Patch My PC Blog

Get expert insights, how-to guides, product updates, and best practices for streamlining patch management, improving endpoint security, and optimizing IT operations.

blog category feature image
Desired State Configuration v3 What Changed and how to Migrate
Blog
Desired State Configuration v3 Explained: What Changed, Why It Matters, and How to Migrate.

This blog dives into Microsoft’s rebuild of Desired State Configuration and how DSC v3 changes configuration management across platforms.

Ben Reader
The History of Intune From OMA DM to Modern Windows Management.
Blog
The History of Intune: From OMA DM to Modern Windows Management

How OMA DM started it all: The early GET–SET–GET model that became the core of Intune and Windows device management.

Rudy Ooms
Windows Finally Translates Entra Group and Role SIDs to Real Names
Blog
Windows Finally Translates Entra Group and Role SIDs to Real Names

Ever wondered what those S-1-12-1 SIDs really were?
This blog takes a closer look at how Windows now translates Entra group and role SIDs into real, readable names.

Rudy Ooms
Blog
Administrator Protection: Secure Your Admins!

Administrator Protection on Windows 11 adds just-in-time permissions to improve admin security and reduce attack risks

Rudy Ooms
Intune Policy Delivery Debugging The 8-Hour Sync Myth
Blog
The Truth About the 8-Hour Intune Sync (and Why It’s a Myth)

Many believe Intune policy delivery only happens during the eight hour Intune sync. In reality Intune pushes new policies within minutes using change based check ins and WNS notifications. This post reveals why the eight hour sync is just a safety net.

Rudy Ooms
Blog
Why Do Required Apps Wait 60 Minutes After Autopilot Enrollment?

Required apps not installing after Autopilot? If your device sits idle for 60 minutes before Win32 apps appear, you’re not alone. This blog unpacks the IME logs, code, and Microsoft’s own explanation for the built-in delay

Rudy Ooms
Understanding the Default Compliance Policy Enrolled User Exist
Blog
Understanding the Default Compliance Policy: What’s Changed and Why Devices Stay Compliant

This blog explores the behavior change in Intune’s built-in compliance policy, specifically why devices are still marked as compliant even when the original enrolled user has long since left the organization.

Rudy Ooms
Windows Autopilot Stuck on Identifying The KB5065848 Story
Blog
Windows Autopilot Stuck on Identifying: The KB5065848 Story

KB5065848 broke Windows Autopilot, leaving devices stuck on Identifying. Delivered through OOBE ZDP, the update was later pulled back by Microsoft.

Rudy Ooms
BitLocker Policies Not Getting Applied in Intune (65000).
Blog
BitLocker Policies Not Getting Applied in Intune (65000)
This blog will discuss a case where BitLocker policies pushed during Windows Autopilot appeared to be applied in the event logs, but they never actually were applied successfully. Instead, every...
Rudy Ooms
Windows Backup for Organizations
Blog
Windows Backup for Organizations: ESR 2.0 With a New Skin?
This blog outlines the new Windows Backup for Organizations feature introduced in Windows 11 by Microsoft. They replace the old “Sync your settings” controls with a modernized backup experience,...
Rudy Ooms