|
1 | 1 | --- |
2 | | -updated_at: June 25, 2025 |
| 2 | +updated_at: July 09, 2025 |
3 | 3 | title: Connect Intune to Smallstep |
4 | 4 | html_title: Connect Intune to Smallstep |
5 | 5 | description: Configure Intune to deploy the Smallstep Agent and distribute certificates and configuration to Mac clients. |
@@ -97,43 +97,27 @@ In this step, we’ll add the Smallstep Agent to Intune for distribution to devi |
97 | 97 |
|
98 | 98 | 1. In Intune, |
99 | 99 | 1. Start at [Windows Apps](https://intune.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsWindowsMenu/~/windowsApps) |
100 | | - 2. Choose **+ Create,** and then select **Windows App (Win32)** |
101 | | - 3. [Download the Smallstep agent package](https://github.com/smallstep/step-agent-plugin/releases/latest) and select it for upload in Intune. |
| 100 | + 2. Choose **+ Create**, and then select **Windows App (Win32)** |
| 101 | + 3. [Download the Smallstep agent `.intunewin` package for `amd64`](https://files.smallstep.com/intune/step-agent-plugin_amd64.intunewin) and select it for upload in Intune. (Contact Smallstep if you need an `arm64` installer). |
102 | 102 | - For the App Information tab: |
103 | | - - Under Publisher, use “Smallstep” |
104 | | - - Choose “Next” |
105 | | - - For the Program tab: |
106 | | - - For Install Command, use: |
107 | | - ``` |
108 | | - step-agent-plugin-Setup_amd64_<version>.exe /silent |
109 | | - ``` |
110 | | - Replace `<version>` with the version of the Smallstep Agent being distributed. |
111 | | - - For Uninstall Command, use: |
112 | | - ``` |
113 | | - msiexec /x "{EDB2FA84-917D-4156-AA1A-4BC5BB10C682}" |
114 | | - ``` |
| 103 | + - For Publisher, use “Smallstep” |
| 104 | + - Note the version number. You'll need it below. |
115 | 105 | - Choose “Next” |
| 106 | + - Continue to the Requirements tab |
116 | 107 | - For the Requirements tab: |
117 | | - - Operating System Architecture: 64-bit |
118 | | - - Minimum operating system: Windows 10 1607 |
| 108 | + - For **Check Operating System Architecture**, choose "Yes" |
| 109 | + - Select "Install on x64 systems" |
| 110 | + - Use minimum operating system: Windows 10 1607 |
| 111 | + - Choose "Next" |
119 | 112 | - For the Detection rules tab: |
120 | 113 | - Rules format: Manually configure detection rules |
121 | 114 | - Choose **+ Add** |
122 | | - - Rule Type: Registry |
123 | | - - Key Path: |
124 | | - ``` |
125 | | - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EDB2FA84-917D-4156-AA1A-4BC5BB10C682}}_is1 |
126 | | - ``` |
127 | | - - Value Name: `VersionMinor` |
128 | | - - Detection Method: Integer Comparison |
| 115 | + - Rule Type: MSI |
| 116 | + - MSI product version check: Yes |
129 | 117 | - Operator: Greater than or equal to |
130 | | - - Value: `<smallstep-agent-minor-version>` |
131 | | - - Make sure you replace this with the current **minor** version (using SemVer conventions) of the Smallstep Agent being distributed. For example: `51` for version `0.51.0`. |
132 | | - - Choose “Next” |
133 | | - - For the Dependencies tab: |
134 | | - - Choose “Next” |
135 | | - - For the Supersedence tab: |
136 | | - - Choose “Next” |
| 118 | + - Value: Paste in the version number you noted earlier |
| 119 | + - Choose “Ok” |
| 120 | + - Continue to the Assignments tab |
137 | 121 | - For the Assignments tab: |
138 | 122 | - Assign the app to devices as desired. |
139 | 123 | - On “Review and Create” click **Create** |
|
0 commit comments