azureblog.co.uk
← cd ~/learn
// hands-on lab · beginner

Package and deploy a Win32 app with Intune

Wrap an installer with the Content Prep Tool, upload it to Intune with a detection rule that works, deploy it to a test group and read the logs when it doesn't.

time
1 hour
level
Beginner
cost
Included with Intune
You'll need
  • Intune Administrator or an app manager role
  • A Windows 10 or 11 test device enrolled in Intune
  • A test group containing that device or its user
  • An MSI or EXE installer to package (this lab uses an MSI)
0 of 8 steps done
Ticks are saved in this browser only. Checked 9 Oct 2026: confirm details in Microsoft's documentation before using in production.
  1. 01

    Get the Content Prep Tool

    Download IntuneWinAppUtil.exe from Microsoft's Microsoft-Win32-Content-Prep-Tool repository on GitHub. Make a source folder that holds only the installer and anything it needs, and an empty output folder. Everything in the source folder goes into the package, so keep it tidy.

  2. 02

    Create the .intunewin package

    shell
    IntuneWinAppUtil.exe -c C:\Packages\src\MyApp -s MyApp-x64.msi -o C:\Packages\out -q

    -c is the source folder, -s the setup file inside it, -o the output folder, and -q runs without prompts. You'll get MyApp-x64.intunewin in the output folder.

  3. 03

    Add the app in Intune

    Go to Intune admin center → Apps → Windows → Create and choose Windows app (Win32). Select the .intunewin file. Because the package contains an MSI, Intune reads the product code and fills in the install and uninstall commands for you. Check the name and publisher and add a logo so it looks right in .

  4. 04

    Check the commands

    For an MSI, the commands should look like this. Set Install behavior to System for apps that install for all users.

    shell
    msiexec /i "MyApp-x64.msi" /qn
    msiexec /x "{PRODUCT-CODE-GUID}" /qn

    For an EXE, you need the vendor's silent switch, such as /S, /silent or /quiet. Test it on a device first: if a dialog appears, the install will hang until it times out.

  5. 05

    Set requirements and detection

    Under Requirements, set the architecture and the minimum Windows version. Under Detection rules, choose Manually configure and use the MSI product code that Intune found. For an EXE, use a file rule instead, for example that C:\Program Files\MyApp\MyApp.exe exists, or a version check on that file. Detection is how Intune decides whether the install worked, so a wrong rule makes a good install show as failed.

  6. 06

    Assign to a test group

    Assign the app as Required to your test group. Leave out production users until it has installed cleanly on at least one device. You can also make it Available for enrolled devices so users can install it from Company Portal.

  7. 07

    Trigger a check-in and watch

    On the test device, open Company Portal and select Settings → Sync, or restart the Microsoft Intune Management Extension service. Then follow the logs in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs: AppWorkload.log covers downloads, installs and detection, and IntuneManagementExtension.log covers check-ins and policy.

    text
    Get-Content "C:\ProgramData\Microsoft\IntuneManagementExtension\Logs\AppWorkload.log" -Tail 50 -Wait
  8. 08

    Confirm and clean up

    In Intune, open the app and check Device install status. If it says Failed but the app is on the device, the detection rule is wrong. When you're done testing, change the test assignment to Uninstall to check the uninstall command too, then widen the assignment in rings.