365 security endpoint missing KBs

%3CLINGO-SUB%20id%3D%22lingo-sub-2276154%22%20slang%3D%22en-US%22%3E365%20security%20endpoint%20missing%20KBs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2276154%22%20slang%3D%22en-US%22%3E%3CP%3EHow%20often%20does%20the%20ATP%20defender%20client%20update%20the%20KBs%20installed.%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20a%20machine%20that%20was%20patched%202%20days%20ago%20but%20it%20not%20reflecting%20on%20the%20missing%20KBs%20section%20of%20the%20device%20inventory.%26nbsp%3B%3C%2FP%3E%3CP%3ELast%20seen%20was%205%20minutes%20ago.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe're%20struggling%20to%20find%20a%20good%20way%20to%20report%20at%20both%20the%20macro%20and%20micro%20level%20on%20windows%20patch%20level%20in%20intune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ejb%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2412279%22%20slang%3D%22en-US%22%3ERe%3A%20365%20security%20endpoint%20missing%20KBs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2412279%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F606641%22%20target%3D%22_blank%22%3E%40Jason_B1025%3C%2FA%3E%26nbsp%3BIf%20you%20are%20using%20TVM%20(Threat%20%26amp%3B%20vulnerability%20Management)%20from%20defender%2C%20you%20could%20add%20the%20reported%20vulnerability%20to%20remediation%20task%20and%20you%20could%20track%20the%20progress%20from%20there.%20I%20have%20a%20video%20on%20TVM%20here%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D2ktppQHFGBY%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EMicrosoft%20Defender%20ATP%20Training%20Series%20Part%202%3A%20Threat%20%26amp%3B%20Vulnerability%20Management%20(TVM)%20-%20YouTube%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20use%20MEM%20portal%2C%20you%20could%20see%20the%20status%20via%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fwindows-update-compliance-reports%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EUse%20Update%20Compliance%20reports%20for%20Windows%20Updates%20in%20Microsoft%20Intune%20-%20Microsoft%20Intune%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2844000%22%20slang%3D%22es-ES%22%3ERe%3A%20365%20security%20endpoint%20missing%20KBs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2844000%22%20slang%3D%22es-ES%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F606641%22%20target%3D%22_blank%22%3E%40Jason_B1025%3C%2FA%3E%26nbsp%3BThe%20problem%20was%20solved%3F%20I%20have%20several%20computers%20the%20same%2C%20the%20patches%20or%20updates%20are%20already%20installed%20but%20they%20continue%20to%20report%20that%20they%20are%20missing.%20I%20don't%20know%20if%20a%20service%20has%20to%20be%20restarted%20or%20a%20firewall%20problem%2C%20but%20run%20the%20test%20detection%20and%20it%20works%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3172135%22%20slang%3D%22en-US%22%3ERe%3A%20365%20security%20endpoint%20missing%20KBs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3172135%22%20slang%3D%22en-US%22%3EHave%20the%20same%20situation.%3CBR%20%2F%3ESeveral%20devices%20have%20connectivity%20to%20WD%20ATP%20and%20installed%20updates.%20But%20there%20is%20a%20list%20of%20Missing%20KBs%20for%20almost%20an%20year%20on%20the%20portal.%3CBR%20%2F%3EWe%20have%20found%20the%20problem%20with%20WIndows%20Server%20OSes%20(Microsoft%20Monitoring%20agent%20to%20connect%20to%20WD%20ATP%20was%20not%20uninstalled%20after%20in-place%20upgrade%20and%20there%20were%20two%20different%20ways%20to%20connect%20to%20WD%20ATP)%2C%20but%20do%20not%20know%20what%20the%20root%20cause%20for%20Windows%2010%20OSes.%3C%2FLINGO-BODY%3E
Contributor

How often does the ATP defender client update the KBs installed. 

I have a machine that was patched 2 days ago but it not reflecting on the missing KBs section of the device inventory. 

Last seen was 5 minutes ago.

 

We're struggling to find a good way to report at both the macro and micro level on windows patch level in intune.

 

jb

 

 

4 Replies

@Jason_B1025 If you are using TVM (Threat & vulnerability Management) from defender, you could add the reported vulnerability to remediation task and you could track the progress from there. I have a video on TVM here Microsoft Defender ATP Training Series Part 2: Threat & Vulnerability Management (TVM) - YouTube

 

If you use MEM portal, you could see the status via Use Update Compliance reports for Windows Updates in Microsoft Intune - Microsoft Intune | Microsoft...

@Jason_B1025 The problem was solved? I have several computers the same, the patches or updates are already installed but they continue to report that they are missing. I don't know if a service has to be restarted or a firewall problem, but run the test detection and it works

Have the same situation.
Several devices have connectivity to WD ATP and installed updates. But there is a list of Missing KBs for almost an year on the portal.
We have found the problem with WIndows Server OSes (Microsoft Monitoring agent to connect to WD ATP was not uninstalled after in-place upgrade and there were two different ways to connect to WD ATP), but do not know what the root cause for Windows 10 OSes.
We started pulling data from log analytics, intune, and our asset manage solution samange to compare the OS version numbers. We haven't added the data from seucurity center yet (need to figure out how to pull that from the api) based on those 3 sources we flag machines two versions back and send tech to see why they are not patching.
So right now I haven't solved the few that were not updating in security center we are focus on getting an accurate view of our patching. Now why some Intune computers are not patching, that's another mystery to solve.
We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE