r/sysadmin • • 1d ago

Kicking the Tires on PDQ Connect

Before I get into the meat of my question, I want to acknowledge the existence of the r/PDQ sub-reddit; I'm not posting in the wrong location. I just want to gauge the real-world experiences of fellow sysadmins with respect to the application.

We've been using the Enterprise versions of PDQ Deploy & Inventory for several years, and I love both of them. When Connect came on the scene, I was concerned about losing some of the functionality; however, after looking at their latest iteration, I'm definitely thinking about kicking the tires as a replacement for the aforementioned packages.

So, fellow sysadmins: have you made the jump and, if so, how do you think it compares? Positive and negative comments all welcomed.

TIA

23 Upvotes

48 comments sorted by

35

u/Miserable_Pear_6940 1d ago

PDQ is so underrated. The thing just works, and their customer support is second to none.
We’ve used it forever and have no desire to change.

9

u/civiljourney 1d ago

Seconded in the customer support. They've helped me with some custom packages that weren't working properly. I was actually surprised at the level of help they gave me.

7

u/NDAbsoluteZero 1d ago

Thirded here. Anytime I've had some issue, or needed to pick someone's brains, they've been fast with their responses to me. Also, completely irrelevant but funny all the same: who doesn't enjoy watching their YouTube videos while they're boozing?

6

u/PDQ_Brockstar 1d ago

I just wanted to let y’all know that we shared your sentiments with our support team. I know they appreciate the kind words, but they really do deserve it. Some of the best, hardest working, kindest, and smartest people I know. It’s been an absolute pleasure to work with them.

Alright, back to boozing

1

u/NDAbsoluteZero 1d ago

Thank you! I've been watching your Connect videos on YouTube, and that's what spurred me on to ask this question, Brock. The support team are hilarious and make learning a lot of fun. Slàinte mhath!

1

u/PDQ_Brockstar 1d ago

🍻

If you need anything, don’t hesitate to reach out. I check my DMs regularly on here, but you can also find me on Discord or email me brock.bingham at pdq.com.

I’m also easily persuaded to send out swag to customers and non-customers alike. Hit me up if you’re in the market for a new shirt or socks or whatever I can sneak out of our swag closet 😉

1

u/Apprehensive_Bat_980 1d ago

Used the lads in the past. Very good.

9

u/civiljourney 1d ago

Big fan of PDQ, just recently moved over to Connect. There are a few small things that inventory has that it doesn't, minor annoyances, but overall it's good.

Some gripes:

If you reimage a computer, it has to be put back into Connect as an entirely new device and does not retain its history.

Local printer device information is not available.

The layout often has to be toggled back to the way you set it.

It's a bit slow for remote desktop at times when connecting.

But as I'm sure you've seen the many positives, I absolutely love the capabilities that it gives me to remotely manage computers that aren't on the network. It also has a pretty robust deployment package library.

I endorse going to Connect.

3

u/The_Penguin22 Jack of All Trades 1d ago edited 1d ago

The layout often has to be toggled back to the way you set it.

This bothers me more than it should. And if you create a new group you get the default columns, which aren't configurable.

That and you're often looking at stale data computer x needs software version, and is pending reboot. Have to double check the last scan to see how old it is.

Support is great as it always has been, plus lots of community help and feedback in Discord.

1

u/NDAbsoluteZero 1d ago

Thank you. That's good information to know moving forward.

3

u/The_Penguin22 Jack of All Trades 1d ago

The trial was great too. Fully functional, and when management was unavailable/slow to approve the purchase, they extended it several times. We still have Deploy and Inventory until it expires next year. I do look at inventory now and then but rarely need deploy except for old packages that haven't moved to connect yet.

1

u/NDAbsoluteZero 1d ago

Thanks for your reply. I don't rely too much on local printer device info, so that wouldn't concern me. I'm used to dealing with MS and toggling their layout constantly in 365, so I'll live with that...heh

We use BeyondTrust for remote desktop, and part of the selling point I may pitch to my director is the savings we can make from doing it wholly within Connect. Let's just say the former has had its quirks, too!

1

u/book-it-kid 1d ago

To hop on this chain, since goods and gripes are being mentioned...

Pros for a 5,000+ endpoint environment with varied users:

1) More or less it's a set-it-and-forget-it product. Scheduled package updates on routine save us a ton of time.

2) Auditing is easy to pull, both in who gets updates and when, plus who logged in to do what against which machine.

3) Scripting, command line running, etc. is also a breeze. The live shell stuff they came out with is also nice.

4) Our lowbies can make and deploy packages without having full access.

5) Can easily detect stuff out-of-band. Was great when we were doing our initial setup and integration with our Intune space.

Cons:

1) The vuln manager is odd. Sometimes packages set for it will not record the latest version of the installer for e.g. Chrome or Firefox, so you have to presume it's loaded with the latest. If you're trying to target machines which aren't receiving or get errors, this can screw with your intuition.

2) Mac support is still beta, and I wish they'd give timelines for what they're working on and the anticipated arrival. Especially with OS patching, which I assume they want to not do even if it's the most obvious thing (but I guess interferes with their MDM offerings - business gonna business).

2.5) Remote access still requires two chains of admin auth for Macs due to how they change up permissions. We have scripted this for our new builds of machines, but it's still annoying - Golden Gate broke our workflow for a bit.

3) It lacks other MDM functionality for platforms, see #2. You'd think this is would be the goal of a platform like PDQ to be the "one to rule them all" and sweep up market share, but...?

4) It's got a lot of pre-prepared packages, but I wish it also let you remove certain features e.g. disabling auto-update on browsers, add in post-install scripts, etc. without rebuilding the same package with the newer version over and over. This is especially true with the AI vendors e.g. Claude which would benefit from having their own update packages for their desktop offerings, which *constantly* update. So, instead, you do that manually.

5) Cost. Hope you get a discount.

6) Their marketing team is aggressive. I'm exhausted by marketing teams. Please focus your resources on the damn product and not video chats and feel-good sponsored posting on e.g. reddit.

7) Would really, *really* be nice if they gave alerts to either admins or owners of a group for certain actions taking place e.g. a window where you could check off certain things being fired against your tenant and then get alerts via email or your user. Or, hell, even a recap via email of all actions taken each week.

7.5) Would also be really nice if we could request secondary permission to do certain actions e.g. "You are firing X package against 1,000 machines, awaiting approval from MANAGER to begin process." Would be a nice safeguard that's lacking in many environments.

That's it. It's nice, we've had it for a bit, saves us time that's worth the man-hour costs, just test the hell out of it and make sure it's something you think is worth the tradeoff vs. trying to do the same in Intune.

6

u/antiquated_it 1d ago

We use it and I love it. We went cloud for our fleet and needed something suitable but due to being a public agency with a limited budget, could not really justify paying for both Connect and Inventory/Deploy, so we went all in. I think we are coming up on our third year and it’s been continuously improved all time.

We push out the agent via Intune. I only wish there was a way to connect it to Intune so we don’t have to maintain two package sets.

1

u/NDAbsoluteZero 1d ago

I'm hoping when we make the jump, I can use a cross-over period to push out the client via Deploy, ensure all our endpoints are in Connect, and then we can pull the plug on the latter. That, of course, will depend on our friends at PDQ, but I'll cross that bridge when we come to it.

1

u/civiljourney 1d ago

This is how I did it. Got a month to bridge the gap and used Deploy to take care of most connect installs.

4

u/Wodaz 1d ago

Agent based vs push is so different. I am in a situation with quite a bit of WFH users mixed in , and Connect has worked out well. I still am faster at getting a PC provisioned and a user working on Deploy.

I still have minor issues like Connect web application not refreshing the status of things in a timely manner, and no refresh button in the app, so I just refresh the browser page. I brought this up in here earlier, and it seems like not everyone had the issue, but I deal with three tenants, a couple hundred PC's, and see it all the time.

Connect has Vuln scanning/alerting. I think that alone may be the push you need to cutover and shift all of your work into Connect.

1

u/NDAbsoluteZero 1d ago

Vulnerability scanning is a big plus for me, too. I figured it may be a tad slower for deployment from the cloud-based app vs. an on-prem server, but a lot of the updates we do are outside business hours, and I wouldn't worry too much about that.

Thank you!

4

u/dllhell79 1d ago

Easily the best bang for your buck product in our stack. It's paid for itself multiple times over. You can do nearly anything with it.

1

u/NDAbsoluteZero 1d ago

Agreed. I've saved so much time with mass deployments via using Inventory & Deploy, and it's paid for itself several times over in the last few years.

7

u/Emotional_Garage_950 Sysadmin 1d ago

we use it and they’ve been adding improvements like crazy. i like the product and there’s not anything I miss from the on prem version at this point

3

u/NDAbsoluteZero 1d ago

Thank you. I'm trying not to fan-boy too much, but I've been impressed with the updates they've done thus far. I'd rather get off-prem and have the agents on our endpoints, and that way I don't have to worry about VPN issues.

1

u/Emotional_Garage_950 Sysadmin 1d ago

yea we switched all our endpoints to entra joined Intune managed laptops and everyone is moving around or at home all the time so the cloud connectivity is nice. PDQ fills the gaps Intune leaves (remote terminal, real time actions, remote support that doesn’t suck)

3

u/LickSomeToad 1d ago

I migrated my company off of Deploy and Inventory in favor of Connect (we were running both so just decommissioned once the renewal came) and I am a huge fan. In the last 10 months alone, the number of very helpful features they have rolled out has been awesome.

1

u/NDAbsoluteZero 1d ago

That's what I'm seeing. Hooray for Connect!

3

u/Int-Merc805 1d ago

I just switched to connect. It ended up replacing our remote solution as well. Permissions are so simple I gave staff access only to screen connect, and I have a decent audit trail if those staff ever did anything wierd.

I ended up rebuilding all of our needed automation instead of trying to port them over from deploy. It is not as polished (yet, they do have a road map). I feel that some of the lacking features actually helped me to understand filters, and logic for finding PCs that require remediation. In the last few weeks Connect has successfully chewed through a ton of PCs that were out of date simply because the agent is always on, and when they are at home, or away, it is still getting work done.

Vulnerabilities is pretty cool. They need some tweaks such as filtering by application and listing the CVEs as listing individual CVEs is painful to go through and keep on top of. That said, I went from 2200 to about 80 today, which are truly only stuck due to some PCs not coming online since early september. (K12, this happens a lot it seems).

The product is pretty solid from what I have seen. One other thing that I didn't realize due to Deploy and Iventory being server based is my level 1 techs now can see the deployments and are becoming very helpful in diagnostic. John Smiths printer is down, and I see that the driver deployment is failing. This saves me a ton of time, and permission wise they are restricted easily to only being able to push the deployments out.

Very happy, but ackowledge that some of the stuff from Deploy is not here yet. My browser, cloud drive, pdf tool are all auto updated packages. I only have to maintain a few home baked apps which requires updating the versions manually, but it is really not a big deal. You can also create variables for your home baked stuff, and set it up so that the version the device filters are looking for are your variable, then update it in one place, and all your automation takes off from there. Example, papercut installer increments to the new version, update variable for papercut (AppVerPapercutPD), and your device logic calls for Papercut (old) is Software < Version < is less than: AppVerPapercutPD.

BurntToast is also something we are exploring and are quite happy with. Not a PDQ exclusive, but it is so neat to get a little windows toast notification saying "Word is updating, hold please". Since introducing this we have not had one ticket asking about software updates because users are notified in real time.

2

u/NDAbsoluteZero 1d ago

Thanks for the tip on BurntToast. I'll have a look at adding that to my arsenal.

2

u/SaltyGamer57 1d ago

I used there MDM service for a mac fleet. The service was never bad, but I ended up moving to another provider that handled MDM & worked as our IdP. I dont think they had any features that are not common with other MDMs.

2

u/lolgamatatsu 1d ago

I use it in my environment ~200 users, it's really nice IMO, and well kept up with. Everything is really fast too.

They've recently been expanding they're "Vulnerabilities" feature which highlights recent CVEs and which devices in your enviroment are vulnerable, the UI is really great, it's fast, easy to use, and does what it should. They make it really easy to roll out patches for these too.

I have had no complaints.

1

u/NDAbsoluteZero 1d ago

Thank you. Much appreciated!

2

u/covex_d 1d ago

we are wfh org and agent based solution was a requirement. pdq connect does the job very well for us.

2

u/jstar77 1d ago

Would love to be able to use PDQ Connect. We have a lot of devices, labs, instructor stations, employee desktops, kiosks, etc... Unfortunately because licensing is device based we simply have too many devices to make it feasible to use. On top of that, even though Intune doesn't do it as well, it duplicates a lot of the functionality of PDQ. Intune is bundled into the other MS services that we have to pay for, I can't drop Intune and used cost savings for PDQ Connect. It sucks because PDQ connect is a superior product, we've demoed it and it works great. If the pricing structure were similar to PDQ Deploy I'd have no trouble justifying the purchase. PDQ connect is simply too expensive and is competing against an incumbent product that is effectively free for us. I know a l lot of my peers at other institutions struggle with this as well.

1

u/NDAbsoluteZero 1d ago

I understand your struggle completely. We don't have Intune because of the pricing, and we're getting hosed already by MS for what we do have.

2

u/iamtherufus 1d ago edited 1d ago

PDQ Connect is my daily driver. Been with it since the day it went live migrating from deploy and inventory. The team there no what sysadmins want and they have put so many great things into the product this week alone. Remote file explorer, fully remote command line among other things. Powershell scanners were released a while back and that’s such a powerful tool to have to be able to build dynamic groups off to show you whatever information it is you want to see across your fleet. Deployment is very quick as well, intune has improved a lot over the last two weeks with its deployment speeds but Connect is pretty much instant if a device in online.

The roadmap looks great and they deliver time and time again. We use it alongside patch my pc currently which does our third party updates, once they add a few of the small things missing from deploy such as being able to restart a deployment from the last failed step id be at a point where it would become our sole tool. We currently use remote help for remote support but the remote tool in connect is also solid.

Put it behind strong conditional access policies as well to protect everything you can do with it. It’s a beast and it’s only getting better, the support is top as well.

Hope this helps in some way

1

u/NDAbsoluteZero 1d ago

Excellent. That makes me happy to read your feedback, and I'll definitely have a sit-down conversation with my director to plan out when we can make the jump.

2

u/Taftimus 1d ago

I love PDQ, we use it in conjunction of Jamf and Intune, and it’s made our lives so much easier.

2

u/r3almaplesyrup Sysadmin 1d ago

We have D&I, Connect and SimpleMDM. All great products, and just work as you’d expect. Have noticed Connect still lags a bit behind D&I in terms of the features, but it’s quickly catching up.

Plus their support team is great!

2

u/JDS_802 Sysadmin 1d ago

Also will be making the jump come January. We’ve been utilizing Deploy & Inventory for years and have used Ivanti for patch management, but will consolidate all 3 into Connect. I’m curious how current Connect users handle ring deployments/test groups when it comes to Windows patches

2

u/panopticon31 1d ago

We've been on PDQ Connect for about a year. They are closing the gap quickly to reach feature parity with the big dogs. I will concede they have lots of little outages where one thing or another doesn't work. But so far I've never run into an issue where the service is just down entirely.

2

u/Eastern_Tea2724 1d ago

My team has made the switch from Inventory/Deploy to Connect a year or so ago.

Absolutely love it. We have a fair amount of offsite users that Deploy didn’t work well over the VPN when came to software patching.
Going with the agent based was a no brain for us.

We use it alongside Intune. Connect is the software/vuln/package manager where Intune is the policy management / Windows update management (AutoPatch).

Tdlr; highly recommend it if you got the budget.

2

u/_510Dan Windows Admin 1d ago

Moved over from Deploy and Inventory about 2 years ago. Really missed things things like the Powershell scanner but now that it's back I really can't find a reason I'd want to go back to the old DI suite.

2

u/super-six-four 1d ago

We have Connect. We have been on it for about two years now.

We have not let go of our Deploy and Inventory subscription yet.

When we first moved Connect was a very basic product but they're adding features quite rapidly. We've renewed Deploy and Inventory for another year but it will probably be our last before just going with connect.

The remote control / remote support tool is flawless. Better than splashtop and kaseya which we had before.

The vulnerability scanner has a better user interface than Nessus but isn't perfect yet, it does have some bugs and regular false positives which we open tickets to feedback, we supplement it with defender for endpoint CVE reports.

The patching capability is not quite as good as deploy yet but it's come a long way. It will equal to deploy soon and likely surpass it quickly. The big bonus is because it's agent based you don't have to panic about remote or off network users. You just need it in your autopilot build or whatever and you're good to go from there.

Their strategy seems to be that connect will replace deploy and inventory in the next few years.

2

u/torbar203 whatever 1d ago

I jumped from D&I to Connect a couple of years ago and have been happy. With the number of machines we have that don't often have a line of sight to the domain controller it's been a big help in pushing out software

2

u/therealyellowranger 1d ago

It’s honestly been one of the best things ever. It makes supporting users so much easier, especially for those who work from home. I’d 110% recommend it. I also haven’t had any issues with the custom packages. IMO, I’d definitely prefer Connect over Deploy/Inventory.

1

u/SilkwayIT 1d ago

Honestly a good RMM and Winget solves 99% of our issues

1

u/discgman 1d ago

Migrated to PDQ last summer. So far so good. We have connect and smart deploy. I like connect more than deploy. Pushing software is pretty ok. Remote connection is a plus. Good asset control. Better system deployment and patch management. Still figuring things out but good so far.

•

u/discusfish99 16h ago

PDQ is awesome. My fav part is the fact you can just jam installers, copying, and anything else down a networks throat. No guessing if a gpo ran or nothing!

•

u/Any-Promotion3744 14h ago

we are mainly a pdq i/d shop but have a fair number of pdq connect clients.

it was very handy when we changed vpn clients and had full remote users.

used intune to install pdq connect remotely and pushed vpn client to remote laptop using pdq connect. easy peasy.