Skip to content
SCCM Server OS Upgrade WSUS SUP Notes from Real World

SCCM Server OS Upgrade WSUS SUP Notes from Real World

Written By Anoop C Nair
Last Updated August 1, 2024
Posted In SCCM
SHARE

Let’s discuss the SCCM Server OS Upgrade WSUS SUP Notes from the Real World. SCCM server OS upgrade (in place) is fully supported if your SCCM server is running SCCM CB 1606 version and above. However, with SCCM CB 1702, we have a hard requirement for an operating system version of SCCM servers.

The minimum requirement for SCCM CB 1702 is to have Server 2012 and above. In my previous post, “Step by Step Video Tutorial of SCCM CB 1702 Baseline version Installation“. In this post, we will see some of the notes/experiences from the field (real world) during the in-place OS upgrade.

The post “SCCM CB 1702 Upgrade of CAS and Primary Sites: A Real-world Experience” provides more details about the SCCM Server OS Upgrade Checklist.

Introduction—SCCM Server OS Upgrade WSUS SUP—The Microsoft SCCM team has documented the steps you need to perform before the SCCM server in-place OS upgrade. In addition to the pre-checks and actions, there are also some cautions in that document.

Patch My PC

SCCM Server OS Upgrade WSUS SUP Notes from Real World

Most of those cautions are pointing towards IIS configuration/reconfigurations. If you have some custom/out-of-box configurations in your IIS settings, you need to research the IIS setting before the in-place OS upgrades.

In my experience of upgrading 2 different SCCM CB hierarchies, when you have not done any custom configuration in your IIS, you will be OK after the upgrade of the server OS.

Otherwise, you may need to reconfigure those custom settings again in IIS (most probably). I have a post here that explains the default settings of IIS for SCCM servers.

SCCM Server OS Upgrade WSUS SUP Notes from Real World - Fig.1
SCCM Server OS Upgrade WSUS SUP Notes from Real World – Fig.1

Pre SCCM Server In-place OS Upgrade – Remove/Uninstall WSUS Services

We removed the WSUS console from the primary server and CAS and then removed WSUS components from the remote SUP server before the SCCM Server placed the OS upgrade. Note that you don’t have (instead should NOT remove) to remove WSUS data, Logs, and DB references while removing WSUS from SCCM SUP/Primary servers.

You must remove/uninstall only the WSUS console and the core component, such as “Windows Server Update Service.” Ensure that you removed the disservice and wsuscertserver services from the SCCM server—there is no need to remove the SUP role.

Post-SCCM Server In-place OS Upgrade – Install WSUS Console

Post-SCCM Server in-place OS upgrade, I noticed that IIS-related services were stopped and disabled. If that is the situation in your case, you need to make sure that all these IIS-related services are not disabled. Ensure that IIS is working before you try to install WSUS 6.0 (for server 2012 R2) on the server.

SCCM Server OS Upgrade WSUS SUP Notes from Real World - Fig.2
SCCM Server OS Upgrade WSUS SUP Notes from Real World – Fig.2

Install the WSUS console (via the Add Roles and Features wizard in Server 2012) on the SCCM Primary/CAS server if you have a remote SUP server. There is no need to install DB and other services related to WSUS on primary and CAS servers if you are hosting the SUP role on a remote server. Make sure you install only the following roles from “Add roles and features wizard“:-
Remote Server Administration Tools – Role Administration Tools – Windows Server Update Services Tools:-
– API and PowerShell cmdlets
– User Interface Management Console

Remote Server Administration Tools
API and PowerShell cmdlets
User Interface Management Console
SCCM Server OS Upgrade WSUS SUP Notes from Real World – Table 1
SCCM Server OS Upgrade WSUS SUP Notes from Real World - Fig.3
SCCM Server OS Upgrade WSUS SUP Notes from Real World – Fig.3

Post-SCCM Server In-place OS Upgrade – Install WSUS Services

Once we install the WSUS console on the SCCM primary/CAS server, we can install WSUS core services on your remote SUP SCCM site system server. Launch the Add Roles and Features wizard, and select the following components, as seen in the pic below.

SCCM Server OS Upgrade WSUS SUP Notes from Real World - Fig.4
SCCM Server OS Upgrade WSUS SUP Notes from Real World – Fig.4

For the WSUS installation, we must complete two specific configurations: 1. Specify the updated store location, and 2. Specify an existing database server setting. In the SCCM In-place OS upgrade scenario, we must use the exact store location and Database name.

Another important point is that we don’t have to click on “Launch Post-installation tasks.” Instead, we can launch the WSUS console and click on the RUN button to complete the WSUS installation process.

SCCM Server OS Upgrade WSUS SUP Notes from Real World - Fig.5
SCCM Server OS Upgrade WSUS SUP Notes from Real World – Fig.5

The Result SUP Sync Works Perfectly after Server OS in Place Upgrade

This post-SCCM OS upgrade activity results in WSUS SYNC working fine with all the existing settings and configurations. There is no need to reconfigure and re-download anything, as per my experience.

SCCM Server OS Upgrade WSUS SUP Notes from Real World - Fig.6
SCCM Server OS Upgrade WSUS SUP Notes from Real World – Fig.6

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His primary focus is Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 9 comments

  1. We recently went from 2012 latest to 1702 on a 2008r2 box.

    Upgrade was fine. Then we went o/s 2008r2 – 2012r2 – 2016. All good.

    Note though. Have an external sup running on 2012r2 with heaps of issues. We eventually gave up and built a new 2016 box for sup. Works great!

    We also threw in a sql upgrade from 2012 to 2016!

    A whole lot of fun!

    1. StaffI have one where we forgot to uninstall/remove WSUS from server 2008 R2 and after upgrade to server 2012 R2 it decided stay there for ever 🙁
      We’ve removed the presence of the old WSUS version using MSI clean etc…. and registry entries also cleaned up.
      We were successfully able to install WSUS on server 2012 R2 via Add Roles and Features Wizard but the configuration stuff is not successful yet 🙁
      So the removal is very critical.
      Probably I will advice to remove WSUS whenever you do in place upgrade (may be for Server 2012 to 2016 as well ). We never know 😉

  2. Hi Anoop, thanks for the wonderful post.
    Can you please also share the link of OS upgrade steps on SCCM servers from 2008R2 to 2012R2 or Server 2016.
    Thanks!

  3. Hi Anoop,

    Currently we are running on SCCM 2012 R2 SP1 with SQL 2008 R2 SP3. We are planning to upgrade SCCM server OS from 2008R2 to 2012. Is SCCM 2012 R2 SP1 will support Windows 2012 OS in place upgrade? Can you please tell me process to upgrade like from First primary then secondary and MP,DP’s etc like that or DP’s, MP,SS and Primary. Which way is best?

    Thanks,
    Sirish Kumar K

  4. Hopefully someone still sees this post. I followed this guide exactly and after completing the step “launch WSUS console and click on RUN button to complete the WSUS installation process” I went home. I came in next day and it completed successfully BUT – every device in our environment was now getting windows updates (including a Windows Upgrade to Windows 10 202H) straight from WSUS. I know its coming straight from Windows Updates because 1. we dont have the 202H version downloaded or deployed anywhere and 2. some hosts are also getting other driver updates etc that we don’t push via sccm at all. Does anyone know what happened here? I have checked all group policy settings and they are correct and they also did not change prior to the upgrade. I simply cannot find a reason why all these updates are getting deployed to all clients suddenly.

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws

Key Takeaways 2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws! The June 2026 Windows 11 Patch Tuesday update brings several improvements to File Explorer. It adds support for additional archive formats, including UU, CPIO, XAR, and NuGet Packages (NUPKG). The update also preserves View and Sort preferences in […]

AC Anoop C Nair 10 min read
Intune

2026 May KB5089549 KB5087420 Windows 11 Patch | 0 Zero Day Vulnerabilities and 120 Flaws

Key Takeaways The Windows 11 May 2026 Patch KB5089549 KB5087420 Update brings important security fixes, performance improvements, and reliability enhancements across the operating system. The update introduces new features such as Xbox Mode for gaming, File Explorer improvements, enhanced input and sharing experiences, better taskbar and Windows Hello reliability, and additional enterprise management capabilities for […]

AC Anoop C Nair 8 min read
SCCM

ConfigMgr 2603 Introduces New Early Update Enrollment Process

Key Takeaways In this post we are discussing the ConfigMgr 2603 Introduces New Early Update Enrollment Process. Microsoft has officially released Configuration Manager version 2603 to the Early Update Ring, giving organizations an opportunity to test upcoming improvements before the global production rollout. The release is targeted at enterprises running ConfigMgr version 2409 or later […]

AC Anoop C Nair 3 min read