Patch My PC Blog

Get expert insights, how-to guides, product updates, and best practices for streamlining patch management, improving endpoint security, and optimizing IT operations.

blog category feature image
Your Windows Compliance Report Is Lying to You
Blog
Your Windows Compliance Report Is Lying to You 
Most enterprise patching programs were built for a different era. Ten years ago, keeping Windows current eliminated a meaningful portion of enterprise risk. Today, the operating system is just one...
White Hat
Autopilot Device Association
Blog
Windows Autopilot Device Association

What happens between importing a Device Association CSV and Windows knowing which tenant it belongs to? This walkthrough follows all 12 steps, using code and lab evidence to explain TPM attestation, the signed association stored in UEFI, and how Windows retrieves OOBE settings before anyone signs in.

Rudy Ooms
Intune Client Driven Compliance Evaluation for Windows
Blog
Inside Intune Client-Driven Compliance Evaluation for Windows Devices
Microsoft has announced client-driven compliance evaluation for Windows devices to reduce delays in compliance reporting. Supported Windows devices can detect important local state changes and...
Rudy Ooms
sync status window
Blog
Inside Intune’s New Sync Status Window
Microsoft has quietly improved the Windows device sync experience in Intune. Instead of only sending a push request that tells the device to check in through IC3 and WNS, the portal can now also...
Rudy Ooms
Blog
The Dead Zone: Your IT Team Isn’t Too Slow. Attackers Just Have Terrible Manners. 
Every security update starts a race.  On one side is the attacker. Modern exploit development is moving faster than ever, and AI is compressing the time between a vulnerability becoming public...
White Hat
Ivanti DSM End of Life: Migration Options & Planning Guide 2026
Blog
Patch Management after Ivanti DSM End of Life: What DSM Customers Need to Know Before 2027

Ivanti DSM reaches end of life on December 31, 2026. Learn how to plan your Ivanti DSM migration, compare replacement options, move applications and eScript packages to Microsoft Intune or Configuration Manager, and modernize third party patch management.

SoftTailor
Intune On Demand Device Sync Now Uses IC3
Blog
Intune On Demand Device Sync Now Uses IC3 for IME Workloads
In our previous investigation, the improved Device Sync action sent two WNS notifications. One woke WindowsMDMPush so the Windows MDM client could trigger the Policy refresh. The other targeted the...
Rudy Ooms
Why Intune Devices Became Noncompliant After the July Windows Update
Blog
Why Intune Devices Became Noncompliant After the July Windows Update

The July Windows update caused newly enrolled devices to appear noncompliant in Intune, even when BitLocker, Secure Boot, and Code Integrity were enabled. This investigation connects the SyncML 404 errors, failed Device Health Attestation, Parallels vTPM reports, AIK v2, feature 62861611, and the code changes Microsoft introduced in KB5101684

Rudy Ooms
Windows Registry Data Is Coming to Intune Device Inventory
Blog
Windows Registry Data Is Coming to Intune Device Inventory
Device Inventory started with predefined Hardware Properties and later added application data. App Inventory then showed that the same agent and upload pipeline could support a completely different...
Rudy Ooms
Blog
How to Evaluate Third-Party Patching Solutions Beyond Price 

Comparing third-party patching solutions based solely on licensing cost can lead to expensive mistakes. This article explores the key questions IT teams should ask when evaluating patching vendors and explains why the cheapest option on paper may not be the most cost-effective choice in practice.

Justin Chalfant