Just Landed for ControlUp for Compliance: Improvements to the Microsoft Intune Integration and Device Restart

ControlUp for ComplianceDigital Employee Experience (DEX)Endpoint SecurityMicrosoft Intune

Now in Beta: ControlUp for Compliance Patch Management Integration for Microsoft Intune 

Microsoft Intune is great for OS and application deployment and patch management. Many enterprises complement Intune by integrating IT Service Management (ITSM) and IT Asset Management (ITAM) applications to provide a complete and accurate audit trail of the company’s security posture and asset health. However, support teams using ControlUp for Compliance often find missing patches before Intune discovers them. That’s where ControlUp steps in, offering an integration that enables support teams to discover and deploy patches while supporting auditing and compliance.

How to ControlUp for Compliance Works with Microsoft Intune to Enhance Patch Management:

  • ControlUp for Compliance automatically (through templates) or manually detects vulnerabilities on endpoints in real time
  • ControlUp for Compliance then creates and sends a package to Microsoft Intune
  • Intune automatically deploys the package to the devices identified by ControlUp for Compliance
  • Intune then notifies the ITSM and/or ITAM
  • ControlUp for Compliance then displays the patching status and confirmation that the patch was applied successfully

This automation isn’t just a convenience; it’s a strategic advantage. It significantly reduces the workload on your IT and security teams, allowing them to focus on more strategic initiatives. More importantly, it minimizes the window of exposure to potential threats in real-time, ensuring greater IT compliance, improved system stability, and a more secure and efficient digital environment for your employees.

Why Real-Time Vulnerability Remediation Matters for Your Business

What does real-time vulnerability mean for your day-to-day operations and your overall security posture? Let’s dive into the core benefits:

  • Stay Ahead of Threats: The faster you can detect and fix a security hole, the less chance an attacker has to exploit it. Our real-time vulnerability detection paired with immediate, automated patching drastically shrinks that window of exposure. This isn’t just about being reactive; it’s a truly proactive approach that significantly slashes the risk of successful cyberattacks and costly data breaches by addressing vulnerabilities before they become a problem.
  • Enhanced Efficiency and Automation: Manual patching processes are a drain on resources. With ControlUp and Microsoft Intune, we automate the entire patching workflow from spotting the vulnerability to deploying the fix and even updating your ITSM and ITAM systems. This eliminates time-consuming manual efforts, freeing up your IT and security teams to tackle more strategic initiatives. The result? Better overall operational efficiency and a significant reduction in human error.
  • Improved Compliance and Readiness: Compliance doesn’t have to be a headache. Our integrated workflow ensures every patch is deployed and accurately recorded across your ITSM and ITAM systems by Microsoft Intune. This creates a clear, comprehensive, and auditable trail of all security activities. Meeting regulatory requirements and proving due diligence becomes straightforward and effortless.
  • Accurate Management and Reporting: Get a clear picture of your IT environment. By automatically updating your ITAM systems, you gain a more accurate and up-to-date view of your asset inventory and its security status. This isn’t just data; it’s intelligence that enables better decision-making for asset lifecycle management, resource allocation, and provides more precise reporting on your organization’s overall security posture.
  • Minimized Disruption: Security incidents can bring your business to a halt. By quickly addressing vulnerabilities, we significantly minimize the risk of system downtime or performance degradation. This directly contributes to greater business continuity and a more stable, reliable IT environment for your employees, ensuring their productivity stays uninterrupted.

ControlUp’s integration with Microsoft Intune isn’t just about applying patches; it’s about transforming your vulnerability management strategy into a proactive, efficient, and auditable process. Empower your organization with real-time protection and unlock a new level of security and operational excellence.

Improvement to the Device Restart Feature

When deploying a patch, rebooting a device, or restarting an application without user consent is rude, but allowing the user to delay the reboot or restart indefinitely is risky. ControlUp for Compliance has found the right balance to allow flexibility and control for the end user and higher compliance for the security team.

How to Use the New and Improved Device Restart Feature:

  • Device and application restarts can now be precisely configured to:
    • Never automatically restart: For critical applications or specific user needs
    • Restart immediately: For urgent security updates
      • When an immediate restart is configured, ControlUp for Compliance provides a clear 10-minute countdown, giving users ample warning before the application or device restarts.
    • User-controlled delay: Users can pause the restart for a configurable period, from one minute up to five days, allowing them to complete their work without interruption.
A screenshot of a "Windows App Patch" configuration wizard, currently on the "Schedule" step (step 3 of 4). The wizard is used to schedule the remediation and define restart behavior for applying patches. Under "Schedule," "Remediation Schedule" is set to "Immediately." Under "Restart behavior," there are sections for "Application close" and "Device reboot." For "Application close," "Enable" is selected. The "Close behavior" allows the user to choose between "Snooze available for" (set to 1 Day) or "Immediately." For "Device reboot," "Enable" is selected. The "Reboot behavior" allows the user to choose between "Snooze available for" (set to 3 Hours) or "Immediately." Below these, there's a "Device reboot - Legacy settings" section for agents with version 1.3.2595 and below. "Notify the user" is "Disabled," and "Force restart" is checked. "User Message" is "Disabled." At the bottom right, there are "Cancel," "Back: Remediation," and "Next: Summary" buttons.
ControlUp for Compliance Device Restart Screen

This intelligent restart functionality enhances user experience while ensuring that critical updates are applied on time, significantly improving compliance and reducing security risks.

Learn More

If you’d like to see these new capabilities in action, schedule a personalized demo with one of our experts today.

Jeff Johnson

Jeff is a product marketing manager for ControlUp. He is responsible for evangelizing the Digital Employee Experience on physical endpoints such as Windows, macOS, and Linux. Jeff has spent his career specializing in enterprise strategies for client computing, application delivery, virtualization, and systems management. Jeff was one of the key architects of the Consumerization of IT Strategy for Microsoft, which has redefined how enterprises allow unmanaged devices to access corporate intellectual property.