Yes, you can allow Windows enrollment without authentication by setting the enrollment mode to No Authentication(also known as Open Enrollment). This lets users enroll devices just by entering the server URL, and the devices will automatically be assigned to a default user that you configure. You can set this up under Enroll > Settings in the Hexnode UEM portal by changing the authentication mode and selecting the default user.
Regarding your second question, third-party application patching is supported for Windows devices. You can manage updates for apps like browsers and other commonly used tools through policies. To configure this, go to the Policies tab, select a Windows policy, and under Patches and Updates, choose App Updates. From there, you can define how and when updates should be applied based on your requirements.