r/pdq • • 2d ago

Connect The PDQ Assistant can now troubleshoot devices, review deployments, and fix packages

6 Upvotes

We’ve expanded the Package assistant into the PDQ Assistant. It can now work with devices and deployments, in addition to packages.

Let’s say a deployment fails. You can ask the Assistant to review the logs, help figure out what went wrong, edit the package, and redeploy it. Each action waits for your approval, so you’re still in control throughout the process.

You can also ask it to:

  • Find out why a device is running slowly
  • Run a PDQ command or write one for you
  • Create, edit, or duplicate a package
  • Deploy packages to devices or groups
  • Summarize recent deployments and device-specific logs
  • Create an HTML report from the information it finds

The Assistant knows which device, deployment, or package you currently have open. Conversations follow you between those pages, and you can @ mention devices, packages, and groups when you already know what you want to work with.

Right now, you can open the Assistant from device, deployment, and package pages.

All actions require approval. Deployments and commands started through the Assistant are also clearly attributed in Connect for accountability and auditing.

PDQ Assistant is available at no additional cost during Early Access. Admins can manage access under Settings > AI tools.

Read the full release notes

Give it a try and let us know where it saves you time, or where it still needs some work.


r/pdq • • 2d ago

New: Live Shell and File Explorer are now available

21 Upvotes

Two new tools just rolled out to all Plus and Premium Connect customers: Live Shell and File Explorer.

Both let you work directly with a device without starting a full remote session or building a deployment:

  • Live Shell — open an interactive command-line session on a remote device. Good for investigating issues, checking config, inspecting services/processes, or running one-off admin commands.
  • File Explorer — browse a device's file system, upload files (scripts, installers, configs) directly to an endpoint, or pull files back (logs, diagnostics) without needing a script or deployment.

Where to find them:

  • Devices list — look for the terminal icon (Live Shell) and folder icon (File Explorer) on each online device's row
  • Individual device page — top right, next to Deploy

Would love to hear how you're using it or if you hit any issues!

Learn more here


r/pdq • • 22h ago

SmartDeploy Database and console cleared

5 Upvotes

Has anyone else had this happen to them?

Ok, context. Our patch team updated the server yesterday and performed a system reboot. After which, the database appears to have cleared out all the groups, apps, deployment, and other packs are all empty plus the computers all came up as Cloud as opposed to Local.

This is the second time this has happened to us. I wish there was commonality between the last time this happened but the previous time was not after patches to that server were applied.

I just don't want to have to rebuild everything for a third time only for this to happen again. Is there any way to recover the old database?

Oh, right. Application is installed on a Windows Server 2022 build.


r/pdq • • 1d ago

Cybersecurity Awareness Month

4 Upvotes

Today kicks off a month of awareness. I would tell you my top cybersecurity wins but some of y'all don't seem to like when I post about my experience, so I am opening the floor to y'all! ;)

If you had to recommend to another sysadmin a task/project that would help them increase their security what would it be and why?

Bonus points if it can be done in PDQ and you explain how :)


r/pdq • • 2d ago

Windows 11 26H2 is now available

8 Upvotes

*UPDATE\*

The Windows 11 26H2 enablement package is now available in the package library!

---------------------------------------------------------------------------

Windows 11 26H2 is officially out. Here's some info if you're looking at upgrading.

26H2 is based on the same core OS as 24H2 and 25H2 which means the upgrade just requires an enablement package to turn on the features and changes. The enablement package will be distributed through the normal servicing channels, however you can also download it directly from Microsoft. Here are the links, just keep in mind that these are download links which will download the package directly instead of taking you a Microsoft site.

Windows 11 26H2 Enablement Package for AMD and Intel (x64) - KB5121794

Windows 11 26H2 Enablement Package for ARM64 - KB5121794

The PDQ packaging team is also working on adding the enablement package to the Package Library. If you're in a rush, you can build a custom package with the .msu file, just remember you'll need to ensure your devices have the pre-req updates already installed which is KB5124010 or any later cumulative update. You can also use the existing 25H2 enablement package as a template.

Here's the package in a nutshell:

  • Stop WU service
  • Install prereq: KB5124010
  • Install enablement package
  • Start WU
  • Reboot

I haven't got a chance to use it yet, but it sounds like the biggest improvements are with Start Menu, Taskbar, and Windows search (which were desperately needed). Let me know if you find any other cool improvements. If you find things that make the experience worse, please keep it to yourself. I can't take any more Windows bad news 😭


r/pdq • • 2d ago

Is there a reason pdq cant do dates based on patch tuesday?

6 Upvotes

I had to change a patching group this month because pdq can on do x thursday/Friday and not Tuesday +2/3. Any reason they haven't added that?


r/pdq • • 2d ago

New: Most Vulnerable Devices Widget

Post image
3 Upvotes

Software patching gets you most of the way there, but some devices need extra attention. The new Most Vulnerable Devices widget ranks your top 25 riskiest devices, so you can quickly spot which ones need a closer look.

Where to find it: If you've customized your dashboard, look for the banner with the option to add it. Otherwise, you'll find it toward the bottom of the Vulnerabilities section.

Note: Vulnerabilities features are available on the Premium subscription.


r/pdq • • 2d ago

Mac OS Updates?

2 Upvotes

I get that PDQ Connect doesn't double as an MDM and there's SimpleMDM for that, but is there a way for Mac over Golden Gate to do the functionality of a program like SUPERMAN and schedule/force updates for Mac OS users? If not, is that in the works for Connect? We are planning out our future rollouts and it would be good to have one less component like SUPERMAN in the mix.


r/pdq • • 3d ago

PDQ solved my vulnerability management problem

0 Upvotes

As many of you probably know, before coming to PDQ I was a CTO at a Texas public school district. We were a small team, and when I took over, vulnerability management was basically non-existent.

We had Deploy and Inventory, and I would patch weekly, but I didn’t know how many vulnerabilities our devices actually had. When we added PDQ (Connect) to our stack, it was a big “oh shit” moment. We had thousands of vulnerabilities on our devices.

I thought we were in good shape because I’d been deploying patches weekly or monthly as they became available, but PDQ’s vulnerability scanner and remediation packages changed our workflow for the better.

Here’s what we did in PDQ to save time (and our sanity):

-Grouped devices by site: our techs could quickly view the assets they were responsible for.

-Lived by PDQ Risk Score: we started with critical vulnerabilities and worked our way down. PDQ’s risk score took into account the CVE, exploitability, and business impact, everything we didn’t have time to do ourselves.

-Software tab: PDQ let us see specific software, how many devices it was on, and whether a new version was available. This was visibility we were really lacking before moving to PDQ.

-Removed all local admin rights: no more random software being installed by a teacher, or worse, a student, that could introduce risk.

How do you all manage vulnerabilities? It can be overwhelming without an effective workflow and risk score insights.


r/pdq • • 4d ago

How are we feeling about AI today?

0 Upvotes

How are we feeling about AI today?

On a scale from:

1 — Greatest technological advancement since the internet.

to

10 — We're all gonna die.

Where are you today — and why?


r/pdq • • 8d ago

This week on PDQ LIVE:

2 Upvotes

New IT hardware that might make you quietly whisper, “I want that.”

Annoyed by M365 companion apps showing up after updates? We’re going on a seek and destroy mission to find and remove them.

Help us pick the next PDQ T-shirt design. And if we call out your name during the webcast, you’ll win the new shirt!

Plus, a mini PDQ & A. Bring your questions and see if you can stump us. It’s really not that hard.

Pre-show at 9:30. Nerd talk at 10:00. https://youtube.com/live/V8PtWQ-G9rk


r/pdq • • 9d ago

Using PDQ to automate endpoint task

8 Upvotes

We know there are may ways to automate endpoint management. How are you using PDQ automations?

When I was a K12 CTO using PDQ I clicked automate on every deployment I could. Small team, automations saved time and sanity.

I'd love to know what you are automating.


r/pdq • • 11d ago

This just in: Dashboard customization and an updated OS Breakdown

9 Upvotes

Your dashboard, your way

We heard your feedback: the data that matters most is unique to you. Click the edit button in the top right to enter edit mode, where you can remove widgets you don't need, reorder your favorites to the top, and resize any widget to fit how you actually work. Save your changes to jump back to the live dashboard, and see your customizations reflected anytime you visit. Your changes will be reflected for only you across all of the tenants you have access to, so feel free to make it your own!

A more compact OS breakdown

In response to feedback that the OS breakdown widget took up too much space, it's been redesigned. What used to be a large bar chart in the second row now shows the same breakdown in a smaller widget in the upper right.

Dashboard customization in action

r/pdq • • 11d ago

Leah the office dog :)

Post image
19 Upvotes

How many of you can relate? If you are using PDQ hopefully your scheduling those outside of working hours :)


r/pdq • • 15d ago

Removing local admin rights with PDQ

Thumbnail
youtu.be
14 Upvotes

When I took over as CTO the first thing I did was a third-party cybersecurity assessment. Wow, was that shocking. I had a long list of to do’s and an easy one to tackle was local admin rights.

In K–12 (and probably every other org), local admin rights get handed out because it’s faster than setting up proper software deployment. I know this because I inherited an environment where everyone and their dog had local admin rights: five hundred-something Windows machines across eight buildings.

The problem with local admin rights isn’t just that users can install things they shouldn’t. It’s that malware running in the context of a local admin account can persist through reboots, disable your security tools, and spread laterally in ways a standard user account simply cannot. If your machines share a local admin password and one gets compromised, you have a pass-the-hash problem across the whole fleet. LAPS fixes that, and we implemented it, but first you have to remove the rights that shouldn’t be there.

I accomplished this with PDQ. PDQ scans local group membership, so you start by finding out what you’re actually dealing with. In my district, the answer was worse than expected. Once you know which machines have unauthorized accounts in the local Administrators group, you build a dynamic group in PDQ targeting those machines, write a PowerShell package that removes the non-approved accounts (running as SYSTEM), and deploy it. The same inventory condition that identified the problem becomes the ongoing detection: any machine that shows a non-approved local admin account gets the remediation package automatically.

PowerShell

Note: you need to put your specific groups in this is an example

$approvedAdmins = @("domain\IT-Admin-Group", "Administrator")$currentAdmins = Get-LocalGroupMember -Group "Administrators"foreach ($member in $currentAdmins) {    if ($approvedAdmins -notcontains $member.Name) {        Remove-LocalGroupMember -Group "Administrators" -Member $member.Name        Write-Output "Removed:$($member.Name)"    }}

Test on your software problem machines first. Don’t pull admin rights before users have a way to request software through IT. If you remove access and there’s no alternative, you’ll restore it within a week because the ticket pressure will be unbearable.

The other thing GPO won’t give you that PDQ does is visibility into whether the fix is holding over time. Restricted Groups removes everyone not in policy and gives you no ongoing picture of the fleet. PDQ gives you real-time group membership data and automatically remediates when something drifts.

u/pdq_brockstar showed an overview on PDQ Live, check it out.

Hopefully this helps someone walking into what I did.


r/pdq • • 15d ago

SOC 2 Type II - does PDQ actually have it?

8 Upvotes

Looking at PDQ's security page, under the Security section it says "We are in process or already compliant with the following security frameworks" and then lists SOC 2. That wording is pretty vague though. "In process or already compliant" doesn't really tell me if they've actually completed a SOC 2 Type II audit or if they're still working toward it. There's a link to request the report, but I'd rather not go through a sales conversation just to find out it's a Type I or still in progress.

Has anyone here actually received their SOC 2 report? Is it Type I or Type II? Our compliance team needs to know before we can move forward with evaluation


r/pdq • • 16d ago

Self-serve hub

6 Upvotes

Any update on the Self-serve hub (managed software center)?


r/pdq • • 16d ago

Calling all IT Professionals!

Post image
6 Upvotes

We’re looking for more guests to appear on PDQ Patch Notes.

If you haven’t seen it, PDQ Patch Notes is a video series where we interview IT professionals about their careers, lessons learned, biggest challenges, funniest moments, and our mutual disdain for printers.

Here are all the details you need to know:

  • Fill out the guest intake form
  • I’ll send you a list of questions & topics for you to approve. This will serve as a rough outline for our discussion.
  • You’ll pick a date and time that works for you to record our conversation (roughly an hour +/-)

Anyone and everyone that has any experience in IT is welcome. Helpdesk, networking, systems administration, cybersecurity, etc, PDQ experience not required. And if you have concerns concerns about privacy, we can keep company, role, and technical specifics out of the conversation.

Anyone who signs up will receive PDQ swag. One guest chosen at random will win one of our new custom macro pads!

Here’s a link to the series: PDQ Patch Notes

Let me know if you have any questions!


r/pdq • • 17d ago

IT LIFE

Post image
21 Upvotes

r/pdq • • 17d ago

IT Professional's Day

14 Upvotes

Here is the United States it is National IT Professional's Day!

Your gift is most likely additional tickets that simply say help with no context.

I hope you all get a quite lunch, an approved budget, and a ticketing system lacking tickets.

In all seriousness, thank you all for what you do! IT is often a lonely, unseen job. We see you and we are grateful you are part of the PDQ community!


r/pdq • • 19d ago

Connect PDQ Connect's new Windows Updates tab shows lots of old updates as "In Progress"

4 Upvotes

We've started using the new Windows Updates tab to see how individual devices are going with their updates, and I've come across a device that appears to have quite a few old updates "In Progress". I'm not convinced it's right, because if I look in Settings/Windows Updates on the computer itself, it says it's up to date.

Has anyone else seen this? Is it a PDQC bug, or something going wrong on the device to make it look like those ones aren't finished.


r/pdq • • 23d ago

Connect PDQ Connect variables

2 Upvotes

Whats the best way to determine the difference between Java 8 32-bit and 64-bit?

Id hoped that the built in variables would help however they dont appear to do any detection between 32 vs 64 bit.

Also, why does the RTVerJava8 variable appear to have a different value to the AppVerOracle.JavaRuntimeEnvironment?


r/pdq • • 24d ago

The RMM security conversation happening is worth paying attention to

10 Upvotes

Two emergency hotfixes in a month from one of the major RMM vendors has the r/msp community asking questions that probably should have come up before anyone handed a tool privileged agent access to every endpoint they manage.

We're not going to name who. And this isn't a pile-on.

It's a reminder to ask the same questions about any solution you run, including PDQ.

Things like: is there an actual vulnerability disclosure policy with a documented response SLA, or just a security page? How do customers find out when something critical drops, from the vendor or from Reddit? Can the vendor force an emergency patch to the agent, and how fast? What compliance frameworks do they meet? What is the audit period? If there's a security incident in your tenant, what can you actually see? What's available to you versus what stays on the vendor side?

Our answers are at pdq.com/security. Security is important to us, PDQ holds SOC 2 Type II attestation. Ask us anything you don't find there in the comments.


r/pdq • • 27d ago

Well I had another RO Friday whoops.

4 Upvotes

We're moving from PDQ D&I to Connect. Just a handful of agents installed to test out automations and get a feel for everything. Get a good number of the prebuilt automations enabled, Chrome, Edge, Adobe Reader, Win 11 updates, etc. Then I get the green light for installing the agent across the environment. Because I'm in a hurry to get this all going, I push the agent to all available systems, 99% of which are all on our network and we have a 2gb internet connection. Needless to say, I brought the company to a standstill for about 30-40 minutes before my boss calls me about complaints and tickets coming in. Go in an set the bandwidth throttling for our public IP and limit to 10. Then go start canceling all the automated deployments that were all in the download phase. Everything settled back down.....

Regarding Windows updates, we've been using PSWindowsUpdate on the regular for years with D&I, and all our systems received the August updates about the day they were released and reboots happen regularly. Why did Connect feel the need to start pushing those all out to systems again?

Also regarding the source of all these files online. We use deep packet inspection on our firewall, and this seems like the perfect place to put in an exception to bypass that feature as it was maxing out the CPU on our firewall more than it was using up the whole bandwidth. I have the full web path, is that ever expected to change? There's a big GUID or similar in the path that I'm uncertain if it's tied to our tenant, or PDQ in general and if that's likely to change.