Where we are going
Roadmap
IntuneBrew today gets macOS apps into Intune without manual packaging. Next it answers the question neither tool can answer alone: which of your Macs are running a version with a known exploited vulnerability, and what should you ship to fix it. A short roadmap on purpose. All of it stays free and open source.
1,133 apps in the catalog today/19 items tracked/3 phases ahead/last reviewed July 2026
The milestones that matter most
- Catalog, CVE data, and Intune uploadShippedLive
- Fleet vulnerability viewIn progressQ3 2026
- Update rings and auto publishNext upQ4 2026
- Endpoint agentExploring2027
Full detail on all 27 items below, including what already ships today.
Filter by theme
Showing all 27 items.
What IntuneBrew already does
The catalog, the packaging pipeline, and the Intune upload path are in production and free to use right now.
Maintained macOS app catalog
Catalog
Versions, hashes, and icons kept current automatically, with no packaging work on your side.
Zero touch packaging
Catalog
DMG, ZIP, and APP sources are repackaged into signed PKG installers. Vendor PKGs pass through untouched.
Direct upload to Intune
Integrations
Chunked, encrypted uploads over Microsoft Graph with retry, duplicate detection, and live progress.
CVE and known exploited vulnerability data
Catalog
Every app is matched against NVD and the CISA KEV catalog so you can prioritize by real risk.
Assignment and scope tag handling
Rollout control
Keep existing assignments across updates, apply scope tags, and optionally remove superseded versions.
Bulk updates and reporting
Fleet visibility
Push many outdated apps in one run, and export inventory, outdated app, and vulnerability reports as CSV or PDF.
Email, Slack, and webhook alerts
Integrations
Per app subscriptions plus outbound webhooks for your own automation.
PowerShell, Azure Runbook, and GitHub Actions
Integrations
Run the whole pipeline unattended inside your own tenant using managed identity or certificate auth.
See the fleet
Intune already knows which apps and versions are on your Macs. IntuneBrew already knows which versions are vulnerable. Joining those two answers the question neither can answer alone, and it needs no software on the endpoint.
Device and app inventory
Fleet visibility
Read installed apps and versions per Mac straight from Intune over Microsoft Graph. No agent to deploy.
Fleet vulnerability view
Fleet visibility
See exactly which devices are running a version with a known exploited vulnerability, and ship the fix from the same screen.
Unmanaged app report
Fleet visibility
Surface apps your users installed themselves that Intune never deployed, and bring them under management in one click.
Catalog matching metadata
Catalog
Bundle identifiers, publishers, and team identifiers on every catalog entry so inventory reliably matches the right app.
Known exploited vulnerability alerts
Fleet visibility
Get told the moment a version running on your Macs picks up a known exploited vulnerability, on the email, Slack, or webhook destination you already configured.
Roles and team access
Fleet visibility
Invite colleagues as administrator or viewer instead of sharing one account.
Control the rollout
Decide when a new version reaches which machines. Because IntuneBrew controls the moment an app is published to Intune, rings and delays are scheduling decisions, not something that has to run on the Mac.
Phased publishing
Rollout control
Hold a new version back by a set number of days before it reaches broad assignment, with wildcard rules per publisher.
Named update rings
Rollout control
Canary, early adopter, and broad rings mapped to your existing Intune groups, published on a staggered schedule.
Scheduled auto publish
Rollout control
Let a new version flow into Intune automatically the moment it ships, or on the cadence you choose.
Automatic vulnerability remediation
Rollout control
When a known exploited vulnerability is confirmed on a version in your fleet, publish the fixed version to the affected groups instead of waiting for the next manual review.
Baseline app sets
Rollout control
Define the apps every Mac in a group should have and publish the whole set in one action, so a new device lands fully equipped. No agent needed.
Microsoft Teams notifications
Integrations
A first class Teams destination alongside the existing Slack and generic webhook support.
Intune custom attributes
Integrations
A shell script that surfaces pending updates and vulnerable app counts inside native Intune device reporting.
Read only API
Integrations
Pull catalog, fleet, and vulnerability data as JSON for your own dashboards, exports, and compliance evidence.
MCP server
Integrations
Point Claude, Copilot, or any other MCP client at the same read only data and ask which Macs are exposed in plain language.
Endpoint agent
A small agent on the Mac, only if the community asks for it. It buys three things Graph and Intune assignment cannot: updating an app the moment it ships rather than on the next check in, letting a user postpone an update, and putting an app back when it is removed. Deliberately not a second app store, because Company Portal already is one.
Narrow macOS agent
Endpoint agent
A signed command line agent that installs and updates catalog apps on device. No self service store, no branding, no local admin rights required.
Update deferrals
Endpoint agent
Give users a configurable window before an update is installed for them, with a clear enforcement deadline.
Mandatory apps
Endpoint agent
Name the apps that must always be present. They reinstall automatically if removed.
Configuration profile generator
Endpoint agent
Build the agent's profile in the portal, or push it straight into your tenant over Graph.
Timeframes are intentions, not commitments. IntuneBrew is a community project, so priorities shift with what admins actually ask for. Items can move between phases and nothing here is a contractual promise. Last reviewed July 2026.
Know when this ships
Every release and roadmap update gets posted on LinkedIn, so following the page is the fastest way to hear what shipped.