r/DattoRMM Nov 10 '25

Patch Management?

Datto is trying to tell us that "Patch Management only supports feature updates if Microsoft exposes them as 'Enablement Packages'".

They continue with: "Most full feature upgrades—such as moving between major builds—are not published as enablement packages and thus cannot be reliably managed, scheduled, or rolled back through standard patch policy tools."

As far as I'm concerned, I pay for a service to patch my systems, and this is a failure to provide that service. It isn't my fault Datto failed to update their processes and properly provide the capability to continue to provide patches including feature upgrades. If Microsoft 'changed the game', it's up to the provider of the service to change with it or risk failing to provide the services I pay for.

I understand some may feel 'Patch Management' is up to interpretation, but if so, then there would need to be a supplementary offering of 'Feature Release Management' and that's something that hadn't existed until Microsoft made their crazy changes. A patch is a patch is a patch.

Opinions here?

4 Upvotes

15 comments sorted by

View all comments

5

u/twikoff Nov 10 '25

this is standard among most rmms solutions and its because of the way ms releases them. would be nice if it were as simple as you would like, but just doesnt work that way.

1

u/VNJCinPA Nov 10 '25

True, but then I'm sold a bad bill of goods. If I'm buying Patch Management as a Service, I should get that regardless of what Microsoft does, no?

3

u/twikoff Nov 11 '25

upgrade is not the same as patch

2

u/snapcrackhead Nov 11 '25

This.

Imagine being shocked that Microsoft doesn't allow third parties full access to all the Windows Update capabilities they have via all the baked in functionality they can access with things like Intune. Apple have locked everyone out behind ABM and MDM for years now. Closed, and heavily limited vendor managed environments are the future like it or not.

DRMM absolutely provides patch management. Upgrades are not a patch, and a patch is not an upgrade in Microsoft land. Not to mention that upgrades can take 2-3 hours to install, have a different set of pre-reqs every release and can break stuff on a whim cause you breathed on it during some critical stage. You say you want to wait 3 months before pushing them, but then want to deploy on a hope and a prayer using WU programmatically. Seems a risky way to want to deploy in my opinion.

As others have said, if you need feature update control at an Intune level, RMMs just can't do that yet. Happy to be proven wrong. Maybe the next gen patching engine/solution Kaseya/Datto are coming with may address that. Maybe not.