Skip to content
Beer Mug Logo
IntuneBrewby UgurLabs.com
Back to home

Where we are going

Roadmap

IntuneBrew today gets macOS apps into Intune without manual packaging. Next it answers the question neither tool can answer alone: which of your Macs are running a version with a known exploited vulnerability, and what should you ship to fix it. A short roadmap on purpose. All of it stays free and open source.

1,133 apps in the catalog today/19 items tracked/3 phases ahead/last reviewed July 2026

The milestones that matter most

  1. Catalog, CVE data, and Intune uploadShippedLive
  2. Fleet vulnerability viewIn progressQ3 2026
  3. Update rings and auto publishNext upQ4 2026
  4. Endpoint agentExploring2027

Full detail on all 27 items below, including what already ships today.

Filter by theme

Showing all 27 items.

Available todayShippedLive8 items

What IntuneBrew already does

The catalog, the packaging pipeline, and the Intune upload path are in production and free to use right now.

  • Maintained macOS app catalog

    Catalog

    Versions, hashes, and icons kept current automatically, with no packaging work on your side.

  • Zero touch packaging

    Catalog

    DMG, ZIP, and APP sources are repackaged into signed PKG installers. Vendor PKGs pass through untouched.

  • Direct upload to Intune

    Integrations

    Chunked, encrypted uploads over Microsoft Graph with retry, duplicate detection, and live progress.

  • CVE and known exploited vulnerability data

    Catalog

    Every app is matched against NVD and the CISA KEV catalog so you can prioritize by real risk.

  • Assignment and scope tag handling

    Rollout control

    Keep existing assignments across updates, apply scope tags, and optionally remove superseded versions.

  • Bulk updates and reporting

    Fleet visibility

    Push many outdated apps in one run, and export inventory, outdated app, and vulnerability reports as CSV or PDF.

  • Email, Slack, and webhook alerts

    Integrations

    Per app subscriptions plus outbound webhooks for your own automation.

  • PowerShell, Azure Runbook, and GitHub Actions

    Integrations

    Run the whole pipeline unattended inside your own tenant using managed identity or certificate auth.

Phase 1In progressQ3 20266 items

See the fleet

Intune already knows which apps and versions are on your Macs. IntuneBrew already knows which versions are vulnerable. Joining those two answers the question neither can answer alone, and it needs no software on the endpoint.

  • Device and app inventory

    Fleet visibility

    Read installed apps and versions per Mac straight from Intune over Microsoft Graph. No agent to deploy.

  • Fleet vulnerability view

    Fleet visibility

    See exactly which devices are running a version with a known exploited vulnerability, and ship the fix from the same screen.

  • Unmanaged app report

    Fleet visibility

    Surface apps your users installed themselves that Intune never deployed, and bring them under management in one click.

  • Catalog matching metadata

    Catalog

    Bundle identifiers, publishers, and team identifiers on every catalog entry so inventory reliably matches the right app.

  • Known exploited vulnerability alerts

    Fleet visibility

    Get told the moment a version running on your Macs picks up a known exploited vulnerability, on the email, Slack, or webhook destination you already configured.

  • Roles and team access

    Fleet visibility

    Invite colleagues as administrator or viewer instead of sharing one account.

Phase 2Next upQ4 20269 items

Control the rollout

Decide when a new version reaches which machines. Because IntuneBrew controls the moment an app is published to Intune, rings and delays are scheduling decisions, not something that has to run on the Mac.

  • Phased publishing

    Rollout control

    Hold a new version back by a set number of days before it reaches broad assignment, with wildcard rules per publisher.

  • Named update rings

    Rollout control

    Canary, early adopter, and broad rings mapped to your existing Intune groups, published on a staggered schedule.

  • Scheduled auto publish

    Rollout control

    Let a new version flow into Intune automatically the moment it ships, or on the cadence you choose.

  • Automatic vulnerability remediation

    Rollout control

    When a known exploited vulnerability is confirmed on a version in your fleet, publish the fixed version to the affected groups instead of waiting for the next manual review.

  • Baseline app sets

    Rollout control

    Define the apps every Mac in a group should have and publish the whole set in one action, so a new device lands fully equipped. No agent needed.

  • Microsoft Teams notifications

    Integrations

    A first class Teams destination alongside the existing Slack and generic webhook support.

  • Intune custom attributes

    Integrations

    A shell script that surfaces pending updates and vulnerable app counts inside native Intune device reporting.

  • Read only API

    Integrations

    Pull catalog, fleet, and vulnerability data as JSON for your own dashboards, exports, and compliance evidence.

  • MCP server

    Integrations

    Point Claude, Copilot, or any other MCP client at the same read only data and ask which Macs are exposed in plain language.

Phase 3Exploring20274 items

Endpoint agent

A small agent on the Mac, only if the community asks for it. It buys three things Graph and Intune assignment cannot: updating an app the moment it ships rather than on the next check in, letting a user postpone an update, and putting an app back when it is removed. Deliberately not a second app store, because Company Portal already is one.

  • Narrow macOS agent

    Endpoint agent

    A signed command line agent that installs and updates catalog apps on device. No self service store, no branding, no local admin rights required.

  • Update deferrals

    Endpoint agent

    Give users a configurable window before an update is installed for them, with a clear enforcement deadline.

  • Mandatory apps

    Endpoint agent

    Name the apps that must always be present. They reinstall automatically if removed.

  • Configuration profile generator

    Endpoint agent

    Build the agent's profile in the portal, or push it straight into your tenant over Graph.

Timeframes are intentions, not commitments. IntuneBrew is a community project, so priorities shift with what admins actually ask for. Items can move between phases and nothing here is a contractual promise. Last reviewed July 2026.

Know when this ships

Every release and roadmap update gets posted on LinkedIn, so following the page is the fastest way to hear what shipped.