Turn vulnerability scans into patches that ship.
Patch Console ingests your vulnerability reports, groups them into actionable patch jobs, and deploys the fixes through Intune & Entra, while a lightweight agent reports each device's real installed software the moment it changes.
Free for up to 20 endpoints. No credit card.
From scan to fix in three steps.
1 · Ingest
Import vulnerability reports and pull device + software inventory from Intune/Entra and the Patch Console agent. Everything lands in one tenant-isolated view.
2 · Group
Vulnerabilities are normalized into patch groups by product and fix version, with CVE severity rolled up, so you act on "update Chrome on 42 devices," not a CVE spreadsheet.
3 · Deploy
Pilot to a test ring, then deploy through Intune. The agent verifies the installed version after, closing the loop from vulnerability to confirmed remediation.
Built for the whole patch lifecycle.
Vulnerability ingestion
Import scan reports; CVEs are deduped, severity-scored, and mapped to the products actually installed on your fleet.
Intune & Entra native
Sync managed devices and users straight from Graph. Deploy patches as Win32 apps, no separate console.
Real-time inventory agent
A tiny Windows agent reports the complete installed-software list the moment it changes, no waiting days for a scan.
Pilot rings & validation
Roll out to a pilot group first; the agent confirms the new version landed before you go fleet-wide.
RBAC, SSO & audit
Role-based access, Microsoft/Google SSO, MFA, and a full audit trail on every deploy, ignore, and override.
Multi-tenant isolation
Every device, vuln, and deployment is tenant-scoped. Built for MSPs and multi-org IT from day one.
Inventory that's always current.
One signed MSI across the fleet. It enumerates the complete installed-software list (registry, Microsoft Store, winget, and portable/path installs), then reports only when something changes. Intune-managed devices can be refreshed on demand; unmanaged devices check in on their own schedule.
- One MSI, per-tenant enrollment token, upgrades in place
- Runs as SYSTEM on a scheduled task with self-heal
- Reports software, local admins, and device facts
- Per-device cadence, server-controlled
Simple, per-endpoint, no surprises.
One product, every feature included: vulnerability ingestion, Intune deployment, the agent, SSO, and audit. You only pay per endpoint over 20.
Same features on both. The only difference is price.