Visit Stack Exchange We have a WSUS server running on Windows Server 2016.

Now you need to configure Group Policy to tell the server to only use the WSUS server.

Per Microsoft these are the required settings (I am dubious on some of them, but I haven't tested each one...

Read on for my experience: In my case the WSUS server was running on Windows Server 2012 R2, had all the patches, had run the VB cleanup script you see floating around, had been through the cleanup process (which took hours), could serve updates to Windows 10 machines but fresh Windows Server 2016 client machines would fail to fetch updates from WSUS and gave 0x8024401c error messages.

The only thing that helped was on the WSUS server: increasing/removing some of the IIS Application Pool resource limits (e.g.

I have a hard time believing that there are 0 applicable updates for a fresh Windows Server 2016 install.

I have ensured that BITS and the Windows Update services are running.

These KBs fix the dual scan issue so the server will respond to the GPO telling it which default source to use.It shows 0 updates needed, all updates show "installed or not applicable".These are fresh server installs, they have just been installed straight from a disk image created November of last year.If I run a report on one of the servers and I set the product filter to "Windows Server 2016" I get 31 updates installed or not applicable. The status for all of them is "Not Applicable" They are all Critical updates and Security Updates.I have manually gone through the installed updates on one of the servers in question and verified that these "Not Applicable" updates are not installed.

