Patch My PC Blog

Get expert insights, how-to guides, product updates, and best practices for streamlining patch management, improving endpoint security, and optimizing IT operations.

blog category feature image
The Intune MDM Device Certificate KSP Renewal Bug Why the Bit4id Provider Caused it
Blog
The Intune MDM Device Certificate KSP Renewal Bug: Why the Bit4id Provider Caused it

A third party smart card KSP caused the Intune MDM certificate renewal flow in Windows 11 to fail before the actual renewal checks even started, leaving devices with expired certificates and almost no useful errors. This blog explains why only specific devices were affected, how the November update changed the Windows renewal flow, and why the same fix could still depend on feature rollout in Windows 11 24H2.

Rudy Ooms
A Deep Dive into Controlled Feature Rollout: Why Features are turned off by default
Blog
A Deep Dive into Controlled Feature Rollout: Why Features are turned off by default
This blog explains what Controlled Feature Rollout (CFR) is, why Microsoft ships features in an off-by-default state, and how a device determines when a new capability or Windows hotfix is allowed...
Rudy Ooms
Autopilot 0x800705b4- App Control Blocks the IME Installation
Blog
Autopilot 0x800705b4: App Control Blocks the IME Installation
This blog looks at an Autopilot failure where the device gets stuck at Preparing your device for mobile management and ends with 0x800705b4. The root cause was not Autopilot itself, but App Control...
Rudy Ooms
Five-Eyes-Intelligence-Alliance-Says-It’s-Time-to-Speed-Up-Patching
Blog
Five Eyes Intelligence Alliance Says It’s Time to Speed Up Patching

Excerpt: Five Eyes warned that AI is shrinking the time between vulnerability discovery and exploitation. That makes AI patch management a real operational problem, especially for organizations still relying on slow testing cycles, manual third party updates, or users clicking update prompts when they feel like it.

Jordan Benzing
Intune-EPM-System-Settings-Network-and-Time-Sync-Elevation
Blog
Intune EPM System Settings: Network and Time Sync Elevation

A look at how Intune EPM appears to be moving beyond file elevation with a System Settings experience for Network Settings and Time Sync.

Rudy Ooms
Intune Multi Admin Approval The x-msft-approval-justification Error
Blog
Intune Multi Admin Approval: The x-msft-approval-justification Error
This blog is about the moment Microsoft expanded Multi Admin Approval to app-based Graph automation, and how Intune app updates suddenly began failing with the x-msft-approval-justification error....
Rudy Ooms
Autopatch Client Broker Fails During Autopilot Pre-Provisioning
Blog
Autopatch Client Broker Fails During Autopilot Pre-Provisioning

When Autopatch Client Broker runs as a blocking app during Autopilot Pre Provisioning, one small Environment check can take down the MSI. Windows already removed the TenantInfo, the custom action still expects it, and ESP ends with 1603.

Rudy Ooms
Company Portal Not Installing During Autopilot Enrollment 0x87D1041C
Blog
Company Portal Not Installing During Autopilot Enrollment 0x87D1041C

The Company Portal suddenly started failing during Autopilot pre provisioning with error 0x87D1041C, even though the app was already present on the device. We traced the issue back to a Windows change introduced with the May update and confirmed the fix after Microsoft reverted the rollout.

Rudy Ooms
Intune Management Extension Release Notes
Blog
Intune Management Extension: Release Notes

The IME does a lot more than most people think. This post is about automating Intune Management Extension Release Notes, so every new version shows what changed instead of leaving us guessing.

Rudy Ooms
When Devices Appear Active but Cannot Sync
Blog
The Illusion of Intune “Last Check-in”: When Devices Appear Active but Cannot Sync

The Intune portal can show a fresh Last check in even when the MDM certificate on the device has already expired. That timestamp only proves the device was able to touch the service. It does not prove that policy sync, app delivery, or real management is still working.

Rudy Ooms