WSUS on Windows Server 2025 cannot complete initial category sync (invalid update identity, AtLeastOne Prerequisite)

Koji Nakamura 0 Reputation points
2026-09-04T01:56:10.3833333+00:00

A newly built WSUS server on Windows Server 2025 (reproduced on every patch level from GA through the August 2026 cumulative update, WID, Microsoft Update as upstream, no proxy) cannot complete its initial synchronization.

Every attempt fails at the category sync stage with:

invalid update identity (AtLeastOne Prerequisite) in XML for update CF56FF39-8BA5-4177-9265-E30D4DD58CF5 revision 100

18 of 19 outstanding configuration updates import successfully; this one fails on every retry, so the handshake anchor is never saved and the same failure repeats indefinitely.

Comparing the SUSDB of the failing server with a known-good WSUS server shows the cause. The failing update is the product category "Windows Subsystem for Linux". It has two prerequisites: the "Microsoft" company category (56309036-4c77-4dd9-951a-99ee9c246a94, present on the failing server) and the product-family category "Windows Subsystem for Linux" (79d72fdc-efcd-4911-8d4f-a3f00c69bdf4 revision 201). The product-family category is never delivered by Microsoft Update to the failing server, so the child cannot be imported.

KB5121986 does not apply (0 TestProduct detectoids in SUSDB), MaxXMLPerRequest is unrelated (the failure is at DB import, not transfer), and the same symptom reproduces on clean installations, so SUSDB rebuild does not help. DNS and TLS to sws.update.microsoft.com are confirmed working.

Questions:

  1. Is category 79d72fdc-efcd-4911-8d4f-a3f00c69bdf4 revision 201 currently delivered by the Microsoft Update server-sync endpoint during initial category sync? If not, can the catalog be corrected so new WSUS installations can complete their first sync without an intermediate WSUS server?
  2. Is there a supported way to import a single missing category revision into SUSDB without a second WSUS server?

The full report, including the log excerpt and the SUSDB query results from both servers, is in the attached PDF. The full SoftwareDistribution.log and query outputs are available on request.

attachment-wsus-sync-failure-report.pdf

Azure Local
0 comments No comments

1 answer

Sort by: Most helpful
  1. David Kind 0 Reputation points
    2026-09-04T08:16:42.94+00:00

    I have the exact same issue

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.