A new Flexera Community experience is coming on November 25th. Click here for more information.
In scenarios where SCCM is used to manage all updates on the network, the Windows Update Agent on local Clients ends up in a dead-end when it queries for Microsoft patches as it attempts to look for updates against the Software Update Point which is not authoritative being under the SCCM, however.
As patches are copied by SCCM and re-created for deployment in the form of SCCM objects, all MS entries in the WSUS remain unapproved to Clients which then blocks the Windows Update Agent service of fetching particular information on Microsoft entries.
This sets a requirement for SCCM-based-networks to either allow the Windows Update Agents on clients to seek update information against the official public Microsoft website, or if the network is closed-down for Clients, then the use of offline CAB file detection could become the only remaining option for evaluating the security state of Windows OS components and programs.
This guide helps you configure the detection of missing Microsoft security updates on machines scanned by SVM's Single-host Agents via the use of offline cabinet (.CAB) database files as provided by Microsoft. The following scenarios may require the detection of missing MS security updates via offline cabinet files:
Below we listed the steps you need to take to enable offline detection of missing MS security updates:
(before taking actions, please review the entire article first)
The prerequisites for querying the offline CAB file should be configured properly now.
Your Agents will check-in to their SVM server and download the instructions from there.
Let's confirm that the configuration is working as expected now.
The next steps will help you confirm the outcome of the procedures you performed:
Download the official updated KB file workaround:
If for some reason you are unable to download the CAB file from the link posted in the steps above, go to this link and download the WsusScn2.cab file manually
Maintaining the file updated at all times?
Many times users expect to see many different versions of the official cab file, but in reality, there is only one and it is being updated by Microsoft regularly. To ensure maximum efficiency of the scans, you should consider re-downloading the file from the same download location minimum once a month and re-deploying it to your hosts. Feel free to overwrite the old file, as all you need is the newest file downloaded most recently (also to avoid confusion and mistakes).
How to deploy the CAB file to all machines?
To deploy the cabinet file to each machine, you can use GPO distribution or you can do it via a custom script. In all cases, performing the automatic distribution of the file in any way would save you time and effort in the long term.
Where to store the offline .cab file?
You need to make sure the file ends up in the same directory location on each system.
SVM will look only at one single URL path and it is therefore important not to place the file in different locations on the different systems to be scanned. "C:\wsuscab\" could be a good option.
Setting up the CAB file to a network-shared location - not a workaround!
Don't put the CAB file on a shared drive because this is very unlikely to work. Windows Update Agent does not support this option.
Nov 15, 2018 04:55 PM - edited Sep 19, 2019 06:41 PM