How is everyone managing Windows and third-party updates? I currently have Windows Autopatch rings configured through Intune, but some machines remain behind with updates that never seem to install. The automatic reboot behavior also does not appear to be working, and I am finding devices with extremely long uptimes, including one at 46 days.
I am testing Atera because it combines ticketing, patch management, software updates, and reboot scheduling. However, I have also seen criticism of its forced AI features. At the same time, I am investigating whether conflicting Intune policies or leftover configuration from an older update system is preventing Autopatch from working correctly.
Would it be a bad idea to use Atera to bring the machines up to date and then return to Intune for ongoing Windows patch management? Has anyone successfully used a similar split setup?
4 Answers
The 46-day uptimes sound more like a restart-policy problem than a patch-management problem. Configure quality-update deadlines, a short grace period, and automatic restarts. Also review active hours and remember that a locked session can still count as a signed-in user, preventing the restart from happening when expected.
Trying to force an exact restart time is not always reliable, so a deadline plus grace period is generally more dependable. Check the behavior on a test group before rolling it out broadly.
A separate patching product can be useful, but I would fix the current Autopatch configuration first rather than using it as a workaround. Pull the Windows Update for Business report, identify a few affected machines, and compare their policies, registry settings, update history, join status, and reboot state.
Once the cause is understood, choose a clear ownership model. For example, Intune can manage Windows quality and feature updates while an RMM handles third-party patching and reporting. The important part is avoiding two systems attempting to enforce the same Windows update settings.
I would not let Atera and Intune both control Windows Update. Two agents or policy sets competing for the same settings can create compliance drift and make troubleshooting much harder. If you use Atera, either make it the sole Windows patching authority or leave Windows patching with Intune and use Atera for monitoring and third-party applications.
Intune Autopatch does not cover every application your organization may depend on, such as Chrome, Acrobat, Zoom, 7-Zip, or line-of-business software. That is where an RMM can add value without taking over Windows Update.
Before adding another patch engine, confirm whether the problem is actually a policy or device-readiness issue. Check the Windows Update for Business reporting data for machines that are behind. On an affected device, look for old WSUS settings under HKLMSOFTWAREPoliciesMicrosoftWindowsWindowsUpdate. Leftover WUServer or legacy automatic-update keys can cause Windows Update for Business policies to be ignored even though Intune says they were applied.
Also check Autopatch eligibility, telemetry requirements, join status, and whether devices are receiving multiple update rings. For ongoing management, use one system as the patching authority and let another system audit compliance or identify missing devices.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures