Tech Community Live: Windows edition
Jun 05 2024, 07:30 AM - 11:30 AM (PDT)
Microsoft Tech Community

SCCM CMG Windows Updates

Copper Contributor



We have recently setup CMG in our environment for VPN devices only, but slightly confused as to how the content for Windows Updates would work as well as content for applications.  Currently have deployed Windows Updates to the CMG as well our Local DPs (which is for devices that not on VPN and in our offices). No Application content is deployed to the CMG. We have setup a boundary group for VPN devices and have added to the CMG to that.  My question is how would VPN devices get content for applications that on the internal DPs if no boundary group is setup for that?


I have followed Rob York article for the updates part.  But would like some help or advice in relation to this.

1 Reply

@nikeshmistry Great question thank you. Depending on how you have your boundary fallback setup your devices could be set up to get content from on-prem DPs. 


A cleaner option might be to set the "Prefer cloud based sources over on-premise sources" option on your VPN boundary which will rearrange your order of content acquisition preference so that the CMG would be first. In this way you could associate both the on-prem DP and CMG with your VPN boundary and the app content which isn't available on the CMG would be acquired from the DP.


Check out Rob's other blog on boundaries for more information:


Finally, make sure you have considered letting clients get Windows Update content directly from the Windows Update service rather than publishing that content to your CMG. It could be more performant and would definitely be cheaper.