Skip to main content
Intune script policies accept one script with no script parameters. Windows supports PowerShell policies and Win32 app packages. Generate a standalone installer for your platform with your SafeDep Cloud credentials embedded, then upload that file.
A SafeDep subscription is required to sync PMG events with SafeDep Cloud.
For Cloud sync, you need a SafeDep Cloud API key and Tenant ID from app.safedep.io/settings/api-keys. Installs sync to Package Guard. PMG blocking works without Cloud. For a local-only deployment, use the prebuilt standalone scripts or omit credentials and --embed-cloud-credentials when generating them.

Install

  1. Clone the main branch of pmg and generate the installer from scripts/mdm/:
    Optionally add --config /path/to/config.yml for managed config. Set cloud.enabled: true in that file.
Base64 is not encryption. Anyone who can read the uploaded installer in Intune can recover the credentials. Use a scoped, revocable API key. Do not commit the generated artifacts.
  1. Upload the generated installer through Intune, using the procedure for your platform:
    Follow Microsoft’s procedure for macOS shell scripts. Upload pmg_setup_install_macos_standalone.sh. Set Run script as signed-in user to No.
  2. Assign the policy to a device group. On macOS and Linux, use a recurring install frequency if new users can be added later. On Windows, only logged-on users receive credentials and sync during a run. Windows platform scripts do not run on a recurring schedule after success. Update the script or policy to rerun the installer when credentials are needed for later sign-ins. A direct standalone upload in Intune cannot pass --cloud-sync-only to the script. Run the normal installer again when you need to sync or configure later users.
Keep macOS and Linux shell scripts below 1 MB. Windows PowerShell scripts must be below 200 KB, including embedded config and credentials.

Uninstall

Upload the matching uninstaller from the same output directory (pmg_uninstall_macos_standalone.sh, pmg_uninstall_linux_standalone.sh, or pmg_uninstall_windows_standalone.ps1), with the same platform settings as install. Do not assign the install and uninstall policies at the same time.

Windows Win32 app

Use a Win32 app to bundle a release binary, including for devices without GitHub access.
  1. Put lib_windows.ps1, pmg_setup_install_windows.ps1, and pmg_uninstall_windows.ps1 from scripts/mdm/windows in one source folder.
  2. Add pmg.exe from the Windows x86-64 release zip of v0.29.0 or later. A bundled binary must be owned by Administrators or SYSTEM. For Cloud sync, add config.yml with cloud.enabled: true and your other policy settings.
  3. Package the folder with Microsoft’s Content Prep Tool and add the Win32 app.
  4. Set the install command:
  5. Set the uninstall command:
  6. Set Install behavior to System. Add a file-exists detection rule for %ProgramFiles%\safedep\pmg\pmg.exe, with Associated with a 32-bit app on 64-bit clients set to No.
  7. Assign the app to the Windows device group.
A Win32 app does not set the Cloud environment variables. Have users run pmg cloud login in their own sessions, or package the credential-bearing standalone installer generated above and use its filename in the install command. Keep cloud.enabled: true in the managed config.

Other MDMs

Jamf, JumpCloud, and the script layout.

MDM scripts README

Source of truth in the PMG repo.