← All solutions
Intune Patch Management

Intune keeps Windows current.
We patch everything else.

Intune does Windows updates well. But browsers, PDF readers, runtimes and line-of-business apps sit outside its scope — and that is where most attacks land. CapaOne Application Manager closes that third-party patch gap automatically, with no manual packaging and audit-ready evidence.

The Third-Party Gap

Intune patches Windows. Not the apps on top of it.

Microsoft Intune keeps the operating system and Store apps up to date, and it does that job well. But the software your users actually work in all day — browsers, PDF readers, Java and .NET runtimes, collaboration tools, and your own line-of-business apps — falls outside what Intune patches automatically.

That is the gap Application Manager is built to close — working with Intune, not replacing it.

Windows is covered — the rest is not

Intune keeps Windows and Store apps current. Browsers, PDF readers, runtimes and line-of-business tools sit outside that scope, and they are exactly where most attacks land.

Manual packaging does not scale

Wrapping every third-party installer as a Win32 app, then re-wrapping it on every new version, is slow, error-prone, and never quite keeps up with the release pace.

Unpatched apps are the open door

The majority of exploited vulnerabilities target common third-party software, not the OS. A single outdated browser or runtime can undo an otherwise clean patch posture.

How It Fits

Intune covers the OS. We cover everything installed on it.

Application Manager slots into your existing Intune setup and takes over exactly the part of the patch estate Intune leaves open — third-party and line-of-business applications.

  1. Managed deviceEnrolled in Intune
  2. IntuneWindows Update + Store apps
  3. The third-party gapBrowsers, runtimes, LOB apps
  4. Application ManagerThird-party apps patched automaticallyCapaOne
  5. Fully patched fleetWith audit-ready evidence

Your existing Intune setup stays exactly as it is. CapaOne simply closes the part of the patch estate Intune was never built to cover.

What You Can Do

Third-party patching, fully automated.

Everything you need to keep the apps Microsoft leaves behind current — without scripting, manual packaging, or chasing vendor releases.

Maintained app catalog

A curated catalog of common enterprise apps that stay current automatically — no chasing vendor release notes.

No manual packaging

New versions are packaged and delivered for you. No Win32 wrapping, no re-wrapping on every release.

Policy-driven updates

Define the versions you want everywhere; updates flow out on schedule without hands-on work.

Staged rollouts

Pilot a new version on a test ring before it reaches the whole fleet — minimize risk systematically.

Entra ID targeting

Reuse your existing Entra ID (Azure AD) groups to target updates — no parallel structure to maintain.

Coverage reporting

See patch status across every app and endpoint on demand — know what is current and what is not.

CVE-aware prioritization

Understand which outstanding updates close known vulnerabilities, so the riskiest gaps get fixed first.

Audit & compliance export

Export patch evidence for NIS2, ISO 27001, SOC 2 and cyber-insurance reviews in a few clicks.

Works standalone too

No Intune? Application Manager runs as a complete third-party patching solution on its own.

What Gets Patched

The apps attackers target — kept current

A maintained catalog of common enterprise software, plus your own installers. A representative selection — the full catalog is broader and updated continuously.

Browsers

Google Chrome, Mozilla Firefox, Opera, Brave

PDF & documents

Adobe Acrobat Reader, Foxit Reader, LibreOffice

Runtimes & frameworks

Java (OpenJDK), .NET runtimes, Node.js, Python

Collaboration

Zoom, Slack, Microsoft Teams, Webex

Remote access

TeamViewer, AnyDesk, Citrix Workspace

Utilities & archivers

7-Zip, Notepad++, VLC, FileZilla, PuTTY

Developer tools

Git, Visual Studio Code, PowerShell

Line-of-business apps

Your own installers, packaged and kept current

How We Compare

The honest comparison

All of these tools close the third-party patch gap for Intune-managed fleets. Here is how Application Manager stacks up on the things that matter beyond the patch job itself.

CapabilityPatch My PCScappmanIvanti NeuronsApplication Manager
Automated third-party patching
Custom / line-of-business app packagingPartial
Works without Intune (standalone)
Part of a unified endpoint platform
Built-in CVE / vulnerability insightPartial
Privilege management includedAdd-on
EU-hosted, GDPR-firstPartial
PricingPer devicePer deviceContact for pricing€1/endpoint/month
Business Case

What it means in practice

What your IT team gains when third-party patching runs itself instead of eating hours every week.

0

Installers to package by hand

The catalog is packaged and kept current for you — reclaim the hours spent wrapping and re-wrapping apps.

Fewer patch-related tickets

Apps that stay current on their own remove an entire category of support and remediation work.

100%

Third-party visibility

See patch status for every covered app across every endpoint — no blind spots outside the OS.

Audit-ready at any moment

Coverage and exception evidence is always on hand for NIS2, ISO 27001 and insurer reviews.

Why Teams Trust CapaOne

Three decades of endpoint management, built in Europe.

30+
years of endpoint experience
150,000+
endpoints managed
EU
Danish-built, EU-hosted
NIS2
GDPR-first & NIS2-aligned
Typical implementation

From decision to production in four steps

01

Connect & discover

Connect the platform and inventory the third-party apps already installed across your fleet.

02

Define your standards

Choose the approved apps and versions you want everywhere — reuse your existing Entra ID groups to target them.

03

Pilot on a test ring

Validate updates on a limited set of endpoints before promoting them to the whole estate.

04

Operationalize & prove

Let updates flow automatically, and export coverage evidence whenever an audit calls for it.

Most teams are up and running in about an hour — connect, define your standards, and updates start flowing the same day.

Security & Compliance

Close the gap attackers rely on

Third-party applications are the most common route to a compromised endpoint. Application Manager keeps them current automatically — and gives you the evidence to prove it.

  • Close the third-party patch gap attackers target most — the majority of exploited vulnerabilities live in common apps, not the OS
  • Keep browsers, PDF readers and runtimes on their latest secure versions automatically, with no manual intervention
  • Prioritize the updates that close known CVEs first, so the riskiest exposures are remediated fastest
  • Demonstrate patch compliance at audit with clear, exportable evidence across your whole fleet
  • Keep all endpoint data in the EU, under European rules — no patch or inventory data sent to U.S. jurisdiction

CVE-aware patching

See which outstanding updates close known vulnerabilities and act on the riskiest first.

Continuous coverage

Apps stay current on policy — the gap never quietly reopens between release cycles.

Audit evidence

Patch status and exception records exportable on demand for NIS2, ISO 27001 and SOC 2.

European data sovereignty

Danish-built, EU-hosted. Your endpoint data stays in Europe, under European rules.

FAQ

Frequently asked questions

Anything else? Talk to our team →

Does Application Manager replace Intune?

No — it completes it. Your Intune deployment keeps handling Windows updates, Store apps and device policy; CapaOne adds the third-party patching it leaves manual. Nothing is ripped out or replaced.

What third-party apps does it keep patched?

A maintained catalog of common enterprise software — browsers, PDF readers, runtimes such as Java and .NET, collaboration and remote-access tools, utilities, and more. You can also package your own line-of-business installers and keep them current the same way. The catalog is updated continuously as new versions ship.

Do I still have to package apps into Win32 packages myself?

No. That manual packaging and re-packaging is exactly what Application Manager removes. New versions are packaged and delivered for you, so apps stay current without anyone wrapping installers by hand.

Can I target updates using my existing Entra ID groups?

Yes. Application Manager reuses your existing Entra ID (Azure AD) groups, so you target updates with the same structure you already use in Intune — no parallel group hierarchy to build or maintain.

How do I prove patch compliance for an audit?

The platform reports patch status across every covered app and endpoint, and lets you export that evidence — including approved exceptions — on demand. That gives you the documentation NIS2, ISO 27001, SOC 2 and cyber-insurance reviews ask for, without manual record-keeping.

Does it work if we do not use Intune?

Yes. Application Manager runs standalone as a complete third-party patching and application-deployment solution. Intune is an option you can layer it onto — never a requirement.

Where is our data stored?

CapaOne is Danish-built and EU-hosted. Your endpoint, patch and inventory data is stored and processed within the EU, under European rules — no endpoint data is sent to U.S. jurisdiction.

Complete your Intune in an hour.

See Application Manager close your third-party patch gap on your own estate — working with Intune, or running entirely on its own.