top of page

ConfigMgr 2503 & 2509 Hotfixes: Everything You Need to Apply Right Now

Writer: Christopher Hazlitt
Christopher Hazlitt
May 7
6 min read

šŸ” Microsoft has shipped a fresh batch of hotfixes targeting Configuration Manager versions 2503 and 2509 — and if your environment runs either of these branches, several of these fixes are time-sensitive. From a co-management update source regression that's been routing devices to the wrong patch channel, to a compliance check failure with a hard October 2026 deadline, to ARM64 client upgrade failures and a NAA security hardening update — this is a set of fixes you'll want to review and action promptly.

šŸ—“ļø What Was Released and When

The update rollup for Configuration Manager 2509 (KB36949461) was released in April 2026 and is available now in the Updates and Servicing node of the console. It bundles several previously released standalone hotfixes along with new fixes not available through any prior update. Separately, standalone hotfixes targeting 2503 (and in some cases 2409) have also been released for issues that cannot wait for a full version upgrade.

Here is the full rundown of what is included and who it affects.

ā˜ļø Co-Management & Third-Party Update Scan Source Regression (KB36495448)

ā˜ļø This is the fix most co-managed environments will feel immediately. In ConfigMgr 2503 (with the 2503 update rollup KB32851084 installed) and 2509, a regression causes Windows Update scan source policies to be incorrectly overwritten on co-managed devices that have third-party update catalogs enabled.

  • The Problem: ConfigMgr writes an incomplete (partial) scan source policy to the registry. Because only SetPolicyDrivenUpdateSourceForOtherUpdates is set to 1, ConfigMgr incorrectly assumes that Feature, Quality, and Driver update sources should also be WSUS — even when the co-management slider is pointing those workloads to Intune or Windows Update for Business.

  • The Impact: Devices that should be receiving Feature Updates or Quality Updates from Intune/WUfB are instead fetching them from WSUS/ConfigMgr. This is a silent compliance and patching correctness issue — devices appear managed but are receiving updates from the wrong authority.

  • The Fix: After applying the hotfix, ConfigMgr will no longer set or modify Windows Update scan source policies on co-managed devices. Devices in a partial policy state are cleaned up once automatically after the update is applied.

  • Who Is Affected: Only environments using both co-management and third-party update catalogs. Pure ConfigMgr-only or pure Intune/WUfB environments are not affected.

If your organization uses co-management and has third-party update catalogs enabled in ConfigMgr, treat this as a high-priority fix. Devices may be silently receiving patches from the wrong channel without any obvious console alerts.

āœ… Software Center Compliance Check Failure — Act Before October 2026 (KB37172183)

āœ… This fix comes with a firm deadline. An internal service used by the ConfigMgr client to acquire authentication tokens for Intune compliance services will be deprecated in October 2026. After that date, Software Center compliance checks will fail in co-managed environments where the Compliance workload is switched to Intune, with the error GET_TOKEN_FROM_STS_ERROR : FFFFFFFF80004003.

  • Affects: ConfigMgr 2409 and 2503 environments with co-management enabled and the Compliance workload set to Intune.

  • Resolution: The client has been updated to use a newer token acquisition method compatible with current Intune compliance services.

  • For 2509: This fix is included in the 2509 update rollup (KB36949461) — no separate hotfix needed.

  • For 2603: This fix is included in version 2603 by default.

Hard deadline: If you are on 2409 or 2503 and have the Compliance workload managed by Intune, apply KB37172183 before October 2026 or your devices will lose the ability to perform Software Center compliance checks.

šŸ” NAA Security Hardening Update (KB37447175)

šŸ” Included in both the 2509 update rollup and version 2603, this security update tightens access controls for the Network Access Account (NAA). This is the same hardening work that shipped in 2603 — it removes legacy access paths to NAA information and restricts access to supported OSD media task sequence scenarios only, aligning with least-privilege security principles.

If you are staying on 2509 for now, this update backports the NAA hardening without requiring a full version upgrade. Given that NAA credentials can be sensitive, this is worth prioritising.

šŸ’» ARM64 Client Upgrade Failures (KB36949461)

šŸ’» Two related ARM64 issues are fixed in the 2509 update rollup, relevant for environments that have begun deploying Windows 11 ARM64 devices.

  • Initial upgrade failure: CcmSetup fails with error 0x80070643 on Windows 11 ARM64 devices when upgrading from ConfigMgr 2403 or 2503 to 2509. The installer attempts to uninstall a 32-bit Microsoft Policy Platform (MPP) component that simply does not exist on ARM64 architecture.

  • Cascading failure: If the initial upgrade failed, all subsequent upgrade attempts also fail — the 64-bit MPP installs without checking whether it is already present, causing client.msi to abort. This fix breaks that retry loop.

  • Affected hardware: Windows 11 25H2 ARM64 and 26H1 ARM64 devices. x64 devices are not affected.

šŸ–„ļø OSD: Applications with OS Requirements Fail with HTTP 404 After 2509 Upgrade (KB36949461)

šŸ–„ļø Admins running OSD task sequences after upgrading to ConfigMgr 2509 may have hit this one hard. Applications with OS requirement rules — such as 'All x64 Windows 11 and higher Clients' — fail to install during task sequence execution with HTTP 404 errors recorded in CIDownloader.log.

Multiple applications that reference the same OS requirement rule fail simultaneously, which can cause an entire OSD deployment to abort mid-flight. The 2509 update rollup resolves this regression.

šŸ›”ļø Defender Endpoint Protection Workload Transition Bug (KB36949461)

šŸ›”ļø When the Endpoint Protection co-management workload is switched from ConfigMgr to Intune, Microsoft Defender does not correctly pick up Intune's EP settings in some environments. Defender continues operating as though ConfigMgr is still managing it — meaning Intune AV policies including tamper protection are not applied.

The root cause is a stale registry key left behind by the ConfigMgr client after the workload transition. The update removes this residual key so Defender correctly recognises the new management authority.

šŸ”­ Intune EDR Policies Failing on Tenant-Attached Clients (KB36949461)

šŸ”­ In ConfigMgr 2509, Intune Endpoint Detection and Response policies fail to apply on ConfigMgr clients managed via tenant attach without co-management. The client does not receive or process EDR policy from Intune in this configuration, and policy deployment errors appear in client logs. This is a regression introduced in 2509 and is resolved in the update rollup.

šŸ”­ Other Fixes in the 2509 Update Rollup

  • Build and Capture task sequences on Windows 11 24H2: Using November or December 2024 media produces a 'Why did my PC restart' error dialog when the captured image is subsequently deployed. Fixed in KB36949461.

  • Windows 10 IoT Enterprise LTSC 2021 incorrectly flagged as unsupported: Devices running Windows 10 IoT Enterprise LTSC 2021 (21H2, Build 19044) are shown as end-of-life in Management Insights and the Product Lifecycle dashboard despite having mainstream support until January 2027. Fixed in KB36949461.

  • Offline feedback authentication (KB36419072): Starting 26 June 2026, feedback submission requires authentication. This hotfix updates the client accordingly. Note: the standalone UploadOfflineFeedback.exe tool has a known issue and will be fixed in a future release — use the in-product feedback UX or Feedback Hub in the meantime.

  • Microsoft Connected Cache behind proxy servers (KB33247081): Fixes MCC installation failures where proxy servers require absolute URLs. Also adds HTTPS content delivery support for Connected Cache, enabling secure distribution of Intune-managed Win32 apps and Microsoft Teams content.

šŸ“‹ How to Apply These Updates

šŸ“‹ The 2509 update rollup (KB36949461) is available directly in the Configuration Manager console under Administration → Updates and Servicing. It will initiate a site reset after installation — plan accordingly.

  • Console version after update: 5.2509.9141.1030

  • Client version after update: 5.0.9141.1030

  • Secondary sites must be manually updated after the primary site is patched. Use Administration → Site Configuration → Sites → Recover Secondary Site.

  • Verify secondary site update status with: select dbo.fnGetSecondarySiteCMUpdateStatus ('YourSiteCode'). A return value of 1 means up to date; 0 means action required.

  • For 2503 environments: apply KB37172183 (Software Center compliance fix) before October 2026. Apply KB36495448 if co-management and third-party catalogs are both enabled.

šŸ“Œ The Bottom Line

This is a meaningful batch of fixes. The co-management update source regression (KB36495448) and the Software Center compliance deadline (KB37172183) are the two that demand the most immediate attention — one is a silent correctness issue affecting patching authority, and the other has a hard expiry date. The NAA security hardening and ARM64 upgrade fixes round out a release that is well worth prioritising in your change management cycle.

If you have already upgraded to 2603, the NAA hardening, EDR regression fix, and compliance check fix are all included in that release. But if you are holding on 2503 or 2509 for now, get these hotfixes applied before the October deadline arrives.

Tags: Configuration Manager | SCCM | ConfigMgr Hotfix | 2503 | 2509 | Co-Management | Software Updates | ARM64 | NAA Security | Microsoft Intune | Patch Management | Endpoint Security | IT Admin | Enterprise IT

Ā 
Ā 
Ā 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating*
bottom of page