Private beta · Waitlist open

Ship every app like your best one. One controlled path from installer to production.

PackageForge turns packaging standards into a repeatable release process—so endpoint teams can build once, publish to Intune and SCCM, and know exactly what happens next.

PF Release cockpit
Live
7z
7-Zip 24.09 PF-2026-0241 · PSADT v4
Ready
Inspectverified
Packagestandardized
Publishdual target
4
Roll outcontrolled
Production rolloutWave 03 / 03
Intune
94% healthy
SCCM
91% healthy
  • PSADT v4 packages
  • Intune + SCCM publishing
  • Staged rollout controls
  • End-to-end audit history

Turn packaging work into a repeatable service

Replace disconnected scripts, portal work, and manual handoffs with one clear process your team can repeat.

Give every application the same path from intake to production. PackageForge brings packaging, publishing, rollout control, and operational visibility together without replacing the Microsoft tools you already use.

Move faster
Start from an installer or catalog entry and reuse your standards instead of rebuilding the same package structure every time.
Stay consistent
Apply shared packaging rules across commercial, internal, and custom applications so quality does not depend on who built the package.
Reduce release risk
Check applications before publishing and move from pilot to production with clear gates and a traceable approval history.
Run one process
Publish the same application to Intune and SCCM while keeping deployment status and lifecycle decisions in one operational view.

One path from request to rollout

A shared workflow for application packaging, deployment, and lifecycle management.

01 / ANALYZE

Start with a trusted source

Discover · Inspect · Assess

Understand the application

PackageForge identifies the information your team needs to package an installer, reducing manual investigation and avoidable mistakes.

MSIEXEMSIX

Find approved software faster

Search trusted Windows and macOS sources from one catalog and bring the right version into your packaging workflow.

WinGetHomebrewSHA256

See risk before release

Surface known vulnerabilities and file reputation early, while there is still time to choose a safer version or stop the release.

VirusTotalNVDDefender TVM
02 / PACKAGE

Build to your standards

Create · Standardize · Review

Create a maintainable package

Generate an editable PSADT v4 foundation for install, uninstall, and repair, then adapt it for the application instead of starting from boilerplate.

PSADT v4Handlebars

Detect installations reliably

Start with suggested detection rules, review them, and keep control over how Intune and SCCM determine installation success.

MSIFileRegistryPowerShell

Reuse what your team knows

Turn proven packaging conventions into reusable blueprints so every engineer can deliver consistent results.

TemplatesReusable
03 / DEPLOY

Publish without duplicating work

Intune · SCCM · One workspace

Publish to Microsoft Intune

Prepare the Win32 application, carry over detection settings, and assign it to the right groups without repeating the process in the portal.

.intunewinGraph APIEntra groups

See every deployment together

Track application status, available updates, and replacement state across both deployment platforms from one view.

UnifiedReal-time

Respond to urgent updates

When risk or version drift appears, move the latest release through the same controlled process without rebuilding the workflow.

One flow
04 / GOVERN

Roll out with evidence, not guesswork

Stages · Status · Audit

Know what happened on each device

Bring installation outcomes back into the deployment view so your team can investigate failures with the right context.

Per-deviceRate-limited

Keep an accountable history

Use organizational sign-in, protected credentials, and a clear audit trail for the lifecycle actions your team performs.

OIDCAES-256-GCMAudit log

Keep the Microsoft stack you already run

PackageForge connects the packaging workflow around your existing platforms—without a new endpoint agent.

Microsoft Intune

Win32 and macOS app upload (DMG/PKG via Graph), group assignment & supersedence

SCCM / ConfigMgr

Relay-queue connector, HMAC-authenticated agents, supersedence, retire/restore.

Entra ID / OIDC

SSO via authorization code flow. Legacy password fallback for first-run.

WinGet

Windows software catalog — SHA256-verified downloads

Homebrew / Cask

macOS software catalog — search, SHA256-verified download, Intune upload (DMG/PKG)

VirusTotal + NVD

File-hash threat intel, CVE lookup by product/version, aggregated risk score.

Defender TVM

Cross-reference packages against your tenant's Defender vulnerability findings.

Common questions

The things the packaging team asks before they sign up.

Does it work with co-managed (Intune + SCCM) environments?

Yes — that's the primary use case. PackageForge publishes the same package to both targets from a single flow.

Does the SCCM relay require an on-premises agent?

Yes. A lightweight .NET connector runs on your ConfigMgr infrastructure and communicates outbound over HTTPS. No inbound firewall rules required.

Do you store our installers?

No. Installers and PSADT packages stay in your environment. PackageForge stores metadata, deployment status, and the audit record — not binaries.

Is the generated PSADT script editable after generation?

Yes. Every generated script is yours to edit before packaging runs. We generate the scaffold; you own the source.

What's included in beta access?

Full access to the packaging pipeline, Intune and SCCM publishing, Iron Chain rollouts, and the deployments dashboard. Capacity is limited per wave.

Is there a self-hosted option?

PackageForge v2 is web-only, hosted on Azure. A self-hosted option is on the roadmap — join the waitlist to vote on it.

Does PackageForge support macOS packaging?

Partially — here is what works today: The software catalog searches both WinGet (Windows) and Homebrew (macOS), and you can download and upload macOS apps (DMG and PKG format) directly to Microsoft Intune from the same workspace. PSADT packaging, SCCM deployment, and Iron Chain rollouts are Windows-only capabilities. If your team manages both Windows and macOS endpoints through Intune, the catalog and upload flow works today.

Join the private beta waitlist

We're letting in packaging engineers and endpoint teams in waves. Tell us what you run — we'll reach out when your spot opens.

Invites go out in waves. When your spot opens, you'll get a short email with early-access instructions — no sales call, no commitment.