Microsoft is retiring SMS and voice MFA. Passkeys become the default on 1 September 2026; SMS and voice switch off on 1 February 2027. Book your free health check
IT Next Door
← All insights
Operations · 4 min read

Intune vs NinjaOne: which patches what, and why we use both

Windows updates and third-party application updates are different problems. The second one is how most estates get breached.

Clients sometimes ask why we run two platforms across their devices. It looks like duplication. It is not — they cover different halves of the same problem, and the half people forget is the more dangerous one.

Intune: the operating system

For clients with Business Premium or an Enterprise plan, Intune handles Windows quality and feature updates through update rings: pilot group first, broader deployment after a deferral period, deadlines enforced so a machine cannot sit unpatched because someone keeps clicking postpone. It also carries the compliance policy and the hardening baseline, so a device that falls behind can be blocked from company data by Conditional Access.

NinjaOne: everything else

Operating system patching is only part of the exposure. The browsers, PDF readers, Java and .NET runtimes, remote access tools, compression utilities and line-of-business applications sitting on the same machine are patched by nobody unless someone makes it their job. These are a very common initial access route, precisely because they are ignored.

NinjaOne handles third-party and non-Windows patching on a defined schedule, and reports compliance per device. It also does the rest of the day-to-day: monitoring disk health and service failures, remote access, scripted remediation, IT asset management and vulnerability management across the estate.

When NinjaOne does both

Clients on Business Basic or Standard have no Intune entitlement. For them, NinjaOne covers operating system patching as well as third-party. It is a workable arrangement and we run it for a number of clients — what it cannot replicate is the Conditional Access link, where a non-compliant device is denied access to company data rather than merely reported as non-compliant.

What good looks like

  • A patch compliance figure you can see per device, not a general assurance that patching happens.
  • A defined maintenance window, so updates do not reboot a machine during a client presentation.
  • Third-party applications on the same schedule and the same report as the operating system.
  • Vulnerability findings feeding back into the patch pipeline, so a scan result produces an action rather than a PDF.

The test is simple. Ask your provider what percentage of your devices are fully patched today, across both operating system and applications. If the answer takes more than a minute to produce, the reporting is not there.

Ask us about your setup More insights →