Instiq
Chapter 4 · Manage and secure applications·v1.0.0·Updated 6/30/2026·~14 min

What's changed: Created MD-102 Chapter 4 (domain: Manage and secure applications). Deploy/update apps (Win32 app .intunewin/LOB app/Microsoft Store app, Microsoft 365 Apps, Office Deployment Tool, Microsoft 365 Apps admin center, Apple VPP/Google Play, Quiet Time policies, deployment status monitoring and installation failures) and app protection/configuration policies (app protection policies MAM in-app data protection for managed/unmanaged BYOD, require app protection via Conditional Access, app configuration policies).

4.1Deploy and update apps

Key points

Understand Win32/LOB/Microsoft Store apps, Microsoft 365 Apps and the Office Deployment Tool, Apple VPP and Google Play, Quiet Time policies, and monitoring/troubleshooting installation failures.

Prepare/deploy apps by format. Intune centralizes distribution and monitoring.

4.1.1App types and deployment

Win32 apps are classic desktop apps packaged as .intunewin for deployment; line-of-business (LOB) apps are in-house apps; Microsoft Store apps are store-delivered. Deploy Microsoft 365 Apps (Office) via Intune, or configure with the Office Deployment Tool (ODT). Manage Office policies also in the Microsoft 365 Apps admin center. License/deploy store apps via Apple Volume Purchase Program (VPP) or Google Play. Distinguish ".intunewin classic" = Win32 app from "store-delivered" = Store app.

4.1.2Quiet time and monitoring

Quiet Time policies suppress notifications for Android/iOS apps during set hours (e.g., off-hours). Monitor deployment status in Intune and investigate installation failures to isolate causes (dependencies, detection rules, requirements).

Exam point

Cues: ".intunewin classic desktop app" = Win32 app. "in-house app" = LOB app. "store-delivered app" = Microsoft Store app. "deploy Office" = Microsoft 365 Apps (ODT/Intune). "license/deploy Apple/Android store apps" = Apple VPP/Google Play. "suppress notifications by time" = Quiet Time policies.

Warning

Watch the mix-ups: (1) Win32 app (.intunewin) vs Microsoft Store app vs LOB app. (2) Microsoft 365 Apps deployment uses ODT/Intune to deploy Office (a dedicated path, not Win32). (3) Apple VPP for Apple, Google Play for Android store apps. (4) Quiet Time policies suppress notifications—distinct from app protection.

Diagram: deploy apps by format — Win32 app (classic, packaged as .intunewin), line-of-business (LOB) app (in-house), Microsoft Store app (store-delivered); Microsoft 365 Apps (Office) via Intune/Office Deployment Tool (ODT), also managed in the Microsoft 365 Apps admin center; store apps via Apple Volume Purchase Program (VPP)/Google Play; Quiet Time policies suppress notifications by time; monitor deployment status to investigate installation failures.
Deploy by format

4.1.3Section summary

  • Deploy by format: Win32 app (.intunewin)/LOB app/Microsoft Store app
  • Microsoft 365 Apps via ODT/Intune; Apple VPP/Google Play for store apps
  • Quiet Time policies suppress notifications; monitor deployment status to investigate failures

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To deploy a classic desktop app (with an installer) via Intune, which package format should you convert it to first?

Q2. You want to deploy Office (Microsoft 365 Apps) via Intune and also configure with ODT. Best?

Q3. For iPhones, you want to distribute org-licensed App Store apps via Intune. Best?

Q4. You want to suppress employees’ mobile app notifications during set hours (e.g., off-hours). Best?

Q5. A deployed app is failing to install on many devices. What should you check first to isolate the cause?

Check your understandingPractice questions for Chapter 4: Manage and secure applications

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.