Automated patching of third-party applications

Global cybercrime costs now exceed $10 trillion annually (Cybersecurity Ventures, 2025), and unpatched third-party applications remain one of the most consistently exploited entry points. Patching Microsoft applications through SCCM or Intune is relatively straightforward, but third-party applications like browsers, PDF readers, and conferencing tools sit outside that native coverage. Failing to patch them puts endpoints at risk, since known vulnerabilities in these applications are routinely targeted in attacks. The most effective way to close this gap is with automated third-party patching.  Patch Connect Plus extends both Microsoft SCCM and Intune to automate the entire third-party patching process, from discovering and downloading new patches, to publishing them for deployment, and reporting on the results.

How does automated third-party application patching work?

Unlike Microsoft, which releases monthly security updates for its applications,there's no specific frequency that third-party applications receive updates. Security patches for third-party applications are generally only rolled out to fix a critical vulnerability,which makes third-party application patching vital for enterprise security. Since third-party application patches are important for keeping organizations secure, any missing patches should be automatically deployed as soon as they're released. Patch Connect Plus includes four processes for automated patch deployment:

  1. Scanning for the latest updates

    Vendors typically release the latest patches for their applications on their respective websites. As soon as patches are released to a vendor's site, Patch Connect Plus fetches the update details, then publishes the patch to a Central Patch Repository. The estimated time at which third-party updates are supported is 6-9 hours from vendor release.

  2. Publishing third-party patches

    Patch Connect Plus contacts the Central Patch Repository every 24 hours to check for any new updates. If found, the update details will be synced and the patches will be downloaded to the Patch Database present on the Patch Connect Plus server. Afterwards, the downloaded patches are published to the WSUS server.

  3. Initiating WSUS-SCCM syncs

    Once a patch is published to the WSUS library, Patch Connect Plus will automatically trigger a sync between WSUS and SCCM, making the patches accessible in the SCCM console. Further, SCCM's Automatic Deployment Rules (ADRs) make sure patches are deployed onto the appropriate systems.

  4. Reporting

    After deploying a patch, Patch Connect Plus will notify users by sending a deployment report to their email. This report contains data on: the publishing process, the sync status, newly supported applications, deployment task failures, and the signing certificate's expiration. These email notifications will make sure that users don't miss out on summaries of their patch deployment tasks.