How to Fix SCCM Software Center Applications Stuck at 0 Percent
Question details
Remote Configuration Manager clients are unable to install applications or updates through Software Center, with downloads continuously hanging at 0%.

- Product
- Microsoft Configuration Manager (SCCM)
- Device & OS
- Windows
- Scenario
- Installing applications or software updates remotely via Software Center after a Cloud Management Gateway (CMG) certificate has been renewed.
- Observed behavior
- Downloads get stuck at 0 percent. Client logs display WinHttpSendRequest error 0x2f8f and indicate an access-check failure.
Ensure you have administrative access to the SCCM Console, permission to view client logs, and access to your PKI or certificate authority to verify certificate validity.
Verify and Fix Cloud Management Gateway (CMG) Certificates
Error 0x2f8f is a WinHTTP secure-communication failure, typically caused by an invalid or improperly configured CMG certificate after a renewal.
When a CMG certificate is renewed, misconfigurations in the certificate's properties or trust chain can block secure communication, resulting in stalled downloads.
Open your Certificate Authority or MMC certificates snap-in. Ensure the renewed CMG certificate has the correct subject name, is within its validity period, and explicitly includes its private key.
Confirm that the remote clients have the corresponding root certificate installed in their Trusted Root Certification Authorities store so they can trust the new CMG certificate.
Ensure the CRL is published and externally accessible to clients. If the client cannot verify the revocation status, the secure connection will fail.

Analyze Configuration Manager Client Logs
Reviewing specific SCCM client logs will pinpoint where the secure communication or access check is failing.
Verify Network Rules and Permissions
Misconfigured firewalls, proxies, or missing user permissions can block client communication, resulting in access-check failures.
Streamline Your Deployments with WPS Office
While resolving complex SCCM deployment and certificate issues for heavy enterprise software, consider switching to WPS Office. It provides a lightweight, easy-to-deploy alternative to Microsoft Office that saves network bandwidth and reduces deployment errors.
- 1. Download the lightweight installer: Visit the WPS Office website and download the enterprise deployment package.
- 2. Deploy via SCCM: Create a new application in Configuration Manager. The small file size ensures fast and reliable distribution to your endpoints.
- 3. Install and run: Deploy the application to your clients. Users can immediately start working with full Microsoft Office compatibility.

Frequently Asked Questions
What does WinHttpSendRequest error 0x2f8f mean in SCCM?
Error 0x2f8f translates to a secure-communication failure. In the context of SCCM, it usually means the client cannot establish a trusted SSL/TLS connection with the Cloud Management Gateway (CMG) because the certificate is expired, untrusted, or missing a private key.
Where are the SCCM client logs located for troubleshooting download issues?
Client logs are typically located in the 'C:\Windows\CCM\Logs' directory. Key logs for download and communication issues include DataTransferService.log, LocationServices.log, and CCMMessaging.log.
Why do Software Center downloads stay at 0% even with an active internet connection?
Downloads remain at 0% if the client fails the pre-download access checks or secure communication handshakes. This happens if the CMG certificate is invalid, network proxies are blocking the traffic, or the client lacks the necessary deployment permissions.




