What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
If SCCM clients are not detecting, reporting, downloading, or installing software updates, do not begin by deleting the SoftwareDistribution folder or reinstalling the client. First identify the failing stage: policy delivery, software update point (SUP) assignment, Windows Update Agent scanning, WSUS communication, compliance reporting, content download, or installation.
SCCM is now called Microsoft Configuration Manager; “SCCM” remains the common search term. This guide applies primarily to current-branch Configuration Manager environments using an on-premises SUP and Windows Server Update Services (WSUS).
First identify what is actually failing
Software-update troubleshooting becomes much faster when you separate scanning from detection, reporting, downloading, and installation. The following table identifies the most likely failure stage and the first evidence to collect.
Recommended Free Tools
| Symptom | Probable stage | First evidence |
|---|---|---|
| Software Updates actions are missing in Control Panel | Client agent, client settings, or damaged client | Configuration Manager client properties and the CcmExec service |
No new entries appear in WUAHandler.log after triggering a scan |
No scan policy or no SUP returned | ScanAgent.log, PolicyAgent.log, and LocationServices.log |
| The client has no valid WSUS URL | SUP location, boundary group, policy, or Group Policy conflict | WUAHandler.log and Windows Update policy registry values |
The scan returns 0x802440xx or timeout errors |
Connectivity, proxy, firewall, IIS, WSUS, or TLS | WUAHandler.log, Windows Update logs, and IIS logs |
| The scan completes but the console remains “Unknown” | State-message, policy, database, or reporting delay | StateMessage.log, UpdatesStore.log, and PolicyAgent.log |
| Updates are detected but do not download | Distribution point, boundary group, content, BITS, or cache | CAS.log, ContentTransferManager.log, and DataTransferService.log |
| Updates download but fail to install | Windows Update Agent, servicing, reboot, applicability, or update-specific issue | UpdatesHandler.log, WUAHandler.log, and Windows Update logs |
| Only one update fails | Supersedence, applicability, detection, or package issue | Update metadata and UpdatesHandler.log |
| All clients fail | SUP/WSUS synchronization, infrastructure, certificate, or network issue | WCM.log, WSUSCtrl.log, wsyncmgr.log, WSUS, and IIS |
| Only a subset of clients fails | Boundary, duplicate identity, local policy, proxy, or machine health | Comparison of failing and working clients |
Microsoft’s software update management troubleshooting flow separates client scanning, synchronization, installation, supersedence, detection, and deployment problems. That separation is more reliable than applying a generic Windows Update reset.
#1 Best Overall
The Configuration Manager software-update scan path
A client must complete several stages before a missing update can be installed:
Policy
→ Management Point
→ SUP location
→ Windows Update Agent
→ WSUS scan
→ Applicability and compliance evaluation
→ State message
→ Deployment, content download, installation, and reporting
- The client receives current machine policy.
ScanAgentrequests a software update point location from the management point.- The client configures Windows Update Agent (WUA) with the SUP’s WSUS URL and port.
WUAHandlerasks WUA to scan.- WUA communicates with WSUS and evaluates update applicability.
- Configuration Manager records local compliance and sends state messages.
- If an update is required and deployed, the client locates content, downloads it, installs it, and reports the result.
A failure at one stage can make a later stage appear broken. For example, an update cannot download if the scan never established that it is required, and the console cannot show current compliance if state messages never reach the management point.
Quick fix checklist
For a single affected device, use the built-in client actions before making invasive changes:
- Record the current time and the last known scan timestamp.
- Open Control Panel → Configuration Manager → Actions.
- Run Machine Policy Retrieval & Evaluation Cycle.
- Wait for policy processing to finish.
- Run Software Updates Scan Cycle.
- If an update is already deployed, run Software Updates Deployment Evaluation Cycle.
- If compliance reporting is stale and the action exists in your client version, run State Message Refresh.
- Review fresh entries in
ScanAgent.logandWUAHandler.log.
From the Configuration Manager console, the equivalent client-notification actions are Download Computer Policy, Software Updates Scan Cycle, and Evaluate Software Update Deployments.
These actions are asynchronous. A scan evaluates applicability; it does not automatically install every missing update. Installation remains subject to deployment targeting, deadlines, maintenance windows, content availability, restart requirements, and deployment settings. Microsoft documents the available scan methods in its software update planning guidance.
Step-by-step client troubleshooting
1. Confirm the client and software-update setting
Verify that the Configuration Manager client is installed, the CcmExec service is running, and the device has current client settings. The Software Updates client setting must be enabled. If the Software Updates actions are absent, investigate client installation, client assignment, client settings, and WMI or client health before troubleshooting WSUS.
Do not reinstall the client automatically. A reinstall will not repair a broken SUP, an incorrect boundary group, a domain Group Policy conflict, a firewall rule, a WSUS database, or missing distribution-point content.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →2. Confirm policy and SUP assignment
Review the logs in this order:
PolicyAgent.log: confirms whether software-update policy was received.LocationServices.log: shows the management point and SUP location returned to the client.ScanAgent.log: records scan requests and SUP location activity.
If a fresh scan produces no new WUAHandler.log activity, do not reset Windows Update yet. The client may not have received policy or may not have received a valid SUP from the management point.
Check that the device belongs to the expected Configuration Manager site and boundary group, and that the boundary group has an associated SUP. If multiple SUPs are available, verify their association and failover design. Configuration Manager can retry a failed scan and switch SUPs under documented conditions, but switching is not necessarily immediate and can increase network traffic.
Rank #2
3. Check the WSUS URL and port
Configuration Manager normally configures local Windows Update policy for the assigned SUP. Check these registry locations:
HKLMSOFTWAREPoliciesMicrosoftWindowsWindowsUpdate
HKLMSOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU
Important values include:
WUServer
WUStatusServer
UseWUServer
WUServer and WUStatusServer should point to the expected SUP’s WSUS URL using the correct protocol and port. Common WSUS defaults are:
HTTP: 8530
HTTPS: 8531
However, WSUS can also use ports 80 or 443. Do not replace the values with a universal example. The client, SUP configuration, WSUS website, IIS bindings, and firewall must all agree.
4. Check for a Group Policy override
A domain Group Policy can overwrite the policy that Configuration Manager configures locally. Compare the expected SUP with the Resultant Set of Policy and the registry values on the client.
gpupdate /force
gpresult /h C:Tempgp.html
Open the generated report and inspect the policy setting for the intranet Microsoft update service location. Also review the relevant Windows Update policy values and the policy-related entries in WUAHandler.log.
The durable fix is to remove, correct, or properly scope the conflicting GPO. Repeatedly deleting the registry values is not a solution: Configuration Manager or domain policy may recreate them, while the underlying assignment conflict remains.
Free tools Windows power users keep installed
One-click scans. No signup required.
5. Test DNS, ports, and HTTP communication
Use the hostname and port shown in the client logs rather than assuming the common defaults:
Resolve-DnsName SUP01.contoso.com
Test-NetConnection SUP01.contoso.com -Port 8530
Test-NetConnection SUP01.contoso.com -Port 8531
A successful TCP test proves only that a connection can be established. It does not prove that WSUS is answering correctly, authentication works, the certificate is valid, or that a proxy is not interfering.
Useful WSUS endpoints, using your actual server and port, include:
Rank #3
/Selfupdate/wuident.cab
/ClientWebService/client.asmx
/ServerSyncWebService/ServerSyncWebService.asmx
/SimpleAuthWebService/SimpleAuth.asmx
For HTTPS SUPs, verify that the client trusts the certificate chain, the certificate name matches the server name used by the client, the certificate is valid, and TLS inspection is not replacing or breaking the connection. Do not change HTTPS to HTTP merely to make a scan work; repair the certificate, binding, trust, TLS, or name-resolution problem instead.
Proxy testing also requires care. A browser test may use the logged-on user’s proxy while WUA or the Configuration Manager client uses a different service or machine context. Test under the relevant context and compare the result with WSUS and IIS logs. Microsoft recommends IIS logs to determine whether an HTTP timeout or error originated at WSUS or between the client and WSUS, such as at a proxy or firewall.
6. Read Windows Update Agent results
WUAHandler.log shows Windows Update Agent search activity and results. WindowsUpdate.log provides deeper Windows Update Agent and WSUS communication details. Look for the exact HRESULT, HTTP status, server URL, timeout, authentication error, or component failure.
Common 0x802440xx and timeout-style errors generally point toward connectivity, proxy, firewall, IIS, WSUS, or TLS problems, but the exact code and surrounding log entries matter. Avoid selecting a repair command solely because an error code appears in a search result.
7. Separate scanning from compliance reporting
A completed WUA scan does not guarantee that the Configuration Manager console immediately displays current compliance. Check:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsWUAHandler.log: did the search complete?UpdatesStore.log: were update states recorded locally?StateMessage.log: were the states generated and sent?PolicyAgent.log: did the device receive the relevant policy?- Management point and site-database processing.
- The last scan and last state-message timestamps.
If the device scans successfully but remains “Unknown,” the fault may be reporting or state-message processing rather than scanning. A triggered scan is not proof of an updated console result.
In co-managed environments, scope the conclusion carefully. The tenant-attach Software Updates view is populated from Configuration Manager scan data and does not show updates managed by Intune when the Windows Update workload is assigned to Intune.
Fix common client-side causes
Windows Update component or servicing corruption
Use component repair only when logs indicate a Windows Update Agent, servicing, missing-file, registry, or component-registration problem. Preserve the error evidence first, export relevant registry keys, check for a pending reboot, and confirm the device is not in the middle of servicing.
These standard Windows servicing commands are reasonable initial checks:
Rank #4
DISM.exe /Online /Cleanup-Image /RestoreHealth
sfc.exe /scannow
A more invasive Windows Update reset may involve stopping update-related services and renaming local update-cache folders instead of immediately deleting them. The correct procedure varies by Windows version, servicing state, update-agent condition, and whether the device is using WSUS, Microsoft Update, or co-management. Do not treat a one-size-fits-all reset script as a universal SCCM repair.
Duplicate WSUS client identity
Cloned or improperly imaged machines can share WSUS client IDs. Possible symptoms include devices replacing one another in WSUS, missing or incorrect WSUS status, and apparently successful scans that produce confusing inventory or compliance results.
Prove that identity is the issue using WSUS and client evidence before performing duplicate-ID cleanup. It is not a generic remedy for a client that cannot locate its SUP.
Pending reboot or servicing state
A pending restart can block installation and sometimes complicate servicing operations. Check reboot-related evidence in RebootCoordinator.log, UpdatesHandler.log, Windows Update logs, and the operating system’s servicing state. A pending reboot does not explain every scan failure, so do not use it as a substitute for checking policy and SUP connectivity.
Fix SUP and WSUS-side problems
If many clients fail at the same time, begin with the SUP and WSUS infrastructure rather than resetting every endpoint. The SUP is required before Configuration Manager can display software-update compliance data or deploy software updates.
Read the server-side logs
SUPSetup.log: whether the SUP role installed successfully.WCM.log: whether Configuration Manager can configure and connect to WSUS.WSUSCtrl.log: whether WSUS is configured, reachable, and healthy from the site’s perspective.wsyncmgr.log: whether synchronization completed or failed.PatchDownloader.log: whether update content could be downloaded to the site server.ruleengine.log: whether an automatic deployment rule identified updates and created or updated deployments.- IIS logs: whether WSUS received and answered client requests.
Check synchronization and catalog scope
If no new updates appear in the console, confirm that WSUS synchronization succeeds independently and that the SUP has the required products, classifications, and languages selected. Then verify WSUS website health, IIS bindings, database connectivity, permissions, and the WSUS administration components required by the site server and any remote SUP.
Select only the products and classifications your organization needs. Excessive catalog scope increases WSUS database workload and the amount of update metadata clients must evaluate. Increasing scan frequency below the normal cadence can also hurt performance rather than fixing stale compliance.
wsusutil.exe reset is a WSUS synchronization or content-repair operation for appropriate WSUS scenarios. It is not a universal client-side scan fix. Use it only after identifying a WSUS content or synchronization problem and following the applicable Microsoft procedure in the WSUS synchronization troubleshooting guidance.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteDo not confuse Configuration Manager update repair with client scan repair
CMUpdateReset.exe, located in the site server’s cd.latestSMSSETUPTOOLS folder, is intended to repair failed or stuck in-console Configuration Manager update downloads or replication. It is not the normal solution for a client that cannot scan software updates. Keep site-server servicing problems separate from endpoint WUA and SUP-location problems.
Best Value
When scanning succeeds but updates do not install
If WUAHandler.log shows a completed scan, move to deployment and content troubleshooting:
- Confirm that the update is detected as required.
- Confirm that an active deployment targets the device or its collection.
- Review
UpdatesDeployment.logfor deployment activation and evaluation. - Check content availability on a distribution point.
- Confirm that the device’s boundary group can locate the correct distribution point.
- Review
CAS.logfor content location and cache processing. - Review
ContentTransferManager.logandDataTransferService.logfor the download request and BITS transfer. - Review
UpdatesHandler.logfor installation activity and errors. - Check maintenance windows, deadlines, maximum runtime, user-experience settings, and restart requirements.
- Check whether the update is superseded, expired, declined, excluded, or not applicable to the operating system, architecture, language, or product.
A manual installation can be useful as an isolation test, but it does not prove that Configuration Manager deployment, content distribution, maintenance-window, or reporting behavior is healthy. Microsoft’s deployment troubleshooting guidance treats content download, installation, detection, supersedence, and reboot problems as separate branches.
Repair or reinstall the client only when evidence supports it
- Refresh policy: use when the client lacks current policy or deployment information.
- Repair Windows Update: use when WUA or servicing logs show component corruption or registration problems.
- Repair the Configuration Manager client: use when client components, WMI, policy processing, or client registration are damaged.
- Reinstall the client: use when repair and evidence indicate a damaged or incomplete client installation.
- Repair or reassign the SUP: use when multiple clients receive no valid SUP, cannot communicate with WSUS, or are affected by infrastructure configuration.
Reinstalling the client cannot fix a broken WSUS database, wrong Group Policy, invalid certificate, blocked port, or missing distribution-point content. Resetting Windows Update cannot create missing Configuration Manager policy or repair a broken boundary group.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →How to prove the issue is fixed
Require evidence from a new scan rather than declaring success after a command runs without an error:
- A new scan request appears in
ScanAgent.log. WUAHandler.logshows a completed Windows Update Agent search.- The expected update is reported as required or not required.
UpdatesStore.logrecords the new local state.StateMessage.logsends the state.- The console’s scan or compliance timestamp advances.
- For a deployed update,
UpdatesDeployment.logandUpdatesHandler.logshow evaluation and installation progress. - After any required restart, the device reports the expected final state.
Compare the result with a known-good device in the same site and boundary group. This helps distinguish a local machine problem from a policy, SUP, network, or WSUS problem.
Escalation packet for unresolved issues
Collect the following before escalating to another administrator, Microsoft support, or a vendor:
- Device name, site code, boundary group, and assigned SUP.
- Whether the issue affects one device, a collection, or all clients.
- The exact error code and the local time and UTC time of reproduction.
- Fresh copies of
PolicyAgent.log,LocationServices.log,ScanAgent.log,WUAHandler.log,WindowsUpdate.log,UpdatesStore.log, andStateMessage.log. - For deployment failures,
UpdatesDeployment.log,UpdatesHandler.log,CAS.log,ContentTransferManager.log, andDataTransferService.log. - For infrastructure failures,
WCM.log,WSUSCtrl.log,wsyncmgr.log, IIS evidence, and synchronization results. - The
gpresultreport and the client’s WSUS URL and port. - DNS and connectivity test results.
- Whether a known-good device works with the same SUP and boundary group.
- Whether the problem affects every update or only one update.
Optional tools: when they help and when they do not
Native Configuration Manager troubleshooting should come first. Commercial tools can reduce operational effort, but they do not repair the underlying patching chain.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Recast Right Click Tools
Recast Right Click Tools can expose remote Configuration Manager client actions, including Software Updates Scan Cycle and Software Updates Deployment Evaluation Cycle. It is useful for teams that need console-based remote actions and collection-scale operations. The action still requires a functioning Configuration Manager client and may require remote WMI and firewall permissions. It will not repair a broken SUP, WSUS service, policy assignment, or network path. See the official scan-cycle documentation.
Patch My PC
Patch My PC publishes and automates third-party application updates through Configuration Manager’s software-update infrastructure. It is a good fit when the real gap is third-party application coverage and publisher maintenance. It is not a fix for failed client scanning, invalid SUP assignment, unhealthy WSUS, or blocked connectivity. Its Configuration Manager integration documentation explains that publishing can trigger SUP synchronization and that the product category must be enabled in the SUP configuration.
Native Microsoft Configuration Manager
Configuration Manager provides SUP/WSUS-based update management, client actions, deployment evaluation, compliance reporting, and current-branch servicing. It suits organizations already licensed for and operating the Microsoft management stack. Licensing is generally tied to Microsoft licensing arrangements rather than a simple standalone utility, so pricing must be checked against the organization’s current agreement.
Use Recast when remote remediation is the operational bottleneck, Patch My PC when third-party application patch coverage is the bottleneck, and native tools when the problem is the underlying scan path. None of these choices replaces fixing policy, boundaries, certificates, ports, WSUS, or client health.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsBottom line
SCCM software-update scan issues are chain failures, not automatically cache failures. Start with scope, refresh policy, trigger a scan, and follow the evidence through ScanAgent.log, WUAHandler.log, Windows Update, state reporting, and deployment logs. Repair the specific failing layer—policy, SUP assignment, WSUS communication, WUA, reporting, content, or installation—and validate the fix with fresh logs and an updated compliance timestamp.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

