Where we are going
Roadmap
IntuneBrew today gets macOS apps into Intune without manual packaging. Next it answers the question neither tool can answer alone: which of your Macs are running a version with a known exploited vulnerability, and what should you ship to fix it. A short roadmap on purpose. All of it stays free and open source.
1,143 apps in the catalog today/13 items tracked/2 phases ahead/last reviewed September 2026
The milestones that matter most
- Catalog, CVE data, and Intune uploadShippedLive
- Fleet vulnerability viewShippedQ3 2026
- Staggered rollouts and auto publishIn progressQ4 2026
- Endpoint agentExploring2027
Full detail on all 29 items below, including what already ships today.
Filter by theme
Showing all 29 items.
What IntuneBrew already does
The catalog, the packaging pipeline, the Intune upload path, and the first rollout controls are in production and free to use right now.
Maintained macOS app catalog
Catalog
Versions, hashes, and icons kept current automatically, with no packaging work on your side.
Zero touch packaging
Catalog
DMG, ZIP, and APP sources are repackaged into signed PKG installers. Vendor PKGs pass through untouched.
Direct upload to Intune
Integrations
Chunked, encrypted uploads over Microsoft Graph with retry, duplicate detection, and live progress.
CVE and known exploited vulnerability data
Catalog
Every app is matched against NVD and the CISA KEV catalog so you can prioritize by real risk.
Assignment and scope tag handling
Rollout control
Keep existing assignments across updates, apply scope tags, and optionally remove superseded versions.
Update rings
Rollout control
Map rings to your existing Entra groups, publish a new version to a ring first, and promote it to the next ring when you are ready. The previous version stays live meanwhile.
Per app hold back
Rollout control
Hold a new version back for up to 30 days per app. Held versions stay out of bulk updates until the window passes, and publishing one early warns you first.
Bulk updates and reporting
Fleet visibility
Push many outdated apps in one run, and export inventory, outdated app, and vulnerability reports as CSV or PDF.
Email, Slack, and webhook alerts
Integrations
Per app subscriptions plus outbound webhooks for your own automation.
PowerShell, Azure Runbook, and GitHub Actions
Integrations
Run the whole pipeline unattended inside your own tenant using managed identity or certificate auth.
See the fleet
Intune already knows which apps and versions are on your Macs. IntuneBrew already knows which versions are vulnerable. Joining those two answers the question neither can answer alone, and it needs no software on the endpoint.
Device and app inventory
Fleet visibility
Read installed apps and versions per Mac straight from Intune over Microsoft Graph. No agent to deploy.
Fleet vulnerability view
Fleet visibility
See exactly which devices are running a version with a known exploited vulnerability, and ship the fix from the same screen.
Unmanaged app report
Fleet visibility
Surface apps your users installed themselves that Intune never deployed, and bring them under management in one click.
Catalog matching metadata
Catalog
Publishers and bundle identifiers on every catalog entry, so apps detected by Intune match the right catalog app by name and publisher.
Known exploited vulnerability alerts
Fleet visibility
Get told when a version of an app deployed in your tenant picks up a known exploited vulnerability, checked daily and sent to the email, Slack, or webhook destination you already configured.
Roles and team access
Fleet visibility
Invite colleagues by email as administrator or viewer instead of sharing one account.
Control the rollout
Decide when a new version reaches which machines. Because IntuneBrew controls the moment an app is published to Intune, rings and delays are scheduling decisions, not something that has to run on the Mac. Update rings and per app hold back are already live; this phase builds on them.
Publisher hold back rules
Rollout control
Set one hold back window for every app from a publisher with a wildcard rule, instead of configuring each app on its own.
Staggered ring schedules
Rollout control
Move a new version from ring to ring on a schedule you define, instead of promoting each step by hand.
Scheduled auto publish
Rollout control
Let a new version flow into Intune automatically the moment it ships, or on the cadence you choose.
Automatic vulnerability remediation
Rollout control
When a known exploited vulnerability is confirmed on a version in your fleet, publish the fixed version to the affected groups instead of waiting for the next manual review.
Baseline app sets
Rollout control
Define the apps every Mac in a group should have and publish the whole set in one action, so a new device lands fully equipped. No agent needed.
Microsoft Teams notifications
Integrations
A first class Teams destination alongside the existing Slack and generic webhook support.
Intune custom attributes
Integrations
A shell script that surfaces pending updates and vulnerable app counts inside native Intune device reporting.
Read only API
Integrations
Pull catalog, fleet, and vulnerability data as JSON for your own dashboards, exports, and compliance evidence.
MCP server
Integrations
Point Claude, Copilot, or any other MCP client at the same read only data and ask which Macs are exposed in plain language.
Endpoint agent
A small agent on the Mac, only if the community asks for it. It buys three things Graph and Intune assignment cannot: updating an app the moment it ships rather than on the next check in, letting a user postpone an update, and putting an app back when it is removed. Deliberately not a second app store, because Company Portal already is one.
Narrow macOS agent
Endpoint agent
A signed command line agent that installs and updates catalog apps on device. No self service store, no branding, no local admin rights required.
Update deferrals
Endpoint agent
Give users a configurable window before an update is installed for them, with a clear enforcement deadline.
Mandatory apps
Endpoint agent
Name the apps that must always be present. They reinstall automatically if removed.
Configuration profile generator
Endpoint agent
Build the agent's profile in the portal, or push it straight into your tenant over Graph.
Timeframes are intentions, not commitments. IntuneBrew is a community project, so priorities shift with what admins actually ask for. Items can move between phases and nothing here is a contractual promise. Last reviewed September 2026.
Know when this ships
Every release and roadmap update gets posted on LinkedIn, so following the page is the fastest way to hear what shipped.