communication-link failure is not, by itself, evidence of database corruption.

  • Confirm that the SQL Server service for the instance used by the secondary site is running and review its error log for connection, startup, or certificate errors.
  • Check name resolution, firewall rules, and the configured SQL and Service Broker ports between the relevant site systems. Confirm the SQL instance and client protocol configuration match the environment.
  • Review Schannel events and SQL client compatibility if the failure coincides with TLS negotiation or a client communication error.
  • For a secondary site, SQL Server must be local to the secondary-site server; the site database uses the default instance of a full SQL Server installation or SQL Server Express. Recovery must preserve the existing SQL version and instance configuration.

Check SQL Native Client when logs point to a client communication problem. Microsoft’s troubleshooting guidance identifies SQL Server Native Client version 11.4.7001.0 or later as required beginning with Configuration Manager 1810. Its installed version can be checked at HKLMSOFTWAREMicrosoftSQLNCLI11InstalledVersion. The documented requirement and update troubleshooting details are in Microsoft’s Updates and Servicing reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These PowerShell commands are generic service-state checks, not Microsoft repair commands. For the default instance, use:

Get-Service -Name MSSQLSERVER,SQLSERVERAGENT -ErrorAction SilentlyContinue

For a named instance, substitute its actual instance name:

Get-Service -Name 'MSSQL$INSTANCE_NAME','SQLAgent$INSTANCE_NAME' `
  -ErrorAction SilentlyContinue

If a service is stopped or SQL reports a connection failure, resolve that condition and confirm connectivity before another upgrade attempt. Do not infer a damaged database from a network or client error alone.

Check permissions and certificates for access-denied failures

When setup reports 0x80070005, LocalSystem access failures, or SQL certificate creation errors, verify the identities and rights involved rather than broadening permissions indiscriminately. Microsoft’s secondary-site prerequisites cover the parent primary computer account’s local administrator membership and required SQL permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Confirm the parent primary-site computer account is still a member of the secondary server’s local Administrators group.
  2. Verify that the parent primary computer account and the secondary server’s LocalSystem account have the required SQL permissions for the existing secondary-site SQL configuration.
  3. Use the first certificate-related setup error to identify which certificate operation failed and which identity needed access. Check that the site exchange certificate exists and that the required service identity can access its private key.
  4. Review certificate stores for stale or duplicate certificates, and check whether Group Policy, endpoint security, or cryptographic policy blocked certificate creation or key access.
  5. Compare the logged operation with certificate policy before changing exportability or replacing a certificate. A non-exportable certificate is not automatically invalid, and the reported error does not establish that every secondary-site certificate must be exportable.

Do not delete certificates blindly, grant broad domain permissions, or permanently add excessive rights as a test. Make only a scoped, policy-approved correction supported by the logs; if the required certificate operation remains unclear, consult Microsoft Support before changing certificate or database state.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Run the secondary-site upgrade prerequisite check

Use the prerequisite checker’s secondary-site upgrade mode against the server’s fully qualified domain name (FQDN). Replace the example host with the actual secondary server:

prereqchk.exe /SECUPGRADE sec01.contoso.com

Microsoft documents /SECUPGRADE for evaluating whether a specified server meets secondary-site upgrade requirements. See the Prerequisite Checker reference. Resolve each reported issue and rerun the check. A clean result does not prove that SQL permissions, certificate access, connectivity, file operations, or update-package processing will succeed; continue to use the setup logs to diagnose those operations.

Retry the upgrade using the correct console path

The console action depends on whether you are reproducing the historical 1910 procedure or using current Configuration Manager documentation. Do not treat Upgrade, Retry installation, and Recover Secondary Site as interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. In the console, go to Administration → Site Configuration → Sites and select the affected secondary site.
  2. For the original 1910-era procedure, Microsoft documented Recover Secondary Site to reinstall or update a pre-existing secondary site after the primary site was updated.
  3. For the current normal secondary-site update path, Microsoft documents selecting Upgrade. Check the current in-console updates guidance for the console version in use.
  4. Monitor Show Install Status, the secondary server’s setup logs, and the site’s Version column to confirm whether setup completed.
  5. Use Retry installation only when the update appears to have completed successfully but the console status has not refreshed. It is not a general fix for a setup failure.

Configuration Manager also provides Invoke-CMSecondarySiteUpgrade in current PowerShell documentation:

Invoke-CMSecondarySiteUpgrade -SiteCode "ABC" -Force

This invokes an upgrade outside scheduled upgrades; it is not a proven 1910-specific repair. Verify the cmdlet and parameters available in the console version you administer in Microsoft’s cmdlet reference.

Recover the secondary site if setup cannot complete

Recovery is the supported route when the secondary installation is genuinely broken or unusable after the underlying prerequisite, SQL, and permission problems are addressed. It is also Microsoft’s documented update action when the secondary-site status query returns 0. Do not choose recovery solely because the console shows a stale failure; first check installation status, logs, and the Version column.

Microsoft’s site recovery procedure reinstalls secondary-site files and reinitializes the secondary-site data from the parent primary site. Configuration Manager does not support backing up the secondary-site database, so recovery does not use a secondary-site database backup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before recovery, ensure the server meets secondary-site prerequisites and preserve the failed site’s configuration:

  • Use the same installation path and the same server configuration, including the FQDN.
  • Use the same SQL Server version and SQL instance configuration as the failed site.
  • If the site used SQL Server Express, install or retain SQL Server Express beforehand; recovery does not install it automatically.
  • Check the content library. Configuration Manager assesses its presence and required content during recovery; an incomplete library can require content redistribution or prestaging.

A distribution point located on a different server does not necessarily need reinstallation as part of recovering the secondary site. Review content status and recovery progress rather than assuming every distribution point must be rebuilt.

Quick Recap

Bestseller No. 1
Tripp Lite SRSCREWS Rack Enclosure Server Cabinet Threaded Hole Hardware Kit
Tripp Lite SRSCREWS Rack Enclosure Server Cabinet Threaded Hole Hardware Kit
Threaded hole hardware kit - 50 each #12-24 screws; Fastens equipment to threaded hole rack mount rails
$23.99

Avoid unsupported shortcuts and prevent repeat failures

  • Do not edit Configuration Manager database tables to clear an upgrade state or make a secondary site appear current.
  • Do not repeatedly retry while the underlying SQL, certificate, or permissions failure remains unresolved.
  • Do not treat a client hotfix or client-upgrade issue in 1910 documentation as proof of a secondary-site setup fix.
  • Before a future site update, record the exact primary build and package identity, validate secondary-site prerequisites, check SQL Native Client and hierarchy health, and confirm required account rights.
  • Plan a recovery window for secondary-site reinstallation and confirm the SQL and content-library requirements for that site.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.