INTUNE WINGET DEPLOYMENT OPTIONS

Attestree vs Intune

Intune offers two distinct capabilities that are easy to conflate. The Microsoft Store app (new) type deploys apps from the Microsoft Store catalog, and is included with Intune. Enterprise App Management is a paid add-on providing Microsoft-hosted, pre-prepared Win32 applications from an Enterprise App Catalog. Worth knowing: Microsoft states plainly that Enterprise App Management does not use winget — those apps are installed directly by the Intune management extension.

Verified against vendor documentation, September 2026

WHERE IT WINS

When Intune is the better answer.

Intune is a capable endpoint-management system and we do not position against it — we sit in front of it. It manages devices, policy, compliance and operating-system updates across platforms, and plenty of teams should keep it for exactly that. If your application needs are met by the Store catalog or the Enterprise App Catalog, that is a legitimately simpler stack than adding another component.

THE DIFFERENCE

Where the two part company.

Two documented gaps drive most of the conversations we have. The first is staged rollout for app auto-update: Microsoft's documentation carries a heading titled “No rollout rings or phased deployment”, and states that when a new version is available it goes out to all targeted devices at the same time rather than through phased deployment groups. The documented alternative is manual per-version supersedence work. The second is evidence. Microsoft's Enterprise App Management FAQ answers the security question directly: “Microsoft doesn't assert compliance, authorization, authenticity, or integrity for apps distributed via Intune. Customers are responsible for ensuring that apps meet their requirements.” That is a fair and honest disclaimer, and it describes precisely the gap we exist to fill.

CAPABILITY BY CAPABILITY

Only what we could verify.

Internal source for your own software
Attestree — Intune LOB apps still need .intunewin packaging
Deploys to endpoints
Both
Deployment rings for apps
Attestree — Microsoft documents no rollout rings for app auto-update
Per-user installs
Both — Intune supports System/User install behavior, with constraints
CycloneDX SBOM per package
Attestree only
Signed attestation
Attestree only
Sandbox detonation
Attestree only
Asserts app authenticity or integrity
Attestree — Microsoft explicitly does not
WHAT WE COULD NOT VERIFY

This one carries a live caveat, and you should weigh it before using anything here in a decision. Our rollout-rings point is scoped specifically to app auto-update, which is where Microsoft documents the limitation. Separately, Microsoft has demonstrated ring-based “Deployment Plans” for Intune app deployment, with per-ring time offsets — presented by an Intune product manager in April 2026 and labelled private preview, not generally available. There is no Microsoft Learn documentation for it yet, and no announced date. If that ships, this comparison changes and we will update it. We also did not verify Enterprise App Management add-on pricing. One nuance on scope worth knowing regardless of tooling: Microsoft documents that the winget CLI is not supported in the system context, and that EXE-based installer behaviour around scope is not necessarily deterministic.

Capabilities are taken from each vendor’s own documentation, and we say “not documented” rather than “not supported” where a vendor is simply silent. If something here is wrong or has changed, tell us and we will correct it — that is a cheaper outcome for everyone than an inaccurate comparison.

Check the claim yourself.

The detonation, the SBOM and the signed attestation all run in the free Community Edition, on your own hardware, for up to 50 endpoints.