Microsoft 365, Intune, identity and endpoint engineeringAdelaide, Australia
Implementation guide

Deploying applications with the Intune Enterprise App Catalog

How to pilot Enterprise Application Management, review catalogue metadata, deploy Win32 apps and establish an update lifecycle.

Enterprise Application Management provides an Enterprise App Catalog of prepared Win32 applications hosted by Microsoft. It can reduce packaging effort, but the organisation remains accountable for application approval, licence compliance, testing, deployment scope and update decisions.

Define governance before adding apps

Decide who can select catalogue apps, who validates vendor terms, who tests application behaviour and who approves production rollout. Catalogue availability is not an automatic security approval.

  • Application owner and business purpose recorded.
  • Vendor licence and terms reviewed.
  • Publisher, install command, detection logic and requirements checked.
  • WDAC/App Control impact assessed.
  • Autopilot and Enrollment Status Page impact tested.
  • Update ownership and rollback path documented.

Add a catalogue application

  1. In the Intune admin centre, go to Apps > All apps > Create.
  2. Select Enterprise App Catalog app under Windows.
  3. Search for and select the approved application.
  4. Review the pre-populated app information. Correct ownership, category, privacy and support details where required.
  5. Review the installation command, requirements and detection rules. Do not assume they match your existing packaging standards.
  6. Set dependencies and supersedence only after testing their effect on existing versions.
  7. Assign first to a small available group, then a required pilot group.

Use a ring-based pilot

RingPurposeSuggested assignment
Packaging validationInstall, uninstall, detection and conflict testingIT lab devices
Technical pilotValidate policies, WDAC, proxy and user contextEndpoint engineering
Business pilotConfirm application workflows and add-insRepresentative users
ProductionStaged broad rolloutPhased device or user groups

Create an update lifecycle

The catalogue can expose newer versions and guided update supersedence. Treat each new version as a change. Export or record the existing app properties before updating, review vendor release notes, test compatibility and maintain an emergency pause mechanism.

Minimum update record

Application: [name]
Current version: [version]
Target version: [version]
Security reason: [CVE / vendor advisory / lifecycle]
Pilot groups: [groups]
Detection validation: [result]
Rollback package: [location / owner]
Production approval: [change reference]

Protect Autopilot performance

Enterprise App Catalog apps can be used as blocking apps in Enrollment Status Page or Device Preparation profiles. Use blocking status only for applications genuinely required before the user reaches the desktop. Large or unreliable installers can extend provisioning time and increase rebuild failures.

Validate deployment

  • Install and uninstall succeed in system or user context as designed.
  • Detection remains true after reboot and application self-update.
  • Existing versions upgrade without data loss.
  • Application launches under WDAC/App Control and endpoint security controls.
  • Required network endpoints are allowed.
  • Intune reporting matches device-side logs.
Catalogue limitationA Microsoft-hosted package does not transfer software-licensing obligations to Microsoft. Your organisation remains responsible for purchasing and assigning any required vendor licence.

Microsoft references

  1. Enterprise Application Management overview
  2. Add an Enterprise App Catalog app
  3. Guided update supersedence
  4. Win32 app management

Review note: Microsoft cloud licensing, rollout dates and portal labels can change. Validate your tenant, Message Centre notices and current documentation before production implementation.