Fix it now
The Windows Update agent could not provide the service or could not initialise its objects, so the scan fails before it reaches any update server. Reset the client’s registration and its download cache, then repair servicing if the reset does not take.
net stop wuauserv
net stop bits
ren %WinDir%\SoftwareDistribution SoftwareDistribution.old
net start bits
net start wuauserv
wuauclt.exe /resetauthorization /detectnow
- Give the client a few minutes after the last command. It rebuilds the datastore and re-registers before it will report anything useful.
- If it still fails, repair servicing itself:
DISM /Online /Cleanup-Image /ScanHealth, then/RestoreHealth, thensfc /scannow. - Check that the machine has a proxy configuration the system account can use:
netsh winhttp show proxy, andnetsh winhttp import proxy source=ieif it needs the browser’s settings. - Confirm the services the update stack depends on are running and not disabled: Windows Update, Background Intelligent Transfer Service, Cryptographic Services and the Windows Installer.
Renaming SoftwareDistribution is reversible until you delete the old folder. Leave the renamed copy in place until the client has scanned successfully at least once.
If a scan completes you can stop here. If not, the next section explains which of these codes is a fault and which is the agent telling you something perfectly ordinary.
Why it happens
The Windows Update agent is a set of COM objects rather than a single program. Something asks it for a session, it builds a searcher, it queries a service, and it returns update objects that the caller reads. Every code in this article comes from that layer, which is why they appear before any network traffic and why the fix is nearly always local.
Two of them are the headline faults. 0x80240001 is WU_E_NO_SERVICE: the Windows Update Agent was unable to provide the service. 0x80240004 is WU_E_NOT_INITIALIZED: the object could not be initialized. Both mean the agent could not get itself into a state where it could do anything, and both are usually a damaged datastore, a broken registration, or a servicing stack that is not healthy enough to answer.
The rest are more specific and some of them are not faults at all. 0x80240008 is WU_E_ITEMNOTFOUND, the key for the item queried could not be found. 0x80240009 is WU_E_OPERATIONINPROGRESS, another conflicting operation was in progress. 0x8024000C is WU_E_NOOP, no operation was required, which is the agent saying there was nothing to do. And 0x8024000E is WU_E_XML_INVALID: the agent found invalid information in the update’s XML data.
The datastore or download cache is damaged
You have this one if 0x80240001 or 0x80240004, and scans that fail immediately rather than after a delay.
- Stop
wuauservandbits, rename%WinDir%\SoftwareDistribution, then start both services. - Run
wuauclt.exe /resetauthorization /detectnowand wait for the client to rebuild. - Scan again and read the new result rather than the old one.
Rename rather than delete. If the rebuild goes badly you still have the previous datastore to look at.
The client’s registration is stale
You have this one if A group of machines built from one image, all failing together.
- Stop the update service and delete
SusClientIdandSusClientIDValidationfromHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate. - Start the service and run
wuauclt.exe /resetauthorization /detectnow. - Fix the reference image if the identity was captured into it, so the next batch does not arrive the same way.
Servicing itself is damaged, so the agent cannot initialise
You have this one if The reset makes no difference, and other servicing operations fail too.
- Run
DISM /Online /Cleanup-Image /ScanHealthand read the result before repairing. - Run
DISM /Online /Cleanup-Image /RestoreHealth, with an explicit/Sourceif it cannot reach a source. - Follow with
sfc /scannow, then retry the scan.
The system account has no usable path out
You have this one if Browsing works for the signed-in user, but the update agent reports it cannot provide the service.
- Check what the system-wide proxy is:
netsh winhttp show proxy. - Set it explicitly, or import the user’s settings with
netsh winhttp import proxy source=ie. - Confirm the machine can reach whichever service it is pointed at, whether that is the public one or a managed one.
The update agent runs as a service. A proxy configured only in a browser profile is invisible to it.
Full reference
The codes, and which of them are actually errors
| Code | Constant | What it says |
|---|---|---|
0x80240001 |
WU_E_NO_SERVICE | The agent was unable to provide the service |
0x80240004 |
WU_E_NOT_INITIALIZED | The object could not be initialized |
0x80240008 |
WU_E_ITEMNOTFOUND | The key for the item queried could not be found |
0x80240009 |
WU_E_OPERATIONINPROGRESS | Another conflicting operation was in progress |
0x8024000C |
WU_E_NOOP | No operation was required |
0x8024000E |
WU_E_XML_INVALID | The agent found invalid information in the update’s XML data |
0x8024000C is worth calling out. It is not a failure. Something asked the agent to do a piece of work that did not need doing, and it said so. Chasing it as though it were a fault is a good way to spend an afternoon reinstalling things that were never broken.
0x80240009 is similar in spirit. Two operations collided, which happens when a management tool triggers a scan while one is already running. Wait for the first to finish and retry before treating it as a defect.
The services this depends on
| Service | Why it matters |
|---|---|
Windows Update (wuauserv) |
Hosts the agent itself |
Background Intelligent Transfer Service (bits) |
Transfers the content once updates are selected |
Cryptographic Services (cryptsvc) |
Verifies signatures on what arrives |
Windows Installer (msiserver) |
Needed by some installers the update stack invokes |
Check that none of them is set to Disabled. A machine hardened by a policy or a script that disabled a service by name will produce initialisation failures that no amount of cache clearing will fix.
Where to look when the reset does not help
%WinDir%\Logs\CBS\CBS.logfor servicing failures underneath the agent.%WinDir%\Logs\WindowsUpdateor the update event log for what the agent recorded at the time.- The registered service list under the client-state key, which tells you which services this client believes it has.
- Policy under
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, in case the client is being pointed somewhere unreachable. - The system-wide proxy, since the agent uses it and the browser’s settings are not it.
A note on what these codes do not prove
0x80240001 in particular is often presented as evidence of something specific about how the agent is being called, including claims about remote use that no Microsoft page makes. This article does not repeat them. What the constant says is that the agent was unable to provide the service, and the productive response is to establish whether the client can initialise at all, which the reset above answers in a few minutes.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80240001 |
WU_E_NO_SERVICE: the Windows Update Agent was unable to provide the service | Microsoft Learn |
0x80240004 |
WU_E_NOT_INITIALIZED: the object could not be initialized | Microsoft Learn |
0x80240008 |
WU_E_ITEMNOTFOUND: the key for the item queried could not be found | Microsoft Learn |
0x80240009 |
WU_E_OPERATIONINPROGRESS: another conflicting operation was in progress | Microsoft Learn |
0x8024000C |
WU_E_NOOP: no operation was required. This is not a failure | Microsoft Learn |
0x8024000E |
WU_E_XML_INVALID: the agent found invalid information in the update’s XML data | Microsoft Learn |
Confirm the fix worked
- A scan completes and either lists updates or reports the machine as up to date.
- A new
SoftwareDistributionfolder has been created and is populating. - The four services above are running and none is set to Disabled.
- On a managed client, the machine reports into its update server with a recent check-in time.
Questions people ask about this
Is 0x8024000C a problem?
No. It is WU_E_NOOP, no operation was required. The agent was asked to do something that did not need doing and said so. It turns up in logs and in scripted output far more often than it turns up as a genuine fault, and treating it as one leads people to reset a client that was working.
Should I delete SoftwareDistribution or rename it?
Rename it. The service recreates it on start, and keeping the old folder means you can put it back or look inside it if the rebuild goes badly. Delete the renamed copy once the client has scanned successfully, not before.
Why does the browser reach the internet when the update agent cannot?
Because they use different proxy configurations. The agent runs as a service and uses the system-wide WinHTTP settings, while the browser uses the signed-in user’s. Check with netsh winhttp show proxy, and import the user’s settings if that is what the network expects.
Does resetting the client lose my update history?
Renaming SoftwareDistribution clears the local history and the download cache, so the list of previously installed updates in the interface will be empty afterwards. The updates themselves stay installed, and a managed server keeps its own record. It is a cosmetic loss rather than a real one.
