PatchPilot Documentation

A self-hosted, multi-tenant Windows patch management console for MSPs.

Get started View on GitHub


What PatchPilot is

PatchPilot bridges Microsoft Defender Vulnerability Management (MDVM) findings to actual remediation — via Winget (third-party apps) and the Windows Update Agent (OS patches) — across every GDAP-linked customer tenant an MSP manages. Instead of working tenant by tenant inside separate Microsoft consoles, an engineer gets one place to see what’s exposed across the whole fleet and act on it.

It doesn’t replace the Microsoft services a customer already pays for — it orchestrates Defender for Endpoint and Intune, using the GDAP relationship the MSP already holds with that customer, with the correct, already established permissions rather than a new standing credential of its own. There’s no agent on a customer’s devices and nothing installed on them; every finding and every fix goes through Microsoft’s own APIs.

A few things that follow from that:

  • No Azure, no SharePoint, no Power Platform, no Dataverse. The entire stack is self-hosted — Docker Compose on a VPS, MSP infrastructure, or on-prem — and you control it end to end.
  • Tokens never touch the browser. The SPA holds only a session cookie; every Microsoft Graph/Defender call happens server-side.
  • PatchPilot holds no standing credential for any customer. Every action runs with the signed-in engineer’s own delegated access, for as long as a single request takes and no longer.

Where to go next

If you want to… Go to
Stand up an instance and see it running Getting Started
Understand how it connects to a tenant and reaches a device Architecture
Check licensing, roles, and network prerequisites before you commit Requirements
See what PatchPilot can’t do yet, before you hit it in the field Known Issues
Find your way around a page you’re looking at right now Navigating PatchPilot
Keep an already-running instance healthy Server Health & Maintenance
Walk through a specific task step by step User Guide

This site covers using and operating PatchPilot as an MSP engineer or admin. For contributor-facing details (monorepo layout, running the test suite, internal design notes), see the repository README.


This site uses Just the Docs, a documentation theme for Jekyll.