Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Configuration Manager (formerly SCCM) includes 31 built-in software-update reports in its documented current-branch catalog: nine compliance reports, eight deployment-management reports, six deployment-state reports, four scan reports and four troubleshooting reports. Together, they help answer whether updates are applicable, deployed, available for download, evaluated, enforced and reported.

These are SQL Server Reporting Services (SSRS) reports that read data stored in the Configuration Manager site database. They are not live client diagnostics. A successful report run does not prove that a client scanned, downloaded, installed or restarted for an update.

What Configuration Manager software-update reports do

The reports are predefined SSRS reports delivered with Configuration Manager. A Reporting Services point copies the report definitions to SSRS, creates the report folders and applies Configuration Manager role-based security. Administrators can run them from the console or, where configured, from the SSRS web portal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

They are different from the Software Updates node in the console, WSUS views, Windows Update history, client logs and custom SQL or Power BI dashboards. Reports show the update and state-message data that has reached the site database at the time the report runs.

The reporting data path

Microsoft Update
  → WSUS / Software Update Point synchronization
  → Configuration Manager metadata
  → Client policy
  → Client scan
  → Applicability and compliance
  → Deployment evaluation
  → Content download
  → Installation and enforcement
  → State messages
  → SSRS report

This is why SSRS can be healthy while compliance data is stale, scan failures remain unresolved or a client has not returned current state messages.

Prerequisites

Before expecting useful software-update results, verify the following:

  • SQL Server Reporting Services is installed and configured on the target site system.
  • The report server is in native mode and its web-service URL is valid.
  • A Configuration Manager Reporting Services point is installed and connected to the site database.
  • The report service is running and the report-server URL opens from the administrator’s workstation.
  • The user has the required Configuration Manager RBAC, site, collection and report-execution permissions.
  • The Software Update Point and WSUS infrastructure are functioning if update compliance data is required.

The Reporting Services point delivers and secures reports; it does not synchronize update metadata or make clients scan. Follow Microsoft’s reporting configuration guidance and software-update setup guidance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s current documentation recommends SQL Server 2017 or later for the Reporting Services point. Compatibility is release-sensitive, particularly with newer SQL Server reporting changes, so verify the supported combination for your Configuration Manager release before upgrading.

How to run a report

  1. Open the Configuration Manager console.
  2. Go to Monitoring > Reporting > Reports.
  3. Filter or sort for the Software Updates category.
  4. Open one of these folders: A Compliance, B Deployment Management, C Deployment States, D Scan or E Troubleshooting.
  5. Right-click a report and select Run.
  6. Choose its collection, update group, deployment, software update, vendor, date or state parameters.

Reports can also be opened through the SSRS web portal if browser access and permissions are available. Secondary reports often receive hidden parameters from a parent report; opening one directly can produce an empty result or missing-parameter error.

Complete software-update report catalog

Compliance reports

Report What it answers Useful next step
Compliance 1 – Overall compliance Overall compliance for an update group. Compliance 7 or 9
Compliance 2 – Specific software update Compliance for one update. Compliance 6 or 8
Compliance 3 – Update group (per update) Results for each update in an update group. Specific-computer report
Compliance 4 – Updates by vendor month year Compliance for a vendor’s updates during a selected month and year. Specific update reports
Compliance 5 – Specific computer Update compliance for one computer, with optional vendor or classification filters. Deployment-state reports
Compliance 6 – Specific software update states (secondary) Counts and percentages by state for one update. Compliance 8
Compliance 7 – Computers in a specific compliance state for an update group (secondary) Devices in a selected state for an update group. Client logs
Compliance 8 – Computers in a specific compliance state for an update (secondary) Devices in a selected state for one update. Update-specific logs
Compliance 9 – Overall health and compliance Combined health and compliance for an update group. Microsoft lists it as available beginning with version 1806. Scan and state reports

Compliance does not necessarily mean “installed successfully in the latest deployment.” An update can be compliant because it is installed, not applicable, superseded or otherwise not required. Use deployment and enforcement reports when installation timing matters.

Deployment-management reports

Report What it answers Common interpretation
Management 1 – Deployments of an update group Which deployments contain all updates in an update group. Confirms deployment existence.
Management 2 – Updates required but not deployed Which required vendor updates are absent from deployments for a collection. Usually a targeting or deployment-design issue.
Management 3 – Updates in a deployment Which updates are included in a deployment. Confirms deployment contents.
Management 4 – Deployments that target a collection Which deployments target a collection. Checks collection targeting.
Management 5 – Deployments that target a computer Which deployments target a device. Checks device targeting.
Management 6 – Deployments that contain a specific update Which deployments contain an update. Checks update placement.
Management 7 – Updates in a deployment missing content Which deployment updates lack available content. Investigate distribution points.
Management 8 – Computers missing content (secondary) Which devices require an update whose content is unavailable from a distribution point. Check boundaries and content location.

Deployment-state reports

Report What it answers Use it when
States 1 – Enforcement states for a deployment Installation and enforcement state across a deployment. You need installation progress.
States 2 – Evaluation states for a deployment How clients evaluated updates in a deployment. You need applicability or evaluation results.
States 3 – States for deployment and computer Combined deployment and device state. You need a device-focused view.
States 4 – Computers in a specific state for a deployment (secondary) Devices in a selected deployment state. You need a state drill-down.
States 5 – States for an update in a deployment (secondary) Update-level state inside a deployment. A deployment contains many updates.
States 6 – Computers in a specific enforcement state for an update (secondary) Devices in a selected enforcement state for one update. You need affected-device detail.

Evaluation means the client assessed the deployment and applicability. Enforcement concerns attempting or completing installation. Compliance describes the current update state. Unknown means Configuration Manager lacks a usable current state; it is not automatically an installation failure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scan reports

Report What it answers
Scan 1 – The last scan states by collection Latest scan-state summary by collection.
Scan 2 – The last scan states by site Latest scan-state summary by site.
Scan 3 – Clients of a collection reporting a specific state (secondary) Devices in a selected scan state within a collection.
Scan 4 – Clients of a site reporting a specific state (secondary) Devices in a selected scan state within a site.

Scan reports show reported scan states. They do not alone prove that a client received policy, contacted the correct SUP or downloaded update content.

Troubleshooting reports

Report What it answers
Troubleshooting 1 – Scan errors Aggregated scan errors by site and error condition.
Troubleshooting 2 – Deployment errors Aggregated deployment errors.
Troubleshooting 3 – Computers failing with a specific scan error (secondary) Devices affected by a selected scan error.
Troubleshooting 4 – Computers failing with a specific deployment error (secondary) Devices affected by a selected deployment error.

An error code is a starting point, not a diagnosis. Correlate it with client software-update logs, SUP/WSUS health, content-location results and deployment context.

Which report should you use?

Question Start with Then investigate
Are devices generally patched? Compliance 1 or 9 Compliance 7/8 and States reports
Is one update installed? Compliance 2 Compliance 6/8 and States 5/6
Which devices missed an update group? Compliance 3 or 7 Specific-computer report and client logs
Was an update deployed? Management 1 or 3 Management 4–6
Is an update required but not deployed? Management 2 Collection membership and deployment design
Is content available? Management 7 Management 8 and distribution-point status
Why are clients unknown? Compliance 1/9 Scan 1–4 and state-message health
Are clients scanning? Scan 1 or 2 Scan 3/4 and client scan logs
What scan errors dominate? Troubleshooting 1 Troubleshooting 3
What deployment errors dominate? Troubleshooting 2 Troubleshooting 4 and deployment logs
Did installation begin but fail? States 1–3 States 4–6, client and Windows Update logs
Which deployments affect one device? Management 5 States 3

End-to-end troubleshooting workflow

1. Separate report access from patching

If report folders are missing or reports cannot run, verify the Reporting Services point, SSRS service, native mode, web-service URL, default report server, RBAC and security scopes. Check the SMS_SRS_REPORTING_POINT component and role installation status. A report-access failure is not evidence of a software-update failure.

2. Validate parameters and scope

Confirm the site database, collection, update group, deployment, software update, vendor and date filters. Compare reports only when their scope and execution time match. Large collections and unfiltered update groups can cause slow queries or timeouts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Check synchronization and scanning

Use Scan 1 or 2 and Troubleshooting 1. Then check client assignment, SUP selection, policy receipt, synchronization status, scan timing, Windows Update errors, stale clients and boundary-group connectivity. The reports identify the affected population; logs establish the cause.

4. Check deployment and evaluation

Use Management 1, 4–6 and States 1–3. Verify collection membership, exclusions, deployment purpose, availability, deadline, maintenance windows, restart settings and update applicability.

5. Check content

Use Management 7 and 8. Confirm that the update is in the deployment package, the package reached the relevant distribution points, content validation succeeded and the client’s boundary group can locate it. Metadata synchronization and content distribution are separate operations.

6. Check enforcement and reporting latency

Use States 1, 2, 5 and 6, then correlate with client enforcement logs, Windows Update logs, return codes, restart state and maintenance-window behavior. A successful installation may not appear immediately if state messages have not reached the site database.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common mistakes and edge cases

  • Treating compliance as installation history: compliance reflects current applicability and state, not necessarily the latest deployment attempt.
  • Treating unknown as failure: unknown can result from stale clients, policy problems, scan failures, inactivity or delayed state messages.
  • Blaming SSRS for missing update data: investigate SUP, WSUS, client scanning and state-message flow.
  • Ignoring content distribution: synchronized metadata does not mean update binaries are available.
  • Ignoring restarts and maintenance windows: evaluation may occur before enforcement, and installation may wait.
  • Opening secondary reports directly: use the parent report when it supplies required parameters.
  • Changing the SSRS URL in place: Microsoft’s supported recovery path is to remove the Reporting Services point, change the URL and reinstall the role.
  • Comparing reports run at different times: state messages and summarization can change results.

Built-in reports, custom SSRS and Power BI

Built-in reports are the best starting point for standard compliance, targeting, content and deployment-state questions. They are supported, integrated with RBAC and require no custom SQL maintenance, but their layouts and parameters are fixed.

Create a custom SSRS report when you need device inventory, ownership, business-unit context, scan timestamps, custom exclusions or organization-specific drill-downs. Use supported views and document performance assumptions; do not modify built-in definitions or depend on undocumented database tables.

Power BI Report Server integration is available beginning with Configuration Manager version 2002 and can be useful for trends and executive dashboards. It is not a universal replacement for paginated SSRS operational reports. Newer SQL Server reporting packaging is version-sensitive, so verify support before planning a migration.

Sources

Frequently Asked Questions

How many default software-update reports does Configuration Manager provide?

The documented current-branch catalog contains 31: nine compliance, eight deployment-management, six deployment-state, four scan and four troubleshooting reports. The exact catalog can vary by product release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which report shows updates required but not deployed?

Use Management 2 – Updates required but not deployed, then verify collection membership and deployment design.

Which report identifies missing update content?

Use Management 7 for deployment-level missing content and Management 8 for affected computers.

Can these reports work without a Software Update Point?

The reports may still run, but useful software-update synchronization and compliance data require a functioning SUP/WSUS and client reporting pipeline.

Can I edit the built-in reports?

Use custom reports for organization-specific requirements. Avoid modifying built-in definitions because upgrades can overwrite changes and unsupported SQL dependencies can break.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.