October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Automatic Deployment Rules

How to Fix “Automatic Deployment Rule Failed to Download the Update from UNC Content Source. Error = 3” in Configuration Manager

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Error = 3 in this Automatic Deployment Rule (ADR) message normally means that Configuration Manager could not find the specified UNC path. Start on the site server: copy the exact path and filename from RuleEngine.log and PatchDownloader.log, test the share with PowerShell, then verify share/NTFS permissions and the account used by the site-server process. This is usually a site-server content-acquisition failure, not a distribution-point or client-installation problem.

Where the failure occurs

An ADR evaluates update criteria, selects matching updates and a deployment package, and then downloads content before distribution and deployment. The reported error is at the download stage:

ADR evaluation
   ↓
Site server downloads update content
   ↓
Deployment-package source
   ↓
Distribution points
   ↓
Clients

Configuration Manager can use internet, WSUS, or a UNC source according to the ADR configuration and source order. The log evidence, rather than the wording of the rule alone, shows which source was attempted. See Microsoft’s process description at Track the software update deployment process.

A UNC path is a network share such as \ServerNameShareNameFolderName. It is the location from which the site server obtains files. It is not the same as the deployment-package source, a distribution point, or the client content location.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • ADR download location: alternate source used by the site server to obtain update files.
  • Deployment-package source: storage where downloaded files are placed before distribution.
  • Distribution point: server from which clients later retrieve package content.
  • Client content source: location selected by a client during deployment.

Therefore, do not begin with client cache or distribution-point logs while the ADR cannot obtain the file.

What Error = 3 means here

In this UNC ADR scenario, Error 3 normally corresponds to “the system cannot find the path specified.” Microsoft’s guidance for this exact situation identifies a missing or unresolvable path: Microsoft Q&A. It does not prove that a share was deleted. The server may be offline, a DFS target unavailable, a subfolder misspelled, or the path accessible to an administrator but not to the execution identity.

Treat the exact path and surrounding log lines as authoritative. A valid share with a missing .cab, .msu, .exe, catalog, or signature file is a content-staging problem, not the same as a nonexistent share. Access-denied errors generally point to permissions, although an inaccessible share can look like a missing path depending on how the request is made.

Check the two logs first

RuleEngine.log: prove what the ADR attempted

On the site server, find the ADR name and run time in RuleEngine.log. Confirm:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • matching update IDs and content IDs;
  • the selected deployment package;
  • the configured source order (for example, Internet, WSUS, and UNC);
  • the exact UNC value; and
  • whether the rule failed while constructing content or while downloading it.

If no updates matched, investigate synchronization, product, classification, language, supersedence, or date filters instead of the share.

PatchDownloader.log: prove which file failed

PatchDownloader.log records the source, requested filename, temporary download file, and path, access, hash, certificate, or network errors. When the Configuration Manager client is installed on the site server, a common location is %windir%CCMLogsPatchDownloader.log; installations can differ, so also check the site’s installation and client-log directories. Microsoft’s ADR download example and log guidance are documented in this Q&A answer.

Search for terms such as UNC, Error = 3, Failed to download, ContentID, FileName, DownloadUpdateContent, and DownloadContentFiles. Copy the path and filename exactly; do not retype them.

Test the path from the site server

Run these commands in a session on the site server, not only from your workstation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Test-NetConnection -ComputerName ServerName -Port 445
Test-Path '\ServerNameShareNameFolderName'
Get-ChildItem '\ServerNameShareNameFolderName'

Port 445 failure indicates DNS, routing, firewall, or SMB trouble. A successful port test with Test-Path returning False points to the share, subpath, authentication, or permissions. A directory listing proves only that the current session can list the folder.

If the location is also the deployment-package source and you are authorized to test writing, use a controlled file:

$test = '\ServerNameShareNameFolderNameConfigMgrWriteTest.txt'
'ConfigMgr test' | Set-Content -Path $test
Remove-Item $test

Do not alter a source-only share unnecessarily. A successful test as a logged-on administrator does not prove that the site-server process can access it.

Verify identity and permissions

Check both share permissions and NTFS permissions; the more restrictive effective result wins. The source requires read access. A deployment-package source normally requires write/modify access so files can be added. Microsoft discusses share and NTFS access requirements in this guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Identify the site-server service or computer context performing the operation. Local System accessing a remote server commonly authenticates as DOMAINSCCMSERVER$, but topology and version can change the identity.
  • Grant narrowly scoped rights to the actual account; do not default to Everyone: Full Control.
  • Do not use a mapped drive such as Z:Updates; server-side services should use a full UNC path.
  • Be cautious with \localhostshare and administrative shares, which can create confusing identity behavior.
  • For cross-domain, workgroup, or isolated networks, verify trust and credentials as well as SMB connectivity.
  • Check for deny entries, expired service-account passwords, and broken computer-account trust.

Confirm the ADR download-location setting

  1. Open the Configuration Manager console.
  2. Go to Software Library and expand Software Updates.
  3. Select Automatic Deployment Rules and open the affected rule.
  4. Review the deployment package and download-location/content-source settings.
  5. Confirm whether the rule is set to download from Microsoft Update, WSUS, or an alternate UNC location.
  6. Ensure the value is a complete UNC path, not a mapped drive or a local path on another server.

Labels vary by current-branch release and language. Use the equivalent download-location setting if wording differs. Microsoft documents ADR configuration at ADR management and the relevant PowerShell properties at Set-CMSoftwareUpdateAutoDeploymentRule.

Verify that the requested content really exists

A familiar folder such as \WSUSServerWSUSContent is not automatically a complete ADR source. Offline or synchronized WSUS content may lack the exact revision, language, architecture, or companion file selected by the update metadata. Microsoft’s offline-WSUS discussion records both the use of a WSUSContent path and cases where the ADR requested different files: Microsoft Q&A.

Compare the filename and directory in PatchDownloader.log with the update’s Content Locations in the Configuration Manager console. Check for:

  • the exact filename and extension;
  • all required files, including catalogs or signatures;
  • the correct update revision;
  • the language and architecture selected by the ADR; and
  • complete synchronization or manual staging.

If content is absent, stage the exact files from the official content locations, change the rule to an internet source where policy permits, or use a documented disconnected-update transfer process. Copying part of a WSUSContent directory is not proof that every selected update is available.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use a single-update test before rerunning production

  1. Identify one failing update from the logs.
  2. Add or download it through a test deployment package.
  3. Observe PatchDownloader.log while the operation runs.
  4. Confirm whether the same path and filename fail.
  5. Only after that test succeeds, run the broad production ADR.

Common symptoms and fixes

Symptom Likely cause Action
Test-Path is False Wrong or missing UNC path Correct the rule or restore the share.
Port 445 fails Firewall, DNS, routing, or SMB issue Fix connectivity from the site server.
Administrator can browse, ADR cannot Execution-identity mismatch Grant access to the actual computer/service account.
Folder exists, requested file does not Incomplete staging or wrong revision Stage the exact content shown in the log.
Package source cannot be updated Missing share or NTFS modify rights Grant narrowly scoped write/modify access.
Only some updates fail Missing language, architecture, companion file, or revision Compare each update’s content locations.
Update group is created, then ADR fails Download or package-source failure Focus on RuleEngine.log and PatchDownloader.log.
UNC works intermittently DFS target, storage, server, or SMB-session instability Test the specific target and review server/network events.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Offline environments and alternate failures

Disconnected deployments need synchronized metadata and complete staged content that corresponds to that metadata. A UNC path alone does not make an offline workflow complete.

If logs show HTTP, proxy, TLS, certificate, or signature errors rather than path resolution, investigate those branches separately. Microsoft has documented proxy-authentication failures affecting ADR downloads in some Configuration Manager scenarios: Microsoft Support. Do not attribute a plain Error 3 to a proxy without that evidence.

Rerun and verify the complete chain

  1. Run the ADR manually after correcting the path, access, or content.
  2. Confirm files appear in the deployment-package source.
  3. Distribute the package to the required distribution points.
  4. Monitor distribution status.
  5. Test deployment on a client only after site-server download and distribution succeed.

Microsoft describes this sequence—software update group, distribution-point content, deployment, then client download—in Deploy software updates. If the error appears only after successful distribution, switch to client and distribution-point logs such as ContentTransferManager.log and DataTransferService.log; that is a different failure stage.

Recreating the ADR is not a first-line fix. A new rule still fails when the UNC path, identity, permissions, or staged files are wrong. A third-party catalog service may reduce application-catalog maintenance, but it will not repair this UNC workflow unless it replaces it entirely. Patch My PC’s product information is available at Performance · Free Tool

Windows Errors? Fix Them Before They Spread

Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.

Fix My PC Now →Free scan · no reinstall
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Does Error = 3 always mean permission denied?

No. In this ADR/UNC message it normally indicates that the specified path could not be found. Test the exact path and execution identity; use permission evidence to distinguish access denial from a missing path.

Can I use a mapped drive for the ADR source?

No. Use a full UNC path. Mapped drives belong to an interactive user session and are generally unavailable to server-side services.

Should the ADR point to WSUSContent?

Only when that location has every file and revision required by the selected update metadata. Verify the exact request in PatchDownloader.log rather than assuming the folder is complete.

Why does manual browsing work while the ADR fails?

Your browser session may use a different account than the site-server process. Test with the relevant computer or service identity and verify both share and NTFS permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is this a distribution-point or client problem?

Not when the ADR reports the error during content acquisition. Investigate distribution points and clients only after the site server has downloaded and distributed the package.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.