Forum Discussion

Jason_B1025's avatar
Jason_B1025
Brass Contributor
Apr 16, 2021

365 security endpoint missing KBs

How often does the ATP defender client update the KBs installed. 

I have a machine that was patched 2 days ago but it not reflecting on the missing KBs section of the device inventory. 

Last seen was 5 minutes ago.

 

We're struggling to find a good way to report at both the macro and micro level on windows patch level in intune.

 

jb

 

 

4 Replies

  • avaldez1's avatar
    avaldez1
    Copper Contributor

    Jason_B1025 The problem was solved? I have several computers the same, the patches or updates are already installed but they continue to report that they are missing. I don't know if a service has to be restarted or a firewall problem, but run the test detection and it works

    • Jason_B1025's avatar
      Jason_B1025
      Brass Contributor
      We started pulling data from log analytics, intune, and our asset manage solution samange to compare the OS version numbers. We haven't added the data from seucurity center yet (need to figure out how to pull that from the api) based on those 3 sources we flag machines two versions back and send tech to see why they are not patching.
      So right now I haven't solved the few that were not updating in security center we are focus on getting an accurate view of our patching. Now why some Intune computers are not patching, that's another mystery to solve.
    • iamdmitriev's avatar
      iamdmitriev
      Copper Contributor
      Have the same situation.
      Several devices have connectivity to WD ATP and installed updates. But there is a list of Missing KBs for almost an year on the portal.
      We have found the problem with WIndows Server OSes (Microsoft Monitoring agent to connect to WD ATP was not uninstalled after in-place upgrade and there were two different ways to connect to WD ATP), but do not know what the root cause for Windows 10 OSes.
  • ambarishrh's avatar
    ambarishrh
    Iron Contributor

    Jason_B1025 If you are using TVM (Threat & vulnerability Management) from defender, you could add the reported vulnerability to remediation task and you could track the progress from there. I have a video on TVM here https://www.youtube.com/watch?v=2ktppQHFGBY

     

    If you use MEM portal, you could see the status via https://docs.microsoft.com/en-us/mem/intune/protect/windows-update-compliance-reports