# PSADT + SCCM Application Deployment — Plain-English Template Notes

> PSADT = **PowerShell App Deployment Toolkit**, the free, standard way IT pros
> wrap an application's installer so it deploys cleanly, quietly, and with
> proper logging through SCCM (ConfigMgr) or Intune. No telemetry in any of
> this — PSADT runs 100% locally on the target machine.

## The 5-minute mental model

Every PSADT package has the same three phases, in one file called
`Deploy-Application.ps1`:

1. **Pre-Install** — close the app if it's running, check disk space, stop
   conflicting processes. ("Is it safe to install right now?")
2. **Install** — run the actual installer silently (`.msi /qn`, `.exe /S`,
   whatever the vendor documents). ("Do the thing.")
3. **Post-Install** — clean up shortcuts, set registry keys, write a log.
   ("Leave the machine tidy and prove it worked.")

SCCM doesn't care what's inside — it just runs your script and reads the
**exit code**: `0` = success, `3010` = success but needs a reboot, anything
else = failure (check the log).

## Folder layout (the convention)

```
MyApp_1.2.3/
├── Deploy-Application.ps1      <- your three phases live here
├── AppDeployToolkit/           <- the PSADT framework files (download once)
└── Files/                      <- the vendor's installer goes here
    └── setup.exe
```

Download the PSADT framework free from https://psappdeploytoolkit.com
and drop it in as `AppDeployToolkit/`. You never edit those files.

## Minimal skeleton (copy, rename, fill in YOUR app)

```powershell
## Pre-Install: close the app so files aren't locked
Show-InstallationWelcome -CloseApps 'myapp' -CloseAppsCountdown 300

## Install: silent install, no user clicking
Execute-Process -Path "$dirFiles\setup.exe" -Parameters '/S' -WindowStyle Hidden

## Post-Install: log it and finish
Write-Log "MyApp 1.2.3 installed successfully."
```

Replace `'myapp'` with the real process name and `'/S'` with the vendor's
documented silent switch (always check the vendor docs — `/S`, `/silent`,
`/qn`, and `--quiet` are all common).

## SCCM checklist (tape this to your monitor)

- [ ] **Detection method:** tell SCCM how to know it's installed
      (e.g. registry key `HKLM\SOFTWARE\Vendor\MyApp` with the version,
      or the MSI product code). Without this, SCCM reinstalls forever.
- [ ] **Install behavior:** "Install for system" in most cases.
- [ ] **Test on ONE machine first** (or a pilot collection), then roll wide.
- [ ] **Read the log** on failure: PSADT writes to
      `C:\Windows\Logs\Software\` by default.
- [ ] **Reboot exit code 3010** is normal — it means "done, reboot pending."
      SCCM handles it; don't treat it as a failure.

## Intune notes

Same package works in Intune: wrap the folder as `.intunewin` with the
Microsoft Win32 Content Prep Tool, then use the same detection rule.
Install command: `Deploy-Application.exe` (the compiled wrapper) or
`powershell.exe -ExecutionPolicy Bypass -File Deploy-Application.ps1`.

## What never goes in a package

- Passwords, API keys, license keys in plain text. Ever.
- Anything that phones home, reports back, or "checks in" — if the vendor's
  installer does it, that's their business; YOUR wrapper adds nothing.
- Hard-coded server names if you can avoid it — use variables at the top
  of the script so the next person can find them.
