Tell me if I'm missing something but I feel like I should be able to dive into a device and on the left should be a Autopatch section. When I click it, it will show me last known outstanding patches. How hard is it for the Intune agent to grab these? If they can be displayed in the UI of the client, surely Intune can inventory that same information and sync it.
Also, where's my "Check for updates" button against each device? How do I trigger a device to check for updates remotely without having to figure out a script?
It's one thing when you've got the time to let the devices just relax and take care of their patches whenever they see fit. It's quite another when you're building or rebuilding systems, and you want them to go out fully patched and want to get them there in the shortest time possible. I'm finding that we have to go into Windows Update in settings on newly built devices and hit Check for Updates to get it moving. Why does it feel like this has been a dark art for the past 20 years!?!