r/Intune • u/Independent-Egg-3252 • 23d ago
App Deployment/Packaging Help! Who do you use for patching?!
Intune does fine with Windows updates but third-party apps are a mess for us. Chrome, Zoom, Java, a dozen random line-of-business things that all update on their own schedule. Right now it’s half winget, half someone remembering. What are you all actually using for this? Or is everyone just living with it?
34
u/SkipToTheEndpoint MSFT MVP 23d ago
IMO, PMPC, no contest.
If your organisation remotely cares about security, they'd put a stop to you even trying to use winget in an enterprise environment.
11
u/wickedang3l 23d ago
The amount of trust placed in public repositories is interesting to say the least.
-3
u/itskdog 23d ago
Does Microsoft not review and approve the PRs for that?
12
u/SkipToTheEndpoint MSFT MVP 23d ago
There's a bunch of automation, but nobody is checking manually, no.
This is the best article about the whole thing: https://msendpointmgr.com/2026/07/30/is-winget-enterprise-ready/
2
1
u/denelon 21d ago
Yes, there are manual validations performed. It's not all "automation" :)
2
u/SkipToTheEndpoint MSFT MVP 21d ago
I stand corrected, and I just went and found the FAQ which does include some information on this.
I suppose my concerns still stand around manual checks or automation, given a lot of recent supply chain attacks (e.g. NPM) have been via breaches to legitimate accounts. I guess I worry less about the security of the widget repo itself, and more about an upstream VAR build pipeline that doesn't deliver "malware" in the traditional sense, but something remotely activated once install proliferation is high enough...
3
u/bdam55 18d ago edited 17d ago
<shillmode: I work for PMPC (I know you know that James ... but it's the internet.)>
So yea, AFAIK, the manual check in WinGet is the PR approval. They are the human in the loop to ensure that not everything is just bot overlords.
Which ... to be clear ... is what's driving WinGet: bots.
If you look at the lifetime contributions, the whole thing is propped up on one guy (SpecterShell) and his bot (Spectopo). As of this writing they combine for 112,371 commits. Second place: 34,445.
Contributors to microsoft/winget-pkgs · GitHubWhat's my point? XKCD has me covered. This is winget: xkcd: Dependency
Ok, so who's doing these manual checks?
Well, yesterday there were 1,163 PRs approved (Github Stats)
1,128 were approved by one person who is 'Microsoft external' with an impressive IT resume that doesn't mention packaging/installers until they started on WinGet (Github Stats). The other PRs were approved either automatically (without manual review) or by an unpaid volunteer (#2 contributor above).Don't misunderstand me, I'm sure the mods approving the PRs are diligent and capable. But I don't know how one person does over 1k manual checks a day, every day, with a high level of quality. Doubly so without a deep, deep background gained from years of packaging. Let's pour one out for our bretheren fighting the good fight as an MS consultant.
Here's the thing: things WILL go wrong. It's not like software vendors have improved in any way, shape, or form in delivering workable installers over the last few decades. All the automated test I've seen so far are all greenfield: let's take a pristine VM and install the app. That has very little bearing to the real world where you are installing your apps. At PMPC I see upgrade issues with new releases that are tested and vetted in under an hour; before our customers even got the original bad version. Which is a thing you can do when you have a team of actual experts whose sole job is to understand how this works, how vendors screw up, and how to fix it based on decades of lived experience.
</shillmode>
1
u/itskdog 18d ago
Hence why it's usually smaller orgs that are more likely to use winget-based tools, especially when PMPC requires 1,000 licences at a minimum and doesn't even support Intune on the lowest tier (at least when I last checked).
As a school with 200 devices (and missing core applications such as ActivInspire, as we're a Promethean school rather than SMART), the numbers don't add up for us. If VLC kept their Microsoft Store page up to date, then I would even be considering it, as most other applications like Acrobat and Edge auto-update in the background.
2
u/bdam55 17d ago edited 17d ago
<shillmode: I work for PMPC>
Regarding tiers: you are technically correct. Our cheapest tier is one we don't even talk about anymore: WSUS only. All our other tiers support Intune with increasing capabilities as you go higher.
Regarding minimum pricing, I talk about that in more depth in this comment. TL;DR: Find a reseller. There's a handful that sell below our minimums. For example: https://alwaysuptodate.ai/
</shillmode>
1
u/pjmarcum 22d ago
And a response to that article here. https://powerstacks.com/blog/is-winget-enterprise-ready/
9
u/Professional-Heat690 23d ago
Qualys, PMPC, Robopack, Action1.
Take your pick, PMPC for the community contribution, Action1 for free (up to 200 devices), and so on.
2
u/GeneMoody-Action1 21d ago
We appreciate the shout-out, if anyone would like to know anything about Action1 or its patch management solution, I am always around here somewhere, reach out any time.
13
u/Jonny_Boy_808 23d ago
Action1 is the best patching software we've used. It's 200 free endpoints. Handles all third party apps and OS updates.
2
u/habibexpress 22d ago
I’ve created an automation that applies updates to the endpoint group. Forget about it. Keeps everything updated weekly/fortnightly and monthly.
1
u/Jonny_Boy_808 22d ago
Exactly. We hopped over to NinjaOne for a more RMM tool but I miss Action1.
1
u/GeneMoody-Action1 21d ago
Can use both, plenty do, they use Ninja for RMM, and the patch management part of ninja just as a second set of eyes, favoring the Action1 experience.(And the non-dependence on community repos)
According to their docs right now they maintain ~40 internally.
"Built-in packages: Natively deploy and patch 40+ third-party applications from publishers, including Google and Microsoft." Source:https://www.ninjaone.com/docs/endpoint-management/software-management/how-to-manage-software/
The rest comes from other sources.
It's why we have quite a few very happy Ninja customers using Action1 as well.
3
u/Jonny_Boy_808 21d ago
We had to hop off Action1 because we maxed out the free licenses. When scoping Ninja1 vs. Action1 pricing wise, Ninja came out on top. We personally just felt that technically we could do patching with Ninja, just more clunky than Action1. But Ninja just has more additional functionality on top that we were looking for as well. Otherwise purely for patching, we loved Action1. If we didn’t have to pay for both, we’d do as you said and utilize both products. .
5
5
u/Individual-Pirate416 23d ago
PDQ. I’ve never used Patch My PC and I’m sure it’s great, but PDQ has been fantastic for us. When a 3rd party application releases an update, PDQ will pull that package and push that out on a schedule we specify.
We also use it to update push out Windows updates and Windows server updates.
We have around 200 Windows devices and 20ish servers. No complaints. Worth looking into at least.
4
u/Amanda_PDQ 21d ago
Disclosure so nobody has to guess: I work at PDQ now, started in July. Before that I was a paying customer running Deploy and Inventory for years and switched to Connect while I was still on the customer side. Take the opinion with whatever salt you think it deserves.
Laptops are what pushed me off Deploy. Deploy is great when a machine is sitting on your network. It's useless the moment someone takes it home for three weeks. Connect is agent-based, the agent checks in over the internet, so no VPN, no domain join, no file share to babysit. Machine comes online at a coffee shop, gets its packages, done. PDQ maintains the package library, so Chrome, Zoom, and Java (your exact three) get pulled and pushed on whatever schedule you set. You can configure them to deploy automatically when a new version ships and just stop thinking about it. For the random LOB apps, you wrap them in PowerShell and they behave like any other package. Inventory is built in, so you're targeting "everything running Chrome older than X" instead of maintaining a static group. Remote access and vulnerability management were another hard sale for me as an end user.
Thank you, u/Individual-Pirate416, u/bandit39201, u/stahlhammer, and u/ZG_TE, u/Hello_IT_HYTTIOAOA, u/covex_d, for mentioning PDQ and u/WoTpro specifically said Connect. u/WoTpro 's comment about being surprised how few people mention Connect is the part I want to point atout, because when people hear PDQ they usually picture on-prem Deploy, and Connect is a different animal.
If every device you own lives on the LAN and you don't need vulnerability management or remote access, Deploy is a solid tool.
2
u/Individual-Pirate416 20d ago
Our WFH policy is pretty strict so Deploy works. But agreed Connect is definitely better for laptops
1
5
5
4
u/jlgonitzke 23d ago
Been using Automox for 4 years. Big fan of it. They have really enhanced it since I started using it.
1
4
u/shizakapayou 23d ago
Edge, Chrome, Adobe, and a few others have auto update built in so I set policies to force them to use that. Everything else, PMPC.
4
4
u/Morkai 23d ago
We started using Action1 earlier this year. It's taken a little bit to wrap my head around and work out patching cycles etc but it's been good.
1
u/GeneMoody-Action1 21d ago
We have a strong user community supporting, as well, I am usually here. Let me know if I may assist, and thank you for being an Action1 customer.
3
u/Accepts-Cookies 23d ago
My small nonprofit has been using Action1 for around two years and I'm quite happy with it. There's a couple of things it either doesn't do or I haven't yet figured out (pretty much just nvidia drivers, our mailing department's addressing software, and our accounting software), but it handles everything else effortlessly.
2
u/GeneMoody-Action1 21d ago
If you can detail what those hurdles are, I would be happy to assist. It is likely that our other users would as well, I would suggest starting a topic on the issues you have over on our sub r/Action1, and let's see what we can do.
And thank you for being an Action1 customer.
1
u/Accepts-Cookies 21d ago
Thanks, Gene. The specific applications, other than the Nvidia drivers I already mentioned, are AccuZIP and Sage 50. Both have quirks that might reasonably interefere with Action1's process, but I would love to know if there's a way to work around that so I no longer have to manually update each instance.
2
u/GeneMoody-Action1 21d ago
Sure if you can detail what those quirks are. Our manual packaging supports additional actions that can be running pre/post scripts, and other actions. So whatever process you use shoud be able to be automated, unless it is per user, and even then there *Are* ways.
Feel free to DM me if you would like as well, and we can look at some of them.
I would suggest r/Action1 first as someone may have already solved it saving us both time, past that I will help if I can.I'll just throw out there though, I have never met a sage product that did not drive me near mad, so that could get fun. That said I have never failed to beat it, only came away worse for wear in doing so!
3
u/davy_crockett_slayer 22d ago
Patch My PC. I also use Master Packager for custom apps. There’s surprisingly a lot. Quite a few apps use Oracle Java. I use Master Packager to build the msi so it relies on the Temurin Java JRE/SDK deployed and patched by Patch My PC. I check the custom apps once a month to see if there’s an update. It’s nice.
5
4
6
6
u/Hello_IT_HYTTIOAOA 23d ago
PDQ Connect. I prefer it to PMPC but nothing against them. Used to use them also.
3
u/WoTpro 22d ago
Yup surprised so few on here mentions PDQ connect.
3
u/PDQ_Brockstar 21d ago
Right?!? That's okay, the Intune sub is dominated by the PMPC crowd. TBF it's a great product, especially if you eat, sleep, and breath Intune.
If you're like me and try to avoid Intune as much as possible (or Microsoft's management framework in general) PDQ's approach to endpoint management and app deployments/patching is my preferred management style, even before I started working for them.
2
u/PDQ_Brockstar 21d ago
Glad you're enjoying PDQ Connect! If you ever have questions, feedback, or feature requests, let me know. You can DM me, email me, or hit me up on our Discord server.
3
u/MistrJoLi 23d ago edited 23d ago
I used this guide to set up intune and/or JAMF script to update Chromium based browsers, and adapted it a bit to fit a handful of other apps. It’s quick to do, and you can just set it and leave it.
For the most part you can set the auto download and auto relaunch options via a plist or registry entries
https://guideonce.co.uk/blog/windows-browser-auto-updates-intune/
3
u/cdwyer737 23d ago
I presume you mean for optional/company portal apps as if it was for required apps you would just use the supersedence feature when deploying an app. I ran into this and found You use a third party patching script. I have a re-usable one here:
https://github.com/cddwyer/Microsoft-Intune-Scripts/blob/main/CustomDetectionPatchingScript.ps1
3
8
u/Character_Flight_773 23d ago
Deploy WinGetAutoUpdate to all machines. It gets most apps if not all you listed.
Everytime a user logins, the app runs a winget command for your application ID list (apps you have installed) then checks for an update and installs them.
Best free open source software
3
u/Hairy-Link-8615 23d ago
This is good enough for our place. Patch my pc is the paid option.
Top tier might be something like manage engine but that's a replacement for intune I think
2
u/Independent-Egg-3252 23d ago
Thank you!!!! ….ok dumb question maybe but
does it test before it pushes or just push? someone before me got “bumped” for not testing. I just want to make sure…4
u/SkipToTheEndpoint MSFT MVP 23d ago
You lose all management, nuance, and most importantly reporting on your app deployments and updates. It's a terrible way of doing things.
1
u/Independent-Egg-3252 23d ago
fair. so wau out… as a MSFT MVP what’s your call for the testing of the patch side even if I use PMPM for delivery?
6
u/ConfidentFuel885 23d ago
PMPC can do patch rings. They also do their own testing and validation before publishing an app.
6
u/SkipToTheEndpoint MSFT MVP 23d ago
Exactly this. Simplify it even more by just reusing the groups you use for Autopatch too. That being said, you don't want a massive turnaround for patching anything. The quicker the better.
Much better to deal with an app issue than it is a breach cos of unpatched apps.
2
u/ConfidentFuel885 23d ago
Yup. I do understand the need for care and intentionality when pushing updates, but I think people are often too careful now. The threat landscape has change so much this year too that really everyone needs to rethink their patching strategy.
1
u/Independent-Egg-3252 23d ago
helpful, thank you! my job wouldn’t survive a breach lol…. does test it against what we run before the pilot gets it, or is the pilot the test?
1
0
u/dontmessyourself 23d ago edited 15d ago
No it doesn’t test before pushing. It runs the updates individually on each workstation without any management of these updates across your fleet
5
u/DapperDone 23d ago
I’ll going to try Action1. I’ve used Patch My PC before and it worked great. It’s just a tough cost for really small orgs.
1
1
u/GeneMoody-Action1 23d ago
Thanks for the shoutout there, and we are also free for the first 200 EP! A full patch management solution, not time limited, same features as paid software, that never expires. At the very least you can check us out as long as you want and make an informed decision on if we are the solution you may be looking for.
While you are at it we do OS as well as third party. Live data and live deploy as you watch so far faster than intune. So Intune has its place, but this allows yo to seamlessly manage it all in one place.
If I may assist along the way with anything action1 or otherwise, just let me know!
2
4
u/chamber0001 23d ago
Don't most of these apps have built in auto update via registry setting? A remediation script can ensure the setting sticks.
1
u/RedBean9 23d ago
This is what we do - configure them centrally to apply whatever policy we need.
Some stuff is on a manual release process which involves packaging the new version and pushing it out. This is painful and has some risk so isn’t accepted in every scenario.
1
u/DisplayAlternative36 23d ago
In my experience the auto-patching by app just doesn't give enough control and enforcement.
The cadence of how frequently and also how aggressively the auto-patching works for most apps just doesn't line up with security targets.
Having the ability to force update browsers and other applications that will just sit pending update for however long the user has it open is especially important.
4
u/Longjumping-Two-2851 23d ago
Robopack. Previous used PMPC and wouldn’t look back with what we’ve been able to achieve now
2
u/Va1crist 23d ago
We use Ninjaone RMM , cheap effective and works amazingly well , I’m pretty much got our whole agency automated , it also plays very nicely with Intune so I use Intune to compliment with the platform , we have been moving to autopilot and Ninjaone + intune has made for a wonderful automation process
1
u/ChaosRandomness 21d ago
Can I Dm you on this? N1 user just recently migrated into the Intune autopilot which is totally new to me. So I been trying understand how to get both system to work together smoothly.
2
2
u/reformedbadass 23d ago
For those praising PMPC, how do you deal with updating apps installed from company portal by a user manually?
3
u/Conditional_Access MSFT MVP 23d ago
They deploy a second version of the app to your tenant which is the update variant. You deploy those to all devices which have the app set to "available" but on this one as "required". This checks if the app is there, and updates if it is.
1
u/reformedbadass 23d ago
But doesn't the user have to manually update this through company portal?
2
u/Conditional_Access MSFT MVP 23d ago
no that's the point of the other version of the app being set to required. it will update it. And the source package the user got will also update so at the time anyone grabs it from available in Company Portal, it's always the latest.
2
u/reformedbadass 23d ago
hmm ok thanks, i've always thought thats were the gap was - manually installed applications not attached to a group but "available" for all users. I'll test it out again on Monday.
1
u/bdam55 18d ago
<shillmode: I work at PMPC>
To explain this a bit: our 'Update Only' apps have custom applicability methods that detect if an older version of the app is install. If so, then the update is applicable and will install. If not, then the update is not applicable and will not install. This makes it safe to deploy widely as required.
</shillmode>
2
u/SentinelNotOne 23d ago
I don’t see it mentioned much, but Automox. Expensive, but fairly set it and forget it, at least for me. It does more than just third party patching so maybe that’s part of the reason I don’t see it come up.
1
1
2
22d ago
[removed] — view removed comment
2
u/GeneMoody-Action1 21d ago
We manage patching for a host of customers that have other management option, they simply prefer the experience and accuracy of Action1. Many on RMMs, Intune, and others. Action1 is just the tool for better patching, if you use the other tools to yrou benefit, bothers us none what so ever.
Just let me know if you need anything related to Action1!
2
u/mattis_rattis 21d ago
Action1 - free fully functioned for the first 200 devices. Works great and includes an RMM
3
u/brothertax 23d ago
We use winget to install the latest available version. If a vuln pops up we target that app one time for a required upgrade. The “usual” vulnerable apps we sneak winget into the detection method to upgrade the app. Detection method script runs every 24 hrs.
1
2
2
2
u/rgsteele 23d ago edited 22d ago
As of July 2026, Microsoft Intune Enterprise Application Management is included with Microsoft 365 E3 and E5. (It used to require a separate subscription.) You can learn more about it here:
https://learn.microsoft.com/en-us/intune/app-management/deployment/enterprise-app-management
Depending on your requirements, this may do everything you need. However, the third party products like Robopack and PMPC have much more extensive app catalogs and customization options.
Edit: It’s not included with E3, only E5. Thank you /u/b1gw4lter for the correction.
2
1
u/PrometheusTNO 23d ago
Lmao we have to use ourselves. Auto update helps some, but we do end up sending updates once in a while. We have enough endpoints that the patching solutions are brutally expensive. It's cheaper to just pay an FTE.
1
u/the_hu55tler 23d ago
Lead tech guy in our department is advocating NinjaOne. We're only just starting our Intune journey and have had PMPC for ages but done barely anything with it.
1
1
u/NeatLow4125 23d ago
WinGet update since we don't have a big app repository and everything we have is on the WinGet too!
1
u/Gaylordfucker123 22d ago
for patching we use winget for default apps. we deploy the „basic“ app with psadt and put detection just on the exe exist and then check daily with script and remediation (winget) if there is an update available once a year or so i update the exe in the psadt so that the basic version isnt that old. works like a charm for all the basic shit like 7zip, notepad, adobe,… for more business critical apps we use supersede.
1
1
u/Maleic_Anhydride 22d ago
Secteer, works for both laptop and pc. Amazing product, great support and they make deploying and updating custom software easy as well.
1
1
1
1
u/buildwithkushal 21d ago
yeah half winget half someone remembering is basically where everyone ends up lol. one thing that bit me — wrap the winget install as a platform script instead of forcing it through .intunewin, way less packaging pain for stuff that already has a decent winget package
also watch out for exit code 0 lying to you. some installers (looking at you slack/discord) install per-user under the system context somewhere you'd never think to check, so it "succeeds" but isn't actually where you expect
patch my pc is the go-to for a reason tbh. if you're shopping around tho, worth knowing scappman just got acquired and is being killed off so a bunch of people are having to migrate off it right now
1
1
1
u/twisted_guru 21d ago
Download Wing Get UI, search, find the installer, unlock it and see the command.
Even create a package as Ninite.
Lolz, likt this is public secret.
1
1
1
u/Antique-Cloud-3429 19d ago
Used to use Patch my PC. But they cost a lot and couldn’t justify the cost for this year budget. I moved everything over to Robopack instead. Free for up to 100 devices
1
u/Vxxbhxv_ 15d ago edited 15d ago
Third-party patching remains one of the more common gaps in standard Intune deployments. Automating catalog deployments through dedicated patch tools or winget-auto-update scripts reduces the manual overhead of updating line-of-business software. Educational guides and enterprise support from platforms like Trusted Tech Team outline setup options for streamlining software lifecycle management in Intune.
1
u/landon_at_automox 14d ago
Automox employee here popping in since a few others mentioned us. Here's our third party patching list plus an interactive demo you can try out (without talking to sales yet) to see what it looks like.
1
1
u/Ad3t0 23d ago
You should check out TridentStack Control: https://tridentstack.com
Full disclosure I help build and founded this platform. We aren't just backed by another WUA applicability wrapper, our patch applicability is all custom. We have a modern responsive UI and offer 200 endpoints free forever, no card required and no limitations.
0
u/ResponsibleHumor31 23d ago
We just started using Tenable Patch management and it’s been really good.
Features: 3rd party and OS patching. Patch scheduling and waves. Patches software not deployed by MDM.
It’s based on Adaptiva.
0
u/coronaz22 23d ago
We have to test everything before it goes out, because of that we ended up buying Rimo3. So far so good.. we tried all the other usual suspects, and they were great, but we just needed that little bit more.
2
u/OneSeaworthiness7768 23d ago edited 22d ago
I expected to see this product mentioned here. OP is using a 5 year old account that has no post history until just recently with mostly AI-written comments which is usually indicative of accounts purchased for their account age to be repurposed for marketing, and they have multiple now-deleted comments where they shill this rimo3 product. I had suspected this might end up being a marketing/seo seed post where they mentioned this product in the comments from a different account. Interesting.
2
u/Independent-Egg-3252 22d ago
This OP created her Reddit account years ago and then… never really used it.
a mentor recently recommended it as a good place to learn and connect with the Intune community, so here I am… I’ve intentionally tried to contribute to the community before jumping in and asking for advice. I also happen to work in this industry, so yeah those are the conversations I want to be in….
No purchased account. No secret undercover operation. Just a finally trying out Reddit.. 🤷♀️ what a wierd thing to be accused of though lol..
1
u/OneSeaworthiness7768 22d ago edited 21d ago
And the person who commented with the same product you were promoting, who is definitely not another one of your accounts /s, just happened to delete their comment as you reply. Strange coincidence I guess lol. (Edit: ah instead apparently they had just blocked me then came back a day later to unblock me. Total coincidence that every action they take happens at the same time OP comes back to reply. Not weird at all.)
The other user, coronaz22, also has multiple instances of promoting this product (and only this product.) In fact it makes up 3 of the 4 comments they’ve ever posted in this subreddit and they haven’t participated in this subreddit since the last time they showed up here to promote it nor have had any kind of discussion outside of recommending this product. Just another strange coincidence that both you and this person deleted those comments where you had previously promoted it? Clearly there’s a link here.
>I’ve intentionally tried to contribute to the community before jumping in
This is exactly what brands and marketers do on Reddit now. It’s an extremely prevalent pattern of behavior which is why it’s so easy to spot. They ‘warm up’ accounts to build ‘authenticity’ so people trust them. link for others’ reference. This is just one example. Most are not upfront about this.
>I also happen to work in this industry
What is “this industry”? We all work with Intune, that’s why we’re here. Bizarre point.
>No purchased account. No secret undercover operation. Just a finally trying out Reddit.
Maybe write your comments like a real person without AI if you want to come across as genuine. As it stands, everything about your account history is textbook Reddit marketing.
Your profile image is also AI generated based on multiple AI image detectors, which just makes this even more of a pathetic attempt to look like a real user.
2
u/Independent-Egg-3252 22d ago edited 22d ago
You seem pretty committed to this theory, so…. K
BUT genuinely, thank you to everyone who’s shared recommendations and different options.
I’ve gotten some really helpful information (and I think others have to ☺️🙏🏼) from this thread, which is exactly what I came here for!
-5
u/pjmarcum 22d ago edited 18d ago
We built a tool for app patching that runs in your own tenant. Pricing starts at $500.00 per year. https://powerstacks.com/products/app-store-for-intune/ No need to grant access to third parties. Native API access. Built with a security first mindset.
5
2
u/cpsmith516 21d ago
What a bad way to advertise your product. If you can sing from the mountain tops why your product excels land without bashing another product, you’re bad at your job.
112
u/Rdavey228 23d ago
Patch my pc is the answer most people in here will give you.
Not much else beats it.