Have you setup target groups using the GPO? I’ve seen multiple (albiet, duplicates only) when target groups are used. If you use the target group, don’t move them around manually or they will be recreated when they check in to the server again. Also, if you do wuauclt /resetauthorization /detectnow it will generate a new sid and you’ll get duplicates. To avoid this, run wuauclt /detectnow to check for new updates.