Intune Import Example
This example demonstrates how to import and deploy detection and remediation scripts to Microsoft Intune. It includes sample scripts that follow proper exit code conventions and logging practices.
Overview
This folder contains:
detection.ps1 - Sample detection script demonstrating proper structure and exit codes
remediation.ps1 - Sample remediation script with ShouldProcess support and logging
- Step-by-step import guide for deploying to Microsoft Intune
Files in this Example
detection.ps1
Detection script that checks for a common system condition and returns proper exit codes:
- Exit 0: System is compliant (no remediation needed)
- Exit 1: Issue detected (remediation required)
Remediation script that fixes the detected issue with:
- ShouldProcess support for safe testing with -WhatIf
- Proper error handling and logging
- Standardized exit codes for Intune integration
Step-by-Step Import Guide
Prerequisites
Step 1: Prepare Scripts
- Download sample scripts from this folder:
detection.ps1
remediation.ps1
- Customize scripts for your environment:
- Update detection logic for your specific use case
- Modify remediation actions as needed
- Test scripts locally with
-WhatIf parameter
- Validate script structure:
# Test detection script
.\detection.ps1
# Test remediation script (safe mode)
.\remediation.ps1 -WhatIf
Step 2: Access Intune Admin Center
- Navigate to Microsoft Intune admin center
- Sign in with administrator credentials
- Go to Reports > Endpoint analytics > Remediations
- Click “+ Create script package”
- Configure basic settings:
- Name:
Sample System Check Remediation
- Description:
Detects and remediates common system configuration issues
- Publisher: Your organization name
- Click “Next”
Step 4: Upload Detection Script
- In the Settings page:
- Click “Browse” under Detection script
- Select your
detection.ps1 file
- Upload the script
- Configure detection settings:
- Run this script using the logged-on credentials:
No (recommended)
- Enforce script signature check:
Yes (for production)
- Run script in 64-bit PowerShell:
Yes
- Upload remediation script:
- Click “Browse” under Remediation script
- Select your
remediation.ps1 file
- Upload the script
- Configure remediation settings:
- Run this script using the logged-on credentials:
No (recommended)
- Enforce script signature check:
Yes (for production)
- Run script in 64-bit PowerShell:
Yes
- Click “Next”
- Select target groups:
- Click ”+ Add group”
- Choose “Include” assignment type
- Select appropriate device groups (start with pilot group)
- Configure assignment settings:
- Run frequency:
Daily (recommended for initial testing)
- Reboot device if required: Configure based on your remediation needs
- Click “Next”
- Add scope tags if your organization uses them:
- Select appropriate scope tags for your deployment
- Ensure tags match your permissions and organizational structure
- Click “Next”
Step 8: Review and Create
- Review configuration:
- Verify script names and settings
- Confirm assignment groups
- Check schedule configuration
- Click “Create” to deploy the remediation
Step 9: Monitor Deployment
- Check deployment status:
- Return to Reports > Endpoint analytics > Remediations
- Select your new remediation package
- Monitor device compliance and remediation results
- Review device-level results:
- Click on the remediation name
- Go to Device status tab
- Check individual device results and any errors
- Analyze results:
- Compliant: Devices where no issues were detected
- Not compliant: Devices where issues were found but not yet remediated
- Remediated: Devices where issues were successfully fixed
- Error: Devices where scripts failed to execute properly
Testing and Validation
Pre-deployment Testing
# Test detection script
.\detection.ps1
Write-Host "Exit code: $LASTEXITCODE"
# Test remediation script safely
.\remediation.ps1 -WhatIf
Pilot Deployment
- Start with small pilot group (5-10 devices)
- Monitor results for 24-48 hours
- Validate remediation effectiveness
- Check for any adverse effects
- Expand to larger groups once validated
Troubleshooting Common Issues
| Issue |
Possible Cause |
Solution |
| Script not running |
Execution policy |
Configure via Intune policy, not Set-ExecutionPolicy |
| Permission errors |
Insufficient rights |
Review script context and required permissions |
| Detection false positives |
Logic errors |
Review detection script conditions |
| Remediation failures |
Resource conflicts |
Add error handling and retry logic |
| Slow deployment |
Assignment propagation |
Allow 8+ hours for full deployment |
Best Practices
Script Development
- Always include proper error handling
- Use Write-Information instead of Write-Host
- Support -WhatIf parameter for testing
- Follow consistent exit code conventions
- Include detailed logging for troubleshooting
Deployment Strategy
- Test scripts thoroughly before deployment
- Start with pilot groups
- Monitor results closely
- Have rollback procedures ready
- Document all changes and results
Security Considerations
- Never hardcode credentials or secrets
- Use appropriate execution contexts
- Sign scripts in production environments
- Limit script modification permissions
- Maintain audit trail of all changes
Next Steps
- Customize the sample scripts for your specific requirements
- Test in your environment using the provided samples
- Follow the import guide to deploy your first remediation
- Review results and iterate on your approach
- Scale to additional use cases using lessons learned
Additional Resources
This example provides a foundation for implementing Intune remediations in your environment. Customize the scripts and processes according to your specific requirements and organizational policies.