Patch, secure, and deploy — all from the Microsoft Intune you already trust

PatchIQ gives IT teams real-time visibility into patch compliance, vulnerability exposure, and third-party app deployment across every Intune-managed device — no new agents, no new infrastructure.

Start Free Trial Request a Demo

Built for IT teams managing Windows devices through Microsoft Intune.

Everything you need to stay on top of your fleet

One dashboard for patching, vulnerabilities, and application deployment — built directly on top of the Microsoft Graph API.

Device Inventory & Compliance

See every Intune-managed device in one place, with real-time patch and compliance status.

Vulnerability Visibility

Understand exactly which CVEs affect your fleet, prioritized by severity, with the ability to formally accept risk when appropriate.

Feature Update Management

Track and manage Windows feature update (Autopatch) deployments across your organization.

Third-Party App Deployment

Deploy and monitor third-party applications directly through Intune, alongside Microsoft's own updates.

Accepted Risk Tracking

Formally document and track accepted risks, so nothing falls through the cracks during an audit.

No Agents, No New Infrastructure

PatchIQ connects directly to your existing Microsoft tenant via the Graph API. Nothing new to deploy on your endpoints.

Secure Score & Exposure Score

See Microsoft's own security scorecards for your tenant, side by side — Defender's Exposure Score and Microsoft Secure Score, tracked over time with clear next steps to improve.

See it in action

Exposure Score and Secure Score, together in one view.

24 / 100

Exposure Score

Lower is better

82 / 100

Secure Score

Higher is better

Illustrative example — your organization's real scores populate automatically once connected.

Up and running in three steps

No agents to deploy, no lengthy rollout — PatchIQ works with the Intune environment you've already built.

1

Connect your tenant

Authorize PatchIQ to access your Microsoft tenant through a standard Graph API consent — you control exactly what's shared.

2

We sync automatically

Device inventory, patch status, and vulnerability data sync in automatically — no manual imports.

3

Manage from one dashboard

Review compliance, prioritize vulnerabilities, and manage deployments — all from a single view.

Modern security, included — not upsold

Every plan includes enterprise-grade sign-in security at no extra cost. Every attempt is logged too, reviewable from your own account.

Single Sign-On

Sign in with the Microsoft account your team already uses — no separate password to manage.

Multi-Factor Authentication

Authenticator app support (e.g. Microsoft Authenticator) included on every plan, with backup codes.

Passkey Support

Sign in with Windows Hello, Touch ID, or your password manager instead of typing a code.

Simple, transparent pricing

No sales calls required to find out what you'll pay. Priced per managed device, billed monthly.

Up to 99 devices

$4/device/mo

100–199 devices

$3/device/mo

200–300 devices

$2/device/mo

300+ devices

Contact us

$149/month minimum per organization

Included in every plan

  • Single Sign-On (Microsoft)
  • Multi-Factor Authentication
  • Passkey support
  • Unified vulnerability & patch visibility
  • Third-party app patching through Intune
  • Compliance PDF exports
  • Full login audit trail

Every plan starts with a free 14-day trial — no credit card required.

Ready to see your fleet's patch status?

Tell us a bit about your organization and we'll set you up personally — whether that's a live demo, a trial, or getting started right away.

Every plan starts with a free 14-day trial — no credit card required.