Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteYes—you can deploy Microsoft Connected Cache for Enterprise and Education without Configuration Manager or an SCCM Distribution Point. Create the cache resource and node in Azure, run Microsoft’s generated deployment package on a supported Windows or Linux host, then direct Intune-managed Windows devices to it with the Delivery Optimization DOCacheHost policy. Optional Delivery Optimization peer-to-peer can provide an additional source, but it is separate from the cache server.
What Connected Cache replaces—and what it does not
Standalone Microsoft Connected Cache for Enterprise and Education is different from the older Configuration Manager-integrated Connected Cache feature. The standalone product requires no Configuration Manager site server, management point, boundary group, or Distribution Point. It runs on customer-supplied physical or virtual infrastructure; Azure provides the management resource and node registration.
The separate Configuration Manager scenario still runs Connected Cache on a Distribution Point. Do not treat the standalone product as merely an SCCM role with the name removed. See Microsoft’s standalone overview and Configuration Manager comparison.
How the topology works
Intune-managed Windows clients
│
├── Connected Cache node ── Microsoft CDN on a cache miss
│
└── Optional Delivery Optimization peers
The first eligible request fills the local cache. Later requests can be served locally. Delivery Optimization may also exchange pieces with eligible Windows peers. If the node or peers are unavailable, clients can fall back to Microsoft’s CDN, so a successful download alone does not prove cache use.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- 64 bit | 1 Server with 16 or less processor cores | provides 2 VMs
- For physical or minimally virtualized environments
- Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
- Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
- Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.
What it can cache
Connected Cache is for supported Microsoft content delivered through Delivery Optimization, not an arbitrary third-party package repository. Eligible categories include:
- Windows feature and quality updates.
- Microsoft 365 Apps, Edge and other supported Microsoft updates.
- Intune Win32 application content.
- Autopilot-related content.
- Microsoft Defender definition updates.
- Teams content when HTTPS support is configured.
Confirm the current endpoint and content list in Microsoft’s Delivery Optimization documentation. Secure URLs that the node cannot serve bypass it and use the CDN.
Prerequisites and sizing
Licensing and cost
Microsoft says the Connected Cache Azure resource itself has no Azure service charge. Your VM compute, managed disks, bandwidth, monitoring, certificates, operations and any Windows licensing still cost money. Eligible Windows desktop subscriptions and Windows Server Standard, Datacenter or Datacenter: Azure Edition licensing are documented in the prerequisites.
Host baseline
- At least 4 GB free memory and 100 GB free disk space.
- Inbound and outbound connectivity on ports 80 and 443.
- One network interface; multiple NICs are unsupported.
- A 1 Gbps NIC is the recommended minimum.
- SSD storage is recommended for this read-intensive workload.
| Deployment size | CPU | Memory | Storage guidance |
|---|---|---|---|
| Branch office | 4 cores | 8 GB (4 GB free) | 100 GB free |
| Small or medium enterprise | 8 cores | 16 GB (4 GB free) | 500 GB free |
| Large enterprise | 16 cores | 32 GB (4 GB free) | Two 200–500 GB drives |
These are Microsoft recommendations, not performance guarantees; concurrency, disk throughput, cache size, network speed and repeated-content volume determine actual results. Microsoft reports more than 90% savings in some customer deployments, but that is not a promised outcome. See the FAQ.
Rank #2
- Offers quick and easy installation on PC
- The software is licensed for 5 User CAL
Choose Windows or Linux
| Consideration | Windows VM | Linux VM |
|---|---|---|
| Supported systems | Windows 11 or Windows Server 2022 or later | Ubuntu Server 24.04 or RHEL 8/9 |
| Runtime | WSL-based deployment | Native Linux deployment bundle |
| Important prerequisites | Nested virtualization, PowerShell 5.1, Hyper-V PowerShell tools, IP Helper and a runtime account | Replace RHEL’s default Podman engine with Moby |
| Best fit | Windows-focused teams reusing existing capacity | Dedicated cache appliances and established Linux/container operations |
| Trade-off | Windows licensing and WSL/virtualization dependencies | Linux lifecycle and container administration |
Windows 11 requires build 22631.3296 or later; Windows Server 2022 requires build 20348.2227 or later. Azure Windows VMs must expose nested virtualization. Trusted Launch or a selected VM size can prevent that. Linux is not universally better; choose according to skills, identity, security and patching standards. Details are in Microsoft’s requirements.
Deploy the cache node
1. Plan the site
- Choose a node per suitable site or region, not automatically per subnet.
- Record client routes, DNS name, IP address, firewall rules and expected concurrency.
- Decide between static
DOCacheHostand DHCP Option 235 discovery. - Reserve disk capacity and plan the certificate and HTTPS name.
The node still needs access to Microsoft services and CDN endpoints; it is not an offline distribution point.
2. Prepare a Windows host
Verify the IP Helper service:
Get-Service -Name iphlpsvc | Select-Object Name, Status, StartType
If necessary:
Set-Service -Name iphlpsvc -StartupType Automatic
Start-Service -Name iphlpsvc
Also verify the supported build, nested virtualization, free port 80, port 443 access, Hyper-V PowerShell Management Tools, PowerShell 5.1 and a supported Group Managed Service Account, local user, domain user or service account. Microsoft’s Windows procedure is at Deploy Connected Cache to Windows.
3. Prepare a Linux host
Use Ubuntu Server 24.04 or RHEL 8/9, open ports 80 and 443, provide the required storage and memory, and replace Podman with Moby on RHEL. Use Microsoft’s Linux deployment procedure.
Rank #3
- Server 2022 Standard 16 Core
4. Create the Azure resource and node
- Open the Connected Cache management experience in Azure.
- Create the Connected Cache resource and a cache node.
- Select Windows or Linux.
- Copy the tenant- and node-specific deployment command generated by the portal.
- Run it on the prepared host with the required privileges and supported shell.
- Wait for the node to report healthy, then record its FQDN or IP address.
Configure Intune Delivery Optimization
Create a device-scoped Delivery Optimization policy in Intune and set DOCacheHost to the node name or address:
mcc-site01.contoso.com
Multiple hosts are comma-separated:
mcc-site01.contoso.com,mcc-site02.contoso.com
Clients do not use all listed hosts simultaneously; they round-robin until one connects successfully. The underlying policy path is ./Device/Vendor/MSFT/Policy/Config/DeliveryOptimization/DOCacheHost. You can also use Group Policy, another MDM, or DHCP Option 235 through DOCacheHostSource. Current Intune profiles may label the setting DO Cache Host or, in older profiles, Cache server host names. Verify the label in your tenant. See the DeliveryOptimization policy CSP.
Connected Cache versus peer-to-peer
| Feature | Connected Cache | Delivery Optimization peer-to-peer |
|---|---|---|
| Dedicated server | Yes | No |
| SCCM Distribution Point | No for standalone MCC | No |
| Source | Cache node, then CDN | Eligible Windows peers, with cache/CDN fallback |
| Predictability | Higher when sized and reachable | Depends on peer availability and network policy |
| Main risk | Host sizing and availability | Unwanted cross-site, VPN or Wi-Fi traffic |
Configuring Connected Cache does not enable peer sharing. Enable peer downloads separately, choose a suitable mode and scope peers to an appropriate network group. VLAN isolation, VPN routing, NAT, Wi-Fi client isolation, firewalls and sleeping devices can prevent peer transfers.
Enable HTTPS before production
HTTP-only guidance is outdated for secure content. Configure HTTPS for Intune Win32 and Teams scenarios; Microsoft announced enforcement for Intune Connected Cache scenarios beginning June 16, 2026, or soon after. Treat HTTPS as a production requirement now.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- 64 bit | 1 Server with 24 or less processor cores | provides 2 VMs
- For physical or minimally virtualized environments
- Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
- Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
- Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.
Plan certificate-signing request generation, CA signing, certificate import, DNS-name matching, client trust-chain validation and separate Windows/Linux procedures. Exclude *.do.dsp.mp.microsoft.com from TLS inspection where required; interception can break deployment and operation. Use Microsoft’s HTTPS overview, Windows reference and the HTTPS enforcement announcement.
Validate that traffic is local
- Confirm the device received
DOCacheHostfrom Intune. - Resolve the cache FQDN and test ports 80/443 from a client subnet.
- Check the node’s health and activity in Azure.
- On a Windows client, run
Get-DeliveryOptimizationStatus - Request a repeatable supported payload from several pilot devices.
- Compare cache-node metrics, Delivery Optimization state and CDN fallback behavior.
- If peers are enabled, verify peer transfers separately rather than assuming cache hits are peer hits.
For standalone Connected Cache, use current portal metrics and client Delivery Optimization status; do not assume fields documented for the Configuration Manager-integrated scenario, such as BytesFromCacheServer, appear identically everywhere.
Troubleshooting branches
Port 80 is occupied
Find and remove or relocate the conflicting IIS, proxy, application or former Distribution Point service. A dedicated host is safest.
PowerShell 7 reports deployment errors
Run Microsoft’s deployment scripts in Windows PowerShell 5.1; they are not compatible with PowerShell 7.x.
Best Value
- Unlock all the features by installing this product on PC
- The software is licensed for 1 User CAL
Nested virtualization is unavailable
Select an Azure VM size that supports it, review security settings such as Trusted Launch, or choose a Linux design.
Remote clients cannot connect
Check that IP Helper is running, DNS resolves correctly, and firewalls or NSGs allow the required ports.
Clients still use the CDN
Check policy arrival, DNS, ports, node health, content eligibility, HTTPS certificates, TLS inspection and conflicting Delivery Optimization policies. CDN fallback is a resilience feature, not automatic proof of failure.
A forward proxy breaks the node
Connected Cache is a reverse proxy. Microsoft warns that forward proxies performing caching or requiring absolute-form URLs, including many Squid configurations, are incompatible unless they support the required origin-form behavior. See the proxy requirements.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →When this design is worthwhile
- Many devices at a site repeatedly download the same Microsoft payloads.
- WAN or internet capacity is constrained.
- The organization is Intune-only or reducing Configuration Manager dependence.
- A supported Windows or Linux host, certificate process and outbound connectivity are available.
- Peer traffic can be tightly scoped—or deliberately disabled for predictability.
Start with one representative site, one node, a controlled Intune group, HTTPS enabled and peer-to-peer disabled or narrowly scoped. Measure WAN bytes, cache activity and deployment duration before expanding.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

