A SafeDep subscription is required to sync PMG events with SafeDep Cloud.
--embed-cloud-credentials when generating them.
Install
-
Clone the
mainbranch of pmg and generate the installer fromscripts/mdm/:- macOS
- Linux
- Windows
Optionally add--config /path/to/config.ymlfor managed config. Setcloud.enabled: truein that file.
-
Upload the generated installer through Intune, using the procedure for your platform:
- macOS
- Linux
- Windows
Follow Microsoft’s procedure for macOS shell scripts. Uploadpmg_setup_install_macos_standalone.sh. Set Run script as signed-in user to No. -
Assign the policy to a device group. On macOS and Linux, use a recurring install frequency if new users can be added later. On Windows, only logged-on users receive credentials and sync during a run. Windows platform scripts do not run on a recurring schedule after success. Update the script or policy to rerun the installer when credentials are needed for later sign-ins.
A direct standalone upload in Intune cannot pass
--cloud-sync-onlyto the script. Run the normal installer again when you need to sync or configure later users.
Uninstall
Upload the matching uninstaller from the same output directory (pmg_uninstall_macos_standalone.sh, pmg_uninstall_linux_standalone.sh, or pmg_uninstall_windows_standalone.ps1), with the same platform settings as install. Do not assign the install and uninstall policies at the same time.
Windows Win32 app
Use a Win32 app to bundle a release binary, including for devices without GitHub access.-
Put
lib_windows.ps1,pmg_setup_install_windows.ps1, andpmg_uninstall_windows.ps1fromscripts/mdm/windowsin one source folder. -
Add
pmg.exefrom the Windows x86-64 release zip of v0.29.0 or later. A bundled binary must be owned by Administrators or SYSTEM. For Cloud sync, addconfig.ymlwithcloud.enabled: trueand your other policy settings. - Package the folder with Microsoft’s Content Prep Tool and add the Win32 app.
-
Set the install command:
-
Set the uninstall command:
-
Set Install behavior to System. Add a file-exists detection rule for
%ProgramFiles%\safedep\pmg\pmg.exe, with Associated with a 32-bit app on 64-bit clients set to No. - Assign the app to the Windows device group.
pmg cloud login in their own sessions, or package the credential-bearing standalone installer generated above and use its filename in the install command. Keep cloud.enabled: true in the managed config.
Other MDMs
Jamf, JumpCloud, and the script layout.
MDM scripts README
Source of truth in the PMG repo.

