PATCH MY PC ALTERNATIVE

Attestree vs Patch My PC

Patch My PC is a commercial third-party application catalog that packages and publishes applications and updates into your existing ConfigMgr, Intune or WSUS infrastructure. It is not a package repository — it uses your existing management infrastructure as the delivery channel. Its catalog covers several thousand applications, and it is widely deployed.

Verified against vendor documentation, September 2026

WHERE IT WINS

When Patch My PC is the better answer.

This is the most capable product on this list at the job it does, and two of its features are genuinely ahead of where a lot of tooling sits. Patch My PC Cloud has real Update Rings — up to ten per deployment, with delayed and immediate ring types — which is more staged-rollout capability than Intune offers natively. And it explicitly supports user-based installs for ConfigMgr and Intune apps, which is more than most of this category. Its published catalog security process is also unusually transparent: vendor-mirror sourcing, hash verification against the vendor digest, multi-engine VirusTotal scanning, and code-signing of its own catalog file with a hardware-based certificate.

THE DIFFERENCE

Where the two part company.

The difference is the nature of the evidence rather than the diligence. Patch My PC verifies that the bytes match the digest the vendor published and that no antivirus engine objects — integrity of transfer plus reputation. Neither answers what the installer does when it runs, and neither is a bill of materials. Attestree detonates the installer in a sandbox, records the observed behaviour, generates a CycloneDX SBOM, and signs a verdict you can hand to an auditor. There is also a scope difference: Patch My PC curates a vendor catalog, so your coverage is what they package, whereas an ingest gate applies to anything you choose to admit.

CAPABILITY BY CAPABILITY

Only what we could verify.

Internal package source
Attestree — Patch My PC publishes into ConfigMgr/Intune/WSUS
Deploys to endpoints
Both
Deployment rings
Both — Patch My PC Cloud Update Rings (Intune), Attestree canary/pilot/broad/all
Per-user installs
Both — Patch My PC for ConfigMgr and Intune apps, not WSUS
Hash verification against vendor digest
Both
Multi-engine AV scanning
Patch My PC via VirusTotal. Attestree: not the mechanism we rely on
Sandbox behavioural detonation
Attestree only
CycloneDX SBOM per package
Attestree only
Signed attestation over the package
Attestree — Patch My PC code-signs its own catalog file
WHAT WE COULD NOT VERIFY

We did not find Patch My PC pricing from a primary source and will not repeat a figure we cannot cite. One correction to an earlier version of this page: we previously implied phased rollout was a Cloud-only capability. The on-premises Publisher documentation does describe phased deployments — building rings by staggering Intune assignment deadlines, for example three, ten and seventeen days. It is presented as illustrative configuration guidance rather than an orchestration feature, and stopping a bad rollout is explicitly a manual action, but it exists and we were wrong to leave that unsaid.

Capabilities are taken from each vendor’s own documentation, and we say “not documented” rather than “not supported” where a vendor is simply silent. If something here is wrong or has changed, tell us and we will correct it — that is a cheaper outcome for everyone than an inaccurate comparison.

Check the claim yourself.

The detonation, the SBOM and the signed attestation all run in the free Community Edition, on your own hardware, for up to 50 endpoints.