-
Notifications
You must be signed in to change notification settings - Fork 3
Intune Custom Attributes
Gil Burns edited this page Sep 3, 2026
·
1 revision
Third Party Patcher ships a set of Microsoft Intune Custom Attribute scripts
for macOS that surface patch status in device inventory and reporting. They live
in the repo under
MDM Examples/Intune Custom Attributes/.
They are the Intune counterparts of the
Jamf Extension Attributes — same logic, but the
script prints the bare value (no <result> wrapper) and Date attributes are
emitted in ISO-8601, the format Intune expects.
Each script shells out to patcherreport (mostly its get
subcommand) and uses only tools present on a stock macOS install.
| Script | Attribute name | Data type | Reports |
|---|---|---|---|
tpp-last-scan.sh |
TPP - Last Scan | Date | Last full Installomator scan (UTC) |
tpp-last-apply.sh |
TPP - Last Apply | Date | Last apply / install pass (UTC) |
tpp-apps-requiring-update.sh |
TPP - Apps Requiring Update | Integer | Managed apps found out of date |
tpp-pending-updates.sh |
TPP - Pending Updates | Integer | Updates staged and awaiting apply |
tpp-oldest-pending-days.sh |
TPP - Oldest Pending Update (Days) | Integer | Age of the oldest staged update |
tpp-days-until-hard-deadline.sh |
TPP - Days Until Hard Deadline | Integer | Days before deferrals are cut off |
tpp-broken-labels.sh |
TPP - Broken Labels | Integer | Scan-broken + stage-broken labels |
tpp-deferrals-30-days.sh |
TPP - Deferrals (Last 30 Days) | Integer | Dialog deferrals in the last 30 days |
tpp-deadlines-forced.sh |
TPP - Deadlines Forced (Lifetime) | Integer | Times a hard deadline forced an install |
tpp-patching-mode.sh |
TPP - Patching Mode | String |
monthly or deadline
|
tpp-pending-update-labels.sh |
TPP - Pending Update Labels | String | Comma-separated staged label list |
tpp-patch-compliance-status.sh |
TPP - Patch Compliance Status | String | Rollup verdict |
TPP - Patch Compliance Status returns one of, in priority order:
| Value | Meaning |
|---|---|
Not Installed |
patcherreport is not present on the device |
Overdue |
A hard deadline has been reached |
Deadline Approaching |
Updates pending, hard deadline within 3 days |
Pending |
Updates staged, deadline not yet close |
Updates Detected |
Updates found but nothing staged yet |
Compliant |
Nothing outstanding |
- In the Intune admin center: Devices ▸ macOS ▸ Custom attributes ▸ Add.
- Basics — name (e.g. TPP - Pending Updates) and description.
-
Attributes — choose the Data type from the table and upload the
matching
.shfile. - Assignments — target the device groups you want.
- Save. Results appear per device under Devices ▸ <device> ▸ Custom attributes.
- Run cadence is fixed at roughly every 8 hours; it can't be shortened. Values are only as current as the last run.
- Runs as root.
-
Binary path. Scripts call
/usr/local/bin/tpp/patcherreport. For the dev build (/usr/local/bin/tpp_dev/), edit thepatcherreport=line. -
Dates. Emitted as ISO-8601 (
2026-08-29T10:31:48Z) — do not reformat. -
Empty output. When a value isn't available the script prints an empty
line; Integer scripts print
0where a zero is meaningful. -
Roll your own.
patcherreport get <dotted.key> [--from <report>]prints any scalar from the JSON payloads — see Reporting ▸ get.
Getting Started
Reference
- Command-Line Reference
- Preference Keys
- Installomator Integration
- Installomator Metadata
- Managed Labels
Patching Behavior
- Deferral and Deadlines
- Patching Walkthrough: Deadline-Based
- Patching Walkthrough: Monthly Cadence
- User Prompts
- Branding and Customization
User-Facing Tools
Reporting
Support