A community where customers and the community can provide feedback to make a better product for everyone! For more details on how we prioritize requests, please see:
We’d like to see support for patching third-party apps on Windows Server in environments where customers are using Microsoft Intune only.
Today, Intune does not support Windows Server for application management. That creates a gap for customers who rely solely on Intune to manage their devices. This includes many organizations that are cloud-native or have moved away from ConfigMgr.
One of our customers shared this request:
“What we've been doing has been working well with laptops and workstations, but I am now seeing if we can use Patch for patching third party applications on servers.”
Since Intune can’t manage apps on servers, and Patch My PC’s current setup depends on either ConfigMgr or Intune, there’s no way to handle server patching in this type of environment.
We’d love to see a solution. Whether that’s an agent, lightweight installer, or something else. The goal is to enable third-party patching on servers for customers who are Intune-only.
This would help close a security gap and extend the same trusted patching workflows to servers.
Thanks for the votes and for laying out the use cases so clearly. The gap you're describing, third-party patching for Windows devices that aren't managed by Intune or ConfigMgr (servers, non-domain-joined machines, shared-tenant scenarios, and similar), is one we recognize as a real problem, not just a niche edge case. Keep the votes and use cases coming on this one; the more weight behind it, the better positioned it is when we look at how to address it.
Since we already use PMPC for workstations it would be amazing to see it work with Windows servers. Honestly, a lightweight agent would be the best approach considering the limitation that AUM gives along with Azure Arc for third party patching and the fact that WSUS is no longer being developed.
i think the easiest way is to keep supporting wsus standalone i guess ;) but the problem is advanced insights doesn't support wsus :')
https://ideas.patchmypc.com/ideas/PATCHMYPC-I-8365
and also add support for custom apps to wsus please
https://ideas.patchmypc.com/ideas/PATCHMYPC-I-3852
wsus isnt dead yet and the only real "proper" solution for non domain joined devices or dmz stuff
A lightweight agent-based approach or similar solution would make a huge difference here. It would allow organisations to standardise their third-party patching across both endpoints and servers, without needing hybrid complexity.
This would not only simplify management but also help close a security gap for environments that are already moving or planning to move to Intune-only.
A standalone agent or something akin to it would be amazing. We have moved our user devices to intune and are working towards reducing our server footprint onprem. Having 3rd party patch management without Configuration Manager or WSUS is a problem that we can't find a good solution to. Other than hosting a cloud wsus server and integrating 3rd party app updates with Azure Arc or scripting it. All of which introduce overhead that is not ideal.
This would be useful in small environments (like ours) that are running Configuration Manager, but where DMZ servers don't have domain access and are configured to patch directly against WU via local policy ... though I suspect that in these cases a license exception to run PMPC Home on these servers may be "good enough".
would be nice to have this in PMPC. Currently we need "a product with three letters" for that :(
Non-Domain joined servers being able to manage it would be wonderful.
I am in need of this as well. Right now I am looking to see if another vendor can accommodate the server side; however would it if PMPC Cloud can do this somehow.
I'd love to see a lightweight agent option. This would be very helpful for servers, but also workstations for folks in a shared Intune tenant. Seems like an easy way to let subsidiaries maintain full control of their 3rd party patching.
since wsus is going eol and has some limitations anyways like the 2gb size, removal/uninstall support, custom apps,... a proper alternative would be welcome and who better than pmpc to come up with a nice and propper patching agent :) and btw not everyone can afford sccm or intune anyways or does want to use it ;)