intunemdms.com

Intune Deployment Guide

Deploy WinSCP (EXE) with Intune

Overview

This Intune guide helps you roll out WinSCP (EXE) 6.3.8 from Martin Prikryl with clear packaging, app setup, and deployment tracking steps.

App nameWinSCP (EXE)
PublisherMartin Prikryl
Version6.3.8
App typeWindows app (Win32)
Install behaviorSystem

Download Installer

Installer fileWinSCP-6.3.8-Setup.exe
Download sourcehttps://winscp.net/eng/index.php

Prepare the Intune Package

  1. Create a working folder on your local machine (for example: D:\Intune).
  2. Create two subfolders inside the working folder: Input and Output.
    • D:\Intune\Input: Folder for all setup files. All files in this folder are compressed into an .intunewin file.
    • D:\Intune\Output: Stores the generated .intunewin package.
  3. Place WinSCP-6.3.8-Setup.exe in the Input folder.
  4. Download the Microsoft Win32 Content Prep Tool (IntuneWinAppUtil.exe) and place it in D:\Intune.

Create a structured working directory before packaging WinSCP (EXE) so rebuilds and troubleshooting remain consistent.

D:\Intune
├── Input
│   └── WinSCP-6.3.8-Setup.exe
├── Output
└── IntuneWinAppUtil.exe
  1. Open Windows PowerShell or Command Prompt as Administrator.
  2. Navigate to the working folder: cd D:\Intune.
  3. Run the following packaging command to generate the WinSCP-6.3.8-Setup.intunewin package. For packaging background, see .intunewin package preparation.
IntuneWinAppUtil.exe -c .\Input -s "WinSCP-6.3.8-Setup.exe" -o .\Output
Command Prompt
  1. After the command finishes, the generated package should be available in the D:\Intune\Output folder.
D:\Intune
├── Input
│   └── WinSCP-6.3.8-Setup.exe
├── Output
│   └── WinSCP-6.3.8-Setup.intunewin
└── IntuneWinAppUtil.exe

Note: Windows application size is capped at 30 GB per app.

Set Up the App in Intune

In Intune, create the Win32 app object for WinSCP (EXE) and align core settings before moving to assignments.

  1. Go to Apps → Overview, then choose the Windows platform card (or expand Platforms and select Windows).

    intunemdms-generated-appsoverview
  2. Click Create to add a new app.

    intunemdms-generated-windowsapps-shot
  3. In the Select app type panel, choose Windows app (Win32).

    intunemdms-generated-selecttype-shot
  4. On the App information page, click Select app package file.

    intunemdms-generated-uploadpkg-shot
  5. Upload WinSCP-6.3.8-Setup.intunewin, then confirm the App package file panel.

    intunemdms-generated-packagefile-modal

Configure App Settings

  1. Tune configuration values for WinSCP (EXE) here to reduce drift between test devices and production cohorts.

    NameWinSCP (EXE) 6.3.8
    DescriptionWinSCP (EXE) 6.3.8
    PublisherMartin Prikryl
    App version6.3.8
    intunemdms-generated-appinfo-shot
  2. Configure how Intune installs and uninstalls the app. Enter the values below in the Program tab and leave all other settings unchanged. See Intune install and uninstall commands for command guidance.

    Install/Uninstall typeCommand line
    Install command"WinSCP-6.3.8-Setup.exe" /VERYSILENT /NORESTART /ALLUSERS
    Uninstall command"%ProgramFiles(x86)%WinSCPunins000.exe" /VERYSILENT /NORESTART
    Install behaviorSystem
    Device restart behaviorApp install may force a device restart
    Allow available uninstallYes
    Installation time required60 minutes
    Return codesKeep the default Intune return codes.
    intunemdms-generated-program-shot
  3. Define which devices are eligible to install the app. Learn more in Intune requirements explained.

    Check operating system architectureNo. Allow this app to be installed on all systems.
    Minimum operating systemWindows 10 1607
    Additional requirement rulesNo requirements are specified.
    intunemdms-generated-req-shot
  4. On the Detection rules page, set Rules format to Manually configure detection rules. For the concept, see Intune detection rules explained.

    intunemdms-generated-detection-format-shot
  5. Click Add to create a detection rule.

    intunemdms-generated-detection-type-shot
  6. Select the appropriate Rule type (MSI, File, or Registry) based on the installer. Use the table below as a reference.

    #TypeTargetMethodValue
    1File%ProgramFiles%\WinSCPWinSCP.exeApp version greater than or equal to 6.3.8.15183greater than or equal to 6.3.8.15183

    Associated with a 32-bit app on 64-bit clients: Yes.

  7. On the Dependencies page, click Next unless this app must install after another app.

    intunemdms-generated-lite-wizard
  8. On the Supersedence page, click Next unless this app replaces an older app.

    intunemdms-generated-lite-wizard

Scope Assignment and Deployment

  1. Assign WinSCP (EXE) in rollout rings (pilot -> controlled broad) so you can gate expansion on install and detection quality.

    Assignment options

    Required

    Installs the app automatically on targeted users or devices. Use this after install, uninstall, and detection are verified.

    Available for enrolled devices

    Shows the app in Company Portal so users can install it manually. Use this for pilot users, IT validation, or optional apps.

    Uninstall

    Automatically removes the app from targeted devices. Use this when you need to retire or remove the app.

    Note: Start with a dedicated test group before broad deployment. For example, use the Required assignment option to automatically install the app on targeted devices.

    intunemdms-generated-lite-wizard
  2. Review all configuration details, then click Create to deploy the app.

    intunemdms-generated-review-create
  3. Verify the app in Intune. Confirm that the upload is finished, the application is saved, and the app overview shows the expected package details.

    Note: If Intune says the app is not ready yet, wait a few minutes and refresh the page.

    intunemdms-generated-postcreate

Sync the Intune Policies

Run a deliberate sync pass for WinSCP (EXE) and capture timestamps for assignment and enforcement correlation.

01

Manual device sync

  1. On the Windows device, open Settings.
  2. Go to Accounts → Access work or school.
  3. Select the connected work account, then click Info.
  4. Click Sync.
02

Remote Intune sync

  1. Open Devices → Windows devices.
  2. Select the pilot device.
  3. Click Sync from the device action bar.
03

Company Portal sync

  1. Open Company Portal on the device.
  2. Go to Settings.
  3. Click Sync.
04

Restart device

  1. Restart the Windows device.
  2. The device will automatically check in and apply policies during startup.

End User Experience

Check end-user outcomes for WinSCP (EXE) early so support teams receive accurate rollout expectations.

intunemdms-generated-enduser

Required apps install automatically. During installation, Windows may show notifications from Microsoft Intune Management Extension. Users can see the app move from installing to installed.

Note: Notification visibility depends on Windows notification settings and Intune app deployment behavior.

Monitor Deployment Status

Use reporting trends from WinSCP (EXE) pilot devices to validate readiness for the next rollout stage.

intunemdms-generated-tracking-overview

Click Device install status or User install status to see the list of devices or users with their installation status.

intunemdms-generated-tracking-device

Uninstall the App from Intune

When the app is no longer needed, remove it by changing the Intune assignment to Uninstall for the target group.

  1. Go to Apps → All apps, then select the app you want to remove.

    intunemdms-generated-uninstall-select
  2. Open Properties and click Edit next to Assignments.

    intunemdms-generated-uninstall-properties
  3. Move the target group to the Uninstall section.

    intunemdms-generated-uninstall-edit
  4. Review the assignment, then click Save. Devices will remove the app after the policy is applied.

    intunemdms-generated-uninstall-review

After saving, the uninstall policy is applied. The device removes the app automatically.

Note: The uninstall process may take a few minutes depending on device check-in and policy sync timing.

Common Issues and Resolutions

Use this troubleshooting pass before changing assignments or detection logic. Validate assignment scope, installer behavior, and Intune Management Extension outcomes first.

IssueWhat to check
App does not installConfirm the app is assigned to the correct user or device group.
App shows as failedReview the install command, silent switch, and Intune Management Extension logs.
Detection rule failsCheck the file path, MSI product code, registry key, or detection value.
App is not visible in Company PortalConfirm the assignment type is Available and the user is in the target group.
Install works manually but fails in IntuneVerify the install command runs silently under system context and does not require user input.
Uninstall does not runValidate the uninstall command and confirm the app is assigned with uninstall intent.
Device has not received policyTrigger a manual sync or wait for the next Intune device check-in.
App stuck on installingCheck if a restart is pending and verify no other installation is blocking the process.
Install fails due to contextVerify the app runs correctly under System or User context based on the install behavior.
Need detailed logsCheck Intune Management Extension logs in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs for installation details and errors.

If the issue repeats after these checks, collect fresh Intune Management Extension logs and compare against the latest assignment and requirement settings.

Deployment Fit and Risks

Use this section to confirm whether WinSCP (EXE) aligns with your deployment policy, endpoint state, and support model before broad assignment.

  • Install behavior is currently set to system; confirm it matches the expected execution context.
  • Restart behavior resolves to basedOnReturnCode; align this with maintenance windows and user-impact constraints.
  • Validate requirements and detection against real endpoint state before widening assignment scope.
  • Track early rollout telemetry and stop expansion if failure patterns appear outside expected thresholds.

Validation Steps Before Broad Rollout

  • Run a pilot rollout of WinSCP (EXE) to a small ring before broad assignment.
  • Confirm the install command executes silently in the target context: "WinSCP-6.3.8-Setup.exe" /VERYSILENT /NORESTART /ALLUSERS.
  • Confirm detection logic (types observed: manual/unspecified) matches real endpoint state after install.
  • Monitor return codes and enforcement state in Intune Device install status and Intune Management Extension logs.
  • Confirm uninstall intent and rollback readiness are documented for the same pilot devices.

Change and Rollback Notes

  • Document a rollback baseline for WinSCP (EXE) (target version: 6.3.8) before broad rollout.
  • Rollback path available via uninstall command: "%ProgramFiles(x86)%WinSCPunins000.exe" /VERYSILENT /NORESTART.
  • Use phased assignments (pilot -> ring1 -> broad) with explicit go/no-go checkpoints after each ring.
  • For upgrades, confirm uninstall/rollback execution on pilot devices before decommissioning previous builds.

Deeper Internal References

Use the focused guides below for deeper implementation details tied to this deployment.

Leave a feedback

Include versions, steps, and any error text if you have them.