Configuration Manager 2503 administrators should plan to leave that branch before September 30, 2026, but the important decision is not simply whether to upgrade. The preferred target is Configuration Manager 2603; if change control requires Configuration Manager 2509, install KB37864969 before treating the upgrade as complete, because 2509 without that later rollup can retain the documented co-management scan-source issue.
Microsoft lists September 30, 2026, Pacific Time, as the end-of-support date for Configuration Manager current branch version 2503. That leaves time for a controlled migration, but it should not be treated as routine lifecycle housekeeping where the first newer version is automatically the finished destination.
The practical concern is co-management. In affected environments, Configuration Manager can leave a partial Windows Update scan-source policy behind when third-party updates are enabled. That policy can interfere with devices that are intended to receive Windows quality and feature updates through Intune and Windows Update for Business.
WindowsForum’s reporting on Configuration Manager servicing, including its coverage of a separate Configuration Manager 2509 security update, has repeatedly highlighted the same operational lesson: a version number alone is not a patch posture. For this co-management issue, the target state matters as much as the decision to leave 2503.

Windows Configuration Manager upgrade roadmap showing baseline 2503, targets 2603 or 2509, and a September 2026 deadline.The Recommended Target Is 2603, or 2509 Fully Updated With KB37864969​

Configuration Manager 2603 is the simpler destination for most organizations because its published change information includes KB36495448, the co-management and third-party update scan-source fix.
A move to 2509 can still be appropriate where a team has a defined validation schedule, application dependency, or change-control reason to use that branch. But a bare 2509 deployment is not the finished state for organizations exposed to this issue. The required 2509 destination is:
  • Configuration Manager 2509 with KB37864969 installed
The supplied update information establishes three important facts:
  • The issue is documented in Configuration Manager 2503 with KB32851084 installed and in Configuration Manager 2509.
  • The April 2026 2509 rollup, KB36949461, did not include the scan-source correction.
  • The later 2509 rollup, KB37864969, includes the scan-source fix.
That is enough to make the upgrade choice operationally clear. Do not use “we reached 2509” as the completion criterion. Use “we reached 2603” or “we reached 2509 and installed KB37864969” as the completion criterion.

Decision Matrix for Co-Managed Environments​

The exposure is not universal across every Configuration Manager deployment. It is most relevant when co-management, third-party updates, and an Intune-controlled Windows Update workload overlap.
Current conditionRequired target stateWhat to validate
Configuration Manager 2503 with KB32851084; third-party updates enabled; Windows Update for Business or Intune owns the Windows Update workloadMove to 2603, or move to 2509 and install KB37864969 before validationConfirm that representative co-managed devices receive Windows update policy and update offers through their intended update-management path.
Configuration Manager 2503 without the identified exposure conditionsMove off 2503 before September 30, 2026Follow the organization’s normal current-branch upgrade and client validation process.
Configuration Manager 2509 with only KB36949461Install KB37864969 before closing the servicing changeRe-test the co-managed devices whose Windows Update workload is assigned to Intune.
Configuration Manager 2603Maintain normal servicing and client rollout planningValidate a representative co-managed device ring after site and client changes.
The first row is the one administrators should prioritize. If the site is on 2503, KB32851084 is present, third-party updates are enabled, and the Windows Update workload is assigned or piloted to Intune, the supported planning choice is not to linger on an intermediate 2509 state. Move to 2603, or make KB37864969 part of the 2509 rollout before validation begins.

What Microsoft Documented About the Scan-Source Issue​

Microsoft documented the issue in Configuration Manager 2503 with KB32851084 installed and in Configuration Manager 2509 when Configuration Manager third-party updates are enabled. The affected client can retain a partial Windows Update scan-source policy.
The key implication is straightforward: a device intended to follow Intune and Windows Update for Business policy for Windows quality and feature updates can instead behave according to an unintended scan-source configuration.
This is not merely a discrepancy between what the co-management workload assignment displays and what an administrator expects. The reason for the upgrade guidance is that the client’s Windows Update behavior must align with the workload path the organization selected.
For organizations using co-management as a staged transition away from WSUS-centered servicing, this deserves focused validation. Co-management deliberately allows workload-by-workload migration and pilot groups. That flexibility means an environment can contain devices with different intended update paths at the same time. A broad site-level upgrade check is therefore not enough; test the clients whose Windows Update workload has actually moved to Intune.

A Focused Execution Plan​

This article is a decision and validation guide rather than a substitute for Microsoft’s current installation documentation or an organization’s approved change procedure. The concrete objective is to reach a supported target state and prove it on the client groups affected by the documented conditions.

1. Inventory the site and rollup level​

For each primary site, record:
  • The current Configuration Manager version.
  • Whether the site remains on 2503.
  • Whether KB32851084 is installed on a 2503 site.
  • Whether a 2509 site has KB37864969 installed.
  • Whether the organization intends to use 2603 or remain temporarily on 2509.
Do not infer the patch level from a project record or a completed maintenance window. Confirm the installed servicing state through the organization’s normal Configuration Manager update-status and update-history process, and retain that evidence with the change record.

2. Identify the client population that needs validation​

Create a test list from devices that meet all of the following conditions:
  • They are co-managed.
  • Their Windows Update workload is assigned or piloted to Intune.
  • They are expected to receive Windows quality updates or feature updates through Windows Update for Business.
  • The environment has Configuration Manager third-party updates enabled.
Use existing pilot collections or a deliberately small validation collection where possible. The goal is not to test every endpoint before the site upgrade; it is to test the endpoints most likely to demonstrate whether the intended update path is working.

3. Select the upgrade destination before the maintenance window​

For most organizations, make 2603 the default destination because the published 2603 information includes KB36495448.
If the approved destination is 2509, build KB37864969 into the same servicing plan. Do not schedule the 2509 upgrade as one change and leave the later rollup as an optional cleanup item. The 2509 rollout is not complete for this issue until KB37864969 is present.
This distinction is particularly useful for teams that divide work between infrastructure administrators, endpoint engineering, and Intune operations. The infrastructure team can complete the site upgrade while the endpoint team validates clients, but both teams need the same target-state definition.

4. Roll out clients through the normal controlled process​

After site servicing, use the organization’s established Configuration Manager client rollout process and maintenance controls. Keep the first client-validation group small enough that administrators can review outcomes before broadening deployment.
The essential evidence is not just that a client upgraded successfully. It is that an affected co-managed client receives the Windows Update behavior expected from its Intune-assigned workload.

5. Validate actual update behavior​

Use representative devices from the identified validation group and test both of the update categories named in the documented concern:
  • A quality update scenario.
  • A feature update scenario, where the organization has an applicable offer or deployment plan.
Confirm the device is in the intended co-management population and that the Windows Update workload is assigned to Intune. Then validate observed update discovery and offer behavior through the organization’s standard endpoint and Intune reporting tools.
Avoid treating a displayed workload assignment by itself as proof that the client is scanning from the intended source. The servicing fix exists because the client-side policy condition can matter even when the intended workload design is clear.

Troubleshooting Hypotheses to Use Carefully​

A device that does not receive an expected update can have many causes. The documented Configuration Manager issue should be treated as a troubleshooting hypothesis only when the known exposure conditions are present:
  1. The site is on the affected 2503 configuration or on 2509 without KB37864969.
  2. Configuration Manager third-party updates are enabled.
  3. The device is co-managed.
  4. The Windows Update workload is assigned or piloted to Intune.
  5. The device is expected to receive quality or feature updates through Windows Update for Business.
If those conditions match, first confirm the site’s actual servicing level and complete the required upgrade path. Do not begin by manually altering client policy or registry settings as a replacement for the Configuration Manager fix. Manual client changes can make one endpoint harder to interpret and do not establish that the site will configure policy correctly after future policy processing.
If the conditions do not match, investigate through the organization’s normal update troubleshooting process rather than assuming this particular scan-source issue is the cause.

Why the September 2026 Deadline Still Matters​

Configuration Manager 2503 remains supported until September 30, 2026, but current-branch servicing is not a reason to postpone a planned move until the last possible maintenance window. Microsoft’s servicing model gives the newest branch both security and critical non-security fixes, while older supported branches receive security updates only.
That makes the deadline relevant for two separate reasons:
  • The organization must remove 2503 before its support period ends.
  • The upgrade should land on a servicing level that addresses the co-management scan-source issue where the documented exposure conditions exist.
A rushed move to 2509 that stops before KB37864969 can create unnecessary follow-up work. A planned move to 2603, or a planned 2509 deployment that includes KB37864969 from the beginning, gives administrators a clearer validation target.

Frequently Asked Questions​

Does Configuration Manager 2503 become unsupported on September 30, 2026?​

Yes. Microsoft lists September 30, 2026, Pacific Time, as the end-of-support date for Configuration Manager current branch version 2503.

Is Configuration Manager 2509 sufficient if KB36949461 is installed?​

Not for this specific co-management scan-source issue. The available information says KB36949461 did not include the scan-source correction. Organizations using 2509 need the later KB37864969 rollup for that fix.

Why is 2603 the preferred upgrade target?​

Configuration Manager 2603 includes KB36495448, the relevant co-management and third-party update scan-source fix. It provides a clearer destination than stopping at an earlier 2509 servicing level.

Which environments should prioritize this issue?​

Prioritize co-managed environments where Configuration Manager third-party updates are enabled and the Windows Update workload is assigned or piloted to Intune for devices expected to receive Windows quality or feature updates through Windows Update for Business.

Should administrators manually edit Windows Update policy or registry settings?​

No manual change should be treated as a substitute for the Configuration Manager servicing fix. Confirm the site’s update level, apply the appropriate target-state update, and validate the affected client population through normal policy and update-management processes.
The practical goal before September 30, 2026 is not merely to remove Configuration Manager 2503. It is to ensure that every affected co-managed device reaches a fixed servicing state and that its real Windows update behavior matches the update workload the organization assigned.

References​

  1. Primary source: learn.microsoft.com
  2. Independent coverage: docs.citrix.com
  3. Primary source: WindowsForum