Effective patch management helps keep your environment secure and productive. Microsoft offers two leading endpoint management platforms: Microsoft Intune and Microsoft Configuration Manager (ConfigMgr). This post compares their approaches to third-party application patching, the tradeoffs of each, and the patterns we hear from the Recast Community.
Core features: Similarities and differences
Both Intune and ConfigMgr help deploy software, enforce configurations, and ensure compliance on managed devices. They can also be used together in a co-managed setup, letting you enjoy the benefits of cloud-based management while retaining on-premises control.
Deployment model and infrastructure
Intune: Intune is a cloud-based service that requires no local servers. This makes it a great fit for remote users and BYOD (Bring Your Own Device) scenarios. Its web portal offers a modern, simplified management experience.
ConfigMgr: ConfigMgr is an on-premises solution that requires server infrastructure in the form of site servers, databases, and client agents. This model works best for organizations with a robust on-premises network and offers detailed control over every patch.
Application patching approach
Intune: Intune uses Windows Update client policies (formerly Windows Update for Business) to manage Windows OS updates. The process is designed to be “set it and forget it,” where updates are automatically applied based on defined deferral policies. This model favors ease of use but offers less granular control over individual updates. Windows Autopatch sits on top of this as a managed orchestration layer for Windows, Microsoft 365 Apps, Edge, and Teams, helping organizations automate update deployment and take advantage of hotpatch updates on supported devices.
ConfigMgr: ConfigMgr leverages Windows Server Update Services (WSUS) to give administrators full control over update approval, scheduling, and deployment. You can carefully select which patches to push to which devices, making it ideal for environments that require detailed testing before full deployment.
Microsoft deprecated WSUS in September 2024. It still ships with Windows Server 2025, remains supported for production use, and is still required for ConfigMgr software update points. Microsoft is no longer adding new WSUS features, but existing capabilities and update content remain available.
Third-party application patching
Neither platform has fully solved this one. In our State of Intune in 2026 survey of 890 IT professionals, third-party patching ranked as the second-biggest Intune challenge at 33%, behind only application packaging and deployment at 37%.
Intune: For years, Intune offered no native catalog for managing third-party application updates, so teams relied on Win32 repackaging, Microsoft Store apps, or scripts using tools such as WinGet. Microsoft has since added Enterprise Application Management, an Intune add-on with a curated catalog of prepackaged Win32 apps. Auto-update is available for required assignments, but the catalog is Windows-only. Niche, in-house, and macOS apps still require custom packaging or another tool.
ConfigMgr: ConfigMgr can subscribe to third-party update catalogs from vendors like Adobe, Oracle, and Dell. These catalogs allow ConfigMgr to manage and deploy third-party patches through its familiar Software Updates workflow. Although the process isn’t completely hands-off (manual intervention may be required for apps without an available catalog), ConfigMgr offers a more integrated solution for managing a broad range of third-party updates.
Pros and cons at a glance
Intune
Pros
- Cloud-based convenience: No need for on-premises infrastructure simplifies management, especially for organizations with remote or mobile workforces.
- Ease of use: Intune’s web-based console is modern and easy to navigate, making routine tasks simple for IT teams.
- Modern update process: Automated update rings and Windows Autopatch reduce the workload of keeping Windows and Microsoft apps up to date, and Enterprise App Management extends that to a catalog of common third-party applications.
Cons
- Third-party coverage has edges: Native coverage has improved, but the Enterprise App Catalog is curated and Windows-focused. Custom applications and macOS apps still require custom packaging or another tool. In the attached survey, 47% of respondents said they manually package Win32 apps, making it the most common approach.
- Different control model: Intune emphasizes policy-based rollout and cloud orchestration rather than ConfigMgr’s per-update approval workflow. That can be a limitation for teams with highly specific testing, scheduling, or exception processes.
- Separate server update management: Intune does not provide the same update-management model for Windows Server. Microsoft’s cloud-based path is Azure Update Manager, which manages Azure virtual machines and Azure Arc-enabled servers across on-premises and other cloud environments.
- Internet dependence: Devices must have reliable internet access, which can be challenging or even impossible in highly secure or isolated networks.
ConfigMgr
Pros
- Granular control: Offers detailed management of patch approval, scheduling, and deployment, essential for environments with strict testing or compliance needs.
- Integrated third-party support: Native integration with third-party update catalogs means many common applications can be patched through the same process as Windows updates.
- Handles complex environments: Ideal for large enterprises with thousands of endpoints, including servers and legacy systems.
- Detailed reporting: Robust reporting capabilities help with tracking patch compliance to meet auditing requirements.
- Extensible and mature: A longstanding solution with deep integrations and support for co-management with Intune.
Cons
- Infrastructure and complexity: Requires significant on-premises infrastructure and a higher level of IT expertise, which can be a barrier for smaller organizations.
- Steep learning curve: Managing ConfigMgr effectively demands a solid understanding of its many features, from site hierarchies to WSUS integration.
- Less suitable for mobile and remote devices: While ConfigMgr can manage remote devices via VPN or cloud management gateways, it isn’t as seamless as Intune’s cloud-first approach.
- Limited support for modern platforms: ConfigMgr is primarily focused on Windows, with limited support for non-Windows endpoints compared to Intune.
Real-world use cases
Small to mid-sized organizations
We find that for companies with a few hundred users, especially those that are cloud-first or have a remote workforce, Intune is often the better fit. Its ease of use, low infrastructure overhead, scaling agility, and integration with cloud services make it ideal for quickly deploying updates to Windows 10/11 devices and mobile endpoints. For third-party app management, supplementing Intune with auto-patching solutions can bridge the gap.
Large enterprises with complex environments
We work with many organizations with thousands of endpoints, environments that often include servers and specialized applications. Most continue to see significant benefits from ConfigMgr (you can explore some of their experiences here). Among our State of Intune in 2026 survey respondents still running it, 55% either have no plans or no timeline for retiring it.
ConfigMgr’s granular control not only allows IT teams to thoroughly test patches before deployment but also provides a high level of customization in the process, giving you full control over both the timing and method of deployment. This flexibility is a huge advantage for larger organizations that need to tailor rollout strategies to meet complex operational demands. Additionally, ConfigMgr’s native support for third-party updates through vendor catalogs, along with its detailed reporting, is critical for industries like banking and healthcare that have strict compliance requirements.
Hybrid environments
Many organizations find that a hybrid approach works best. By co-managing endpoints with both Intune and ConfigMgr, you can leverage the strengths of each platform. For example, use Intune to manage remote, mobile, or Windows 11 endpoints, while ConfigMgr continues managing server patches and devices needing granular update control. This balance allows you to transition gradually to a cloud-first model without sacrificing the capabilities needed for legacy systems.
That transition is a long one, and for many teams, this “messy middle” may not have an end. 62% of survey respondents manage devices with both platforms, and the single largest group, 38% of everyone we asked, still run most workloads in ConfigMgr. Even ConfigMgr-only teams don’t necessarily see Intune-only as the goal: Only 12% pictured it when asked to describe their ideal state in five years.
Conclusion
Choosing between Intune and ConfigMgr depends on your infrastructure, application estate, and control requirements. Intune reduces on-premises overhead and fits cloud-managed environments, but its third-party catalog will not cover every application. ConfigMgr offers a mature, controlled update workflow, but it requires more infrastructure and administration.
Either way the manual work adds up: 65% of survey respondents lose between six and 15 hours a week to manual packaging, patching, troubleshooting, and reporting, and another 22% lose more than that.
For many organizations, the practical answer is a deliberate mix. Use each platform where its control model fits, then close third-party coverage gaps with the processes or tools your application estate requires.
Find additional third-party application management and patching posts here, or download the full State of Intune in 2026 report to see how your environment compares.
Recast complements Intune and ConfigMgr
Microsoft’s tools provide the foundation for endpoint management. Recast adds deeper device control and broader application management without replacing that foundation.
When teams need broader third-party and custom application coverage, server support, or more precise update controls, Recast extends the Microsoft ecosystem with additional device and application management capabilities.
Microsoft continues to expand its endpoint management capabilities. Recast helps IT teams get more from the tools they already use.
If you don’t already have our free Right Click Tools for Intune and ConfigMgr, you can download them here.