I'm managing Windows endpoints in a Microsoft 365 environment and want to improve application patching. I understand that Intune and Windows Update for Business can handle operating system updates and deploy packaged Win32 applications, but I'm unclear about the differences between native Microsoft capabilities, Patch My PC, and SCCM/Configuration Manager. What does each option provide, and when would it make sense to use one over another?
3 Answers
Intune’s Enterprise Application Catalog covers some common software and is improving, but its selection and update timing may not be enough for a large application estate. Patch My PC is useful when you need broad coverage for products such as browsers, PDF tools, conferencing apps, utilities, and other frequently updated software. It works as an add-on to Intune rather than replacing it.
SCCM is a much larger deployment platform. It provides distribution points, maintenance windows, phased deployments, detailed on-premises control, and other infrastructure features. That can be worthwhile if you already use it for imaging or complex deployment requirements, but setting it up solely to patch applications is usually excessive for a cloud-managed Microsoft 365 tenant. A common approach is Windows Update for Business for the OS, Intune for management, and a third-party catalog for application updates.
The biggest native gap is automated patching for third-party applications. Intune can deploy Win32 apps, but you generally have to package and update those apps yourself. Patch My PC maintains a large application catalog, automatically repackages updates, and publishes them to Intune or Configuration Manager. You can then use deployment rings, deadlines, user notifications, and rules to control rollout. For an Intune-focused environment, it avoids a lot of repetitive packaging work.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures