A community where customers and the community can provide feedback to make a better product for everyone! For more details on how we prioritize requests, please see:
Organizations may have multiple business units or device populations within the same Intune tenant that operate under different PowerShell execution policies. Some devices require signed scripts (AllSigned), while others do not. Today, when Patch My PC Publisher digitally signs a detection script, it also forces the Intune"Enforce signature check" setting to be enabled. This creates an all-or-nothing scenario that limits deployment flexibility.
Customer Need
Customers want the ability to publish applications and updates with digitally signed detection scripts while independently controlling whether Intune enforces signature validation. This would allow organizations to:
Deploy a signed detection script to satisfy environments that require signed content.
Publish the same application/update across different device populations within the same tenant.
Support mixed execution policy environments without maintaining separate packaging processes.
Align Patch My PC publishing behavior with varying organizational security requirements.
Requested Enhancement
Separate the following Publisher behaviors into independent configuration options:
Digitally Sign Detection Script
Enable Intune Signature Enforcement ("Enforce Signature Check")
This would allow administrators to:
Sign detection scripts without automatically enabling Intune signature enforcement.
Continue using the current behavior when both options are desired.
Configure signing and enforcement independently based on organizational or deployment requirements.
Business Value
Supports enterprises with varying security policies across departments or divisions.
Reduces the need for duplicate applications or deployment workarounds.
Provides greater flexibility when publishing Win32 applications to Intune.
Accommodates both highly regulated environments and less restrictive device groups within the same tenant.
Example Scenario
A customer has multiple divisions within a single Intune tenant. One division operates with an AllSigned PowerShell execution policy and requires signed scripts, while another division does not enforce script signing. The customer wants to publish a single application containing a signed detection script but does not want Intune's signature enforcement setting enabled for every deployment. Today, Publisher automatically couples these settings, preventing that deployment model.
Thank you - we've read and noted this Feature Request and believe we understand the ask.
We triage and stack rank based on customer demand (Vote counts), resourcing and other factors and will update the status if/when this Feature makes progress.