Patch My PC Blog

Get expert insights, how-to guides, product updates, and best practices for streamlining patch management, improving endpoint security, and optimizing IT operations.

blog category feature image
Why Intune Devices Became Noncompliant After the July Windows Update
Blog
Why Intune Devices Became Noncompliant After the July Windows Update

The July Windows update caused newly enrolled devices to appear noncompliant in Intune, even when BitLocker, Secure Boot, and Code Integrity were enabled. This investigation connects the SyncML 404 errors, failed Device Health Attestation, Parallels vTPM reports, AIK v2, feature 62861611, and the code changes Microsoft introduced in KB5101684

Rudy Ooms
Windows Registry Data Is Coming to Intune Device Inventory
Blog
Windows Registry Data Is Coming to Intune Device Inventory
Device Inventory started with predefined Hardware Properties and later added application data. App Inventory then showed that the same agent and upload pipeline could support a completely different...
Rudy Ooms
Blog
How to Evaluate Third-Party Patching Solutions Beyond Price 

Comparing third-party patching solutions based solely on licensing cost can lead to expensive mistakes. This article explores the key questions IT teams should ask when evaluating patching vendors and explains why the cheapest option on paper may not be the most cost-effective choice in practice.

Justin Chalfant
Company Portal Error Loading Apps
Blog
Company Portal: Error Loading Apps

Some time ago, the Company Portal suddenly failed to load its apps. In this blog, I explain what happened behind the scenes, how the IWService path works, why the issue could affect only one Intune Azure Scale Unit, and how you can check that tenant specific service path yourself.

Rudy Ooms
Custom Compliance Policies and the Eight-Hour Waiting Game
Blog
Intune Custom Compliance Policies and the Hourly Cadence Fix

Custom compliance in Intune can leave devices reporting stale results for up to eight hours. IME 1.103.101.0 appears to introduce a new hourly cadence that could rerun discovery scripts and send fresh PolicyResult data back to Intune much sooner.

Rudy Ooms
Inside the Improved on-demand sync for Windows devices
Blog
Inside the Improved on-demand sync for Windows devices

The new Improved on-demand Sync in Intune is expanding beyond policies to include Win32 apps, PowerShell scripts, and Remediations.

Rudy Ooms
The Intune MDM Device Certificate KSP Renewal Bug Why the Bit4id Provider Caused it
Blog
The Intune MDM Device Certificate KSP Renewal Bug: Why the Bit4id Provider Caused it

A third party smart card KSP caused the Intune MDM certificate renewal flow in Windows 11 to fail before the actual renewal checks even started, leaving devices with expired certificates and almost no useful errors. This blog explains why only specific devices were affected, how the November update changed the Windows renewal flow, and why the same fix could still depend on feature rollout in Windows 11 24H2.

Rudy Ooms
A Deep Dive into Controlled Feature Rollout: Why Features are turned off by default
Blog
A Deep Dive into Controlled Feature Rollout: Why Features are turned off by default
This blog explains what Controlled Feature Rollout (CFR) is, why Microsoft ships features in an off-by-default state, and how a device determines when a new capability or Windows hotfix is allowed...
Rudy Ooms
Autopilot 0x800705b4- App Control Blocks the IME Installation
Blog
Autopilot 0x800705b4: App Control Blocks the IME Installation
This blog looks at an Autopilot failure where the device gets stuck at Preparing your device for mobile management and ends with 0x800705b4. The root cause was not Autopilot itself, but App Control...
Rudy Ooms
Five-Eyes-Intelligence-Alliance-Says-It’s-Time-to-Speed-Up-Patching
Blog
Five Eyes Intelligence Alliance Says It’s Time to Speed Up Patching

Excerpt: Five Eyes warned that AI is shrinking the time between vulnerability discovery and exploitation. That makes AI patch management a real operational problem, especially for organizations still relying on slow testing cycles, manual third party updates, or users clicking update prompts when they feel like it.

Jordan Benzing