Skip to content
Every tool security-scanned or hand-vetted

Every Intune tool worth knowing.

168+ free tools, scripts and modules, curated by the community, scanned for security, and searchable by the problem you are facing.

168+
free tools
101
passed all 6 security checks
108+
community contributors
Sponsored by

Browse 168 Microsoft Intune tools

Desktop App
Verified

Baseline

Baseline is an MDM-agnostic, zero-touch or light-touch macOS deployment tool. It uses swiftDialog, Installomator, and custom code to automate app installation and script execution. Behavior is configured via a mobileconfig or plist, with Baseline installing packages, scripts, and Installomator labels as defined in the configuration.

SecondSonConsulting
SecondSonConsulting
Configuration
Documentation
Curated

Conditional Access Baseline

Conditional Access Baseline is a ready-to-use Intune baseline aligned with the Microsoft Conditional Access Baseline. It provides a reduced but comprehensive set of CA policies across identities, apps, and platforms, enforcing MFA, blocking legacy authentication, and applying risk-based controls. The baseline includes guidance to automate policy import (via IntuneManagementTool) and recommends adding break-glass accounts to the exclusion group CA-BreakGlassAccounts - Exclude.

Web App
Curated

GetCurrent

GetCurrent centralizes Microsoft 365 updates from Message Center, Roadmap, and What's New into a single, structured view. It surfaces important notifications, upcoming features, and latest changes across Defender, Intune, Entra, Windows 365, and more, helping IT teams stay informed and plan action items. Use it to monitor tenant updates, track roadmap items, and review new capabilities to optimize your environment.

Frans Oudendorp
Frans Oudendorp
Monitoring
PS Script
Verified

Intune Remote Help Launcher

Intune Remote Help Launcher is a PowerShell WPF tool for IT admins to search Intune-managed devices by name or primary user, view device details, and launch Microsoft Remote Help sessions from one interface. It supports Windows, Android, iOS, and macOS devices, displays OS, compliance, ownership, model and last sync, and can issue sync or restart commands or open the device in the Intune admin center. It uses Microsoft Graph delegated authentication (auto-installs the Graph module if needed) and requires Remote Help licensing to be configured.

Mert Efe Kanlikilic
Mert Efe Kanlikilic
Troubleshooting
PowerShell Module
Verified

IntuneGraph

IntuneGraph turns your Microsoft Intune tenant into an interactive relationship graph. It provides a read-only, offline snapshot showing what applies to a device and why, and lets you preview the impact of membership changes before you touch a group. By surfacing nesting, filters, and include/exclude paths, it helps identify orphaned, broken, or misconfigured targets and assess assignment hygiene.

Web App
Verified

IntuneShade

IntuneShade is a free community console for Microsoft Intune admins that lets you sign in with a Microsoft 365 account to view and manage your tenant—assignments, device compliance, Autopilot, and reports—without any install or app registration. This multi-tenant SPA runs in the browser with delegated Graph permissions and no server-side data storage. Key features include Group Assignment Manager, Bulk Assign, AI policy analysis and script generation, conflict detection, smart bulk automation, assignment matrix, compliance reporting, and audit history.

Alper Atar
Alper Atar
Configuration
Web App
Curated

LanguagePackDeployer

LanguagePackDeployer is a web-based Intune deployment tool that streamlines multilingual rollouts for Windows and macOS. From a browser, you select languages, region, timezone, and keyboard overrides, then publish assigned policies or download ready-to-run deployment bundles. It includes 100 locale presets, the option to designate a primary UI language, and supports packaging as a Win32 app, Platform Script, or macOS Intune shell script with granular assignment controls.

Roy Klooster
Roy Klooster
Configuration
PS Script
Verified

LAPS Reader

LAPS Reader is a Windows PowerShell/WPF GUI tool that retrieves Windows LAPS passwords stored in Intune (Entra) via Microsoft Graph. It signs in to Graph, resolves a device by display name, and displays the local account, password, backup time, and account SID with a one-click copy. Intended for IT/helpdesk staff, it requires the Microsoft.Graph.Authentication module and permissions DeviceLocalCredential.Read.All and Device.Read.All.

Web App
Curated

MSIinfo

MSIinfo is a browser-based viewer for Windows Installer (.msi) packages. It surfaces the MSI Property table (ProductCode, UpgradeCode, ProductVersion, Manufacturer) and Summary Information, with ready-to-copy deployment commands. It analyzes install scope, provides Intune-friendly detection/uninstall hints, and exports the Property table as JSON/CSV. All processing is local in the browser with lazy file reading - no upload or install required.

Desktop App
Curated

Third Party Patcher

Third Party Patcher is a macOS daemon-based patching system for IT administrators that automatically discovers installed third-party apps, checks for updates, downloads installers in the background, and applies them with optional user prompts via swiftDialog. Updates are driven by Installomator label files and can be customized with override labels. The solution provides a PatcherMenu and a self-service Available Software window, plus scheduled patching phases (Scan, Check, Stage, Apply) and detailed reporting.

Gil Burns
Gil Burns
Packaging
Desktop App
Verified

TrayLight

TrayLight is a lightweight Windows System Tray app that provides instant device info, IT support shortcuts, and Intune sync, configurable via ADMX policy or Intune Settings Catalog. It ships with six default info tiles (Computer Name, OS Version, Last Reboot, Storage Usage, Serial Number, Intune Sync), supports extra ADMX tiles, up to six Quick Action shortcuts, and dynamic placeholders for live data. It supports branding, localization, dark/light themes, and zero-configuration deployment via MSI or policy-based provisioning through Intune or Group Policy.

Daniel Fraubaum
Daniel Fraubaum
Troubleshooting
PowerShell Module
Verified

win32-toolkit

win32-toolkit delivers end-to-end Intune Win32 packaging: point at a winget package or any installer, scaffold a PSAppDeployToolkit v4 project, and capture real installs in a disposable Windows Sandbox or Hyper-V VM. It derives detection and uninstall logic, validates install/update paths, packages a .intunewin, and publishes to Intune with dependencies, branding, and requirements.

PS Script
Verified

Windows Update Remediation Tool

Windows Update Remediation Tool is an automated WinForms utility for diagnosing and repairing Windows Update issues. It offers a selectable sequence of remediation steps—stopping services, cleaning caches, resetting permissions, re-registering DLLs, Winsock reset, restarting services, update scans, and SetupDiag diagnostics—with built-in logging. Administrators can run it elevated, monitor per-step progress, and generate logs for troubleshooting.

Mert Ozsoy
Mert Ozsoy
Troubleshooting
Web App
Curated

CMTrace Web

CMTrace Web (CMTrace.dev) is a free, browser-based log viewer for ConfigMgr/SCCM and Intune logs. Reimplementing CMTrace in the browser, it handles 1M+ line logs with color-coded severities, error-code lookups, and side-by-side diffs, all client-side and offline as a PWA. It opens .log, .txt, .gz, and .zip, with Intune/IME presets to jump straight to relevant logs.

Other
Verified

Adobe DC (Computer) ADMX

Adobe DC (Computer) ADMX provides machine-level Group Policy and Intune management templates for Adobe Acrobat DC and Reader DC on Windows. It ships as a combined AdobeDC.admx/ADML pair (plus separate x64 and x86 files) and enables 552 policies covering cloud connectors, security hardening, trust, UI, updates, and upsell controls via HKLM. The documentation notes per-architecture deployment, unified installer considerations, and inverted registry values for some bToggle policies, ensuring consistent Enabled/Disabled behavior in GPO and Intune.

Darren Milne
Darren Milne
Configuration
Other
Verified

Adobe DC (User) ADMX Templates

Per-user Adobe Acrobat DC and Reader DC ADMX/ADML templates for Intune, enabling HKCU policy management on Windows. The v1.10 User bundle includes 501 policies (across Reader and Acrobat), with security hardening, nags reduction, and full documentation to configure per-user preferences via Intune or GPO. It ships AdobeDC_User.admx/adml files and user-scoped policy controls for per-user settings.

Darren Milne
Darren Milne
Configuration
PS Script
Verified

Apple Compliance Version Updater

Apple Compliance Version Updater automatically updates the osMinimumVersion in macOS and iOS/iPadOS Intune compliance policies based on the SOFA feed. It provides per-platform control, supports flexible version strategies (track major, pin to major, or track minor), and runs in Azure Automation with Managed Identity for zero-secret maintenance. Choose separate or unified runbooks for scalable, diagnostics-driven policy updates.

Niklas Bruhn
Niklas Bruhn
Automation
Why you can trust these tools

101 of 168 listed tools passed every automated security check.

Automatically security-scanned

Every open-source tool's code is scanned for six classes of risk: obfuscation, remote execution, credential theft, data exfiltration, malicious patterns, and hardcoded secrets.

Curated by the community

Tools are reviewed and selected by Intune practitioners. Closed-source tools that can't be scanned are vetted manually before they're listed.

Free and open

Every tool in the directory is free to use. Source links and downloads go straight to the original author's repository - nothing is paywalled here.