Problem
A team of 20 from an acquired company was moving into the parent company's Microsoft 365 tenant on a fixed cutover date, with a 94-entry software list of specialist tools, drivers, and utilities that all had to install silently through Intune.
What I built
- A PowerShell toolkit that detects each installer's engine and builds Intune packages, with install, uninstall, and detection rules, from a single JSON manifest.
- Silent installs for MSI, InstallShield, NSIS, Inno, WiX bundles, self-extractors, portable apps, and driver INFs, consolidating component rows (for example, 20 rows from one vendor into 6 apps).
- Every app tested through Company Portal on an Autopilot test machine for silent install, launch, and silent uninstall, working under least-privilege PIM roles.
Result
All 94 entries were covered by Day 1, delivered as 60+ tested Intune apps. I also gave the client's security team the findings they needed, each with a proven fix: an attack surface reduction rule blocking plug-ins, a driver blocked by memory integrity with a supported replacement, and a signed driver that only installed after I imported the publisher certificate.
Swipe sideways to see the whole diagram →




