How Devicie's application catalogue works
Devicie has recently made significant enhancements to our application catalogue that change how our management process works. Read more: Feature Release: Enhanced Application Catalogue
Devicie's third-party application catalogue lets you deploy tested, Intune-packaged applications to your tenant in a few clicks, and then keeps them up to date automatically. This article explains how applications get into the catalogue, how you deploy them, and what happens in your tenant as new versions are released.
The catalogue
Devicie maintains a growing catalogue of over 1,500 third-party applications across both Windows and macOS. We prioritise what's commonly used, what we detect running across our customer base, and what market and industry monitoring tells us matters.
You can browse the full catalogue from the Devicie portal, no matter your role, to see what's available.
Requesting an application
If something you need isn't there, submit a request through the Devicie portal. The one thing to check is that the publisher provides the latest installer at a publicly accessible URL. If the installer is only available behind a login or a licence gate, we can't add it to the catalogue.
How Devicie tests and packages applications
Every version of every catalogue application goes through the same automated process before it lands in the catalogue:
-
Monitor. Devicie continuously monitors publisher release sources for new versions.
-
Download and verify. When a new version appears, we download the installer directly from the publisher and verify it's unaltered.
-
Package. We build the actual Intune package, so that our testing is completed on exactly what your tenant will receive.
-
Scan. The package is malware-scanned.
-
Test on a clean machine. We install the package on a clean test machine across every architecture and install scope the app supports, recording the machine state throughout the install and uninstall process.
-
Check detection. We check that the Intune detection rule works correctly throughout that same process.
-
Publish. Only then does the new version land in the catalogue.
This process is completely automated, and ensures you get an Intune-packaged and tested version of the application within hours of the vendor's release.
macOS applications follow a shorter chain suited to the platform: version lookup, signature or Team ID verification, wrapping into a signed package, an install test, and recording the checksum.
Deploying an application
Full detail here: How to deploy catalogue applications
Admin users can select an app from the catalogue, configure assignments, and deploy it to your tenant instantly. Deploying an application is three steps:
-
Select the application from the catalogue.
-
Configure assignments and any custom install arguments, if the application needs them.
-
Deploy.
Assignments
An assignment requires a target group, plus an intent, plus a delay.
| Setting | What it does |
|---|---|
| Target group | The Entra ID group of users or devices the assignment applies to. |
| Intent: Required | The app installs silently and forcibly on the target devices. |
| Intent: Available | The app appears in Company Portal, and the end user can choose whether or not to install it. |
| Intent: Uninstall | The app is forcibly removed from devices in the target group. |
| Delay | How long after deployment the assignment becomes active for that group. |
Typically, when you're first deploying a new app, you'll set the delay to zero so you can test immediately or get the app out to users straight away. See recommended rings and delays below.
Apps deployed as Available: the Update companion app
There's an extra process to be aware of for apps set as Available. When you deploy an app as Available, Devicie automatically deploys a second app to your tenant to manage updates.
- The initial app you chose is set as Available to the target group, for example, Google Chrome.
- The update-only version of the app- Google Chrome - Update is automatically assigned as Required to the same group.
The update-only app carries a requirement rule: the update will install on a device where an earlier version of the app is already installed, but it won't affect devices where the app hasn't been installed. This means users who choose to install the app from Company Portal are kept up to date automatically, without the app being forced onto anyone who hasn't.
As a result, two apps will appear in your Intune tenant and on the Devicie Managed Apps page. This is expected.
You may also notice the update versions appear in the catalogue list. That's because there are cases where you'll want to deploy the update-only app on its own.
How the app reaches the endpoint
When you click Deploy, the app (or the pair of apps) is created in your Intune tenant immediately, with the assignments you set.
Actual delivery to endpoints then depends on two things:
- Your configured assignment delays- the assignment only becomes active for a group once its delay has passed.
- The device checking in to Intune to pick up the assignment.
A device that is offline, or hasn't checked in yet, receives the app on its next check-in after the delay has passed.
Recommended rings and delays
With a brand new app, assign it to a test group with a zero-hour delay first, to complete your testing.
For the initial rollout to everyone who needs the application, you'll often deploy to the relevant user group at a zero-hour delay as well, to get that first install out immediately.
After that, edit the assignment delays back to your business-as-usual patching cadence. Every future version will follow that cadence automatically.
Our recommendation is to use two rings:
- A test or pilot ring, with a shorter delay.
- The full user group, with a longer delay.
This is good standard practice, with a gap between the two to catch any problems that might occur. Use your best judgement, depending on the risk of the application, as to how you set this up- a low-risk application may only need a single ring, while a high-risk application may warrant three or more.
Note: Delays are measured from the time of deployment, not from the previous ring. A pilot ring at 24 hours and a full group at 72 hours means the full group receives the version 72 hours after deployment.
Automated updates
Once you have a Devicie managed app deployed in your environment, the real value of the automation kicks in.
Every time Devicie detects a new release from the publisher, it runs through the same testing and packaging automation described above. A new, tested version is deployed to your tenant, and your existing assignments and custom arguments are all maintained. New versions roll out through your rings on the delays you configured.
Version retention
Devicie keeps the current version plus the two previous versions of each managed app in your tenant, all still assigned. When a new version arrives, the oldest of the three is automatically removed. This allows you to roll back to a previous version if an issue ever occurs.
What you'll see in your tenant
For a single managed app deployed as Available, at any one time you may see:
- the current version,
- its update companion, and
- the two previous versions,
all deployed and assigned. This is expected and gives you the full benefit of the automation.
The end user will only ever see the latest app installed on their machine, or the latest app available in Company Portal.
Summary
With Devicie automated patching, you set it once and Devicie does the rest. Your end users stay productive, your devices stay secure, and your team isn't bogged down with manual packaging effort.