Intune Deployment Guide
Deploy WinSCP (EXE) with Intune
Overview
This Intune guide helps you roll out WinSCP (EXE) 6.3.8 from Martin Prikryl with clear packaging, app setup, and deployment tracking steps.
| App name | WinSCP (EXE) |
| Publisher | Martin Prikryl |
| Version | 6.3.8 |
| App type | Windows app (Win32) |
| Install behavior | System |
Download Installer
| Installer file | WinSCP-6.3.8-Setup.exe |
| Download source | https://winscp.net/eng/index.php |
Prepare the Intune Package
- Create a working folder on your local machine (for example: D:\Intune).
- Create two subfolders inside the working folder: Input and Output.
- D:\Intune\Input: Folder for all setup files. All files in this folder are compressed into an .intunewin file.
- D:\Intune\Output: Stores the generated .intunewin package.
- Place WinSCP-6.3.8-Setup.exe in the Input folder.
- Download the Microsoft Win32 Content Prep Tool (IntuneWinAppUtil.exe) and place it in D:\Intune.
Create a structured working directory before packaging WinSCP (EXE) so rebuilds and troubleshooting remain consistent.
D:\Intune
├── Input
│ └── WinSCP-6.3.8-Setup.exe
├── Output
└── IntuneWinAppUtil.exe
- Open Windows PowerShell or Command Prompt as Administrator.
- Navigate to the working folder: cd D:\Intune.
- Run the following packaging command to generate the WinSCP-6.3.8-Setup.intunewin package. For packaging background, see .intunewin package preparation.
IntuneWinAppUtil.exe -c .\Input -s "WinSCP-6.3.8-Setup.exe" -o .\Output- After the command finishes, the generated package should be available in the D:\Intune\Output folder.
D:\Intune
├── Input
│ └── WinSCP-6.3.8-Setup.exe
├── Output
│ └── WinSCP-6.3.8-Setup.intunewin
└── IntuneWinAppUtil.exe
Note: Windows application size is capped at 30 GB per app.
Set Up the App in Intune
In Intune, create the Win32 app object for WinSCP (EXE) and align core settings before moving to assignments.
Go to Apps → Overview, then choose the Windows platform card (or expand Platforms and select Windows).

Click Create to add a new app.

In the Select app type panel, choose Windows app (Win32).

On the App information page, click Select app package file.

Upload WinSCP-6.3.8-Setup.intunewin, then confirm the App package file panel.

Configure App Settings
Tune configuration values for WinSCP (EXE) here to reduce drift between test devices and production cohorts.
Name WinSCP (EXE) 6.3.8 Description WinSCP (EXE) 6.3.8 Publisher Martin Prikryl App version 6.3.8 
Configure how Intune installs and uninstalls the app. Enter the values below in the Program tab and leave all other settings unchanged. See Intune install and uninstall commands for command guidance.
Install/Uninstall type Command line Install command "WinSCP-6.3.8-Setup.exe" /VERYSILENT /NORESTART /ALLUSERS Uninstall command "%ProgramFiles(x86)%WinSCPunins000.exe" /VERYSILENT /NORESTART Install behavior System Device restart behavior App install may force a device restart Allow available uninstall Yes Installation time required 60 minutes Return codes Keep the default Intune return codes. 
Define which devices are eligible to install the app. Learn more in Intune requirements explained.
Check operating system architecture No. Allow this app to be installed on all systems. Minimum operating system Windows 10 1607 Additional requirement rules No requirements are specified. 
On the Detection rules page, set Rules format to Manually configure detection rules. For the concept, see Intune detection rules explained.

Click Add to create a detection rule.

Select the appropriate Rule type (MSI, File, or Registry) based on the installer. Use the table below as a reference.
# Type Target Method Value 1 File %ProgramFiles%\WinSCPWinSCP.exe App version greater than or equal to 6.3.8.15183 greater than or equal to 6.3.8.15183 Associated with a 32-bit app on 64-bit clients: Yes.
On the Dependencies page, click Next unless this app must install after another app.

On the Supersedence page, click Next unless this app replaces an older app.

Scope Assignment and Deployment
Assign WinSCP (EXE) in rollout rings (pilot -> controlled broad) so you can gate expansion on install and detection quality.
Assignment options
Required Installs the app automatically on targeted users or devices. Use this after install, uninstall, and detection are verified.
Available for enrolled devices Shows the app in Company Portal so users can install it manually. Use this for pilot users, IT validation, or optional apps.
Uninstall Automatically removes the app from targeted devices. Use this when you need to retire or remove the app.
Note: Start with a dedicated test group before broad deployment. For example, use the Required assignment option to automatically install the app on targeted devices.

Review all configuration details, then click Create to deploy the app.

Verify the app in Intune. Confirm that the upload is finished, the application is saved, and the app overview shows the expected package details.
Note: If Intune says the app is not ready yet, wait a few minutes and refresh the page.

Sync the Intune Policies
Run a deliberate sync pass for WinSCP (EXE) and capture timestamps for assignment and enforcement correlation.
End User Experience
Check end-user outcomes for WinSCP (EXE) early so support teams receive accurate rollout expectations.
Required apps install automatically. During installation, Windows may show notifications from Microsoft Intune Management Extension. Users can see the app move from installing to installed.
Note: Notification visibility depends on Windows notification settings and Intune app deployment behavior.
Monitor Deployment Status
Use reporting trends from WinSCP (EXE) pilot devices to validate readiness for the next rollout stage.
Click Device install status or User install status to see the list of devices or users with their installation status.
Uninstall the App from Intune
When the app is no longer needed, remove it by changing the Intune assignment to Uninstall for the target group.
Go to Apps → All apps, then select the app you want to remove.

Open Properties and click Edit next to Assignments.

Move the target group to the Uninstall section.

Review the assignment, then click Save. Devices will remove the app after the policy is applied.

After saving, the uninstall policy is applied. The device removes the app automatically.
Note: The uninstall process may take a few minutes depending on device check-in and policy sync timing.
Common Issues and Resolutions
Use this troubleshooting pass before changing assignments or detection logic. Validate assignment scope, installer behavior, and Intune Management Extension outcomes first.
| Issue | What to check |
|---|---|
| App does not install | Confirm the app is assigned to the correct user or device group. |
| App shows as failed | Review the install command, silent switch, and Intune Management Extension logs. |
| Detection rule fails | Check the file path, MSI product code, registry key, or detection value. |
| App is not visible in Company Portal | Confirm the assignment type is Available and the user is in the target group. |
| Install works manually but fails in Intune | Verify the install command runs silently under system context and does not require user input. |
| Uninstall does not run | Validate the uninstall command and confirm the app is assigned with uninstall intent. |
| Device has not received policy | Trigger a manual sync or wait for the next Intune device check-in. |
| App stuck on installing | Check if a restart is pending and verify no other installation is blocking the process. |
| Install fails due to context | Verify the app runs correctly under System or User context based on the install behavior. |
| Need detailed logs | Check Intune Management Extension logs in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs for installation details and errors. |
If the issue repeats after these checks, collect fresh Intune Management Extension logs and compare against the latest assignment and requirement settings.
Deployment Fit and Risks
Use this section to confirm whether WinSCP (EXE) aligns with your deployment policy, endpoint state, and support model before broad assignment.
- Install behavior is currently set to system; confirm it matches the expected execution context.
- Restart behavior resolves to basedOnReturnCode; align this with maintenance windows and user-impact constraints.
- Validate requirements and detection against real endpoint state before widening assignment scope.
- Track early rollout telemetry and stop expansion if failure patterns appear outside expected thresholds.
Validation Steps Before Broad Rollout
- Run a pilot rollout of WinSCP (EXE) to a small ring before broad assignment.
- Confirm the install command executes silently in the target context:
"WinSCP-6.3.8-Setup.exe" /VERYSILENT /NORESTART /ALLUSERS. - Confirm detection logic (types observed: manual/unspecified) matches real endpoint state after install.
- Monitor return codes and enforcement state in Intune Device install status and Intune Management Extension logs.
- Confirm uninstall intent and rollback readiness are documented for the same pilot devices.
Change and Rollback Notes
- Document a rollback baseline for WinSCP (EXE) (target version: 6.3.8) before broad rollout.
- Rollback path available via uninstall command:
"%ProgramFiles(x86)%WinSCPunins000.exe" /VERYSILENT /NORESTART. - Use phased assignments (pilot -> ring1 -> broad) with explicit go/no-go checkpoints after each ring.
- For upgrades, confirm uninstall/rollback execution on pilot devices before decommissioning previous builds.
Deeper Internal References
Use the focused guides below for deeper implementation details tied to this deployment.
- IntuneWin packaging baseline and validation flow
- Intent-based assignment decisions for user impact control
- Endpoint log analysis flow for Win32 troubleshooting
- Command-line reliability playbook for Win32 deployments

Leave a feedback
Include versions, steps, and any error text if you have them.