Vulnerability → Patch, in one place

Turn vulnerability scans into patches that ship.

Patch Console ingests your vulnerability reports, groups them into actionable patch jobs, and deploys the fixes through Intune & Entra, while a lightweight agent reports each device's real installed software the moment it changes.

Free for up to 20 endpoints. No credit card.

Patch Console dashboard: vulnerabilities, patch groups, and device status at a glance
How it works

From scan to fix in three steps.

1 · Ingest

Import vulnerability reports and pull device + software inventory from Intune/Entra and the Patch Console agent. Everything lands in one tenant-isolated view.

2 · Group

Vulnerabilities are normalized into patch groups by product and fix version, with CVE severity rolled up, so you act on "update Chrome on 42 devices," not a CVE spreadsheet.

3 · Deploy

Pilot to a test ring, then deploy through Intune. The agent verifies the installed version after, closing the loop from vulnerability to confirmed remediation.

Features

Built for the whole patch lifecycle.

Vulnerability ingestion

Import scan reports; CVEs are deduped, severity-scored, and mapped to the products actually installed on your fleet.

Intune & Entra native

Sync managed devices and users straight from Graph. Deploy patches as Win32 apps, no separate console.

Real-time inventory agent

A tiny Windows agent reports the complete installed-software list the moment it changes, no waiting days for a scan.

Pilot rings & validation

Roll out to a pilot group first; the agent confirms the new version landed before you go fleet-wide.

RBAC, SSO & audit

Role-based access, Microsoft/Google SSO, MFA, and a full audit trail on every deploy, ignore, and override.

Multi-tenant isolation

Every device, vuln, and deployment is tenant-scoped. Built for MSPs and multi-org IT from day one.

The agent

Inventory that's always current.

One signed MSI across the fleet. It enumerates the complete installed-software list (registry, Microsoft Store, winget, and portable/path installs), then reports only when something changes. Intune-managed devices can be refreshed on demand; unmanaged devices check in on their own schedule.

  • One MSI, per-tenant enrollment token, upgrades in place
  • Runs as SYSTEM on a scheduled task with self-heal
  • Reports software, local admins, and device facts
  • Per-device cadence, server-controlled
Patch Console device detail: full installed-software inventory reported by the agent
Pricing

Simple, per-endpoint, no surprises.

One product, every feature included: vulnerability ingestion, Intune deployment, the agent, SSO, and audit. You only pay per endpoint over 20.

Free

$0

Up to 20 endpoints

Same features on both. The only difference is price.