Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Automatic Deployment Rules

ADR Rule Failure in Configuration Manager: How to Diagnose and Fix It

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Configuration Manager Rule Failure Alert means an Automatic Deployment Rule (ADR) execution failed; it is not, by itself, a root-cause error code. Start with the alert’s ADR name and timestamp, then inspect the site server’s ruleengine.log around that time. The log and the stage that failed—not the alert label alone—determine whether to correct synchronization, filters, deployment objects, content handling, or site infrastructure.

What an ADR Rule Failure means

An Automatic Deployment Rule automates software-update selection and deployment. Depending on its settings, an ADR can evaluate a schedule, query synchronized update metadata, apply filters, add matches to a software update group, handle content, and create or update a deployment. Not every ADR downloads content during every run; content handling depends on its configuration.

When configured to do so, Configuration Manager generates a Rule Failure Alert if an ADR execution fails. That alert reports a failed rule, not the detailed cause. This is different from a client-side problem: an ADR can complete successfully even if clients later fail to scan, download, install, or restart for an update. Alert setup and ADR failure guidance

First, confirm which ADR failed

  1. In the console, go to Monitoring > Alerts > All Alerts and open the Rule Failure Alert.
  2. Read its description to identify the ADR. Record the alert time and time zone.
  3. Go to Software Library > Software Updates > Automatic Deployment Rules, open that ADR, and compare its schedule and last-run time with the alert.
  4. Check whether a later run succeeded. An older alert may remain visible after recovery, or it may refer to another ADR with a similar name.

The alert details can identify the rule associated with the failure; correlate them with the execution log before changing the rule. ADR alert details in Configuration Manager

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Capture evidence before rerunning

Save the relevant log context before another run adds new entries or makes the original failure harder to isolate. Open ruleengine.log on the site server in CMTrace or another viewer that understands Configuration Manager log formatting. Filter around the alert time, find the ADR name or deployment, and copy the complete error block—not just a hexadecimal code.

  • ADR name, site code, and site-server name.
  • Configuration Manager current-branch version and alert timestamp, including time zone.
  • ADR schedule, full error text, and any error code.
  • Whether other ADRs are succeeding and whether update synchronization completed.
  • How many updates the rule returned, if the log or console shows that result.

ruleengine.log is the primary starting point for an ADR execution failure. The relevant error and stage may also be recorded by synchronization, content, provider, SQL, or distribution components. No single list of related logs applies to every failure.

Use the failure pattern to narrow the cause

Only one ADR is failing

First inspect that rule’s filters, deployment settings, collection, package, and content source. Check whether a referenced object was renamed, deleted, moved, or changed. If other ADRs work, a site-wide outage is less likely, though it is not ruled out.

All ADRs are failing

Treat this as a possible shared infrastructure issue before editing individual rules. Check software-update-point synchronization, site-component status, SQL and SMS Provider health, and access to content locations. Note whether failures began after an upgrade, maintenance, a SQL or SUP change, certificate work, or another site change. Do not start by deleting ADRs or rebuilding the software update point.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The expected update is absent

Check synchronization status and confirm that the update’s product, classification, and language metadata are enabled and visible in the console. If the update is not present there, the ADR may be operating correctly against incomplete or unavailable metadata. Review wsyncmgr.log and the Software Update Point synchronization status when synchronization is incomplete.

The rule returns zero updates

Compare the update’s metadata with every ADR criterion: product, classification, release or revision date, language, supersedence, expiry, status, and any title, article-ID, or description filters. A narrow rule can legitimately match nothing. Zero matches are not automatically the same as an execution failure; behavior can depend on configuration and Configuration Manager release.

The ADR succeeds but updates do not reach clients

Stop treating this as an ADR failure. Investigate client policy retrieval, update scanning and applicability, boundary groups, distribution-point availability, content download, maintenance windows, enforcement and restart settings, and client health. Use client-side scan, download, enforcement, and state-message logs for those later stages rather than relying on ruleengine.log alone.

Check synchronization timing and ADR filters

An ADR can only select update metadata that has synchronized and been processed. Confirm synchronization completed before the ADR ran, especially after a monthly release or a change to products and classifications. If an ADR is scheduled too close to synchronization, it may evaluate before the expected metadata is ready. Review wsyncmgr.log and adjust the schedule so the rule runs after synchronization and processing finish.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect each filter independently rather than changing several at once. Common causes of unexpected results include a product selection that does not match the update’s metadata, a date boundary that excludes the release, supersedence or expiry settings that remove the desired update, a language mismatch, or a title filter made brittle by naming changes. Preview, feature, driver, or definition updates can also be included or excluded unintentionally.

Check the update group, deployment, and content path

Review what the ADR is set to create or update: a new or existing software update group, a new or existing deployment, its target collection, and any package or content source. Verify that referenced objects still exist and that the site server can access the content path. A missing collection, removed package, inaccessible source, or manually altered object can cause a failure at a later stage even when update selection is correct.

For content-related failures, inspect the relevant context in ruleengine.log and, as indicated by the operation, PatchDownloader.log, PkgXferMgr.log, or distmgr.log. These logs correspond to different download, transfer, and distribution activities; not every ADR failure will appear in all of them. A package or content problem is not fixed by changing update filters.

Read the actual error, not just the alert name

“ADR Rule Failure” is not a universal error code. The hexadecimal code and message in the log must be interpreted with the operation that failed, the surrounding entries, and the Configuration Manager version. One reported ADR example includes 0x87D20417 in a Microsoft 365 update context; it should not be treated as the standard code for ADR failures or as a diagnosis on its own. Reported ADR error example

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Provider- or SQL-related exceptions call for checking the matching SMS Provider or SQL logs and service availability. Deployment and collection interactions may also warrant reviewing colleval.log and status messages. Follow the specific error context rather than assuming every failure belongs to one component.

A message such as “Failed to load additional properties XML doc” has appeared alongside CRuleHandler::CreateFailureAlert in a forum report, but that report does not establish a general cause or verified fix. Treat it as a clue to examine surrounding log entries, not as a diagnosis by itself. Example forum report

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Enable alerts and email notifications

Turn on an ADR failure alert

  1. For an existing rule, go to Software Library > Software Updates > Automatic Deployment Rules, right-click the ADR, and choose Properties.
  2. Open the Alerts tab, enable Generate an alert when this rule fails, and apply the change.
  3. When creating an ADR, enable the equivalent failure-alert option on the wizard’s Alerts page.

Console labels can vary with Configuration Manager release and console language, so check the installed console. ADR failure alert configuration · Alert setup for existing and new ADRs

Subscribe to email

  1. Go to Monitoring > Alerts > All Alerts, select the relevant Rule Failure Alert, and choose Create Subscription.
  2. Enter a subscription name and recipient address.
  3. Under Monitoring > Alerts > Subscriptions, configure the required email settings, including SMTP server and sender; supply authentication and encryption settings if required by your environment.
  4. Test delivery and check subscription status.

An alert in the console with no email is a notification-delivery problem, not proof that the ADR failed differently. Check SMTP reachability, TLS and authentication requirements, relay permissions, firewall rules, recipient filtering, and quarantine or spam handling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recover safely and verify the result

Edit the existing ADR when the evidence points to a filter mistake or another correctable setting and its referenced objects remain valid. This preserves its existing deployment history. Recreating it is a later option when metadata is demonstrably corrupted, referenced objects cannot safely be restored, or a verified product-specific procedure recommends it. Recreation can produce duplicate update groups, deployments, alerts, and reporting objects, so validate the current objects first.

  1. Correct the identified cause, then confirm synchronization and relevant component health.
  2. Check the ADR filters and referenced collection, deployment, package, and content source.
  3. Run the ADR manually if the console offers that action, or allow its next scheduled run. Watch ruleengine.log for the new execution.
  4. Confirm the expected software update group and deployment were created or updated.
  5. Verify content distribution separately, then check that clients receive policy, scan, and proceed with deployment.

Do not keep retrying while the same error repeats, synchronization is still in progress, SQL or provider health is degraded, or the run risks creating duplicate objects. If the failure remains unclear, preserve the complete error context and escalate with the Configuration Manager version, site details, synchronization state, and steps already taken.

Prevent the next silent patching gap

  • Schedule ADRs after software-update synchronization and metadata processing complete.
  • Enable failure alerts and test their email subscriptions rather than assuming notifications work.
  • Keep filters understandable and review them when products, classifications, update naming, or deployment requirements change.
  • Monitor site-component and synchronization status, and compare the ADR result with the expected update set.
  • Use a pilot collection where appropriate, and document the ADR’s schedule, intended update scope, and target objects.

When another management platform is relevant

Moving to Intune or co-management is a strategic change to endpoint management, not a repair for a failed Configuration Manager ADR. Configuration Manager may remain appropriate for organizations with an established site infrastructure and deployment workflows; Intune can be a cloud-management alternative or complement. Licensing and included capabilities depend on the specific plan, agreement, assignment model, and region. Review Microsoft’s Configuration Manager licensing terms and Intune plans and pricing for the applicable terms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.