Patch My PC Blog

Get expert insights, how-to guides, product updates, and best practices for streamlining patch management, improving endpoint security, and optimizing IT operations.

blog category feature image
Faster Win32App Delivery
Blog
Faster Win32 App Delivery in Intune with Push Notifications

Microsoft Intune is improving Win32 app delivery with push notifications. Changes made by administrators or the service can now prompt devices to check sooner, reducing delivery and refresh delays without changing how you manage apps. Win32_Pull_vs_Push_Illustrated_… This blog follows the tested IC3 notification into the IME, showing how intent 2 selects Win32AppWorkload and brings the normal app check forward.

Rudy Ooms
Autopilot Required Apps No Longer Need to Wait 60 Minutes
Blog
Faster Required App Delivery After Autopilot

Required Win32 apps sometimes waited 60 minutes after Autopilot ESP completed. IME 1.103.101.0 introduces a FirstSync registry watcher that detects ESP completion and immediately triggers another app workload check in.

Rudy Ooms
Intune App Inventory
Blog
Intune App Inventory From Four Hours to About Five Minutes

Intune App Inventory no longer has to wait for the regular four hour collection cycle. A new app install can now trigger detection, validation, a fresh inventory run, and a small delta upload within about five minutes.

Rudy Ooms
defender turned off
Blog
Defender is On. Intune Says Noncompliant

Defender was running. Windows said it was off. Intune could then mark the device noncompliant, and Conditional Access could block the user. Here is how the startup race happened, what our PowerShell workaround did, and what we found when testing Defender 4.18.26080.4

Rudy Ooms
Blog
Autopilot Device Preparation vs Device Association vs Classic Autopilot: What Is the Difference?

At first glance, Device Association looks almost identical to Classic Autopilot. Both can involve collecting device information, uploading a CSV, and linking the device to a tenant. But underneath that familiar admin workflow, Windows uses a different deployment, identity, and OOBE model.

Rudy Ooms
Your Windows Compliance Report Is Lying to You
Blog
Your Windows Compliance Report Is Lying to You 
Most enterprise patching programs were built for a different era. Ten years ago, keeping Windows current eliminated a meaningful portion of enterprise risk. Today, the operating system is just one...
White Hat
Autopilot Device Association
Blog
Windows Autopilot Device Association

What happens between importing a Device Association CSV and Windows knowing which tenant it belongs to? This walkthrough follows all 12 steps, using code and lab evidence to explain TPM attestation, the signed association stored in UEFI, and how Windows retrieves OOBE settings before anyone signs in.

Rudy Ooms
Intune Client Driven Compliance Evaluation for Windows
Blog
Inside Intune Client-Driven Compliance Evaluation for Windows Devices
Microsoft has announced client-driven compliance evaluation for Windows devices to reduce delays in compliance reporting. Supported Windows devices can detect important local state changes and...
Rudy Ooms
sync status window
Blog
Inside Intune’s New Sync Status Window
Microsoft has quietly improved the Windows device sync experience in Intune. Instead of only sending a push request that tells the device to check in through IC3 and WNS, the portal can now also...
Rudy Ooms
Blog
The Dead Zone: Your IT Team Isn’t Too Slow. Attackers Just Have Terrible Manners. 
Every security update starts a race.  On one side is the attacker. Modern exploit development is moving faster than ever, and AI is compressing the time between a vulnerability becoming public...
White Hat