Skip to content
SCCM ConfigMgr Software Updates Deployment Group Policy

SCCM ConfigMgr Software Updates Deployment Group Policy

Written By Anoop C Nair
Last Updated August 1, 2024
Posted In SCCM
SHARE

SCCM ConfigMgr Software Updates Deployment Group Policy. In this post, I will cover the Group Policy changes you need to plan and the SUP enhancements of SP1.

In ConfigMgr 2012 SP1, multiple software update points (SUPs) are available per Primary Site. This change allows for placing SUPs cross-forest and providing fault tolerance without requiring NLB.

If you have already assigned a WSUS server to the clients via group policy, then you won’t be able to take advantage of the new SUP Failover design in SCCM 2012 SP1.

SCCM ConfigMgr Software Updates Deployment Group Policy

SCCM ConfigMgr Software Updates Deployment Group Policy?

Patch My PC
SCCM ConfigMgr Software Updates Deployment Group Policy
SCCM ConfigMgr Software Updates Deployment Group Policy -Fig.1

You must rethink specifying a WSUS server on clients using group policy. SCCM ConfigMgr Software Updates Deployment Group Policy.

How can you take advantage of SUP failover without using NLB?

When you use a WSUS-based method to install client agents, you must use Group Policy to set up a WSUS server. Group Policy is great for assigning a WSUS server to deploy the client. However, it’s not so great if you think from the SUP failover perspective without using NLB. It impacts a client’s ability to switch SUPs for failover. This is one of the disadvantages of the WSUS (SUP) based client installation method.

How to get rid of this issue: Solution for this :

Use GPP. Group Policy Preferences (GPP) provides a great way to conditionally set a WSUS server for your initial client installation. The advantage of GPP is that it still allows ConfigMgr local policy to set the SUP on failover conditions. If you set traditional GPOs for setting the WSUS server on the clients, then the clients will lose the ability to switch SUPs when needed for failover.

Implementing the conditional logic with the help of GPP to set the WSUS server is a great option for both delivering the ConfigMgr client through WSUS and taking advantage of SUP failover after the ConfigMgr client is installed.

Resources

What’s New In SCCM Windows 10 Servicing Dashboard | ConfigMgr HTMD Blog (anoopcnair.com)

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and leader of the Local User Group Community. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc..

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 5 comments

  1. I still have a confusion, Do we need to create GPO for SCCM clients to point to SUP? this will be taken care by MP, is it not?, then what is the need for creating GPO for pointing to SUP? Please help me to understand better.

      1. But often I see many blogs talks about configuring the following GPO during the software update point setup (HKLM/Software/Policies/Microsoft/windows/Windows Update), Do you really think that this is necessary to enforce through GPO, by enforcing through GPO wont it create conflict?

  2. But often I see many blogs talks about configuring the following GPO during the software update point setup (HKLM/Software/Policies/Microsoft/windows/Windows Update), Do you really think that this is necessary to enforce through GPO, by enforcing through GPO wont it create conflict?

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws

Key Takeaways 2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws! The June 2026 Windows 11 Patch Tuesday update brings several improvements to File Explorer. It adds support for additional archive formats, including UU, CPIO, XAR, and NuGet Packages (NUPKG). The update also preserves View and Sort preferences in […]

AC Anoop C Nair 10 min read
Intune

2026 May KB5089549 KB5087420 Windows 11 Patch | 0 Zero Day Vulnerabilities and 120 Flaws

Key Takeaways The Windows 11 May 2026 Patch KB5089549 KB5087420 Update brings important security fixes, performance improvements, and reliability enhancements across the operating system. The update introduces new features such as Xbox Mode for gaming, File Explorer improvements, enhanced input and sharing experiences, better taskbar and Windows Hello reliability, and additional enterprise management capabilities for […]

AC Anoop C Nair 8 min read
SCCM

ConfigMgr 2603 Introduces New Early Update Enrollment Process

Key Takeaways In this post we are discussing the ConfigMgr 2603 Introduces New Early Update Enrollment Process. Microsoft has officially released Configuration Manager version 2603 to the Early Update Ring, giving organizations an opportunity to test upcoming improvements before the global production rollout. The release is targeted at enterprises running ConfigMgr version 2409 or later […]

AC Anoop C Nair 3 min read