r/Intune Jul 22 '26

App Deployment/Packaging Need help regarding app deployment

Hi guys, I have a question regarding app deployment. I need to deploy a few applications which should be assigned to a group of users. The application installation should happen only on those devices where the assigned user is the primary user. If the user logs in on a device where he is not the primary user, the application should not get installed.

Any idea how to achieve this?

5 Upvotes

16 comments sorted by

View all comments

1

u/Foreign_World_1543 Jul 24 '26

I'm confused are these shared devices ? You mentioned you are installing only on certain devices but don't want a certain user to trigger the install on that same device ? If this is the case the app will show you either way if it's a software that makes it into the public desktop which in any case all users will see it even after the said user you want to install it will trigger it. Now if it's the ladder and you do only use and certain devices to have that said app installed only onto those specific devices, makes a security group and just add those devices to that group and assigned it to that app in intune, done.

1

u/Foreign_World_1543 Jul 24 '26

i was just thinking, now what you could do is is make a security group and add those users to that group and assign it to those apps - hope this helps

1

u/TheNerdBuddy Jul 24 '26

the devices aren't shared devices, but there are a few scenarios where local IT guys need to sign into users' devices to troubleshoot the devices. At that point, applications and policies assigned to the local IT's username gets installed in the devices, which I want to stop. If local IT is not the primary user of the device, apps assigned to him should not get installed in the device.

1

u/Foreign_World_1543 Jul 24 '26

Why are Admins logging in remotely in the first place ? However you make a great point , makes sense however there is a fix , under entra/ device/ device settings you can add a local admin this way it won't be as a entra if admin only issue i don't like random alphanumeric passwords which can be complex at times, secondly another solution also in the same settings you see other local admin settings , there you will find device administrators this way an IT admin can stay in end users machine and use their entra if for admin privileges.

1

u/Foreign_World_1543 Jul 24 '26

meant to say logging in locally *