#Requires -Version 5.1 <# JbTecWiz Support Centre -- generated fix script Fault : The WSUS console crashes, or clients stop reporting Fix : Get clients reporting again Source: https://jbtecwiz.com/support/srv-app-wsus-console Run as : Elevated PowerShell on a client Expect : 45 minutes Risk : medium Reversible : yes WHEN THIS IS THE RIGHT FIX The console is healthy but computers are missing or stale. HOW TO UNDO IT The client re-registers with a new identity; nothing is lost. This script walks the fix one step at a time and asks before each one. Steps with no command are things you do yourself -- it prints those and waits. Run with -DryRun to print without executing. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param( # Print every step and command without running anything. [switch]$DryRun, # Do not ask before each step. Read the script first if you use this. [switch]$Unattended ) $ErrorActionPreference = 'Stop' $script:Failed = 0 function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Show-Prose { param([string]$Text, [string]$Colour = "Gray") if (-not $Text) { return } $words = $Text -split "\s+"; $line = " " foreach ($w in $words) { if (($line.Length + $w.Length) -gt 74) { Write-Host $line -ForegroundColor $Colour; $line = " " } $line += "$w " } if ($line.Trim()) { Write-Host $line -ForegroundColor $Colour } } function Invoke-Step { param( [int]$Number, [string]$Do, [string]$Why, [scriptblock]$Command, [switch]$Manual, [string]$Shell = "powershell" ) Write-Rule " Step $Number of 6" Show-Prose $Do "White" if ($Why) { Write-Host ""; Show-Prose $Why "DarkGray" } if ($Manual) { Write-Host '' Write-Host ' -> Do this yourself, then press Enter to carry on.' -ForegroundColor Yellow if (-not $Unattended -and -not $DryRun) { [void](Read-Host) } return } Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor Green } Write-Host '' if ($DryRun) { Write-Host " (dry run -- not executed)" -ForegroundColor DarkGray; return } if (-not $Unattended) { $a = Read-Host " Run this step? [Y]es / [S]kip / [Q]uit" if ($a -match "^[Qq]") { Write-Host " Stopped at your request."; exit 0 } if ($a -match "^[Ss]") { Write-Host " Skipped." -ForegroundColor DarkGray; return } } try { & $Command } catch { $script:Failed++ Write-Host (" Step $Number failed: " + $_.Exception.Message) -ForegroundColor Red Show-Prose "The rest of the fix may depend on this. Read the write-up before carrying on." "Red" if (-not $Unattended) { $c = Read-Host " Carry on anyway? [y/N]" if ($c -notmatch "^[Yy]") { exit 1 } } } } Write-Rule Write-Host ' The WSUS console crashes, or clients stop reporting' -ForegroundColor White Write-Host ' Get clients reporting again' -ForegroundColor Cyan Write-Host '' Write-Host ' Risk: medium Reversible 45 minutes' Write-Host '' Show-Prose 'No warranty. Use at your own risk - JbTecWiz accepts no liability. Read it before you run it, and have a backup.' 'DarkYellow' Write-Rule if (-not $Unattended -and -not $DryRun) { $go = Read-Host ' Ready? [y/N]' if ($go -notmatch "^[Yy]") { Write-Host " Nothing was changed."; exit 0 } } Invoke-Step -Number 1 -Do 'Check what the client is configured to use.' -Command { Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' | Format-List WUServer,WUStatusServer,TargetGroup } Invoke-Step -Number 2 -Do 'Read the client''s own log for the failure.' -Command { Get-WindowsUpdateLog -LogPath $env:USERPROFILE\Desktop\wu.log Get-Content $env:USERPROFILE\Desktop\wu.log -Tail 60 } Invoke-Step -Number 3 -Do 'Look for duplicate SusClientIDs, which happens when machines are cloned from an image without generalising. Every clone reports as the same computer.' -Why 'This is the classic cause of a WSUS console showing three machines for a fleet of forty. It cannot be diagnosed from the server, only from the clients, and the fix has to run on each one.' -Command { Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate' | Format-List SusClientId,SusClientIDValidation } Invoke-Step -Number 4 -Do 'Reset the client identity on an affected machine.' -Command { Stop-Service wuauserv,bits -Force Remove-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate' -Name SusClientId,SusClientIDValidation -ErrorAction SilentlyContinue Remove-Item 'C:\Windows\SoftwareDistribution' -Recurse -Force -ErrorAction SilentlyContinue Start-Service wuauserv,bits wuauclt /resetauthorization /detectnow (New-Object -ComObject Microsoft.Update.AutoUpdate).DetectNow() } Invoke-Step -Number 5 -Do 'Confirm the client can reach the server on the right port -- 8530 and 8531 by default, not 80 and 443.' -Command { Test-NetConnection wsus.example.local -Port 8530 -InformationLevel Detailed } Invoke-Step -Number 6 -Do 'For images, remove the SusClientId as part of the sysprep process so this cannot recur.' -Manual Write-Rule " Confirm it worked" Show-Prose 'The client appears in the console with a recent contact time.' 'White' Write-Host '' if (-not $DryRun) { (Get-WsusServer).GetComputerTargets() | Sort-Object LastReportedStatusTime -Descending | Select-Object -First 10 FullDomainName,LastReportedStatusTime } Write-Rule if ($script:Failed -gt 0) { Write-Host (" Finished with " + $script:Failed + " failed step(s).") -ForegroundColor Yellow Show-Prose 'Read the full write-up at https://jbtecwiz.com/support/srv-app-wsus-console' 'Yellow' } else { Write-Host ' Finished.' -ForegroundColor Green } Write-Host '' Show-Prose 'To undo: The client re-registers with a new identity; nothing is lost.' 'DarkGray' Write-Rule