Documentation

An overview of how PatchIQ connects to your Microsoft tenant and exactly what access it requests. Full step-by-step setup guides, screenshots, and troubleshooting are available inside your dashboard once you start a trial.

Getting Started

Content coming soon.

Connecting Your Microsoft Tenant

PatchIQ connects to your Microsoft 365 / Entra tenant in three independent pieces, each covering a different part of the product. You only need to set up the ones for the features you plan to use. Below is exactly what each one requests and why — useful for a security or IT review before you connect anything.

Don't have in-house IT to do this? The Defender and Autopatch connections below involve creating an app registration in your own tenant, which some smaller teams don't have the in-house experience for. PatchIQ offers paid one-on-one setup assistance — we'll do a screen-share with your admin and walk through every step live. Reach out to your PatchIQ contact to arrange it.

1. Single Sign-On (SSO) One click

Lets your team log into PatchIQ with their existing Microsoft work account. This is the simplest of the three — there is nothing to build on your side. Your admin opens a consent link tied to our multi-tenant application, PatchIQ Sign-In, reviews the permission below, and accepts it. No app registration, client ID, or secret is created on your end.

APIPermissionTypeWhy it's needed
Microsoft GraphUser.ReadDelegatedConfirms the signed-in user's identity and basic profile so PatchIQ can match them to their account.

This is a delegated, sign-in-only permission — it does not grant PatchIQ access to your mailbox, files, or any other tenant data.

2. Defender Vulnerability Export Setup required

Feeds Microsoft Defender for Endpoint's device, vulnerability, and security score data into PatchIQ's risk and Secure Score dashboards. Unlike SSO, this integration reads data directly from your tenant, so you create and own the app registration in your own Entra ID, and hand PatchIQ a client ID and secret to connect with. You remain the owner at all times and can revoke access whenever you like.

APIPermissionTypeWhy it's needed
Microsoft GraphUser.ReadDelegatedDefault permission added automatically when the app is registered.
WindowsDefenderATPMachine.Read.AllApplicationReads your organization's device (machine) inventory from Defender for Endpoint.
WindowsDefenderATPVulnerability.Read.AllApplicationPulls vulnerability findings for those devices to power PatchIQ's risk view.
WindowsDefenderATPScore.Read.AllApplicationReads your organization's Exposure Score to power PatchIQ's Secure Score dashboard.
Microsoft GraphSecurityEvents.Read.AllApplicationReads your organization's Microsoft Secure Score and control breakdown to power PatchIQ's Secure Score dashboard.
Step-by-step app registration walkthrough (with screenshots) is available in your dashboard after you start a trial, or ask your PatchIQ contact for a live screen-share.

3. Windows Autopatch & Third-Party App Patching Setup required

Powers Autopatch feature-update rings and third-party app deployment through Intune. Like Defender, you create this app registration in your own tenant and share the resulting credentials with PatchIQ — a second, separate registration from the one above. You remain the owner at all times and can revoke access whenever you like.

APIPermissionTypeWhy it's needed
Microsoft GraphDevice.Read.AllApplicationReads your enrolled device inventory.
Microsoft GraphDeviceManagementApps.ReadWrite.AllApplicationDeploys and manages third-party apps through Intune.
Microsoft GraphDeviceManagementConfiguration.ReadWrite.AllApplicationReads and writes Intune device configuration and update-ring policies.
Microsoft GraphGroupMember.Read.AllApplicationResolves the Entra security groups PatchIQ uses for Test/Last deployment rings.
Microsoft GraphUser.ReadDelegatedDefault permission added automatically when the app is registered.
Microsoft GraphWindowsUpdates.ReadWrite.AllApplicationManages Windows Autopatch feature-update deployment settings for your organization.
Step-by-step app registration walkthrough (with screenshots) is available in your dashboard after you start a trial, or ask your PatchIQ contact for a live screen-share.

Intune Enrollment Guide

Content coming soon.

Frequently Asked Questions

Content coming soon.