What is best way to keep up to date employer's devices?

Mohsen Akhavan 936 Reputation points
2024-04-03T00:01:57.0166667+00:00

I'm looking for a solution with minimum administrator effort for keeping up to date on all employer's devices.

In the organization, I have about 50 devices that they onboarded to Defender for Cloud's portal. All devices showing on Microsoft Defender > Assets > Devices.

Every day we receive a lot of update notifications and our security score decreases based on updates.
It's very hard to manually update all applications that are installed on devices. For example, applications are:
Adobe Acrobat
Firefox
Edge

Chrome

Winzip

and etc.

My question how can I update all devices and manage them? With Intune or Defender for Endpoint?
How do medium or large companies handle it?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,213 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,465 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
19 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 44,321 Reputation points Microsoft Vendor
    2024-04-03T02:06:22.84+00:00

    @Mohsen Akhavan, Thanks for the reply. To manage the app on the devices, you can consider enroll the devices into Intune and manage it.

    Based as i know, some app types we deployed via Intune like Store app, built-in app, web app can update automatically.

    https://learn.microsoft.com/en-us/mem/intune/apps/apps-add

    For example, for windows platform, if the app can be found in Microsoft Store new, we can deploy the app via Microsoft store new and Apps that are deployed from the Microsoft Store are automatically kept up to date to the latest version of the app. For this feature to work properly for UWP apps, the Turn off Automatic Download and Install of updates shouldn't be enabled.

    https://learn.microsoft.com/en-us/mem/intune/apps/store-apps-microsoft

    If the app is not available in Microsoft Store new, we can check if the app has silent install command. If yes, then we can consider deploy the app via Intune win32. And deploy update via supersedence.

    https://learn.microsoft.com/en-us/mem/intune/apps/apps-win32-add

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.