Skip to content

Intune Custom Attributes

Gil Burns edited this page Sep 3, 2026 · 1 revision

Intune Custom Attributes

Third Party Patcher ships a set of Microsoft Intune Custom Attribute scripts for macOS that surface patch status in device inventory and reporting. They live in the repo under MDM Examples/Intune Custom Attributes/.

They are the Intune counterparts of the Jamf Extension Attributes — same logic, but the script prints the bare value (no <result> wrapper) and Date attributes are emitted in ISO-8601, the format Intune expects.

Each script shells out to patcherreport (mostly its get subcommand) and uses only tools present on a stock macOS install.


Available attributes

Script Attribute name Data type Reports
tpp-last-scan.sh TPP - Last Scan Date Last full Installomator scan (UTC)
tpp-last-apply.sh TPP - Last Apply Date Last apply / install pass (UTC)
tpp-apps-requiring-update.sh TPP - Apps Requiring Update Integer Managed apps found out of date
tpp-pending-updates.sh TPP - Pending Updates Integer Updates staged and awaiting apply
tpp-oldest-pending-days.sh TPP - Oldest Pending Update (Days) Integer Age of the oldest staged update
tpp-days-until-hard-deadline.sh TPP - Days Until Hard Deadline Integer Days before deferrals are cut off
tpp-broken-labels.sh TPP - Broken Labels Integer Scan-broken + stage-broken labels
tpp-deferrals-30-days.sh TPP - Deferrals (Last 30 Days) Integer Dialog deferrals in the last 30 days
tpp-deadlines-forced.sh TPP - Deadlines Forced (Lifetime) Integer Times a hard deadline forced an install
tpp-patching-mode.sh TPP - Patching Mode String monthly or deadline
tpp-pending-update-labels.sh TPP - Pending Update Labels String Comma-separated staged label list
tpp-patch-compliance-status.sh TPP - Patch Compliance Status String Rollup verdict

Compliance status values

TPP - Patch Compliance Status returns one of, in priority order:

Value Meaning
Not Installed patcherreport is not present on the device
Overdue A hard deadline has been reached
Deadline Approaching Updates pending, hard deadline within 3 days
Pending Updates staged, deadline not yet close
Updates Detected Updates found but nothing staged yet
Compliant Nothing outstanding

Adding a Custom Attribute to Intune

  1. In the Intune admin center: Devices ▸ macOS ▸ Custom attributes ▸ Add.
  2. Basics — name (e.g. TPP - Pending Updates) and description.
  3. Attributes — choose the Data type from the table and upload the matching .sh file.
  4. Assignments — target the device groups you want.
  5. Save. Results appear per device under Devices ▸ <device> ▸ Custom attributes.

Notes

  • Run cadence is fixed at roughly every 8 hours; it can't be shortened. Values are only as current as the last run.
  • Runs as root.
  • Binary path. Scripts call /usr/local/bin/tpp/patcherreport. For the dev build (/usr/local/bin/tpp_dev/), edit the patcherreport= line.
  • Dates. Emitted as ISO-8601 (2026-08-29T10:31:48Z) — do not reformat.
  • Empty output. When a value isn't available the script prints an empty line; Integer scripts print 0 where a zero is meaningful.
  • Roll your own. patcherreport get <dotted.key> [--from <report>] prints any scalar from the JSON payloads — see Reporting ▸ get.

Clone this wiki locally