Task-oriented guides and references for everything Patch Console does, from ingesting vulnerability scans to proving the fix landed on every device.
What Patch Console is, the pieces of the product, and how a vulnerability scan becomes a verified fix.
The two delivery channels, the deployment methods, hybrid groups, and the one rule about Intune-managed devices.
The daily scan, the six intelligence feeds it matches against, and why findings only resolve on inventory proof.
Turn weekly scanner reports into patch groups with fix targets, with late-arriving devices swept in automatically.
Pilot, validate, approve, expand, verify, clean up: every stage, plus auto-halt and version gates.
Defender platform and Microsoft 365 Apps update through their own vendor updaters, from a single deploy card.
A PowerShell agent on scheduled tasks: MSI install, per-tenant enrollment, five collectors, signed script runs.
Exit codes are evidence, not proof. How inventory closes findings, and why a clean install resolves in minutes.
The weekly client-ready report, the A-to-F grade with KEV and EOL caps, SLA tiers, and the time machine.
Deploy states, fleet statuses, finding statuses, and grade bands: every status word, defined in one place.