{"id":534,"date":"2023-10-06T10:09:39","date_gmt":"2023-10-06T08:09:39","guid":{"rendered":"https:\/\/configroar.com\/?p=534"},"modified":"2023-10-06T16:20:11","modified_gmt":"2023-10-06T14:20:11","slug":"enable-the-allow-available-uninstall-feature-for-all-win32-apps-in-intune-with-powershell-and-graph-api","status":"publish","type":"post","link":"https:\/\/configroar.com\/?p=534","title":{"rendered":"Enable the &#8220;Allow available uninstall&#8221; Feature for all Win32 Apps in Intune with PowerShell and Graph API"},"content":{"rendered":"\n<p class=\"has-medium-font-size wp-block-paragraph\">Recently Microsoft announced the &#8220;new&#8221; Intune feature allowing end-users to uninstall Apps from the Company Portal: <a href=\"https:\/\/www.youtube.com\/watch?v=rLJU9ERO81Y\">https:\/\/www.youtube.com\/watch?v=rLJU9ERO81Y<\/a><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">I&#8217;ve written &#8220;new&#8221; like that, because SCCM had this feature in the Software Center since ages and quite frankly it makes sense to be able to uninstall an application, if you installed by yourself on the first place (not talking about push apps)<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"811\" height=\"416\" src=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image.png\" alt=\"\" class=\"wp-image-539\" srcset=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image.png 811w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-300x154.png 300w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-768x394.png 768w\" sizes=\"auto, (max-width: 811px) 100vw, 811px\" \/><\/figure>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">This feature is activated for all new Win32 Apps, which are created in the tenant, but what about the old ones ? <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">In order to activate it, you need to enable it in Intune, on the application program settings: <br><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"865\" height=\"395\" src=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-1.png\" alt=\"\" class=\"wp-image-540\" srcset=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-1.png 865w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-1-300x137.png 300w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-1-768x351.png 768w\" sizes=\"auto, (max-width: 865px) 100vw, 865px\" \/><\/figure>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Since I have many client tenants and if I have to do something more than twice, I usually automate it, I wrote a quick PowerShell script to do the trick for all Apps in the tenant <\/p>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\">Prerequisites: <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\" style=\"font-style:normal;font-weight:500\">You&#8217;d need an Enterprise App in Azure with the Application Permissions <em>DeviceManagementApps.ReadWrite.All<\/em><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"488\" src=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-2-1024x488.png\" alt=\"\" class=\"wp-image-546\" srcset=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-2-1024x488.png 1024w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-2-300x143.png 300w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-2-768x366.png 768w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-2.png 1026w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Secondly you need to create a certificate for authentication.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">You can use an official certificate provider or, like in this demo, create a self-signed one. <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The process is documented here: <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/develop\/howto-create-self-signed-certificate\">Create a self-signed public certificate to authenticate your application &#8211; Microsoft Entra | Microsoft Learn<\/a><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$certname = \"&lt;REPLACE WITH CERTIFICATE NAME&gt;\"\n$cert = New-SelfSignedCertificate -Subject \"CN=$certname\" -CertStoreLocation \"Cert:\\CurrentUser\\My\" -KeyExportPolicy Exportable -KeySpec Signature -KeyLength 2048 -KeyAlgorithm RSA -HashAlgorithm SHA256\n\nExport-Certificate -Cert $cert -FilePath \"C:\\tmp\\Test\\Certificates\\$certname.cer\"   ## Specify your preferred location<\/code><\/pre>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Once you have created the self-signed certificate, import it in your app registration and you&#8217;re ready to go: <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"171\" src=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-3-1024x171.png\" alt=\"\" class=\"wp-image-557\" srcset=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-3-1024x171.png 1024w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-3-300x50.png 300w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-3-768x128.png 768w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-3.png 1316w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Here is the script, which gets all Win32 Applications from your Intune Tenant and enables the &#8220;Allow Available Uninstall&#8221; feature, if it was not already enabled: <\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><a href=\"https:\/\/github.com\/Nikolay-Marinov\/Intune-Allow-available-uninstall\/blob\/main\/Intune-Enable-Uninstall-on-Demand.ps1\" target=\"_blank\" rel=\"noreferrer noopener\">Intune-Allow-available-uninstall.ps1<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">**<em>Disclaimer: The script is provided AS IS without warranty of any kind. For detailed disclaimer, please look in the script<\/em><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Just add the correct parameters for TenantID , ApplicationID and Certificate Thumbprint, like this: <\/p>\n\n\n\n<p class=\"has-small-font-size wp-block-paragraph\"><em>Intune-Enable-Uninstall-on-Demand.ps1 -TenantId &#8220;12345678-90ab-cdef-1234-567890abcdef&#8221; -ApplicationId &#8220;00000000-0000-0000-0000-000000000000&#8221; -CertificateThumbprint &#8220;1234567890abcdef1234567890abcdef12345678&#8221;<\/em><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Once you execute the script, it will get all Win32 Apps from your Intune tenant, and if the feature is disabled, it will get enabled via GraphAPI: <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"687\" height=\"180\" src=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-4.png\" alt=\"\" class=\"wp-image-564\" srcset=\"https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-4.png 687w, https:\/\/configroar.com\/wp-content\/uploads\/2023\/10\/image-4-300x79.png 300w\" sizes=\"auto, (max-width: 687px) 100vw, 687px\" \/><\/figure>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Happy Scripting \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently Microsoft announced the &#8220;new&#8221; Intune feature allowing end-users to uninstall Apps from the Company Portal: https:\/\/www.youtube.com\/watch?v=rLJU9ERO81Y I&#8217;ve written &#8220;new&#8221; like that, because SCCM had<\/p>\n","protected":false},"author":2,"featured_media":567,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[60,6,42],"tags":[50,51,63,2,49],"class_list":["post-534","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-graph-api","category-intune","category-powershell","tag-automation","tag-azure","tag-graphapi","tag-intune","tag-powershell"],"_links":{"self":[{"href":"https:\/\/configroar.com\/index.php?rest_route=\/wp\/v2\/posts\/534","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/configroar.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/configroar.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/configroar.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/configroar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=534"}],"version-history":[{"count":17,"href":"https:\/\/configroar.com\/index.php?rest_route=\/wp\/v2\/posts\/534\/revisions"}],"predecessor-version":[{"id":569,"href":"https:\/\/configroar.com\/index.php?rest_route=\/wp\/v2\/posts\/534\/revisions\/569"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/configroar.com\/index.php?rest_route=\/wp\/v2\/media\/567"}],"wp:attachment":[{"href":"https:\/\/configroar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=534"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/configroar.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=534"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/configroar.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=534"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}