Intune keeps Windows current.
We patch everything else.
Intune does Windows updates well. But browsers, PDF readers, runtimes and line-of-business apps sit outside its scope — and that is where most attacks land. CapaOne Application Manager closes that third-party patch gap automatically, with no manual packaging and audit-ready evidence.
Intune patches Windows. Not the apps on top of it.
Microsoft Intune keeps the operating system and Store apps up to date, and it does that job well. But the software your users actually work in all day — browsers, PDF readers, Java and .NET runtimes, collaboration tools, and your own line-of-business apps — falls outside what Intune patches automatically.
That is the gap Application Manager is built to close — working with Intune, not replacing it.
Windows is covered — the rest is not
Intune keeps Windows and Store apps current. Browsers, PDF readers, runtimes and line-of-business tools sit outside that scope, and they are exactly where most attacks land.
Manual packaging does not scale
Wrapping every third-party installer as a Win32 app, then re-wrapping it on every new version, is slow, error-prone, and never quite keeps up with the release pace.
Unpatched apps are the open door
The majority of exploited vulnerabilities target common third-party software, not the OS. A single outdated browser or runtime can undo an otherwise clean patch posture.
Intune covers the OS. We cover everything installed on it.
Application Manager slots into your existing Intune setup and takes over exactly the part of the patch estate Intune leaves open — third-party and line-of-business applications.
- Managed deviceEnrolled in Intune
- IntuneWindows Update + Store apps
- The third-party gapBrowsers, runtimes, LOB apps
- Application ManagerThird-party apps patched automaticallyCapaOne
- Fully patched fleetWith audit-ready evidence
Your existing Intune setup stays exactly as it is. CapaOne simply closes the part of the patch estate Intune was never built to cover.
Third-party patching, fully automated.
Everything you need to keep the apps Microsoft leaves behind current — without scripting, manual packaging, or chasing vendor releases.
Maintained app catalog
A curated catalog of common enterprise apps that stay current automatically — no chasing vendor release notes.
No manual packaging
New versions are packaged and delivered for you. No Win32 wrapping, no re-wrapping on every release.
Policy-driven updates
Define the versions you want everywhere; updates flow out on schedule without hands-on work.
Staged rollouts
Pilot a new version on a test ring before it reaches the whole fleet — minimize risk systematically.
Entra ID targeting
Reuse your existing Entra ID (Azure AD) groups to target updates — no parallel structure to maintain.
Coverage reporting
See patch status across every app and endpoint on demand — know what is current and what is not.
CVE-aware prioritization
Understand which outstanding updates close known vulnerabilities, so the riskiest gaps get fixed first.
Audit & compliance export
Export patch evidence for NIS2, ISO 27001, SOC 2 and cyber-insurance reviews in a few clicks.
Works standalone too
No Intune? Application Manager runs as a complete third-party patching solution on its own.
The apps attackers target — kept current
A maintained catalog of common enterprise software, plus your own installers. A representative selection — the full catalog is broader and updated continuously.
Browsers
Google Chrome, Mozilla Firefox, Opera, Brave
PDF & documents
Adobe Acrobat Reader, Foxit Reader, LibreOffice
Runtimes & frameworks
Java (OpenJDK), .NET runtimes, Node.js, Python
Collaboration
Zoom, Slack, Microsoft Teams, Webex
Remote access
TeamViewer, AnyDesk, Citrix Workspace
Utilities & archivers
7-Zip, Notepad++, VLC, FileZilla, PuTTY
Developer tools
Git, Visual Studio Code, PowerShell
Line-of-business apps
Your own installers, packaged and kept current
The honest comparison
All of these tools close the third-party patch gap for Intune-managed fleets. Here is how Application Manager stacks up on the things that matter beyond the patch job itself.
| Capability | Patch My PC | Scappman | Ivanti Neurons | Application Manager |
|---|---|---|---|---|
| Automated third-party patching | ✓ | ✓ | ✓ | ✓ |
| Custom / line-of-business app packaging | ✓ | Partial | ✓ | ✓ |
| Works without Intune (standalone) | ✗ | ✗ | ✓ | ✓ |
| Part of a unified endpoint platform | ✗ | ✗ | ✓ | ✓ |
| Built-in CVE / vulnerability insight | Partial | ✗ | ✓ | ✓ |
| Privilege management included | ✗ | ✗ | Add-on | ✓ |
| EU-hosted, GDPR-first | ✗ | Partial | ✗ | ✓ |
| Pricing | Per device | Per device | Contact for pricing | €1/endpoint/month |
What it means in practice
What your IT team gains when third-party patching runs itself instead of eating hours every week.
Installers to package by hand
The catalog is packaged and kept current for you — reclaim the hours spent wrapping and re-wrapping apps.
Fewer patch-related tickets
Apps that stay current on their own remove an entire category of support and remediation work.
Third-party visibility
See patch status for every covered app across every endpoint — no blind spots outside the OS.
Audit-ready at any moment
Coverage and exception evidence is always on hand for NIS2, ISO 27001 and insurer reviews.
Three decades of endpoint management, built in Europe.
- 30+
- years of endpoint experience
- 150,000+
- endpoints managed
- EU
- Danish-built, EU-hosted
- NIS2
- GDPR-first & NIS2-aligned
From decision to production in four steps
Connect & discover
Connect the platform and inventory the third-party apps already installed across your fleet.
Define your standards
Choose the approved apps and versions you want everywhere — reuse your existing Entra ID groups to target them.
Pilot on a test ring
Validate updates on a limited set of endpoints before promoting them to the whole estate.
Operationalize & prove
Let updates flow automatically, and export coverage evidence whenever an audit calls for it.
Most teams are up and running in about an hour — connect, define your standards, and updates start flowing the same day.
Close the gap attackers rely on
Third-party applications are the most common route to a compromised endpoint. Application Manager keeps them current automatically — and gives you the evidence to prove it.
- Close the third-party patch gap attackers target most — the majority of exploited vulnerabilities live in common apps, not the OS
- Keep browsers, PDF readers and runtimes on their latest secure versions automatically, with no manual intervention
- Prioritize the updates that close known CVEs first, so the riskiest exposures are remediated fastest
- Demonstrate patch compliance at audit with clear, exportable evidence across your whole fleet
- Keep all endpoint data in the EU, under European rules — no patch or inventory data sent to U.S. jurisdiction
CVE-aware patching
See which outstanding updates close known vulnerabilities and act on the riskiest first.
Continuous coverage
Apps stay current on policy — the gap never quietly reopens between release cycles.
Audit evidence
Patch status and exception records exportable on demand for NIS2, ISO 27001 and SOC 2.
European data sovereignty
Danish-built, EU-hosted. Your endpoint data stays in Europe, under European rules.
Does Application Manager replace Intune?
No — it completes it. Your Intune deployment keeps handling Windows updates, Store apps and device policy; CapaOne adds the third-party patching it leaves manual. Nothing is ripped out or replaced.
What third-party apps does it keep patched?
A maintained catalog of common enterprise software — browsers, PDF readers, runtimes such as Java and .NET, collaboration and remote-access tools, utilities, and more. You can also package your own line-of-business installers and keep them current the same way. The catalog is updated continuously as new versions ship.
Do I still have to package apps into Win32 packages myself?
No. That manual packaging and re-packaging is exactly what Application Manager removes. New versions are packaged and delivered for you, so apps stay current without anyone wrapping installers by hand.
Can I target updates using my existing Entra ID groups?
Yes. Application Manager reuses your existing Entra ID (Azure AD) groups, so you target updates with the same structure you already use in Intune — no parallel group hierarchy to build or maintain.
How do I prove patch compliance for an audit?
The platform reports patch status across every covered app and endpoint, and lets you export that evidence — including approved exceptions — on demand. That gives you the documentation NIS2, ISO 27001, SOC 2 and cyber-insurance reviews ask for, without manual record-keeping.
Does it work if we do not use Intune?
Yes. Application Manager runs standalone as a complete third-party patching and application-deployment solution. Intune is an option you can layer it onto — never a requirement.
Where is our data stored?
CapaOne is Danish-built and EU-hosted. Your endpoint, patch and inventory data is stored and processed within the EU, under European rules — no endpoint data is sent to U.S. jurisdiction.
Complete your Intune in an hour.
See Application Manager close your third-party patch gap on your own estate — working with Intune, or running entirely on its own.