Event details
Join the Intune engineering team for an interactive session on streamlining app management with Microsoft Intune. We’ll talk about current investments and what we're exploring next—then open the floor to your feedback. Tell us what’s working, what’s missing, and what would make app deployment and management even easier for your organization. Your real‑world scenarios and needs directly shape how we prioritize and design upcoming capabilities. Come help us build the next chapter of Enterprise App Management.
Speakers: Nicole Zhao, David Guyer, & Heena Macwan
Moderator: Joe Lurie
This session is part of the Microsoft Technical Takeoff: Windows + Intune. Add it to your calendar, click Attend for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event.
89 Comments
- BillGallopCopper Contributor
Kind of a wishlist for future features, to make provisioning a replacement device friendlier for the user.
With Windows Backup when a user sets up a new PC they are asked if they want to restore data (configs, settings etc.)
It would be nice if they were also asked if they want to install any self-service apps that they have previously installed from Company Portal.
Obviously everything that is flagged as Required will be installed, but I am talking about those that are Available which they have previously downloaded. Maybe give them checkboxes so that they can select which ones they want or don't want.
These don't have to necessarily install during ESP but if a progress dialog is automatically shown to the user so that they can see what is happening that would be nice. Actually that would be great for the Required apps as it would stop users from calling the help desk when things that aren't blockers in ESP haven't installed yet. Yes they can check Downloads in Company Portal but which users ever actually do that? Needs to be something nice and obvious along the lines of "We aren't quite finished yet but you can get on with your day while we do this in the background"
Don't offer to install Available items which have been superseded, and allow admins to mark apps as not being appropriate to offer to install, e.g. a script which gathers data and sends to the help desk and which is packaged as a script to make the user able to run it without admin creds.
- Jason_Sandys
Microsoft
Hi BillGallop, Do you have access to our internal development information? I ask because this almost exact feature is in development. No guarantees or commitments and nothing to more to share other than great suggestion, we're on it 😀 and thank you.
- Joe_FriedelBrass Contributor
Something I do quite a bit in Config Manager that isn't doable in Intune:
For many apps that are deployed as available to devices, I have an app that is the current version and an app that is superseded by the current version and the detection methods for these use the application's exe and version number. The current version app will have the current version string with greater than or equal and the superseded app will have the current version string with less than.
This allows for apps to be deployed as available to all devices and will install the superseding version over any older version regardless of how the old version was installed. This is helpful for devices migrated to Intune management or for users with admin rights or if users are allowed to install apps with EPM. When we want to deploy a new version, all I have to do is update the content and possibly install string for the current version app and the detection method in both apps with the new version string. This does not work in Intune because supersedence is only applicable if the previous app was installed via Intune and is still deployed. This is much worse than the supersedence behavior in Config Manager where I only need the current app deployed and the detection methods handle everything during an app deployment evaluation cycle.- David_Guyer
Microsoft
Joe_Friedel , thank you for this feedback. With available apps or user installed apps that need supersedence, this is an issue that we are looking in to.
For apps that do in-place upgrades, or if you can use Enterprise App Catalog or WinGet apps, these issues will often be taken care of for you.
That said, we do need to look into improving this for the many apps that don't make this easy!
-David Guyer - Intune Product Manager
- Pearl-Angeles
Community Manager
Thank you everyone for your valuable feedback! Below are the topics addressed during the live session, along with associated timestamps. As noted, comments will be open for your continued feedback through Friday at 12p PT.
Feedback/question – Is there a plan to provide more visibility to the supersedence portion of app deployment? For example, I have an app that I deployed an update to that supersedes an existing deployment. If I deploy an app that supersedes both the update an the original deployment, then weeks later go back and delete the original deployment, I have to find the app that is preventing the deletion because of the supersedence relationship. In SCCM, I can at least see the offending app. In Intune, I'm not able to other than that there's a supersedence rule applied. – answered at 3:06.
Feedback/question – Also, what about dependencies? You can see down the chain but not up. As I'm modifying an app, it'd be good to know which other apps depend on it. – answered at 5:07.
Feedback/question –What about adding the running process check like in ConfigMgr, before upgrading or superseding an application. If the native app is running, alert user first. – answered at 5:22.
Feedback/question – Will there ever be a way to create a dynamic group of devices that have a particular program installed in Intune? I have this set up in Config Manager and this helps with program deployment. – answered at 8:18.
Feedback/question – Most of our applications are migrated to Intune from ConfigMgr. However, we have some rather large packages, like AutoDesk applications (some take up to 25-30GB), that we prefer to push via ConfigMgr, since it is typically much faster than going from the internet. --- Similar feedback from Sinan -- We deploy big CAD software (100+ GB) via SCCM. How to do that with Intune? – answered at 11:05.
Feedback/question – The inclusion of a bespoke "Microsoft 365 Apps" app type is useful and simplifies the deployment of the M365 apps to endpoints. However, the process of adding an individual app to a pre-existing install is not smooth; for example, where the company base profile excludes Microsoft Access but some users later require Access, it's tricky to add it when the suite is already installed, largely because most users have at least one of the M365 apps open at all times, which blocks config changes. It's also infeasible to have users self-service via Company Portal since the apps are all delivered as a single bundle. This adds to the request for adding support for running process handling natively in Intune. – answered at 17:27.
Feedback/question – Can you work on integrating app discovery with App Control for Business. My concern is that our endpoints already have a large number of apps installed through previous deployment processes, and so even with "managed installer" allowed, that does not cover previously deployed apps which then get blocked. The whole app control for business side of intune would be much easier to deploy if that team was totally looped in with the teams building app deployment, app inventory, and app updates for Intune. – answered at 22:02. - jbennettCopper Contributor
The "sync" button for devices in the Intune Admin Center and for users in Company Portal feels like it should review app assignments and platform scripts, but it doesn't. These are only evaluated based on a poller timer in the IME, every 1 hour for apps and every 8 hours for platform and remediation scripts.
Having the IME be responsive to the Sync action would more accurately align with what administrators and end users expect to happen when they press the Sync button. Are there plans to work towards this?
- David_Guyer
Microsoft
jbennett , I don't know if we'll specifically solve this by using the Sync button that is primarily around an MDE device checkin, but we do want to either make all app deployments much more predictable and faster so that kind of button isn't needed, or for troubleshooting cases enable an "install now" type action. I don't have any timelines for that, but your feedback helps us prioritize and ensure we have the right sceanrios in mind. Thank you.
-David Guyer - Intune Product Manager
- egoodmanBrass Contributor
Hi guys,
Having to prepare app packages using the Content Prep tool is less than ideal. Are there any plans to allow uploading of files/folders directly to Intune for Win32 apps? Or to use the native ZIP format?
While using the intunewin format is tolerable when building a new app, it's also challenging for existing apps when we may want to change only a single file within the payload. With the current situation we have to re-wrap the entire contents and upload the entire updated file. For some apps, all we need to update is the license file or configuration files and not the entire "bundle". Combining this with my first request to remove the dependency on the intunewin format - it'd be awesome if there was some kind of "package explorer" in the UX where we could see the files/folders in use for this package and edit/remove/update them one at a time.
And while I'm at it! :) For files that are text-based files (bat, ps1, lic, txt, csv, etc) it'd be SO great if those files could be edited in-place using a lightweight text-editor of some sort. (Same for Intune Remediations & Scripts)
Thank you!!
- David_Guyer
Microsoft
egoodman ,
I agree. It'll take some time to explore how we can make Win32 apps more cloud friendly and streamlined, but it is something we are looking at how to we can improve. Thank you for your feedback!
-David Guyer - Intune Product Manager
- Heather_Poulsen
Community Manager
Keep the feedback coming. Your thoughts on the following topics are greatly appreciated!
ConfigMgr to Intune:
- What are the hardest app-related blockers preventing you from going cloud first?
- What workloads do you see as incomplete or missing in intune?
App creation & operational simplicity
- How much time do you spend on getting an app ready to deploy
- What would 'cloud-native' app management actually mean to you in day-to-day work?
App inventory
- What do you want to do with app inventory that you can't do today and why?
- If you could use application inventory to target policy and actions, what fields would you need?
Keeping apps up to date and secure
- What is your current update flow?
- What slows you down from deploying updates quickly?
- Which apps would you want to "set and forget"
Security & trust
- How do you decide which apps are "trusted" today?
AI readiness
- Where do you see AI helping in app workflows today?
- What data do you trust or not trust?
- lalanc01Iron Contributor
Are you working on something kinda like Asset Intelligence so that there's a way to merge multiple software minor versions and metadata errors from vendors to help in the inventory?
- David_Guyer
Microsoft
lalanc01, yes, that is exactly something I am looking at for app inventory, so you don't have pages and pages of the same app, just variations in names and versions expanding the list. Glad you'll find something like that useful. Now, I can't promise we'll get it perfect... I think there will be cases where the same app will have a few rows or records, but that should be down significantly from today's experience! I hope that will make your lives much easier!
-David Guyer - Intune Product Manager- lalanc01Iron Contributor
David_Guyer glad to know it's in the roadmap. To reduce some of the complexity, having a way to create our own tags, like in sccm would be great, because yes it's hard to reduce all those differences into one.
We use Category/Family and the 3 labels from Asset intelligence to do that.
- treestryderSteel Contributor
I thought we solved these application installation/licensing/update/uninstall problems via the original Microsoft Store. 😏
#ShouldBeUWP #ShouldBeMSIX #CouldBeAPPX
- Jason_Sandys
Microsoft
Hi treestryder, On a technical level, I agree. However, ISVs and app vendors unfortunately did not embrace this paradigm and the changes required in their apps to embrace it and we did not force this. We have many running internal conversations on this topic and are open to suggestions.
- shin0933Brass Contributor
I think having a strong incentivization program for UWP apps would help the adoption, provided the stakeholders can see that UWP is more secure and convenient than the traditional .exe and .msi.
To give a specific example, Dell's Command Update program has a UWP deployment, but it has not been meeting our organizations operational goals. Since Dell continues to release and support both .exe and .msi methods, our org has continued to use their .exe deployment method.
If Microsoft were to strongly incentivize Dell to utilize UWP, I'm sure that would allow Dell to dedicate resources to stabilizing their UWP deployment.
- lalanc01Iron Contributor
Is there any plans to have metering added to Intune so we can track license usages and save money by removing non-used licenses?
- Jason_Sandys
Microsoft
Hi lalanc01. This is something we are investigation and understand the ask in general. There's nothing to share about this at this time though. If you have specific thoughts on what you'd like to see, please add them here to ensure the team has visibility.
- lalanc01Iron Contributor
We just want to be able to know when was the last time specific software, based on the executable's metadata was run.
No need to know how long it ran or how many sessions
- aglassbergCopper Contributor
Time matters because some deployments are required to install, be repaired, or updated quickly during small windows (in-between courses, presentations, etc.)
- Per-Larsen
Microsoft
Is their a questrion here?
- BryanDamIron Contributor
[No, it's a response to a question Joe asked in the livestream]