u/NoTime4YourBullshit

▲ 20 r/Intune

How are you managing employee expectations with patching and reboots?

We’re currently using SCCM for patch management. IT has set the expectation with employees that computers always get patched and rebooted at 7PM on the 4th Tuesday of each month. Patches become available on the 3rd Tuesday for users to self-install, but an email notice goes out on the 4th Tuesday telling everyone to log out of their computers and leave them running overnight if they haven’t taken that month’s updates yet. Anybody who misses the window is in for a rude awakening the next time they turn their computer on.

SCCM allows this degree of control which Intune seems incapable of.

We have a volunteer group of canaries that get forcibly patched and rebooted on the 3rd Tuesday in case Microsoft botched any updates that month. I’ve enrolled this group into Intune as a pilot, but here we are on the 3rd Tuesday of the month and only some of them are showing updates available.

I have an update ring configured with a deferral of 7 days, a scheduled install of the 3rd Tuesday at 7PM, and a hard deadline of 14 days. One machine checked for updates at 11:17 AM and includes drivers that I’ve explicitly set to require approval and have not approved. There’s no verbiage about when the install will happen or what the deadline is.

On another machine, it last checked for updates at 9:04 AM and isn’t showing any updates available at all. I’m assuming because a 7-day deferral means 10:30 Pacific time, which is when Microsoft actually publishes updates on Patch Tuesday. So with a default 22-hour check interval, that machine won’t even see updates until tomorrow morning, which is a day late.

On a 3rd computer, I freshly imaged it and deliberately withheld patches to see what update behavior is like when the deadline has already passed. It correctly offered me July’s patches, but not August’s (I did this yesterday before the 7-day deferral expired). However, it warned me that it would reboot on the 26th, which is next Wednesday — for last month’s patches.

I’m having a hard time figuring out how to set employee expectations in light of Intune’s fuzzy update logic. I’m accustomed to being able to schedule the exact update/reoot timing with SCCM and guarantee that my entire fleet will by compliant by the end of each month. But Intune doesn’t offer that kind of precision. How do you folks do it at your company?

reddit.com
u/NoTime4YourBullshit — 2 days ago
▲ 4 r/Intune

Signed in as Global Admin. Why don’t I have permissions to create Autopatch groups?

I can do everything else in Intune. Only Intune -> Tenant Admin -> Windows Autopatch -> Autopatch groups (and also Tenant management under the same mode) are unavailable to me.

It explicitly says in the banner “You do not have permissions to create or edit Autopatch an group” and “Tenant settings: You are not authorized to view this setting.”

I even added myself to the Intune Role Administrator role, but that didn’t help.

What’s up with this??

EDIT: I found the answer through an unbelievably fortunate coincidence.

We just so happen to be in the middle of a pen test right now. Something they were doing generated a suspicious activity alert from our SIEM software. So while I was browsing the firewall logs, I happened to see a bunch of blocked connections to services.autopatch.microsoft.com this morning from my PC (unrelated to the alert). I don't know why it got flagged, but I added to the whitelist and holy shit it's working now.

If we hadn't been doing a pen test, I never would have even thought to look at firewall logs -- especially since I was receiving an actual, informative (although incorrect) error message and not some rando page content error as is usually the case with this kind of thing. I can only describe the coincidence as miraculous. I never would have figured it out otherwise.

reddit.com
u/NoTime4YourBullshit — 1 month ago