Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Windows Update display stuck at 0% is a symptom, not a diagnosis. On Windows Server 2016, Microsoft documents one specific cause: when BITS handles the download, a disabled Windows Defender Firewall service can leave the download at 0%, sometimes with error 0x800706D9. Check the update logs and error code before changing services or resetting components. The exact 0% scenario is documented for Server 2016; it is not established as a universal cause on Server 2019 or 2022.

1. Find out whether the update is scanning, downloading, or installing

Before applying a fix, identify the update, the stage where progress stops, and any associated error. A 0% display alone does not show whether the server cannot find an update, cannot download it, or has failed during installation.

  1. Check Event Viewer. Review Windows Update Agent events in the System log and related errors in the System and Application logs around the time of the attempt.
  2. Open the Windows Update operational log. In Event Viewer, go to Applications and Services Logs > Microsoft > Windows > WindowsUpdateClient > Operational. Match events to the failed update and note the error code.
  3. Review the update log files. For download or connection failures, inspect %windir%logswindowsupdate. Keep the relevant entries before clearing caches or resetting components.

Use the error and phase to choose a matching check. Microsoft’s Windows Server update troubleshooting guidance recommends starting with logs and working through troubleshooting in stages.

2. Check the documented Server 2016 BITS and firewall case

If this is Server 2016 and the log shows 0x800706D9 or a related BITS download error, check the Windows Defender Firewall service in the Services console and confirm that it is enabled. Microsoft identifies BITS as the default download manager in this particular 0% scenario and associates the problem with the firewall service being disabled. See Microsoft’s Windows Update issues troubleshooting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Dell PowerEdge T340 Tower Server, Windows 2019 STD OS, Intel Xeon E-2124 Quad-Core 3.3GHz 8MB, 32GB DDR4 RAM, 8TB Storage, RAID, Single PSU (Renewed)
  • 3.5 Inch Hot Plug Hard Drive PowerEdge T340 Tower Server Chassis
  • Microsoft Windows Server 2019 Standard Operating System
  • Processors: Intel Xeon E-2124 Quad-Core 3.3GHz 8MB CPU, Up To 4.3GHz Turbo
  • Memory: 32GB (2 x 16GB) DDR4 PC4-21300 2666MHz Unbuffered Memory
  • Hard Drive: 8TB (4 x 2TB) 7.2K RPM 6Gb/s SATA 3.5 Inch HDDs in RAID

Do not stop or disable the firewall service to try to get updates moving. Microsoft states: “Stopping the service associated with Windows Firewall with Advanced Security isn’t supported by Microsoft.”

3. If the code points to connectivity, check network access and TLS

When logs indicate a connection problem, check the route from the server to its configured update source—not just the Windows Update screen. Microsoft identifies firewall rules or proxies blocking Microsoft download URLs as a possible cause of 0x80072EFD, and TLS cipher issues affecting connections to Microsoft sites as a possible cause of 0x80072EFE. These code mappings appear in Microsoft’s Windows Server troubleshooting guidance, last updated February 12, 2026.

  • Check whether a proxy or network virtual appliance handles outbound traffic and whether its rules permit the required update endpoints.
  • Verify that outbound ports 80 and 443 are available where required by your update path.
  • Confirm TLS 1.2 is enabled. If ordinary external sites work but Microsoft endpoints do not, review any managed SSL cipher Group Policy as well.
  • Use the endpoint allowlist that matches the server operating system and update channel. Microsoft notes endpoint details can vary, so do not assume a list for a client Windows release is complete for Server 2019 or Server 2022.

4. Check update policy, WSUS, and pending reboot state

On a managed server, verify that policy settings do not conflict and that the machine is scanning the intended update source. A server configured for WSUS will not necessarily retrieve updates directly from Microsoft Update.

If the server uses WSUS

  • Confirm the Update Services and World Wide Web Publishing Service are running.
  • Check that the WSUS site is running and review its IIS logs for connection errors.
  • Check whether the update is actually offered to the server. A paused or scheduled deployment can mean an update is not yet available; that differs from a download that has started and remains at 0%.

If a restart may be pending

Check whether the server has a pending restart and whether it has restarted since the last servicing operation. Microsoft’s server checklist includes restarting when the machine has not restarted, then reviewing servicing-stack status and following the applicable troubleshooting guidance. Avoid changing multiple settings at once: record the current policy and update source so you can identify which change affects the result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Acer Aspire 14in AI Copilot+ Laptop 16GB RAM 1TB SSD Intel Arc 140V
  • Powerful Processing: Equipped with the advanced Intel Core Ultra 7 256V, ensuring swift, reliable performance for complex tasks and AI applications.
  • Rapid Memory: Features 16GB LPDDRX Onboard RAM, providing the bandwidth necessary for fluid multitasking across numerous applications.
  • Expansive Storage: Includes a high-speed 1TB NVMe M.2 SSD for rapid data access, quick system startups, and substantial capacity for all your data.
  • Vivid Display: Presents stunning visuals on a 14-inch IPS LED screen, offering excellent clarity, color accuracy, and wide viewing for all your content.
  • AI Optimized: Certified as a Copilot+ PC, this laptop fully leverages next-gen Windows AI features for enhanced productivity and intuitive computing.

5. Repair component corruption when logs support it

If the evidence points to damaged Windows image or system files, Microsoft’s repair guidance for Server 2016 and later recommends running DISM followed by System File Checker from an elevated command prompt:

  1. Run DISM.exe /Online /Cleanup-image /Restorehealth.
  2. After DISM completes, run sfc /scannow.

DISM normally uses Windows Update to obtain repair content. If the server cannot reach that source, Microsoft describes using a working repair source from the same operating system version. If DISM reports that repair did not complete successfully, review %windir%LogsCBSCBS.log for details. See Microsoft’s guidance for fixing Windows Update errors. These commands address component or system-file corruption; they do not identify or resolve every network, policy, or WSUS issue.

Rank #4
Dell Latitude E6530 Notebook 15.6' Business Laptop PC (Intel Core i5-3210M, 4GB Ram, 128GB SSD, Webcam, HDMI, WiFi, DVD-RW) Win 7 Pro (Renewed)
  • This Certified Refurbish product is tested and certified to look and work like new. The refurbishing process includes functionality testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high performance bar may offer Certified Refurbish products on Amazon.com
  • Processor : Intel 3rd Generation Core i5-3210M @ 2.50GHz, (Turbo Boost Upto 3.30GHz) High Performance Processor.
  • 4 GB DDR3 Ram / 128 GB 2.5 Inch Sata Solid State Drive.
  • 15.6 Inch HD (1366 x 768) Anti Glare Scree, Intel HD Graphics, HQ Camera, Wireless WIFI, HDMI, VGA, 3 x USB 3.0, Numeric KeyBoard, Head Phone Jack, eSATA Port, RJ-45.
  • Windows 7 Professional (64 Bit). Comes With AC Adapter.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Reset Windows Update components only after targeted checks

Manual component resets are an escalation, not the first response to a 0% display. Microsoft’s reset guidance recommends using the troubleshooter first and places a manual reset after other steps. Its documented process stops BITS, Windows Update, and Cryptographic services and renames relevant cache folders. Consult Microsoft’s Windows Update component reset guidance and follow the instructions appropriate to the server.

Be especially cautious with the more aggressive step that resets BITS and Windows Update service security descriptors: Microsoft warns that it overwrites existing service ACLs. Do not run a broad reset script before capturing relevant logs and identifying the failure mode.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
2-Bay RAID 0/1 USB 3.2 Gen 2/eSATA External Hard Drive (HDD RAID 0, 48TB)
  • high capacity with 2 hard drives
  • USB-A 3.2 Gen 2 10Gbps/eSATA
  • RAID 0 striping for fast transfer
  • built-in quiet fan for cool operation
  • TAA and 889 compliant, ECCN: EAR99, HTS: 8471705065

Which check should you try first?

Evidence First check
Server 2016, BITS download failure, or 0x800706D9 Confirm the Windows Defender Firewall service is enabled; do not disable it.
0x80072EFD or evidence of failed endpoint access Check proxy, firewall, network appliance egress, and the applicable update endpoint allowlist.
0x80072EFE or evidence of TLS negotiation failure Check TLS 1.2 and, where managed, SSL cipher Group Policy.
Managed server that may not be receiving the update Verify policy, intended update source, deployment schedule, and WSUS services and logs.
Logs indicate component or system-file corruption Run DISM, then SFC; inspect CBS.log if DISM fails.

For Server 2019 and 2022, use the same log-first diagnostic approach, but do not assume the Server 2016 firewall finding is the cause. The specific 0% passage applies to Server 2016; the appropriate fix on any release depends on the error, update source, and phase of failure.

Quick Recap

Bestseller No. 1
Dell PowerEdge T340 Tower Server, Windows 2019 STD OS, Intel Xeon E-2124 Quad-Core 3.3GHz 8MB, 32GB DDR4 RAM, 8TB Storage, RAID, Single PSU (Renewed)
Dell PowerEdge T340 Tower Server, Windows 2019 STD OS, Intel Xeon E-2124 Quad-Core 3.3GHz 8MB, 32GB DDR4 RAM, 8TB Storage, RAID, Single PSU (Renewed)
3.5 Inch Hot Plug Hard Drive PowerEdge T340 Tower Server Chassis; Microsoft Windows Server 2019 Standard Operating System
$2,009.46
Bestseller No. 4
Dell Latitude E6530 Notebook 15.6' Business Laptop PC (Intel Core i5-3210M, 4GB Ram, 128GB SSD, Webcam, HDMI, WiFi, DVD-RW) Win 7 Pro (Renewed)
Dell Latitude E6530 Notebook 15.6' Business Laptop PC (Intel Core i5-3210M, 4GB Ram, 128GB SSD, Webcam, HDMI, WiFi, DVD-RW) Win 7 Pro (Renewed)
4 GB DDR3 Ram / 128 GB 2.5 Inch Sata Solid State Drive.; Windows 7 Professional (64 Bit). Comes With AC Adapter.
$249.95
Bestseller No. 5
2-Bay RAID 0/1 USB 3.2 Gen 2/eSATA External Hard Drive (HDD RAID 0, 48TB)
2-Bay RAID 0/1 USB 3.2 Gen 2/eSATA External Hard Drive (HDD RAID 0, 48TB)
high capacity with 2 hard drives; USB-A 3.2 Gen 2 10Gbps/eSATA; RAID 0 striping for fast transfer

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.