Skip to content

PatchBee docs

Tracking deployed apps

Once you publish an app, PatchBee keeps an eye on it: what version is out, what the catalog has, and everything you might need to do about it.

Deployed Apps

Open Deployed Apps to see everything you have published to your Intune tenants, with the current version against the latest available in the catalog. Each app row carries its update policy (manual or automatic) and the actions below.

Change who gets an app

Select Assignments on the app's row to edit its assignments in place: add or remove Entra groups, switch between Required and Available, or adjust filters. Saving applies the change directly in Intune; there is no repackaging and no new version, so it takes effect as devices next check in.

Redeploy on the same row re-publishes the app's current version as a fresh job, useful if the app was removed in Intune or you need to rebuild it. Changing assignments alone never requires a redeploy.

Roll back a bad update

If a new version causes problems, select Roll back on the app's row to return to the previous version. PatchBee re-publishes the previous version (superseding the current one) as a job you can watch in Jobs, and affected devices move back. The button only appears when there is a previous version to return to.

Remove or uninstall an app

Two actions on the row (admins only) retire an app. Both show how many devices currently have it, so you know the impact before confirming.

  • Uninstall from devices: tells Intune to remove the app from the devices it is assigned to. The app stays in PatchBee and Intune while devices process it; the install count drops as they check in.
  • Delete: opens a dialog. Leave Also delete from Intune unchecked to just stop tracking the app in PatchBee (it stays in Intune untouched). Check it to delete the app from Intune as well, choosing all versions or current only. Deleting from Intune does not uninstall the app from devices that already have it.

Update Candidates

When a newer version appears in the catalog, PatchBee lists it under Update Candidates. For each one you can Approve (creates a packaging job for the new version, superseding the old) or Reject (dismiss it). Approving runs the same publish flow as always, pre-filled with the new version.

Example: the monthly patch pass, by hand

  1. Open Update Candidates. Chrome, Firefox and 7-Zip each show a newer version.
  2. Approve Chrome and 7-Zip; Reject the Firefox one because your team is pinned to the ESR release.
  3. Two jobs run; both apps supersede their old versions and devices update on next check-in. Total time spent: about a minute.

Doing even this much by hand gets old, which is what rings and auto-approve are for; see the next guide.

Managed vs deployed

Deployed Apps are apps PatchBee published. Apps already in your tenant from elsewhere can be brought under management too; see Migrating existing apps.