Fix it now
The 0x8024401x and 0x8024402x codes are HTTP statuses with a Windows wrapper round them. Microsoft publishes 0x80244017 as the equivalent of HTTP 401, the requested resource requires user authentication, and 0x80244024 as HTTP 505, the server does not support the HTTP protocol version used. The fix is in IIS and in the network path, not on the client.
netsh winhttp show proxy
netsh winhttp reset proxy
net stop wuauserv
net start wuauserv
- Confirm which server the client talks to: read
WUServerunderHKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, or rungpresult /h report.html. - From that client, open the client web service URL on the WSUS port in a browser. WSUS uses 8530 for HTTP and 8531 for HTTPS by default. You should get a service description page.
- If you are prompted for credentials instead, anonymous authentication is off. On the WSUS server, open IIS Manager, select the WSUS Administration site, open Authentication and enable Anonymous Authentication.
- If a proxy sits between client and server, take it out of the path or put the WSUS host in the bypass list, then rescan.
- If the IIS log shows 405 against the client web service, check whether WebDAV Publishing is installed on that server. It handles verbs the client needs and can answer them with 405. Disable it for the WSUS site first, and remove the feature only if nothing else on the server uses it.
Anonymous authentication has to be checked at the site and on each virtual directory beneath it. A hardening baseline that disables it server-wide breaks WSUS every time it reapplies.
If a scan now completes, you are done. Below is the full code-to-status mapping and where the evidence lives on the server.
Why it happens
A WSUS client is an ordinary HTTP client. It posts SOAP requests to the client web service to register and pull metadata, reports to the reporting web service, and downloads binaries over BITS from the content path. Microsoft’s defaults give it two ports: 8531, which carries update metadata over TLS, and 8530, which carries the update payloads over HTTP. Every code in this family is an HTTP status the transport layer could not use, translated into a Windows error, which means the diagnosis is a web-server diagnosis rather than a Windows Update one.
That translation is the useful part. Once you know the status, the IIS logs on the WSUS server show you the exact request and its substatus, and the problem stops being an opaque hexadecimal string. 0x80244016 is 400, 0x80244017 is 401, 0x8024401A is 405 and 0x80244024 is 505. 0x80244023 is the odd one: Microsoft names it WU_E_PT_HTTP_STATUS_GATEWAY_TIMEOUT and glosses it as the request timing out waiting for a gateway, while printing the status in its own table as 503. Read it as a gateway or upstream timeout and look at whatever sits in front of the server.
The two headline codes have very different roots. A 401 almost always means anonymous authentication was disabled somewhere it should not have been, usually by a hardening baseline that was scoped too broadly. A 505 almost always means an intermediary is rewriting the request line: a proxy, a web application firewall, a load balancer or an inspection appliance. IIS itself speaks the HTTP versions the client uses, so WSUS rarely produces a 505 on its own.
Anonymous authentication is switched off on the WSUS site
You have this one if 0x80244017 across many clients at once, and browsing the client web service from a client produces a credentials prompt rather than a page.
- On the WSUS server, open IIS Manager and expand Sites to the WSUS Administration site.
- Open Authentication on the virtual directory the IIS log shows the client being refused on, and confirm Anonymous Authentication is enabled there.
- Work through the web services Microsoft names for that site rather than guessing at the list: ApiRemoting30, ClientWebService, DSSAuthWebService, ServerSyncWebService, SimpleAuthWebService and Content. ApiRemoting30 is the console and API path rather than a client path.
- Do not make a blanket authentication change at the top of the WSUS Administration site. Microsoft’s own configuration guidance for WSUS sets properties on the individual web services and warns against applying them at the top level, because the directories underneath do not all want the same settings.
- Run
iisresetand rescan from a client.
Scope the hardening baseline to exclude the WSUS site rather than fixing this by hand each month. Otherwise it comes back on the next policy cycle.
A proxy is answering on behalf of WSUS
You have this one if 0x80244017 or 0x80244024, and netsh winhttp show proxy on the client shows a proxy configured.
- Remember the update client uses the WinHTTP proxy, not the browser proxy. Checking the browser tells you nothing here.
- Put the WSUS host in the bypass list, for example
netsh winhttp set proxy proxy-server="http=proxy.example.local:8080" bypass-list="wsus.example.local;<local>". - If these clients need no proxy at all, run
netsh winhttp reset proxyand rescan. - Ask whoever runs any inspection appliance to exclude the WSUS host and port from TLS inspection and from HTTP rewriting.
WebDAV or request filtering is refusing the client’s verb
You have this one if 0x8024401A, and the IIS log on the WSUS server shows 405 against a POST to the client web service.
- In Server Manager, remove the WebDAV Publishing feature under Web Server (IIS), then reboot the WSUS server.
- If WebDAV must stay for another site, open the WSUS site in IIS Manager, open WebDAV Authoring Rules and disable WebDAV for that site only.
- Open Request Filtering on the WSUS site and confirm no rule denies POST, then rescan from a client.
The WSUS application pool keeps falling over
You have this one if 0x80244023, sometimes alternating with the 503 code, and the pool stopping on its own after a period of client activity.
- In IIS Manager, open Application Pools, select the WSUS pool and open Advanced Settings.
- Raise the Private Memory Limit substantially or set it to 0, and set the Regular Time Interval under Recycling to 0.
- Run the WSUS Server Cleanup Wizard, then decline superseded updates.
- Reindex the WSUS database, restart the pool, and watch it through a full scan cycle.
On a WSUS that has run for years without maintenance, the first cleanup pass takes hours. Run it overnight and do not interrupt it.
The client’s registration is stale or duplicated
You have this one if 0x80244016 on one machine or a small group, very often machines built from the same image.
- Stop the update service with
net stop wuauserv. - Delete the
SusClientIdandSusClientIdValidationvalues underHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate, which is where client state lives rather than policy. - Rename
C:\Windows\SoftwareDistribution, start the service and trigger detection with(New-Object -ComObject Microsoft.Update.AutoUpdate).DetectNow(). - Confirm the machine appears in the WSUS console with its own entry and a current last contact time.
Images captured without Sysprep share one client identifier, so each machine built from that image overwrites the last in the console. Fixing the image is the durable answer.
Full reference
Code to HTTP status, as Microsoft publishes it
| Code | Published name | Status and description | Where to look first |
|---|---|---|---|
0x80244017 |
WU_E_PT_HTTP_STATUS_DENIED | 401, the requested resource requires user authentication | Anonymous authentication on the WSUS site, or a proxy demanding credentials |
0x80244024 |
WU_E_PT_HTTP_STATUS_VERSION_NOT_SUP | 505, the server does not support the HTTP protocol version used | A proxy or inspection device rewriting the request |
0x80244016 |
WU_E_PT_HTTP_STATUS_BAD_REQUEST | 400, the server could not process the request due to invalid syntax | A stale or duplicated client registration |
0x8024401A |
WU_E_PT_HTTP_STATUS_BAD_METHOD | 405, the HTTP method is not allowed | WebDAV or request filtering blocking POST |
0x80244023 |
WU_E_PT_HTTP_STATUS_GATEWAY_TIMEOUT | The request timed out waiting for a gateway; Microsoft’s table prints the status as 503 | A proxy timing out, or the application pool falling over |
The 0x80244023 row is worth reading twice. Microsoft’s symbolic name says gateway timeout and its printed status says 503, which is normally service unavailable. Treat the code as an upstream timeout and confirm the actual status from the IIS log rather than from the code.
Default ports and paths
| Direction | Default ports | Note |
|---|---|---|
| Clients to WSUS | 8530 for HTTP, 8531 for HTTPS | Microsoft’s documented defaults for serving updates to workstations |
| WSUS to Microsoft Update | 80 for HTTP, 443 for HTTPS | Used for server synchronisation, and what a corporate firewall has to permit |
Where the evidence lives
| Log | Path or command |
|---|---|
| IIS request log | C:\inetpub\logs\LogFiles\W3SVC<site id> |
| WSUS log | C:\Program Files\Update Services\LogFiles\SoftwareDistribution.log |
| Client trace | Get-WindowsUpdateLog in PowerShell |
Deleting the SusClientId values is a registry edit on a production machine. Export HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate first so you can put it back.
Moving to HTTPS without breaking the estate
Running the client connection over 8531 is worth doing, but the policy has to change at the same time. The WUServer value must use the https scheme and the matching port, and every client must trust the certificate chain. What you cannot do is require TLS across the whole WSUS website: Microsoft states that WSUS is designed to encrypt update metadata only, and its own guidance sets Require SSL on the individual web services rather than at the top of the WSUS Administration site, because content still moves over HTTP. An untrusted certificate produces different codes in the same family, so change one pilot group first and confirm the console shows them reporting before you move everybody.
Where WSUS itself stands
Before investing a weekend in tuning an ageing WSUS instance, it is worth knowing that Microsoft lists Windows Server Update Services among the features no longer in development, while stating that all existing capabilities and content continue to be available for current deployments. Nothing stops working, and there is no deadline attached, but it is a reasonable prompt to decide whether the estate should be moving towards a cloud-managed update service rather than being rebuilt around this one.
Checks that separate client from server
- Test from a client on the same subnet as WSUS with no proxy configured. Success there puts the fault in the path.
- Compare
netsh winhttp show proxyand the WindowsUpdate policy key on a working and a failing machine. - Read the current IIS log and confirm the POST to the client web service from that client returned 200.
- Check the last contact time in the WSUS console. A client that has never contacted the server at all is a different problem from one that is being refused.
- Confirm no second update mechanism is also configured on the device, since a client pointed at two places tends to report inconsistently.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80244017 |
WU_E_PT_HTTP_STATUS_DENIED. The same as HTTP 401: the requested resource requires user authentication | Microsoft Learn |
0x80244024 |
WU_E_PT_HTTP_STATUS_VERSION_NOT_SUP. The same as HTTP 505: the server does not support the HTTP protocol version used for the request | Microsoft Learn |
0x80244016 |
WU_E_PT_HTTP_STATUS_BAD_REQUEST. The same as HTTP 400: the server could not process the request due to invalid syntax | Microsoft Learn |
0x8024401A |
WU_E_PT_HTTP_STATUS_BAD_METHOD. The same as HTTP 405: the HTTP method is not allowed | Microsoft Learn |
0x80244023 |
WU_E_PT_HTTP_STATUS_GATEWAY_TIMEOUT. The request timed out waiting for a gateway. Microsoft’s table prints the status for this row as 503 | Microsoft Learn |
Confirm the fix worked
- From a previously failing client, the client web service URL returns a service description page with no credentials prompt.
- A detection cycle completes and the WindowsUpdateClient operational log records a successful scan.
- The WSUS console shows that client with a last contact time from the last few minutes.
- The current IIS log shows the POST to the client web service from that client returning 200.
Questions people ask about this
Why does one machine work while its neighbour fails?
The difference is usually per-machine: a stale client identifier, or a WinHTTP proxy set on one and not the other. Compare netsh winhttp show proxy and the WindowsUpdate policy key on a working and a failing machine before touching the server.
Should I move WSUS to HTTPS on 8531?
It is worth doing, but change the client policy at the same time. The WUServer value must use the https scheme and the matching port, and every client must trust the certificate chain. An untrusted certificate produces different codes in the same family.
Does WSUS need its own licence?
No. It is a server role included with Windows Server, so there is no separate product to buy. You still need a licence for the server it runs on and your usual client access licensing applies, but nothing about these codes changes that.
Can a 505 ever be WSUS’s own fault?
Rarely. IIS speaks the HTTP versions the client uses, so a 505 almost always comes from something in between. Test with a client on the same subnet as WSUS and no proxy configured; if that succeeds, the fault is in the path.
Is WSUS still supported?
It still works and Microsoft states that existing capabilities and content remain available for current deployments, but it is listed among the features no longer in development. Treat it as stable rather than as somewhere to invest heavily.
