Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesIf a Configuration Manager secondary site fails to upgrade after its parent primary site moves from version 1906 to 1910, treat the failure as a symptom—not proof of one universal 1910 bug. The reported errors point to different causes, including SQL communication problems and certificate or permissions failures. Start with the first meaningful error in the setup logs, verify the installed 1910 build and secondary-site prerequisites, then choose a retry or recovery action based on the evidence.
Configuration Manager 1910 is a historical release from 2020. This guide distinguishes the procedure Microsoft documented for that release from the current console’s normal secondary-site upgrade path.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Tripp Lite SRSCREWS Rack Enclosure Server Cabinet Threaded Hole Hardware Kit | $23.99 | Buy on Amazon |
What a secondary-site upgrade failure means
Updating the parent primary site does not automatically update every existing secondary site. Microsoft’s 1910-era guidance said administrators had to update pre-existing secondary sites manually. A primary site can therefore complete its update while a secondary site remains behind or fails during its own setup.
Two reported 1910-era failure patterns illustrate why the first useful log error matters. One administrator reported SQL Native Client communication errors, including 08S01, Winsock error 10054, and “Communication link failure” (reported SQL communication failure). Another reported a certificate and access-denied sequence: a non-exportable certificate, a missing site exchange certificate, failures to set a security descriptor and grant LocalSystem access, and failure to create a SQL Server certificate (reported certificate and permissions failure). These are user reports, not evidence that every 1910 failure shares one cause.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Threaded hole hardware kit - 50 each #12-24 screws
- Fastens equipment to threaded hole rack mount rails
- Compatible with all #12-24 threaded hole racks
The parent primary’s success does not validate the secondary server’s local SQL instance, permissions, certificates, prerequisites, or network path. Diagnose the affected secondary site on its own evidence before retrying setup.
Capture the actual failure before changing anything
Open the affected secondary site’s installation status in the Configuration Manager console, then correlate it with setup and SQL logs. Record the first failure in chronological order; the final setup return code is often less useful than the operation that first failed.
- On the secondary server: review
ConfigMgrSetup.log,ConfigMgrPrereq.log,smsexec.log,sitecomp.log, andhman.log. - For local SQL: inspect the SQL Server error log and confirm the relevant SQL services are running.
- In Windows: check Event Viewer’s Application and System logs, plus Schannel or SQL-related events when connectivity or TLS is implicated.
- On the primary site: review
hman.logfor hierarchy/update activity,cmupdate.logfor update and database activity,sitecomp.logfor component installation, anddmpdownloader.logfor update package activity. Checkdistmgr.logwhen content distribution is involved.
For update installation guidance and log interpretation, see Microsoft’s Updates and Servicing troubleshooting reference. Microsoft notes that cmupdate.log can help identify a SQL session or program blocking a database upgrade. For the secondary site itself, use the detailed setup sequence to distinguish the cause from the later “setup failed” message.
Verify the 1910 build and whether the secondary site is current
Before comparing the failure with another environment or applying a release-specific fix, record the primary site’s exact Configuration Manager build, update package identity, and installed rollups. Microsoft revised the globally available 1910 release on January 17, 2020; that revision and later 1910 rollups do not establish that a particular secondary-site setup failure was fixed. See Microsoft’s 1910 change summary and 1910 update rollup.
Free tools Windows power users keep installed
One-click scans. No signup required.
Microsoft documented this query for checking whether a secondary site has installed all fixes applied to its parent primary site. Run it against the Configuration Manager site database and replace the example with the actual secondary-site code:
SELECT dbo.fnGetSecondarySiteCMUpdateStatus ('SiteCode_of_secondary_site');
1means the secondary site is up to date with fixes applied to the primary site.0means it has not installed all those fixes; Microsoft’s documented action is to use Recover Secondary Site to update it.
This query is a status check, not a repair command. Do not edit Configuration Manager database tables to force a status change. The query and release-specific guidance appear in Microsoft’s 1910 secondary-site update guidance.
Classify the error and take the matching first action
| Evidence in logs or status | Likely area | First checks |
|---|---|---|
08S01, 10054, or communication-link failure |
SQL connectivity, service availability, network, or client protocol | Check SQL service state, name resolution, firewall and ports, SQL logs, and SQL client/TLS compatibility. |
0x80070005 or failure to grant LocalSystem access |
Permissions or security policy | Check the parent primary computer account’s local and SQL rights, LocalSystem SQL rights, and relevant security controls. |
| Site exchange certificate missing or marked non-exportable | Certificate setup, identity, or key access | Inspect the certificate stores, private-key access, setup operation, and certificate policy; do not assume non-exportable alone proves the cause. |
| Failure to create a SQL Server certificate | SQL permissions, certificate access, or cryptographic policy | Correlate the certificate error with SQL rights, Windows security controls, and the preceding setup events. |
| Prerequisite checker reports a failure | Incomplete or unsupported server configuration | Correct each reported prerequisite, then rerun the checker. |
| Console reports failure but the site version and logs show completion | Possibly stale console status | Open Show Install Status and verify the Version column before deciding to retry or recover. |
Status query returns 0 |
Secondary site has not received all parent-site fixes | Follow Microsoft’s documented secondary-site recovery/update path. |
Check SQL connectivity and the local SQL installation
For communication errors, establish whether the secondary server can reach and use its SQL instance before rerunning Configuration Manager setup. A communication-link failure is not, by itself, evidence of database corruption.
- Confirm that the SQL Server service for the instance used by the secondary site is running and review its error log for connection, startup, or certificate errors.
- Check name resolution, firewall rules, and the configured SQL and Service Broker ports between the relevant site systems. Confirm the SQL instance and client protocol configuration match the environment.
- Review Schannel events and SQL client compatibility if the failure coincides with TLS negotiation or a client communication error.
- For a secondary site, SQL Server must be local to the secondary-site server; the site database uses the default instance of a full SQL Server installation or SQL Server Express. Recovery must preserve the existing SQL version and instance configuration.
Check SQL Native Client when logs point to a client communication problem. Microsoft’s troubleshooting guidance identifies SQL Server Native Client version 11.4.7001.0 or later as required beginning with Configuration Manager 1810. Its installed version can be checked at HKLMSOFTWAREMicrosoftSQLNCLI11InstalledVersion. The documented requirement and update troubleshooting details are in Microsoft’s Updates and Servicing reference.
Recommended Free Tools
These PowerShell commands are generic service-state checks, not Microsoft repair commands. For the default instance, use:
Get-Service -Name MSSQLSERVER,SQLSERVERAGENT -ErrorAction SilentlyContinue
For a named instance, substitute its actual instance name:
Get-Service -Name 'MSSQL$INSTANCE_NAME','SQLAgent$INSTANCE_NAME' `
-ErrorAction SilentlyContinue
If a service is stopped or SQL reports a connection failure, resolve that condition and confirm connectivity before another upgrade attempt. Do not infer a damaged database from a network or client error alone.
Check permissions and certificates for access-denied failures
When setup reports 0x80070005, LocalSystem access failures, or SQL certificate creation errors, verify the identities and rights involved rather than broadening permissions indiscriminately. Microsoft’s secondary-site prerequisites cover the parent primary computer account’s local administrator membership and required SQL permissions.
- Confirm the parent primary-site computer account is still a member of the secondary server’s local Administrators group.
- Verify that the parent primary computer account and the secondary server’s LocalSystem account have the required SQL permissions for the existing secondary-site SQL configuration.
- Use the first certificate-related setup error to identify which certificate operation failed and which identity needed access. Check that the site exchange certificate exists and that the required service identity can access its private key.
- Review certificate stores for stale or duplicate certificates, and check whether Group Policy, endpoint security, or cryptographic policy blocked certificate creation or key access.
- Compare the logged operation with certificate policy before changing exportability or replacing a certificate. A non-exportable certificate is not automatically invalid, and the reported error does not establish that every secondary-site certificate must be exportable.
Do not delete certificates blindly, grant broad domain permissions, or permanently add excessive rights as a test. Make only a scoped, policy-approved correction supported by the logs; if the required certificate operation remains unclear, consult Microsoft Support before changing certificate or database state.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Run the secondary-site upgrade prerequisite check
Use the prerequisite checker’s secondary-site upgrade mode against the server’s fully qualified domain name (FQDN). Replace the example host with the actual secondary server:
prereqchk.exe /SECUPGRADE sec01.contoso.com
Microsoft documents /SECUPGRADE for evaluating whether a specified server meets secondary-site upgrade requirements. See the Prerequisite Checker reference. Resolve each reported issue and rerun the check. A clean result does not prove that SQL permissions, certificate access, connectivity, file operations, or update-package processing will succeed; continue to use the setup logs to diagnose those operations.
Retry the upgrade using the correct console path
The console action depends on whether you are reproducing the historical 1910 procedure or using current Configuration Manager documentation. Do not treat Upgrade, Retry installation, and Recover Secondary Site as interchangeable.
- In the console, go to Administration → Site Configuration → Sites and select the affected secondary site.
- For the original 1910-era procedure, Microsoft documented Recover Secondary Site to reinstall or update a pre-existing secondary site after the primary site was updated.
- For the current normal secondary-site update path, Microsoft documents selecting Upgrade. Check the current in-console updates guidance for the console version in use.
- Monitor Show Install Status, the secondary server’s setup logs, and the site’s Version column to confirm whether setup completed.
- Use Retry installation only when the update appears to have completed successfully but the console status has not refreshed. It is not a general fix for a setup failure.
Configuration Manager also provides Invoke-CMSecondarySiteUpgrade in current PowerShell documentation:
Invoke-CMSecondarySiteUpgrade -SiteCode "ABC" -Force
This invokes an upgrade outside scheduled upgrades; it is not a proven 1910-specific repair. Verify the cmdlet and parameters available in the console version you administer in Microsoft’s cmdlet reference.
Recover the secondary site if setup cannot complete
Recovery is the supported route when the secondary installation is genuinely broken or unusable after the underlying prerequisite, SQL, and permission problems are addressed. It is also Microsoft’s documented update action when the secondary-site status query returns 0. Do not choose recovery solely because the console shows a stale failure; first check installation status, logs, and the Version column.
Microsoft’s site recovery procedure reinstalls secondary-site files and reinitializes the secondary-site data from the parent primary site. Configuration Manager does not support backing up the secondary-site database, so recovery does not use a secondary-site database backup.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Before recovery, ensure the server meets secondary-site prerequisites and preserve the failed site’s configuration:
- Use the same installation path and the same server configuration, including the FQDN.
- Use the same SQL Server version and SQL instance configuration as the failed site.
- If the site used SQL Server Express, install or retain SQL Server Express beforehand; recovery does not install it automatically.
- Check the content library. Configuration Manager assesses its presence and required content during recovery; an incomplete library can require content redistribution or prestaging.
A distribution point located on a different server does not necessarily need reinstallation as part of recovering the secondary site. Review content status and recovery progress rather than assuming every distribution point must be rebuilt.
Quick Recap
Avoid unsupported shortcuts and prevent repeat failures
- Do not edit Configuration Manager database tables to clear an upgrade state or make a secondary site appear current.
- Do not repeatedly retry while the underlying SQL, certificate, or permissions failure remains unresolved.
- Do not treat a client hotfix or client-upgrade issue in 1910 documentation as proof of a secondary-site setup fix.
- Before a future site update, record the exact primary build and package identity, validate secondary-site prerequisites, check SQL Native Client and hierarchy health, and confirm required account rights.
- Plan a recovery window for secondary-site reinstallation and confirm the SQL and content-library requirements for that site.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




