Summary
This article provides instructions on how to configure and patch Microsoft Visual Studio using OneSite Patch. Due to Visual Studio's default behavior, administrative intervention is required to enable Administrator-managed updates, allowing OneSite Patch to manage the update process centrally.
Prerequisites
Licensing: Each device must have the Microsoft Patch Add-on license. (Review the Target Collections for the product Microsoft Add-on for OneSite Patch. Note: This is included with our Vulnerability Management integrations and will not be a separate product. Ensure the devices with Visual Studio are members of the Target Collections).
Visual Studio Client Detector Utility: Must be installed on all target devices. While OneSite Patch does not install new software, OneSite Patch will attempt to install the detector utility once Visual Studio is added to a Strategy. See the section Detection and Deployment Process below for more information.
Administrator Updates Configuration: Visual Studio must be configured to allow updates managed by a central administrator. See the Configuration Method options below to complete this prerequisite.
Configuration Method 1: Group Policy (GPO) - Recommended
To manage this setting via GPO, you must first install the Visual Studio Administrative Templates (ADMX/ADML).
Download Templates: Grab the Visual Studio Group Policy Administrative Template files (ADMX/ADML) from the Microsoft Download Center.
Install Templates: Copy the files to
C:\Windows\PolicyDefinitionson your domain controller or management machine.-
Configure Policy:
Open the Local Group Policy Editor.
Navigate to: Computer Configuration > Administrative Templates > Visual Studio > Install and Update Settings.
Set Administrator updates to Enabled.
Configuration Method 2: Microsoft Intune
Visual Studio policies are now included in the Intune Settings Catalog, making manual template imports unnecessary for cloud-managed devices.
Create a Device Configuration Profile in Intune.
Select Settings catalog.
Search for Visual Studio and add the Administrator Updates policy.
Configuration Method 3: Registry Key
If GPO/Intune is not feasible, set the following registry key:
Path:
HKLM:\SOFTWARE\Policies\Microsoft\VisualStudio\SetupValue Name:
AdministratorUpdatesEnabledValue Type:
REG_DWORDValue Data:
1(Enables updates) or2(Enables updates and background downloads)
Detection and Deployment Process
Cycle 1: Visual Studio is detected; Client Detector Utility is installed via policy.
Cycle 2: Once the Detector Utility and Registry/GPO settings are present, OneSite Patch detects applicable patches.
Cycle 3: Patches are deployed the next time the Strategy runs.
Expect at least two scans and two Strategy cycles for a device to be fully updated.
Verify you see the patch Visual Studio Client Detector Utility in Software, Patches as Installed or Applicable on the devices with Visual Studio installed. If not installed, the utility can be downloaded from the Microsoft Update Catalog (https://catalog.update.microsoft.com) by searching for KB5001148. The Detector utility should be automatically installed if Visual Studio has applied any updates post May 12, 2020.
See also: https://learn.microsoft.com/en-us/visualstudio/liveshare/use/policies-visual-studio