Microsoft Publishes Manual Fix for WSUS Sync Failures


microsoft ntlm
Image credit: Microsoft

The WSUS synchronization issue can cause Windows Update scans to fail, time out, or take much longer than expected. Microsoft has now published manual mitigation steps for administrators who still experience the problem.

The issue may prevent organizations from deploying Windows updates through Windows Server Update Services or Microsoft Configuration Manager.

Which Windows Versions Are Affected?

Microsoft says the WSUS synchronization problem affects Windows 10 version 1607 and later as well as Windows Server 2012 and later.

Systems that receive updates directly from Windows Update should not require the WSUS database cleanup procedure.

What Causes the WSUS Sync Issue?

The problem stems from unnecessary publishing metadata accumulating inside WSUS databases.

As the volume of metadata grows, WSUS synchronization operations can take significantly longer to complete. In more severe cases, synchronization jobs may time out entirely.

Administrators may also notice slower Windows Update scans on managed devices because WSUS must process and deliver the oversized update catalog.

Microsoft Deploys a Service-Side Mitigation

Microsoft has deployed a service-side mitigation for newly installed and rebuilt WSUS servers.

According to the company, synchronization operations and completion times have returned to normal for new WSUS installations and servers rebuilt after the mitigation.

However, the service-side change does not automatically remove metadata already stored in existing WSUS databases. Administrators managing older installations may still need to perform a manual cleanup.

How to Fix the WSUS Synchronization Issue

Microsoft recommends completing the following steps on affected WSUS environments:

  1. Back up each SUSDB database before making any database changes.
  2. Run Microsoft’s cleanup query against every SUSDB database in the environment, including databases used by WSUS replica servers.
  3. Restore the MaxXMLPerRequest value to its default configuration if administrators previously changed it as a workaround.
  4. Reindex the SUSDB database to improve database performance after removing the unnecessary metadata.
  5. Run the WSUS Server Cleanup Wizard to remove obsolete updates, unused update files, and outdated computer records.
  6. Run IISReset or recycle the WsusPool application pool to clear catalog data cached by Internet Information Services.

Administrators should apply the cleanup procedure across the entire WSUS hierarchy. Leaving replica databases unchanged could allow synchronization delays to continue.

What Happens After the Cleanup?

The first Windows Update scan completed by a managed device may still take longer than usual.

During that initial scan, the Windows Update client must process the updated catalog and refresh locally stored information. Subsequent scans should return to normal completion times.

Microsoft also notes that the client-side DataStore.edb database will not automatically shrink after the cleanup. The remaining file size does not affect Windows Update scan performance and does not require additional action.

Administrators should monitor synchronization jobs and client scan times after completing the mitigation to confirm that WSUS operations have returned to normal.

In other news, Windows 11 is testing a dark-themed Properties dialog, while a new Windows 11 Insider Experimental 26H1 build is also available.

Via BleepingComputer

More about the topics: microsoft, Windows Update

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages