Application Deployment
Deploy Win32 LOB apps from Chocolatey and WinGet, manage Intune mobile apps, and configure Enterprise App registrations — directly from the CONFIG365 web interface or via JSON definitions in your baseline Git repository.
Overview
CONFIG365 supports four application deployment methods, each controlled by a dedicated feature toggle in the pipeline. Apps can be added and managed directly from the CONFIG365 web interface, or by committing JSON definitions to the baseline repository and letting the pipeline handle packaging, uploading, and assignment.
Deploy via the GUI
The CONFIG365 web interface lets you add, edit, and deploy applications without touching JSON or the pipeline directly. Search for a Chocolatey or WinGet package by name, configure assignment groups and install intent, and trigger a deployment — the platform generates the JSON and runs the pipeline stage automatically.
Feature Toggles
Each deployment method is enabled or disabled per-tenant via a boolean parameter in the pipeline:
deployChocoApps,
deployWingetApps,
deployEnterpriseApps, and
deployIntune.
Chocolatey Apps
/apps/chocolatey/ toggle: deployChocoApps Packages sourced from your private Chocolatey repository. CONFIG365 wraps each package as a Win32 LOB app, uploads it to Intune, and manages the assignment — all from a JSON definition in Git.
- 01 Add a JSON definition file to /apps/chocolatey/ in your baseline repo
- 02 Pipeline detects the file and calls Configure-ChocoApps.ps1
- 03 Script downloads the package from your private Choco feed
- 04 Package is wrapped as a Win32 LOB .intunewin file
- 05 Win32 app is created or updated in Intune
- 06 Assignment groups are applied from the JSON definition
WinGet Apps
/apps/winget/ toggle: deployWingetApps Packages from the public WinGet catalog. Ideal for standard business applications that do not require custom packaging. CONFIG365 wraps them as Win32 LOB apps for consistent Intune deployment.
- 01 Add a JSON definition with the WinGet package ID to /apps/winget/
- 02 Pipeline calls Configure-WingetApps.ps1
- 03 Script resolves the package from the WinGet catalog
- 04 Package is wrapped as a Win32 LOB .intunewin file
- 05 Win32 app is created or updated in Intune
- 06 Assignment groups are applied from the JSON definition
Enterprise Apps
/enterprise-apps/ toggle: deployEnterpriseApps Entra ID service principals (Enterprise Applications) deployed from JSON. App roles, delegated permissions, and Conditional Access exclusion tags are configured automatically.
- 01 Add a JSON definition for the service principal to /enterprise-apps/
- 02 Pipeline calls Configure-EnterpriseApps.ps1
- 03 Service principal is created or updated in Entra ID
- 04 App roles and delegated permission grants are applied
- 05 CA exclusion Custom Security Attributes are tagged if specified
- 06 Consistent across all tenants from the same baseline definition
Intune Mobile Apps
/intune/mobile-apps/ toggle: deployIntune iOS and Android apps managed via Intune. App protection policies, required apps, and store app assignments are defined in JSON and deployed with the Intune feature toggle.
- 01 Add a JSON definition to /intune/mobile-apps/ in your baseline repo
- 02 Configure-Intune-MobileApps.ps1 is called as part of the Intune deploy stage
- 03 Store app or managed app is created or updated in Intune
- 04 App protection policy assignments are linked if specified
- 05 Assignment groups are applied from the JSON definition
JSON Definition Example
Each app is defined in a single JSON file. The {{GROUP:name}} placeholder
in the assignment target is resolved to a real group ID at deploy time.
{
"displayName": "Google Chrome",
"packageId": "Google.Chrome",
"source": "winget",
"description": "Google Chrome browser — deployed via WinGet.",
"publisher": "Google LLC",
"installCommandLine": "winget install --id Google.Chrome --silent",
"uninstallCommandLine": "winget uninstall --id Google.Chrome --silent",
"assignments": [
{
"target": "{{GROUP:Baseline – Modern Workplace Devices}}",
"intent": "required"
}
]
} Required Fields
displayName— shown in Intune and Company PortalpackageId— Choco/WinGet package identifiersource—chocolateyorwingetinstallCommandLine— command used by Intune to installuninstallCommandLine— command used by Intune to remove
Assignment Intents
required— app is mandatory, installed silentlyavailable— app appears in Company Portal for self-serviceuninstall— app is removed from targeted devices