Line-of-business installers, vendor MSIs with transforms, and anything that needs a wrapper script all go through the Win32 app model in Intune. It is more work than the Microsoft Store integration but gives you full control over install commands, requirements, detection and dependencies. This tutorial walks through the full loop on Windows 10 and Windows 11 devices, from packaging on an admin workstation to confirming the install in the Intune Management Extension (IME) log.
Table of Contents
Short answer: Download the Microsoft Win32 Content Prep Tool (IntuneWinAppUtil.exe), run it against the folder containing your installer to produce a .intunewin file, upload that in Intune » Apps » Windows » Add » Windows app (Win32), supply silent install and uninstall commands, and define a detection rule (MSI product code, file version or registry value) that is true only after a successful install. Assign to a device or user group and check C:\ProgramData\Microsoft\IntuneManagementExtension\Logs\IntuneManagementExtension.log on a client to verify.
Package the installer
Put the installer and any supporting files (transforms, config, wrapper script) in a clean folder. Then run the prep tool from a command prompt:
IntuneWinAppUtil.exe -c C:\Packages\7zip\src -s 7z2408-x64.msi -o C:\Packages\7zip\out -q
-c is the source folder, -s the setup file, -o the output folder and -q quiet mode. The result is an encrypted, compressed .intunewin file named after the setup file. Everything in the source folder is included, so keep it lean; a folder with stray ISO files becomes a very large upload.
For installers that need a script, write a PowerShell wrapper and package that as the setup file:
IntuneWinAppUtil.exe -c C:\Packages\App\src -s Install-App.ps1 -o C:\Packages\App\out -q
Choose install and uninstall commands
Typical commands, all running as SYSTEM unless you set the install behaviour to User:
msiexec /i "7z2408-x64.msi" /qn /norestart
msiexec /x "{23170F69-40C1-2702-2408-000001000000}" /qn /norestart
setup.exe /S
powershell.exe -ExecutionPolicy Bypass -File Install-App.ps1
Set “Device restart behaviour” to “Determine behaviour based on return codes” and keep the default return code map (0 and 1707 success, 3010 soft reboot, 1641 hard reboot, 1618 retry). Add vendor-specific codes if the installer returns something else on success.
Write detection rules that work
Detection runs after install and again at every check-in. A rule that is too loose reports success on machines that never installed; too strict, and Intune reinstalls forever. Options:
- MSI product code: the most reliable for MSI installs. Intune reads the code from the package automatically.
- File: path plus file name, with “String (version)” and an operator such as greater than or equal to a version number. Use
%ProgramFiles%variables and tick the 64-bit box when the path is under Program Files rather than Program Files (x86). - Registry: key path, value name, and a version or string comparison. Good for uninstall keys under
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\<GUID>with DisplayVersion. - Custom script: a PowerShell script that writes to STDOUT and exits 0 when detected. Output anything on success; output nothing or exit non-zero when not installed.
A minimal custom detection script:
$path = "C:\Program Files\Vendor\App\app.exe"
if (Test-Path $path -and (Get-Item $path).VersionInfo.FileVersion -ge "5.2.0") { Write-Output "Installed"; exit 0 }
exit 1
Requirements, dependencies and supersedence
Requirement rules stop the install starting on the wrong machines: set the OS architecture and minimum Windows build (for example 10.0.26100 for Windows 11 24H2 and later). Dependencies let you chain a runtime (a .NET or VC++ redistributable) before the main app. Supersedence replaces an older version and can uninstall it first, which is how you handle upgrades that the vendor’s installer will not do in place.
Assign and verify
Assign as Required to a device group for baseline software, or Available for enterprise apps in Company Portal. On a test client, force a sync from Settings » Accounts » Access work or school » Info » Sync, or restart the IME service:
Restart-Service IntuneManagementExtension
Get-Content "C:\ProgramData\Microsoft\IntuneManagementExtension\Logs\IntuneManagementExtension.log" -Tail 200 | Select-String "7z2408"
Look for the download, the “Installer exit code” line, and the detection result. The app status in Intune » Apps » Monitor » Device install status updates within an hour.
Common pitfall
The most common failure is a detection rule pointing at the 32-bit registry or file view for a 64-bit app. Intune’s detection runs in a 32-bit context unless you tick “Associated with a 32-bit app on 64-bit clients” correctly, so HKLM\SOFTWARE\WOW6432Node paths and Program Files (x86) confusion account for most “installed but reported as failed” cases. Reinstall loops usually mean the detection rule references a version string with a different format from what the installer writes.
Intune Win32 app deployment at a glance

Official documentation: Microsoft Intune documentation, Windows Server documentation.
Related guides: Fix Windows Autopilot enrollment errors 80180003 and 80180014 · Bulk-enroll Windows 11 devices into Intune with a provisioning package · Fix AD replication errors 8453 and 1722 “The RPC server is unavailable”.
Frequently asked questions
Does the .intunewin file need to be rebuilt after changing the install command?
No. The install and uninstall commands live in the Intune app record, not in the package, so you can edit them in the portal. Rebuild only when the installer, script or supporting files change.
How long does a Win32 app take to reach a device after assignment?
The IME checks in roughly every hour and at sign-in, so most devices receive a Required app within an hour of assignment. A manual sync from the device or Intune portal shortens that to a few minutes.
Can I uninstall a Win32 app deployed by Intune?
Yes. Change the assignment to Uninstall for the group, or use the uninstall command manually on the device; once the detection rule no longer matches, Intune reports the app as not installed and stops managing it.