Skip to content
Install New ConfigMgr Software Update Point Role | SUP | SCCM

Install New ConfigMgr Software Update Point Role | SUP | SCCM

Written By Kannan CS
Last Updated July 26, 2024
Posted In SCCM
SHARE

Let’s go through the Install New ConfigMgr Software Update Point Role Guide. In this blog, I have detailed steps to configure the First (Upstream) Software update Role (SUP) role installation for Configuration Manager.

You must Install WSUS for the ConfigMgr Software Update Point Role. This guide explains how to set up a Remote SUP role for SCCM.

The software update point on the central administration site and primary sites is essential to ensure software update compliance assessment and the deployment of software updates to clients. However, it is optional for secondary sites.

It is important to validate that the server fulfils the necessary requirements and evaluate the site’s software update point infrastructure to successfully install the software update point site system role (SUP).

Patch My PC

Related Post SCCM WSUS Cleanup – Fix SCCM Scan Timeout Errors

Index
SCCM SUP Prerequisites -Software Update Point Role
Add Site Server Account
Upstream SUP Role Installation
Add Site Systems Roles
Select a Server to Use as a Site System
Specify Internet Proxy Server
Specify Roles for this Server
Specify Software Update Point Settings
Specify Proxy & Account Settings for Software Update Point
Specify synchronization source settings
Synchronization Settings
Select Behavior for Software Updates is Superseded
Configure WSUS Maintenance Behavior
Configure Maximum Run Time
Specify Configuration for Software Update Content
Select the Software update classifications that you want to Synchronize
Select the Products that You Want to Synchronize
Specify the Language Settings that you want to Synchronize
Confirm the Settings
Progress
Summary
Check the installation Status using the Log File
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Table1

SCCM SUP PrerequisitesSoftware Update Point Role

You need to confirm the operating system support for the SCCM Software Update Point installation from here. The following are some of the other prerequisites of SCCM SUP.

  • Windows Server roles and features
    • .NET Framework 3.5
    • IIS configuration
      • Application Development:
        • ISAPI Extensions
      • Security:
        • Windows Authentication
      • IIS 6 Management Compatibility:
      • IIS 6 Metabase Compatibility
      • IIS 6 WMI Compatibility
  • .NET Framework
    • .NET Framework.NET Framework version 4.5 or later
    • .NET Framework 4.8 (ConfigMgr 1906 or later)
  • SQL Server Native Client

NOTE! If you are installing WSUS and SUP on a remote server, you need to install WSUS Console-related components on your primary server. Otherwise, your SUP installation won’t work.

Add Site Server Account

Ensure your site server has administrative privileges on the remote Software Update Point server before starting the activity.

  • Add Site Server Computer account to SUP (Software Update Point) Server’s local administrator’s Group.

Upstream SUP Role Installation

The following steps will help you learn how to install the Upstream SUP for SCCM. The steps below will instruct you to install the Software Update Role (SUP).

Add Site Systems Roles

Launch the Configuration Manager Console, Select the Administration tab, Expand Overview -> expand Site Configuration, and Select Servers & Site System Roles. Select the < Server>; Right-click and select Add Site Systems Roles in the right-hand panel.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.1
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.1

Select a Server to Use as a Site System

In the Add Site System Roles Wizard window, click Next in the General Tab.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.2
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.2

Specify Internet Proxy Server

In the “Add Site System Roles Wizard” window, navigate to the Proxy tab.

Note: Mention proxy information and account information to connect to the Internet to download the metadata from the Internet

  • Click Next
Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.3
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.3

Specify Roles for this Server

In the Add Site System Roles Wizard window, Select the Software Update point role in the System Role Selection Tab and Click Next.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.4
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.4

Specify Software Update Point Settings

In the Add Site System Roles Wizard window, in the Software Update Point Tab, Select the option WSUS is configured to use ports 8530 and 8531 for client communication (these are the default settings for WSUS on Windows Server 2020).

Click Next.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.5
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.5

Specify Proxy & Account Settings for Software Update Point

In the Add Site System Roles Wizard window, click Next in the Proxy and Account Settings Tab.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.6
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.6

Specify synchronization source settings

In the Add Site System Roles Wizard window, in the Synchronization source Tab, Select the option Synchronize from Microsoft Update and click Next.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.7
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.7

Synchronization Settings

In the Add Site System Roles Wizard window, click Next in the Synchronization Schedule Tab.

NOTE! : Enable the Synchronization on a schedule based on the requirement

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.8
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.8

Select Behavior for Software Updates is Superseded

In the Add Site System Roles Wizard window, click Next in the Superintendence Rules Tab.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.9
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.9

Configure WSUS Maintenance Behavior

In the Add Site System Roles Wizard window, click Next in the WSUS Maintenance Tab.

Note: From SCCM Current branch 1906, enabling the WSUS maintenance options is part of SUP role configuration at the top-level site. For more information https://support.microsoft.com/en-us/help/4490644/complete-guide-to-microsoft-wsus-and-configuration-manager-sup-maint

Configure WSUS Maintenance Behavior - New ConfigMgr Software Update Role
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.10

Configure Maximum Run Time

In the Add Site System Roles Wizard window, click Next in the Maximum Run Time Tab.

Note: Change the update installation maximum amount of time-based on the environment.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.11
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.11

Specify Configuration for Software Update Content

In the Add Site System Roles Wizard window, In the Update Files Tab, Select the option Download full files for all approved updates, and Click Next.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.12
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.12

Select the Software update classifications that you want to Synchronize

In the Add Site System Roles Wizard window, Select the Software update classifications based on the environment in the Classifications Tab.

Click Next.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.13
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.13

Select the Products that You Want to Synchronize

NOTE! – Do Not Setup SUP With Default WSUS Product Selection ConfigMgr SCCM. More details https://howtomanagedevices.com/sccm/1625/default-wsus-product-selection/

  • In the Add Site System Roles Wizard window,
  • In the Products Tab,
  • Select the Products based on the environment
  • Click Next

A new SUP product filter option is available in the SCCM 2203 version or later.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.14
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.14

Specify the Language Settings that you want to Synchronize

In the Add Site System Roles Wizard window, Select the Languages based on the environment in the Languages Tab.

Click Next

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.15
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.15

Confirm the Settings

In the Add Site System Roles Wizard window, click Next in the Summary Tab.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.16
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.16

Progress

In the Add Site System Roles Wizard window, Role installation initiation is in progress in the Process Tab.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.17
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.17

Summary

In the Add Site System Roles Wizard window, click Close in the Completion Tab.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.18
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.18

Check the installation Status using the Log File.

The below log information will provide complete setup information. Logfile folder Location: <Drive>\Program Files\Microsoft Configuration Manager\Logs.

SUPSetup.log: The log represents the installation of the Software Update role

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.19
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.19

Logfile folder Location: <Drive>\Program Files\Microsoft Configuration Manager\Logs

WCM.log: The log represents the  site server that connects to the WSUS server

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.20
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.20

Logfile folder Location: <Drive>\Program Files\Microsoft Configuration Manager\Logs

WSUSCtrl.log: The log represents the site server configuration, database connectivity, and health of the WSUS server of the site.

Install New ConfigMgr Software Update Point Role | SUP | SCCM - Fig.21
Install New ConfigMgr Software Update Point Role | SUP | SCCM – Fig.21

Resources

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

Kannan is a Technical Architect with more than 15 years of experience in the IT domain. He has worked on various technologies, such as Windows server administration, SCCM, SCOM, and Desktop Engineering. For the last 10 years, he has been working in Microsoft SCCM, focusing on Configuration Manager and Intune technologies.

Written by

Kannan is a Technical Architect with more than 15 years of experience in the IT domain. He has worked on various technologies like Windows server administration, SCCM, SCOM, Desktop Engineering domains. For the last 10 years, he has been working in Microsoft SCCM with the focus on Configuration Manager and Intune technologies.

Discussion · 2 comments

  1. Great post! I’m upgrading my ConfigMgr environment and this guide was very helpful in understanding the new SUP role. Can you provide more details on how to troubleshoot common issues that may arise during the upgrade process?

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws

Key Takeaways 2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws! The June 2026 Windows 11 Patch Tuesday update brings several improvements to File Explorer. It adds support for additional archive formats, including UU, CPIO, XAR, and NuGet Packages (NUPKG). The update also preserves View and Sort preferences in […]

AC Anoop C Nair 10 min read
Intune

2026 May KB5089549 KB5087420 Windows 11 Patch | 0 Zero Day Vulnerabilities and 120 Flaws

Key Takeaways The Windows 11 May 2026 Patch KB5089549 KB5087420 Update brings important security fixes, performance improvements, and reliability enhancements across the operating system. The update introduces new features such as Xbox Mode for gaming, File Explorer improvements, enhanced input and sharing experiences, better taskbar and Windows Hello reliability, and additional enterprise management capabilities for […]

AC Anoop C Nair 8 min read
SCCM

ConfigMgr 2603 Introduces New Early Update Enrollment Process

Key Takeaways In this post we are discussing the ConfigMgr 2603 Introduces New Early Update Enrollment Process. Microsoft has officially released Configuration Manager version 2603 to the Early Update Ring, giving organizations an opportunity to test upcoming improvements before the global production rollout. The release is targeted at enterprises running ConfigMgr version 2409 or later […]

AC Anoop C Nair 3 min read