Let’s discuss the SCCM Patch Deployment issue with Windows 10 KB5004237 July cumulative update. The July cumulative update KB5004245 for Windows 10 1909 might also have similar ConfigMgr (a.k.a SCCM) patching issues.
Since the last two months, Microsoft has started deviating from the standard they introduced a while back to combine Windows SSUs and LCUs. This is what we can notice with June and July cumulative updates for Windows 10. This is causing problems/confusion for IT admins.
SCCM admins faced a similar issue with last month’s cumulative update KB5003637 as well. The scenario becomes more critical when you have configured to Decline superseded updates immediately policy. We have a post where we discussed the issue with June CU for Windows 10.
Patch Deployment issue with Windows 10 KB5004237
Let’s check the prerequisite for deploying Windows 10 July CU KB5004237. This prerequisite is only applicable for WSUS/SCCM patch deployment scenarios. Don’t worry about this if you are using WUfB/Intune to deploy patches.
NOTE! – The July CU KB5004237 is applicable for Windows 10 2004, 20H2, and 21H1.
As mentioned above, the latest servicing stack update (SSU) for your operating system should be part of the latest cumulative update (LCU). You don’t need to install it separately. But, this is not true with June and July 2021 cumulative updates.
Issue: The prerequisite for WSUS/SCCM patch deployment is installing the May 11, 2021 update (KB5003173) before installing the latest cumulative update, KB5004237.
If you have not installed KB5003173, then the CU patch deployment of July month might fail or give inconsistent reports like “this” patch is not applicable for “this” Windows version. You need to ensure that all the devices are already installed with KB5003173 before installing the July CU update (KB5004237) for Windows 10 2004, 20H2, and 21H1.
Patch Deployment issue with Windows 10 kb5004245
The latest cumulative update for Windows 10 1909 version kb5004245(July CU) and this patch also has a dependency on previous cumulative patches and SSU. The prerequisite for Windows 10 1909 July CU (kb5004245) is a bit complex than the previous releases.
You must install either of the following before installing the July cumulative update (LCU) for 1909. Otherwise, the SCCM patch installation will fail, or the reports will show the LCU for July is not applicable, etc.
- Servicing stack update (SSU) (KB5001406)
- Latest SSU (KB5004748)
Recover Expired Updates from SCCM/WSUS
Let’s learn how to recover Expired Updates from the ConfigMgr console. The SCCM patch management is not very easy if you are new to this process. I have a blog post that talks about an end-to-end process of the recovery of expired updates.