Can SCCM or WSUS actively initiate a new TCP connection to the client?

Solution 1:

No neither SCCM nor WSUS pushes to end client. End clients always pull from SCCM or WSUS.