Hello,
So we are having a bit of a struggle here, since the begining I've never wanted to use the Patch Management feature because there was only a defined set of apps usable, and thus you had to have apps in here, and the unsuported ones in the policy section. I didn't like that so I went for a full policy updating workflow.
It actually works pretty well, I even created some scripts so you can easy add any type of pckage you want and you just have to tweak thhe paramters to control the installation process, very handy.
But the problem we have is that it seems impossible to filter computers in smart group by "less than" for a software version. It's a nightmare, so we've been updating as soon as possible the precise version in these groups and update de package as sson as possible. But if for some reason an update gets released and we don't react fast enough some computers might auto update some stuff, and then jamf would then downgrade the app, cause it doesnt match our policy.....
And this is precisely why patch management should be used you might say, and yeah you're right, they're made for that reason. But something is still triggering me about that feature: you can't use a script. if you want any kind of custom interaction with the end user, you can't. I wish they could defer the update process, and then it tries later. Here you can only warn the user with only a notification, not even a pop up window (so for our idiots in here, this will be litteraly unnoticable). And at the end of the timer the update triggers. Theres no choice for the user.
And i really don't want to script the installation process and dialog with the user in a pre install script that we would have to compose each and everytime we have to push a package.
Is this really that stupid, or am I missing something ?