Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0x80244017

0x80244017 and 0x80244024: WSUS rejects the client with 401 or 505

12 min read Updated October 5, 2026 Windows Update & Setup

Fix it now

The 0x8024401x and 0x8024402x codes are HTTP statuses with a Windows wrapper round them. Microsoft publishes 0x80244017 as the equivalent of HTTP 401, the requested resource requires user authentication, and 0x80244024 as HTTP 505, the server does not support the HTTP protocol version used. The fix is in IIS and in the network path, not on the client.

Run these on a failing client, in an elevated Command Prompt

netsh winhttp show proxy
netsh winhttp reset proxy
net stop wuauserv
net start wuauserv
  1. Confirm which server the client talks to: read WUServer under HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, or run gpresult /h report.html.
  2. From that client, open the client web service URL on the WSUS port in a browser. WSUS uses 8530 for HTTP and 8531 for HTTPS by default. You should get a service description page.
  3. If you are prompted for credentials instead, anonymous authentication is off. On the WSUS server, open IIS Manager, select the WSUS Administration site, open Authentication and enable Anonymous Authentication.
  4. If a proxy sits between client and server, take it out of the path or put the WSUS host in the bypass list, then rescan.
  5. If the IIS log shows 405 against the client web service, check whether WebDAV Publishing is installed on that server. It handles verbs the client needs and can answer them with 405. Disable it for the WSUS site first, and remove the feature only if nothing else on the server uses it.

Anonymous authentication has to be checked at the site and on each virtual directory beneath it. A hardening baseline that disables it server-wide breaks WSUS every time it reapplies.

If a scan now completes, you are done. Below is the full code-to-status mapping and where the evidence lives on the server.

Why it happens

A WSUS client is an ordinary HTTP client. It posts SOAP requests to the client web service to register and pull metadata, reports to the reporting web service, and downloads binaries over BITS from the content path. Microsoft’s defaults give it two ports: 8531, which carries update metadata over TLS, and 8530, which carries the update payloads over HTTP. Every code in this family is an HTTP status the transport layer could not use, translated into a Windows error, which means the diagnosis is a web-server diagnosis rather than a Windows Update one.

That translation is the useful part. Once you know the status, the IIS logs on the WSUS server show you the exact request and its substatus, and the problem stops being an opaque hexadecimal string. 0x80244016 is 400, 0x80244017 is 401, 0x8024401A is 405 and 0x80244024 is 505. 0x80244023 is the odd one: Microsoft names it WU_E_PT_HTTP_STATUS_GATEWAY_TIMEOUT and glosses it as the request timing out waiting for a gateway, while printing the status in its own table as 503. Read it as a gateway or upstream timeout and look at whatever sits in front of the server.

The two headline codes have very different roots. A 401 almost always means anonymous authentication was disabled somewhere it should not have been, usually by a hardening baseline that was scoped too broadly. A 505 almost always means an intermediary is rewriting the request line: a proxy, a web application firewall, a load balancer or an inspection appliance. IIS itself speaks the HTTP versions the client uses, so WSUS rarely produces a 505 on its own.

Anonymous authentication is switched off on the WSUS site

You have this one if 0x80244017 across many clients at once, and browsing the client web service from a client produces a credentials prompt rather than a page.

  1. On the WSUS server, open IIS Manager and expand Sites to the WSUS Administration site.
  2. Open Authentication on the virtual directory the IIS log shows the client being refused on, and confirm Anonymous Authentication is enabled there.
  3. Work through the web services Microsoft names for that site rather than guessing at the list: ApiRemoting30, ClientWebService, DSSAuthWebService, ServerSyncWebService, SimpleAuthWebService and Content. ApiRemoting30 is the console and API path rather than a client path.
  4. Do not make a blanket authentication change at the top of the WSUS Administration site. Microsoft’s own configuration guidance for WSUS sets properties on the individual web services and warns against applying them at the top level, because the directories underneath do not all want the same settings.
  5. Run iisreset and rescan from a client.

Scope the hardening baseline to exclude the WSUS site rather than fixing this by hand each month. Otherwise it comes back on the next policy cycle.

A proxy is answering on behalf of WSUS

You have this one if 0x80244017 or 0x80244024, and netsh winhttp show proxy on the client shows a proxy configured.

  1. Remember the update client uses the WinHTTP proxy, not the browser proxy. Checking the browser tells you nothing here.
  2. Put the WSUS host in the bypass list, for example netsh winhttp set proxy proxy-server="http=proxy.example.local:8080" bypass-list="wsus.example.local;<local>".
  3. If these clients need no proxy at all, run netsh winhttp reset proxy and rescan.
  4. Ask whoever runs any inspection appliance to exclude the WSUS host and port from TLS inspection and from HTTP rewriting.

WebDAV or request filtering is refusing the client’s verb

You have this one if 0x8024401A, and the IIS log on the WSUS server shows 405 against a POST to the client web service.

  1. In Server Manager, remove the WebDAV Publishing feature under Web Server (IIS), then reboot the WSUS server.
  2. If WebDAV must stay for another site, open the WSUS site in IIS Manager, open WebDAV Authoring Rules and disable WebDAV for that site only.
  3. Open Request Filtering on the WSUS site and confirm no rule denies POST, then rescan from a client.

The WSUS application pool keeps falling over

You have this one if 0x80244023, sometimes alternating with the 503 code, and the pool stopping on its own after a period of client activity.

  1. In IIS Manager, open Application Pools, select the WSUS pool and open Advanced Settings.
  2. Raise the Private Memory Limit substantially or set it to 0, and set the Regular Time Interval under Recycling to 0.
  3. Run the WSUS Server Cleanup Wizard, then decline superseded updates.
  4. Reindex the WSUS database, restart the pool, and watch it through a full scan cycle.

On a WSUS that has run for years without maintenance, the first cleanup pass takes hours. Run it overnight and do not interrupt it.

The client’s registration is stale or duplicated

You have this one if 0x80244016 on one machine or a small group, very often machines built from the same image.

  1. Stop the update service with net stop wuauserv.
  2. Delete the SusClientId and SusClientIdValidation values under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate, which is where client state lives rather than policy.
  3. Rename C:\Windows\SoftwareDistribution, start the service and trigger detection with (New-Object -ComObject Microsoft.Update.AutoUpdate).DetectNow().
  4. Confirm the machine appears in the WSUS console with its own entry and a current last contact time.

Images captured without Sysprep share one client identifier, so each machine built from that image overwrites the last in the console. Fixing the image is the durable answer.

Full reference

Code to HTTP status, as Microsoft publishes it

Code Published name Status and description Where to look first
0x80244017 WU_E_PT_HTTP_STATUS_DENIED 401, the requested resource requires user authentication Anonymous authentication on the WSUS site, or a proxy demanding credentials
0x80244024 WU_E_PT_HTTP_STATUS_VERSION_NOT_SUP 505, the server does not support the HTTP protocol version used A proxy or inspection device rewriting the request
0x80244016 WU_E_PT_HTTP_STATUS_BAD_REQUEST 400, the server could not process the request due to invalid syntax A stale or duplicated client registration
0x8024401A WU_E_PT_HTTP_STATUS_BAD_METHOD 405, the HTTP method is not allowed WebDAV or request filtering blocking POST
0x80244023 WU_E_PT_HTTP_STATUS_GATEWAY_TIMEOUT The request timed out waiting for a gateway; Microsoft’s table prints the status as 503 A proxy timing out, or the application pool falling over

The 0x80244023 row is worth reading twice. Microsoft’s symbolic name says gateway timeout and its printed status says 503, which is normally service unavailable. Treat the code as an upstream timeout and confirm the actual status from the IIS log rather than from the code.

Default ports and paths

Direction Default ports Note
Clients to WSUS 8530 for HTTP, 8531 for HTTPS Microsoft’s documented defaults for serving updates to workstations
WSUS to Microsoft Update 80 for HTTP, 443 for HTTPS Used for server synchronisation, and what a corporate firewall has to permit

Where the evidence lives

Log Path or command
IIS request log C:\inetpub\logs\LogFiles\W3SVC<site id>
WSUS log C:\Program Files\Update Services\LogFiles\SoftwareDistribution.log
Client trace Get-WindowsUpdateLog in PowerShell

Deleting the SusClientId values is a registry edit on a production machine. Export HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate first so you can put it back.

Moving to HTTPS without breaking the estate

Running the client connection over 8531 is worth doing, but the policy has to change at the same time. The WUServer value must use the https scheme and the matching port, and every client must trust the certificate chain. What you cannot do is require TLS across the whole WSUS website: Microsoft states that WSUS is designed to encrypt update metadata only, and its own guidance sets Require SSL on the individual web services rather than at the top of the WSUS Administration site, because content still moves over HTTP. An untrusted certificate produces different codes in the same family, so change one pilot group first and confirm the console shows them reporting before you move everybody.

Where WSUS itself stands

Before investing a weekend in tuning an ageing WSUS instance, it is worth knowing that Microsoft lists Windows Server Update Services among the features no longer in development, while stating that all existing capabilities and content continue to be available for current deployments. Nothing stops working, and there is no deadline attached, but it is a reasonable prompt to decide whether the estate should be moving towards a cloud-managed update service rather than being rebuilt around this one.

Checks that separate client from server

  • Test from a client on the same subnet as WSUS with no proxy configured. Success there puts the fault in the path.
  • Compare netsh winhttp show proxy and the WindowsUpdate policy key on a working and a failing machine.
  • Read the current IIS log and confirm the POST to the client web service from that client returned 200.
  • Check the last contact time in the WSUS console. A client that has never contacted the server at all is a different problem from one that is being refused.
  • Confirm no second update mechanism is also configured on the device, since a client pointed at two places tends to report inconsistently.

Every code this article covers

Code What it points at Source
0x80244017 WU_E_PT_HTTP_STATUS_DENIED. The same as HTTP 401: the requested resource requires user authentication Microsoft Learn
0x80244024 WU_E_PT_HTTP_STATUS_VERSION_NOT_SUP. The same as HTTP 505: the server does not support the HTTP protocol version used for the request Microsoft Learn
0x80244016 WU_E_PT_HTTP_STATUS_BAD_REQUEST. The same as HTTP 400: the server could not process the request due to invalid syntax Microsoft Learn
0x8024401A WU_E_PT_HTTP_STATUS_BAD_METHOD. The same as HTTP 405: the HTTP method is not allowed Microsoft Learn
0x80244023 WU_E_PT_HTTP_STATUS_GATEWAY_TIMEOUT. The request timed out waiting for a gateway. Microsoft’s table prints the status for this row as 503 Microsoft Learn

Confirm the fix worked

  1. From a previously failing client, the client web service URL returns a service description page with no credentials prompt.
  2. A detection cycle completes and the WindowsUpdateClient operational log records a successful scan.
  3. The WSUS console shows that client with a last contact time from the last few minutes.
  4. The current IIS log shows the POST to the client web service from that client returning 200.

Questions people ask about this

Why does one machine work while its neighbour fails?

The difference is usually per-machine: a stale client identifier, or a WinHTTP proxy set on one and not the other. Compare netsh winhttp show proxy and the WindowsUpdate policy key on a working and a failing machine before touching the server.

Should I move WSUS to HTTPS on 8531?

It is worth doing, but change the client policy at the same time. The WUServer value must use the https scheme and the matching port, and every client must trust the certificate chain. An untrusted certificate produces different codes in the same family.

Does WSUS need its own licence?

No. It is a server role included with Windows Server, so there is no separate product to buy. You still need a licence for the server it runs on and your usual client access licensing applies, but nothing about these codes changes that.

Can a 505 ever be WSUS’s own fault?

Rarely. IIS speaks the HTTP versions the client uses, so a 505 almost always comes from something in between. Test with a client on the same subnet as WSUS and no proxy configured; if that succeeds, the fault is in the path.

Is WSUS still supported?

It still works and Microsoft states that existing capabilities and content remain available for current deployments, but it is listed among the features no longer in development. Treat it as stable rather than as somewhere to invest heavily.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error 0xC1420127 and 0xC1900403: the upgrade rolls back every single attempt License Error 0x8024A000 and 0x8024A004: Automatic Updates is paused or has no service Free Fix 0x80245001 and 0x80245003: the update redirector cab cannot be used Free Fix 0x8024402C: the update client cannot resolve the WSUS or proxy name
โ† Back to Knowledge Base