Microsoft Endpoint Manager Configuration Manager (MEMCM / SCCM) and Microsoft Intune use Detection Rules to determine the presence of Applications & Win32 Apps. The detection rules ensure that application installations only begin to run if the application is not already installed on the device. This article will serve as an informative guide and give you a clear understanding of how to create an updated custom detection script for each new version of the Azure Active Directory Application Proxy Connector using PowerShell.
How to Create a Custom Detection Script for Azure Active Directory Application Proxy Connector
Azure Active Directory Application Proxy Connector (File Detection Method)
- Install the version of Azure Active Directory Application Proxy Connector you want to deploy on a test box or VM
- Check out the following posts for further details
- Open Windows PowerShell ISE by Right-Clicking on Windows PowerShell ISE and selecting Run as Administrator
- Copy the following code into the Windows PowerShell ISE
## Check for Azure Active Directory Application Proxy Connector (File Detection Method) $AADProxyConnectorExe = (Get-ChildItem -Path "C:\Program Files\Microsoft AAD App Proxy Connector\ApplicationProxyConnectorService.exe" -ErrorAction SilentlyContinue) $AADProxyConnectorExe.FullName $AADProxyConnectorPath = $($AADProxyConnectorExe.FullName).Replace("C:\Program Files\","") $FileVersion = (Get-Item -Path "$($AADProxyConnectorExe.FullName)" -ErrorAction SilentlyContinue).VersionInfo.FileVersion ## Create Text File with Azure Active Directory Application Proxy Connector File Detection Method $FilePath = "C:\Windows\Temp\AAD_Application_Proxy_Connector_Detection_Method.txt" New-Item -Path "$FilePath" -Force Set-Content -Path "$FilePath" -Value "If([String](Get-Item -Path `"`$Env:ProgramFiles\$AADProxyConnectorPath`" -ErrorAction SilentlyContinue).VersionInfo.FileVersion -ge `"$FileVersion`"){" Add-Content -Path "$FilePath" -Value "Write-Host `"Installed`"" Add-Content -Path "$FilePath" -Value "Exit 0" Add-Content -Path "$FilePath" -Value "}" Add-Content -Path "$FilePath" -Value "else {" Add-Content -Path "$FilePath" -Value "Exit 1" Add-Content -Path "$FilePath" -Value "}" Invoke-Item $FilePath
- Click Run Script (F5)
- A text file will open with the Azure Active Directory Application Proxy Connector Detection Method script required to detect the current version of Azure Active Directory Application Proxy Connector that is installed on the device you are running the script from.
Example:
If([String](Get-Item -Path "$Env:ProgramFiles\Microsoft AAD App Proxy Connector\ApplicationProxyConnectorService.exe" -ErrorAction SilentlyContinue).VersionInfo.FileVersion -ge "1.5.3437.0"){ Write-Host "Installed" Exit 0 } else { Exit 1 }
- Copy the Azure Active Directory Application Proxy Connector Detection Method script content into the Custom Detection Rules (Script)
- Microsoft Endpoint Manager Configuration Manager (MEMCM / SCCM)
- Microsoft Intune
Azure Active Directory Application Proxy Connector (Registry Detection Method)
- Install the version of Azure Active Directory Application Proxy Connector you want to deploy on a test box or VM
- Check out the following posts for further details
- Open Windows PowerShell ISE by Right-Clicking on Windows PowerShell ISE and selecting Run as Administrator
- Copy the following code into the Windows PowerShell ISE
## Check for Azure Active Directory Application Proxy Connector (Registry Detection Method) $AADProxyConnector = Get-ChildItem -Path "HKLM:\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall" | Get-ItemProperty | Where-Object {$_.DisplayName -match 'Microsoft Azure Active Directory Application Proxy Connector' } | Select-Object -Property DisplayName, DisplayVersion, PSChildName $AADProxyConnector.DisplayVersion $AADProxyConnector.PSChildName ## Create Text File with Azure Active Directory Application Proxy Connector Registry Detection Method $FilePath = "C:\Windows\Temp\AAD_Application_Proxy_Connector_Detection_Method.txt" New-Item -Path "$FilePath" -Force Set-Content -Path "$FilePath" -Value "If([Version](Get-ItemPropertyValue -Path 'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\$($AADProxyConnector.PSChildName)' -Name DisplayVersion -ea SilentlyContinue) -ge '$($AADProxyConnector.DisplayVersion)') {" Add-Content -Path "$FilePath" -Value "Write-Host `"Installed`"" Add-Content -Path "$FilePath" -Value "Exit 0" Add-Content -Path "$FilePath" -Value "}" Add-Content -Path "$FilePath" -Value "else {" Add-Content -Path "$FilePath" -Value "Exit 1" Add-Content -Path "$FilePath" -Value "}" Invoke-Item $FilePath
- Click Run Script (F5)
- A text file will open with the Azure Active Directory Application Proxy Connector Detection Method script required to detect the current version of Azure Active Directory Application Proxy Connector that is installed on the device you are running the script from.
Example:
If([Version](Get-ItemPropertyValue -Path 'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{dbbca520-abc4-4b19-9bc7-ba7928c56923}' -Name DisplayVersion -ea SilentlyContinue) -ge '1.5.3437.0') { Write-Host "Installed" Exit 0 } else { Exit 1 }
- Copy the Azure Active Directory Application Proxy Connector Detection Method script content into the Custom Detection Rules (Script)
- Microsoft Endpoint Manager Configuration Manager (MEMCM / SCCM)
- Microsoft Intune
Always make sure to test everything in a development environment prior to implementing anything into production. The information in this article is provided “As Is” without warranty of any kind.