Cleaning Up Legacy SCCM Windows Update Settings with Intune Remediations

Cleaning Up Legacy SCCM Windows Update Settings

As organizations transition from System Center Configuration Manager (SCCM) to Microsoft Intune and Windows Update for Business (WUfB), it’s critical to ensure that legacy configurations don’t interfere with modern update management.

One common issue is the lingering presence of Group Policy (GP) cache and WSUS registry settings that were previously managed by SCCM.

In this blog, we’ll walk through a detection and remediation script pair designed for use with Intune Proactive Remediations.

These scripts identify and clean up outdated Windows Update configurations, ensuring a clean slate for WUfB.

Windows Update Detection Script for SCCM to Intune Migration

This script checks for the presence of legacy Windows Update configurations that may interfere with Intune and WUfB.

Here’s what it looks for:

  1. GP Cache – CacheSet001 and CacheSet002

    • Registry Path: HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet001\WindowsUpdate
    • Purpose: Stores cached Group Policy settings for Windows Update. These can persist even after GPOs are removed and may cause conflicts with Intune policies.
  2. WSUS Configuration Registry Key

    • Registry Path: HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
    • Purpose: This key is used by Group Policy to configure WSUS settings. If present, it indicates the system may still be trying to use WSUS instead of WUfB.
  3. Local GPO Reset Marker

    • Registry Path: HKLM:\SOFTWARE\Intune_Migration\WUfB Local GPO Reset Complete
    • Purpose: A custom marker used to indicate whether the local Group Policy registry settings have been reset. If missing, the system may still be influenced by old GPO configurations.

PowerShell Detection Script for Cleaning Legacy SCCM Windows Update Settings:

<#

.DESCRIPTION

Checks for items that need to be cleaned up as part of the conversion from SCCM to Intune/WUfB for Windows updates.

#>

$ad_domain_name = “contoso.com”

# set count variable

$rm_needed = 0

# test for GP Cache 001

if ((test-path -path “HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet001\WindowsUpdate”) -eq $true) {

$rm_needed++

}

# test for GP Cache 002

if ((test-path -path “HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet002\WindowsUpdate”) -eq $true) {

$rm_needed++

}

# test for WSUS configuration folder

if ((test-path -path “HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate”) -eq $true) {

$rm_needed++

}

# if connected to the domain, test for registry key to know if local GP has been deleted and reset

if (((test-netconnection $ad_domain_name -warningaction silentlycontinue).PingSucceeded) -eq $true) {

try {get-itemproperty -path HKLM:\SOFTWARE\Intune_Migration -name “WUfB Local GPO Reset Complete” -erroraction stop | out-null}

catch {$rm_needed++}

}

# exit based on script results

if ($rm_needed -eq 0) {

exit 0}

if ($rm_needed -ne 0) {

exit 1}

READ: Endpoint privilege management with Microsoft Intune

PowerShell Remediation Script for Fixing Legacy SCCM Windows Update Settings

<#

.DESCRIPTION

Cleans up items that need to be cleaned up as part of the conversion from SCCM to Intune/WUfB for Windows updates.

#>

$ad_domain_name = “contoso.com”

# get if is computer connected to the domain

$domain_connection = 0

if (((test-netconnection $ad_domain_name -warningaction silentlycontinue).PingSucceeded) -eq $true) {

$domain_connection = 1

}

# remove GP Cache 001

if ((test-path -path “HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet001\WindowsUpdate”) -eq $true) {

remove-item -path “HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet001\WindowsUpdate” -force -recurse

}

# remove GP Cache 002

if ((test-path -path “HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet002\WindowsUpdate”) -eq $true) {

remove-item -path “HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet002\WindowsUpdate” -force -recurse

}

# remove WSUS configuration folder

if ((test-path -path “HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate”) -eq $true) {

remove-item -path “HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate” -force -recurse

}

# reset local GP registry settings if connected to the domain

if ($domain_connection -eq 1) {

try {

get-itemproperty -path HKLM:\SOFTWARE\Intune_Migration -name “WUfB Local GPO Reset Complete” -erroraction stop | out-null

}

# runs if reg key does not exist, indicating that local GP settings have not been reset

catch {

$file = $env:windir + “\system32\GroupPolicy\Machine\Registry.pol”

$file_old = $env:windir + “\system32\GroupPolicy\Machine\Registry.old”

if ((test-path -path $file_old) -eq $true) {remove-item $file_old -recurse -force}

rename-item -path $file -newname $file_old -force

new-itemproperty -path HKLM:\SOFTWARE\Intune_Migration “WUfB Local GPO Reset Complete” -propertytype string -force | out-null

}

}

# restart Windows Update service

stop-service wuauserv

start-sleep -s 2

start-service wuauserv

# run gpupdate if connected to the domain

if ($domain_connection -eq 1) {

gpupdate /force | out-null

}

READ: Automating Sensitivity Label and Encryption Removal in SharePoint Online with PowerShell

Best Deployment Tips for Intune Proactive Remediations

  • Assign the remediation to a pilot group first to validate behavior.
  • Monitor results in the Intune portal under Reports > Endpoint analytics > Proactive remediations.
  • Customize the domain name (e.g., contoso.com) to match your environment.

Final Thoughts

This script pair is a great example of how Intune Proactive Remediations can be used to surgically clean up legacy configurations that may otherwise go unnoticed. By ensuring a clean update policy environment, you reduce the risk of update failures and improve compliance with modern management practices.

READ: Automating Data Protection with Microsoft Purview Post-Migration

Comprehensive IT Solutions for SCCM to Intune Migration

Windows Management Experts (WME) specializes in SCCM to Intune migration, Windows Update management, and legacy configuration cleanup, among many other services related to M&A, security, Office 365, and whatnot.

Our expertise spans PowerShell scripting, Intune Proactive Remediations, endpoint analytics, and ultimately, we ensure for you a seamless system transition and some really optimal compliance.

We provide custom solutions for Group Policy cleanup, WSUS configuration removal, and cloud-based device management. We make sure the enhanced system has better security and operational efficiency for your business. In fact, we offer all the expertise you need to drive your IT infrastructure forward.

CTA: Contact our Intune & Endpoint Management Experts

Disclaimer

At Windows Management Experts, Inc., we strive to provide accurate, insightful content to help you guide your IT decisions on your own. We work diligently to ensure the information shared here is helpful and accurate but we always encourage you to consult with any of our technical consultants for any personalized advice and to address any specific needs you may have. Your success is our priority and we are here to support your technological troubleshooting and deployments every step of the way.

READ: Implementing Zero-trust across your endpoints

Windows Management Experts

Now a Microsoft Solutions Partner for:

✓ Data & AI

✓ Digital and App Innovation

✓ Infrastructure

✓ Security

The Solutions Partner badge highlights WME’s excellence and commitment. Microsoft’s thorough evaluation ensures we’re skilled, deliver successful projects, and prioritize security over everything. This positions WME in a global tech community, ready to innovate on the cloud for your evolving business needs.

Contact us: sales@winmgmtexperts.com

Share:

Facebook
Twitter
LinkedIn
Picture of Andrew

Andrew

Contact Us

Name
  • United States+1
  • United Kingdom+44
  • Afghanistan+93
  • Åland Islands+358
  • Albania+355
  • Algeria+213
  • American Samoa+1
  • Andorra+376
  • Angola+244
  • Anguilla+1
  • Antigua & Barbuda+1
  • Argentina+54
  • Armenia+374
  • Aruba+297
  • Ascension Island+247
  • Australia+61
  • Austria+43
  • Azerbaijan+994
  • Bahamas+1
  • Bahrain+973
  • Bangladesh+880
  • Barbados+1
  • Belarus+375
  • Belgium+32
  • Belize+501
  • Benin+229
  • Bermuda+1
  • Bhutan+975
  • Bolivia+591
  • Bosnia & Herzegovina+387
  • Botswana+267
  • Brazil+55
  • British Indian Ocean Territory+246
  • British Virgin Islands+1
  • Brunei+673
  • Bulgaria+359
  • Burkina Faso+226
  • Burundi+257
  • Cambodia+855
  • Cameroon+237
  • Canada+1
  • Cape Verde+238
  • Caribbean Netherlands+599
  • Cayman Islands+1
  • Central African Republic+236
  • Chad+235
  • Chile+56
  • China+86
  • Christmas Island+61
  • Cocos (Keeling) Islands+61
  • Colombia+57
  • Comoros+269
  • Congo - Brazzaville+242
  • Congo - Kinshasa+243
  • Cook Islands+682
  • Costa Rica+506
  • Côte d’Ivoire+225
  • Croatia+385
  • Cuba+53
  • Curaçao+599
  • Cyprus+357
  • Czechia+420
  • Denmark+45
  • Djibouti+253
  • Dominica+1
  • Dominican Republic+1
  • Ecuador+593
  • Egypt+20
  • El Salvador+503
  • Equatorial Guinea+240
  • Eritrea+291
  • Estonia+372
  • Eswatini+268
  • Ethiopia+251
  • Falkland Islands+500
  • Faroe Islands+298
  • Fiji+679
  • Finland+358
  • France+33
  • French Guiana+594
  • French Polynesia+689
  • Gabon+241
  • Gambia+220
  • Georgia+995
  • Germany+49
  • Ghana+233
  • Gibraltar+350
  • Greece+30
  • Greenland+299
  • Grenada+1
  • Guadeloupe+590
  • Guam+1
  • Guatemala+502
  • Guernsey+44
  • Guinea+224
  • Guinea-Bissau+245
  • Guyana+592
  • Haiti+509
  • Honduras+504
  • Hong Kong SAR China+852
  • Hungary+36
  • Iceland+354
  • India+91
  • Indonesia+62
  • Iran+98
  • Iraq+964
  • Ireland+353
  • Isle of Man+44
  • Israel+972
  • Italy+39
  • Jamaica+1
  • Japan+81
  • Jersey+44
  • Jordan+962
  • Kazakhstan+7
  • Kenya+254
  • Kiribati+686
  • Kosovo+383
  • Kuwait+965
  • Kyrgyzstan+996
  • Laos+856
  • Latvia+371
  • Lebanon+961
  • Lesotho+266
  • Liberia+231
  • Libya+218
  • Liechtenstein+423
  • Lithuania+370
  • Luxembourg+352
  • Macao SAR China+853
  • Madagascar+261
  • Malawi+265
  • Malaysia+60
  • Maldives+960
  • Mali+223
  • Malta+356
  • Marshall Islands+692
  • Martinique+596
  • Mauritania+222
  • Mauritius+230
  • Mayotte+262
  • Mexico+52
  • Micronesia+691
  • Moldova+373
  • Monaco+377
  • Mongolia+976
  • Montenegro+382
  • Montserrat+1
  • Morocco+212
  • Mozambique+258
  • Myanmar (Burma)+95
  • Namibia+264
  • Nauru+674
  • Nepal+977
  • Netherlands+31
  • New Caledonia+687
  • New Zealand+64
  • Nicaragua+505
  • Niger+227
  • Nigeria+234
  • Niue+683
  • Norfolk Island+672
  • North Korea+850
  • North Macedonia+389
  • Northern Mariana Islands+1
  • Norway+47
  • Oman+968
  • Pakistan+92
  • Palau+680
  • Palestinian Territories+970
  • Panama+507
  • Papua New Guinea+675
  • Paraguay+595
  • Peru+51
  • Philippines+63
  • Poland+48
  • Portugal+351
  • Puerto Rico+1
  • Qatar+974
  • Réunion+262
  • Romania+40
  • Russia+7
  • Rwanda+250
  • Samoa+685
  • San Marino+378
  • São Tomé & Príncipe+239
  • Saudi Arabia+966
  • Senegal+221
  • Serbia+381
  • Seychelles+248
  • Sierra Leone+232
  • Singapore+65
  • Sint Maarten+1
  • Slovakia+421
  • Slovenia+386
  • Solomon Islands+677
  • Somalia+252
  • South Africa+27
  • South Korea+82
  • South Sudan+211
  • Spain+34
  • Sri Lanka+94
  • St. Barthélemy+590
  • St. Helena+290
  • St. Kitts & Nevis+1
  • St. Lucia+1
  • St. Martin+590
  • St. Pierre & Miquelon+508
  • St. Vincent & Grenadines+1
  • Sudan+249
  • Suriname+597
  • Svalbard & Jan Mayen+47
  • Sweden+46
  • Switzerland+41
  • Syria+963
  • Taiwan+886
  • Tajikistan+992
  • Tanzania+255
  • Thailand+66
  • Timor-Leste+670
  • Togo+228
  • Tokelau+690
  • Tonga+676
  • Trinidad & Tobago+1
  • Tunisia+216
  • Turkey+90
  • Turkmenistan+993
  • Turks & Caicos Islands+1
  • Tuvalu+688
  • U.S. Virgin Islands+1
  • Uganda+256
  • Ukraine+380
  • United Arab Emirates+971
  • Uruguay+598
  • Uzbekistan+998
  • Vanuatu+678
  • Vatican City+39
  • Venezuela+58
  • Vietnam+84
  • Wallis & Futuna+681
  • Western Sahara+212
  • Yemen+967
  • Zambia+260
  • Zimbabwe+263
6 * 6 =
On Key

More Posts

Be assured of everything

Get WME Services

Stay ahead of the competition with our Professional IT offerings.

12 * 9 =