In this post I will cover how to configure Software update role in secondary site server. Software update point is a role. The SUP integrates with Windows Server Update Services (WSUS) to provide software updates to Configuration Manager Clients. Software Update Point (SUP) must be installed on the server that has WSUS installed. SUP interact with WSUS service (Called Synchronization) for metadata.  When you have set like CAS, primary and secondary – Software Update Point role should be installed in the CAS server first, then primary server and optionally in secondary site server. So if setup do not have CAS server, then software update point role should installed first on SCCM primary site. Software update point role must be installed post configuration of windows update service (WSUS)

Why Secondary site server is optional for SUP? If you have plan for Software update, then we have to install the SUP role in secondary site server.


  • You can install more than one software update points on a site.
  • It is not supported to install the software update point site system role on a standalone WSUS server
  • Software update point is optional for secondary site


We can configure Software update point role Post installation of secondary site server and WSUS configuration

Navigate to Administration-> Sites-> Select the Site where we need to configure SUP role-> Click on Add site system roles

Then installation wizard page will open. There we can see the server name and site code of the secondary site server. By default installation account will be site server’s account. The active directory forest and domain of the server will be displayed. Click Next

On the Proxy page, if roles on this server require an internet proxy, then specify settings for a proxy server. Then click next

On the System Role Selection page, select the Software Update Point

On the Software update point setting page you will be having two options for WSUS configuration

  • WSUS configured to use ports 80 and 443 for client communications.
  • WSUS configured to use ports 8530 and 8531 for client communications.

Select second option an it’s the default option

You will be having three options under client connection type

  • Allow intranet only client connections
  • Allow internet only client connections
  • Allow intranet and internet client connections

This should be checked according to your setup

You can configure proxy when connecting to WSUS or else by default configuration manager take computer account

Click next to complete the configuration


How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?


Leave a Reply

Your email address will not be published. Required fields are marked *