ArchitektApx/IntuneBrew

IntuneBrew is a PowerShell-based tool that simplifies the process of uploading and managing macOS applications in Microsoft Intune. It automates the entire workflow from downloading apps to uploading them to Intune, complete with proper metadata and logos.

โ˜… 0Forks 0ShellGitHub โ†—Compare

Project website โ†—

README

๐Ÿบ IntuneBrew

IntuneBrew is a PowerShell-based tool that simplifies the process of uploading and managing macOS applications in Microsoft Intune. It automates the entire workflow from downloading apps to uploading them to Intune, complete with proper metadata and logos.

Watch the full walkthrough of the tool:

Table of Contents

๐Ÿšจ Public Preview Notice

Important

๐Ÿšง Public Preview Notice

IntuneBrew is currently in Public Preview. While it's fully functional, you might encounter some rough edges. Your feedback and contributions are crucial in making this tool better!

Thank you for being an early adopter! ๐Ÿ™

๐Ÿ”„ Latest Updates

Last checked: 2025-04-25 00:27 UTC

Application Previous Version New Version
PowerShell 7.5.0 7.5.1
Anki 25.02.1 25.02.4
Microsoft Edge 135.0.3179.85 135.0.3179.98
BoltAI 1.34.1 1.35.0
Amazon Q 1.7.3 1.8.0
Adobe Acrobat Reader 25.001.20432 25.001.20467
Adobe Acrobat Pro DC 25.001.20458 25.001.20467

โœจ Features

  • ๐Ÿš€ Automated app uploads to Microsoft Intune
  • ๐Ÿ“ฆ Supports both .dmg and .pkg files
  • ๐Ÿ”„ Automatic version checking and updates
  • ๐Ÿ–ผ๏ธ Automatic app icon integration
  • ๐Ÿ“Š Progress tracking for large file uploads
  • ๐Ÿ” Secure authentication with Microsoft Graph API
  • ๐ŸŽฏ Smart duplicate detection
  • ๐Ÿ’ซ Bulk upload support
  • ๐Ÿ” Automatic retry mechanism for failed uploads
  • ๐Ÿ”’ Secure file encryption for uploads
  • ๐Ÿ“ˆ Real-time progress monitoring

๐Ÿš€ Getting Started

Prerequisites

  • PowerShell 7.0 or higher
  • Administrator rights (script must be installed as administrator, specially if you use "Install-Script IntuneBrew -Force")
  • Microsoft.Graph.Authentication Module must be installed
  • Azure App Registration with appropriate permissions OR Manual Connection via Interactive Sign-In
  • Windows or macOS operating system

๐Ÿ“ Usage

Basic Usage

Download the script: IntuneBrew.ps1

Run the script:

.\IntuneBrew.ps1

Follow the interactive prompts to:

  1. Select which apps to upload
  2. Authenticate with Microsoft Graph
  3. Monitor the upload progress
  4. View the results in Intune

๐Ÿ“ฑ Supported Applications

Application Latest Version
1Password 8.10.72
Acorn 8.1
Adobe Acrobat Pro DC 25.001.20467
Adobe Acrobat Reader 25.001.20467
Adobe Creative Cloud 6.6.0.611
Airfoil 5.12.4
Airtable 1.6.6
Airy 3.29.2
Alacritty 0.15.1
Alfred 5.6
AltTab 7.23.0
Amadine 1.6.7
Amazon Chime 5.23.22318
Amazon Q 1.8.0
Android Studio 2024.3.1.15
Angry IP Scanner 3.9.1
Anki 25.02.4
Any.do 5.0.68
AnyDesk 9.0.1
Apidog 2.7.7
Apparency 2.2
Arc 1.91.0
Asana 2.3.0
Audacity 3.7.3
Autodesk Fusion 360 latest
AWS Corretto JDK 21.0.7.6.1
Azul Zulu Java Standard Edition Development Kit 24.0.1
Azure Data Studio 1.51.1
Badgeify 1.5.8
Bartender 5.3.5
Basecamp 3
BBEdit 15.1.4
Beeper 4.0.640
BetterDisplay 3.5.4
BetterMouse 1.6
BetterTouchTool 5.340
BetterZip 5.3.4
Beyond Compare 5.0.7.30840
Bitwarden 2025.3.1
Blender 4.4.1
blip 1.1.7
Blizzard Battle.net 1.18.10.3141
BoltAI 1.35.0
Boop 1.4.0
Boxcryptor 3.13.680
Brave 1.77.101.0
BreakTimer 1.3.2
Bruno 2.2.0
BusyCal 2025.1.1
BusyContacts 2025.1.1
Caffeine 1.5.1
calibre 8.3.0
Calmly Writer 2.0.59
Camtasia 25.0.3
Canva 1.106.0
CapCut 3.3.0.1159
ChatGPT 1.2025.105
Chrome Remote Desktop 136.0.7103.19
Cisco Jabber 20241220015538
Citrix Workspace 25.03.0.95
Claude 0.9.2
CleanMyMac 5.0.7
CLion 2025.1
Clipy 1.2.1
Cloudflare WARP 2025.2.664.0
CodeEdit 0.3.4
CodeRunner 4.4.1
Company Portal 5.2502.1
Crystalfetch 2.2.0
Cursor 0.49.5
Cyberduck 9.1.3
DaisyDisk 4.31
Dangerzone 0.9.0
Dataflare 1.9.5
DataGrip 2025.1
DataSpell 2025.1
DB Browser for SQLite 3.13.1
DbGate 6.3.3
DeepL 25.4.11926442
DevToys 2.0.8.0
DevUtils 1.17.0
Discord 0.0.343
Docker Desktop 4.40.0
Doughnut 2.0.1
Downie 4.9.14
draw.io Desktop 26.2.2
DrawBot 3.132
DriveDX 1.12.1
Dropbox 222.4.5042
DropDMG 3.6.8
Dropshare 6.2
DuckDuckGo 1.134.0
EasyFind 5.0.2
Eclipse Temurin Java Development Kit 24.0.1
Elephas 11.1086
Elgato Camera Hub 2.0.0.5750
Elgato Stream Deck 6.8.1.21263
Elgato Wave Link 2.0.6.3780
Epic Games Launcher 18.5.0
Etcher 2.1.0
Evernote 10.105.4
f.lux 42.2
Fantastical 4.0.9
Figma 125.3.6
Fission 2.8.8
Flameshot 12.1.0
Foxit PDF Editor 13.1.7
FreeCAD 1.0.0
FreeMacSoft AppCleaner 3.6.8
FSMonitor 1.2
Geany 2.0
Geekbench 6.4.0
Geekbench AI 1.3.0
Gemini 2.9.11
Ghostty 1.1.3
gifox 2.6.5+0
GIMP 3.0.2
Git Credential Manager 2.6.1
GitFinder 1.7.11
GitHub Desktop 3.4.19-d147b1a3
GitKraken 11.0.0
Godot Engine 4.4.1
Goland 2025.1
Google Ads Editor 2.9
Google Chrome 135.0.7049.115
Google Drive 107.0.3
Grammarly Desktop 1.115.0.0
Hammerspoon 1.0.0
HazeOver 1.9.4
Hidden Bar 1.9
Home Assistant 2025.3
HP Easy Admin 2.15.0
Hyper 3.4.1
Ice 0.11.12
IINA 1.3.5
iMazing 3.1.2
iMazing Profile Editor 1.9.2
Inkscape 1.4.028868
Insomnia 11.0.2
Insta360 Studio 5.6.1
IntelliJ IDEA Community Edition 2025.1
iTerm2 3.5.13
Jabra Direct 6.21.01701
Jellyfin 10.10.7
Jetbrains PyCharm Community Edition 2025.1
JetBrains Toolbox 2.6.1
Joplin 3.2.13
Jumpcut 0.84
Jumpshare 3.3.16
Karabiner Elements 15.3.0
KeePassXC 2.7.10
Keeper Password Manager 17.1.1
Keka 1.4.8
Keybase 6.5.1
KeyClu 0.30.1
kitty 0.41.1
Klokki 1.3.7
Krisp 2.57.14
Krita 5.2.9
LangGraph Studio 0.0.37
LibreOffice 25.2.2
Little Snitch 6.2.3
LM Studio 0.3.14
Logitech G HUB 2025.3.696161
Logitech Options+ 1.89.705126
LookAway 1.11.3
Maccy 2.3.0
macFUSE 4.10.1
MacTeX 2025.0308
MenuBar Stats 3.9
Micro Snitch 1.6.1
Microsoft Auto Update 4.79.25033028
Microsoft Azure Storage Explorer 1.38.0
Microsoft Edge 135.0.3179.98
Microsoft Office 16.96.25041326
Microsoft Teams 25079.2107.3576.1611
Microsoft Visual Studio Code 1.99.3
Miro 0.10.95
mitmproxy 11.1.3
MongoDB Compass 1.46.1
Mountain Duck 4.17.3
Mounty for NTFS 2.4
Mozilla Firefox 137.0.2
NetBeans IDE 25
NoMachine 8.16.1
NordVPN 8.36.1
Nota Gyazo GIF 9.8.0
Notion 4.9.1
Notion Calendar 1.130.0
Nucleo 4.1.6
OBS 31.0.3
Obsidian 1.8.10
Ollama 0.6.6
OneDrive 25.051.0317.0003
OnyX 4.6.2
OpenVPN Connect client 3.7.0
Opera 118.0.5461.60
Oracle VirtualBox 7.1.8
OrbStack 1.10.3
Parallels Desktop 20.3.0-55895
PDF Expert 3.10.14
pgAdmin4 9.2
Podman Desktop 1.18.0
Postman 11.42.4
PowerShell 7.5.1
Principle 6.38
Privileges 2.3.0
ProtonVPN 4.8.0
Rancher Desktop 1.18.2
Raycast 1.96.0
Real VNC Viewer 7.13.1
Rectangle 0.87
Remote Desktop Manager 2025.1.13.3
Remote Help 1.0.2404171
Rotato 147
RStudio 2024.12.1
Santa 2025.3
Shottr 1.8.1
Signal 7.52.0
Sketch 101.8
Slack 4.43.52
Snagit 2025.1.0
Splashtop Business 3.7.4.0
Spline 0.12.5
Spotify 1.2.61.443
Stats 2.11.41
Steam 4.0
Sublime Text 4192
Suspicious Package 4.5
Sync 2.2.48
Synology Drive 3.5.2
Tableau Desktop 2025.1.0
Tailscale 1.82.5
TeamViewer QuickSupport 15
Telegram for macOS 11.8.2
Tenable Nessus Agent 10.8.4
Termius 9.19.0
Todoist 9.13.1
Transmission 4.0.6
Transmit 5.10.8
UTM 4.6.5
Vivaldi 7.3.3635.11
VLC media player 3.0.21
VSCodium 1.99.32704
Webex Teams 45.4.0.32158
WebStorm 2025.1
WhatsApp 2.25.11.76
Windows App 11.1.4
Windsurf 1.7.0
WineHQ-stable 10.0
Wireshark 4.4.6
XMind 25.01.01061-202501070704
Yubikey Manager 1.2.5
Zed 0.183.10
Zen Browser 1.11.5b
Zoom 6.4.6.53970

Note

Missing an app? Feel free to request additional app support by creating an issue!

๐Ÿ”ง Configuration

First decide which authentication method you would like to use. There are currently the following methods implemented:

  • System Managed Identity
  • User Managed Identity
  • ClientSecret & ClientID using App Registration
  • Certificate based authentication

Using System Managed Identity

  1. Open your Automation Account and select Account Settings -> Identity.
  2. Turn Status on tab "System assigned" to "On".
  3. Add the following API permissions to your System Managed Identity using this PowerShell script: Microsoft Tech Community
    • DeviceManagementApps.ReadWrite.All
  4. Open Entra admin center -> Applications -> Enterprise Applications. Change Filter "Application type" to "Managed Identities" and search for your Automation Account name. Open the entity.
  5. Verify that the right permissions are set to the Managed Identity in the Security -> Permissions tab.
  6. Create a new Variable in your Automation Account with the name "AuthenticationMethod" and value "SystemManagedIdentity" to use the System Managed Identity.

Using User Assigned Managed Identity

  1. Open Azure Portal and search for "Managed Identities".
  2. Click "Create" and select your Azure Subscription & Resource group. Choose your region and set a name for the identity.
  3. Open your Automation Account and select Account Settings -> Identity.
  4. Switch to tab "User assigned" and click "Add". Choose the previously created Managed Identity.
  5. Add the following API permissions to your System Managed Identity using this PowerShell script: Microsoft Tech Community
    • DeviceManagementApps.ReadWrite.All
  6. Open Entra admin center -> Applications -> Enterprise Applications. Change Filter "Application type" to "Managed Identities" and search for your Automation Account name. Open the entity.
  7. Verify that the right permissions are set to the Managed Identity in the Security -> Permissions tab.
  8. Create a new Variable in your Automation Account with the name "AuthenticationMethod" and value "UserAssignedManagedIdentity" to use the User Assigned Managed Identity.

Using ClientSecret from Entra ID App Registration

  1. Create a new App Registration in Azure
  2. Add the following API permissions:
    • DeviceManagementApps.ReadWrite.All
  3. Update the parameters in the script with your Azure details.
    • $appid = '' # App ID of the App Registration
    • $tenantid = '' # Tenant ID of your EntraID
    • $certThumbprint = '' # Thumbprint of the certificate associated with the App Registration

Certificate-Based Authentication

  1. Generate a self-signed certificate:
$cert = New-SelfSignedCertificate -Subject "CN=IntuneBrew" -CertStoreLocation "Cert:\CurrentUser\My" -KeyExportPolicy Exportable -KeySpec Signature -KeyLength 2048 -KeyAlgorithm RSA -HashAlgorithm SHA256 -NotAfter (Get-Date).AddYears(2)
  1. Export the certificate:
$pwd = ConvertTo-SecureString -String "YourPassword" -Force -AsPlainText
Export-PfxCertificate -Cert $cert -FilePath "IntuneBrew.pfx" -Password $pwd
  1. Upload to Azure App Registration:
    • Go to your App Registration in Azure Portal
    • Navigate to "Certificates & secrets"
    • Upload the public key portion of your certificate

App JSON Structure

Apps are defined in JSON files with the following structure:

{
  "name": "Application Name",
  "description": "Application Description",
  "version": "1.0.0",
  "url": "https://download.url/app.dmg",
  "bundleId": "com.example.app",
  "homepage": "https://app.homepage.com",
  "fileName": "app.dmg"
}

๐Ÿ”„ Version Management

IntuneBrew implements sophisticated version comparison logic:

  • Handles various version formats (semantic versioning, build numbers)
  • Supports complex version strings (e.g., "1.2.3,45678")
  • Manages version-specific updates and rollbacks
  • Provides clear version difference visualization

Version comparison rules:

  1. Main version numbers are compared first (1.2.3 vs 1.2.4)
  2. Build numbers are compared if main versions match
  3. Special handling for complex version strings with build identifiers

๐Ÿ› ๏ธ Error Handling

IntuneBrew includes robust error handling mechanisms:

  1. Upload Retry Logic

    • Automatic retry for failed uploads (up to 3 attempts)
    • Exponential backoff between retries
    • New SAS token generation for expired URLs
  2. File Processing

    • Temporary file cleanup
    • Handle locked files
    • Memory management for large files
  3. Network Issues

    • Connection timeout handling
    • Bandwidth throttling
    • Resume interrupted uploads
  4. Authentication

    • Token refresh handling
    • Certificate expiration checks
    • Fallback to interactive login

๐Ÿค” Troubleshooting

Common Issues

  1. File Access Errors

    • Ensure no other process is using the file
    • Try deleting temporary files manually
    • Restart the script
  2. Upload Failures

    • Check your internet connection
    • Verify Azure AD permissions
    • Ensure file sizes don't exceed Intune limits
  3. Authentication Issues

    • Verify your Azure AD credentials
    • Check tenant ID configuration
    • Ensure required permissions are granted

๐Ÿค Contributing

Contributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.

  1. Fork the Project
  2. Create your Feature Branch (git checkout -b feature/AmazingFeature)
  3. Commit your Changes (git commit -m 'Add some AmazingFeature')
  4. Push to the Branch (git push origin feature/AmazingFeature)
  5. Open a Pull Request

๐Ÿ“œ License

This project is licensed under the MIT License - see the LICENSE file for details.

๐Ÿ™ Acknowledgments

  • Thanks to all contributors who have helped shape IntuneBrew
  • Microsoft Graph API documentation and community
  • The PowerShell community for their invaluable resources

๐Ÿ“ž Support

If you encounter any issues or have questions:

  1. Check the Issues page
  2. Review the troubleshooting guide
  3. Open a new issue if needed

Made with โค๏ธ by Ugur Koc

Contributors

ugurkocdeactions-userlucanoahcaprezebob9Appelcloudniklasrst

Issues