Intune: Reliable Win32 app detection with a registry marker

Intune


A Win32 app that installs successfully but then shows failed in Intune is almost always a detection problem, not an install problem. The usual trigger is a detection rule tied to something the app changes on its own — a file version that self-updates, or an uninstall key whose GUID changes between builds.

The pattern

Have your install wrapper write a marker you own, and detect on that instead:

# At the end of a successful install (e.g. PSADT Post-Installation)
$key = 'HKLM:\SOFTWARE\Contoso\Packages\MyApp'
New-Item -Path $key -Force | Out-Null
New-ItemProperty -Path $key -Name 'Version'     -Value '3.2.2' -PropertyType String -Force | Out-Null
New-ItemProperty -Path $key -Name 'InstalledOn' -Value (Get-Date -Format s) -PropertyType String -Force | Out-Null

Remove the key in your uninstall section, so uninstall assignments report correctly too.

The detection rule

In the app’s Detection rules, choose Manually configure detection rules → Registry:

FieldValue
Key pathHKEY_LOCAL_MACHINE\SOFTWARE\Contoso\Packages\MyApp
Value nameVersion
Detection methodString comparison → Equals → 3.2.2
Associated with a 32-bit app on 64-bit clientsNo

If you need a script instead

A custom detection script counts as detected only when it exits 0 and writes something to STDOUT. Exit 0 with no output means “not detected”.

$v = (Get-ItemProperty 'HKLM:\SOFTWARE\Contoso\Packages\MyApp' -ErrorAction SilentlyContinue).Version
if ($v -eq '3.2.2') { Write-Output "Detected $v"; exit 0 }
exit 0   # no output = not detected

#Win32 apps#Detection rules#PSADT#Registry