If you deployed cloud-hosted environments (CHE) last year, you probably noticed that many of them had issues with Windows update. When you try to search for the updates, the error appears: "We couldn't connect to the update service. We'll try again later, or you can check now. If it still doesn't work, make sure you're connected to the Internet." 
The internet connection works fine, all required services are running, so the problem must be somewhere else.
The solution was found on Yammer, below are the steps how to fix the machine:
- Open a command prompt as Administrator and run: reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /f /v WinREVersion /t REG_SZ /d "10.0.20348.2201" 
- Open a regedit, and navigate to HKLM/Software/Policies/Microsoft/Cryptography/Configuration/SSL/00010002
- Modify the "Functions" key to add the follow two ciphers to the end of the existing list:
 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA256
- Restart the VM
 



