Ship every app like your best one. One controlled path from installer to production.
PackageForge turns packaging standards into a repeatable release process—so endpoint teams can build once, publish to Intune and SCCM, and know exactly what happens next.
Why PackageForge
Turn packaging work into a repeatable service
Replace disconnected scripts, portal work, and manual handoffs with one clear process your team can repeat.
Give every application the same path from intake to production. PackageForge brings packaging, publishing, rollout control, and operational visibility together without replacing the Microsoft tools you already use.
How it works
One path from request to rollout
A shared workflow for application packaging, deployment, and lifecycle management.
Start with a trusted source
Discover · Inspect · AssessUnderstand the application
PackageForge identifies the information your team needs to package an installer, reducing manual investigation and avoidable mistakes.
Find approved software faster
Search trusted Windows and macOS sources from one catalog and bring the right version into your packaging workflow.
See risk before release
Surface known vulnerabilities and file reputation early, while there is still time to choose a safer version or stop the release.
Build to your standards
Create · Standardize · ReviewCreate a maintainable package
Generate an editable PSADT v4 foundation for install, uninstall, and repair, then adapt it for the application instead of starting from boilerplate.
Detect installations reliably
Start with suggested detection rules, review them, and keep control over how Intune and SCCM determine installation success.
Reuse what your team knows
Turn proven packaging conventions into reusable blueprints so every engineer can deliver consistent results.
Publish without duplicating work
Intune · SCCM · One workspaceManage the SCCM application lifecycle
Publish, replace, retire, and restore applications with impact previews and safeguards around high-risk changes.
Publish to Microsoft Intune
Prepare the Win32 application, carry over detection settings, and assign it to the right groups without repeating the process in the portal.
See every deployment together
Track application status, available updates, and replacement state across both deployment platforms from one view.
Respond to urgent updates
When risk or version drift appears, move the latest release through the same controlled process without rebuilding the workflow.
Roll out with evidence, not guesswork
Stages · Status · AuditMove through controlled stages
Roll out from pilot to broad and production groups using success thresholds that make the next step explicit and repeatable.
Know what happened on each device
Bring installation outcomes back into the deployment view so your team can investigate failures with the right context.
Keep an accountable history
Use organizational sign-in, protected credentials, and a clear audit trail for the lifecycle actions your team performs.
Fits your environment
Keep the Microsoft stack you already run
PackageForge connects the packaging workflow around your existing platforms—without a new endpoint agent.
Microsoft Intune
Win32 and macOS app upload (DMG/PKG via Graph), group assignment & supersedence
SCCM / ConfigMgr
Relay-queue connector, HMAC-authenticated agents, supersedence, retire/restore.
Entra ID / OIDC
SSO via authorization code flow. Legacy password fallback for first-run.
WinGet
Windows software catalog — SHA256-verified downloads
Homebrew / Cask
macOS software catalog — search, SHA256-verified download, Intune upload (DMG/PKG)
VirusTotal + NVD
File-hash threat intel, CVE lookup by product/version, aggregated risk score.
Defender TVM
Cross-reference packages against your tenant's Defender vulnerability findings.
FAQ
Common questions
The things the packaging team asks before they sign up.
Does it work with co-managed (Intune + SCCM) environments?
Yes — that's the primary use case. PackageForge publishes the same package to both targets from a single flow.
Does the SCCM relay require an on-premises agent?
Yes. A lightweight .NET connector runs on your ConfigMgr infrastructure and communicates outbound over HTTPS. No inbound firewall rules required.
Do you store our installers?
No. Installers and PSADT packages stay in your environment. PackageForge stores metadata, deployment status, and the audit record — not binaries.
Is the generated PSADT script editable after generation?
Yes. Every generated script is yours to edit before packaging runs. We generate the scaffold; you own the source.
What's included in beta access?
Full access to the packaging pipeline, Intune and SCCM publishing, Iron Chain rollouts, and the deployments dashboard. Capacity is limited per wave.
Is there a self-hosted option?
PackageForge v2 is web-only, hosted on Azure. A self-hosted option is on the roadmap — join the waitlist to vote on it.
Does PackageForge support macOS packaging?
Partially — here is what works today: The software catalog searches both WinGet (Windows) and Homebrew (macOS), and you can download and upload macOS apps (DMG and PKG format) directly to Microsoft Intune from the same workspace. PSADT packaging, SCCM deployment, and Iron Chain rollouts are Windows-only capabilities. If your team manages both Windows and macOS endpoints through Intune, the catalog and upload flow works today.
Join the private beta waitlist
We're letting in packaging engineers and endpoint teams in waves. Tell us what you run — we'll reach out when your spot opens.