News

Devicie makes application management automatic within Microsoft Intune, matching the speed of AI

Written by Devicie | Sep 11, 2026, 12:18:10 AM

AI-accelerated vulnerability discovery is increasing application updates and shortening remediation deadlines. Devicie's AI-assisted automation handles the operational work required to keep Windows and macOS applications current within Microsoft Intune.

TAMPA BAY, Fla. — September 14, 2026 — Microsoft Intune gives organizations comprehensive control over their end-user computing environment, but realizing its full value requires teams to continuously operate and maintain it. As AI accelerates vulnerability discovery and increases the volume and urgency of application updates, that operational burden is growing.

Devicie today announced a major expansion of the application management capabilities within its Intune management and automation platform, designed to automate that work rather than add more work for IT teams to manage.

Devicie now automatically manages more than 1,500 Windows and macOS applications, alongside an organization's own line-of-business software at no additional charge. Devicie's investment in AI-assisted testing and validation enables new application versions to be made ready within Microsoft Intune, typically within hours of publisher release.

The expansion is part of Devicie's broader approach to Microsoft Intune: automate the ongoing endpoint operations required to keep environments current, secure and aligned to policy, while organizations retain Microsoft Intune as their management platform.

Application updates are accelerating

The volume and frequency of application security updates are increasing sharply. On 8 September 2026 Microsoft's monthly security update addressed more than 950 vulnerabilities in a single release — Jerry Gamblin's analysis of the CVE List records 1,255 Microsoft CVEs across the whole of 2025. In July 2026 Adobe moved from monthly to twice-monthly security bulletins, giving the reason plainly: "the window between public vulnerability disclosure and active exploitation is compressing from days to hours."

Software publishers attribute the shift in part to AI-assisted vulnerability discovery. Microsoft's Pavan Davuluri said, "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code," with customers seeing "a higher volume of security updates included in each security release."

Remediation deadlines have moved with it. In June 2026 the U.S. Cybersecurity and Infrastructure Security Agency replaced its earlier fourteen-day deadline for known exploited vulnerabilities with a tiered directive whose fastest tier is three days, and stated that threat actors' "use of AI may further narrow the time defenders have to react between patch release and possible exploitation."

Matching the increasing speed

Detection has accelerated. The work required to make updates ready for deployment has to accelerate with it, and at the volume publishers are now shipping, that is not a staffing problem an organization can hire its way out of.

Devicie's investment in AI-assisted testing and hardening allows its application catalog to be kept current at this pace. Applications are monitored against publisher release sources, then packaged, tested and made ready for assignment, typically within hours of release.

“The U.S. government just cut its remediation deadline for known exploited vulnerabilities from fourteen days to three. Enterprise remediation SLAs written for a slower world are heading in the same direction. You cannot meet that pace by adding more manual work. It requires automation, and automation at this speed requires trust.

That matters beyond application updates. Intune can do far more than most organizations have had the time to switch on. The teams we work with aren't short of capability; they're short of hours. Our investment in AI is about building trusted automation that gives teams that capacity back — so they can do more with Intune as endpoint operations become faster and more demanding,” said Alex Hesterberg, Chief Executive Officer at Devicie.

Endpoint operations are becoming critical

Microsoft Intune is among the most capable device management platforms available. The challenge is not what Intune can do; it is the capacity required to operate it continuously and take advantage of its full capabilities.

Application management is among the most time-consuming of those recurring operations. Every new version means finding the installer, determining the correct installation parameters, testing it, packaging it and assigning it — then doing it again when the next version ships.

Devicie automates that function inside the organization's existing Intune tenant, without requiring an IT team to raise a request. And where a commercial application catalog stops, Devicie continues: an organization's own line-of-business and in-house software is automated through the same process.

The catalog spans widely used software including Microsoft 365 Apps, Microsoft Visual Studio Code, Microsoft OneDrive, Google Chrome, Adobe Acrobat, Slack, Zoom Workplace and Mozilla Firefox. Coverage is prioritized based on what Devicie detects across its customer base and market monitoring, with new applications added continuously.

Do more with Microsoft Intune

Capacity, back where it is worth more. Application updating stops competing for IT attention, giving teams more capacity for the parts of Intune they have not had time to turn on.

One answer when someone asks. Application currency is reported per device from the same system that reports CIS and ACSC Essential Eight baseline compliance for Windows and macOS end-user devices.

The software the business actually runs is included at no additional charge. Line-of-business systems, in-house tools and vendor applications with complex installers can be managed alongside Devicie's application catalog.

A version that causes a problem can be rolled back. Devicie keeps the current version and the two versions before it in the tenant, preserving the ability to step back from an update.

macOS managed to the same standard, in the same place. Administrators browse, configure and deploy macOS applications from the same portal, with the same controls, natively through Intune — avoiding the need for a second application management vendor for mixed fleets.

In production today

John Holland Group runs cloud-native device management across more than 60 worksites with Devicie's enhanced application management in production and full ACSC Essential Eight maturity level one compliance, and reports $1.2 million in annual return.

Toyota Financial Services retired Microsoft Configuration Manager and moved a 1,300-device fleet to modern management on Intune with Devicie, reducing device builds to 20 minutes.

Microsoft Intune remains the control plane

Devicie runs inside the customer's existing Microsoft stack and change process. There is no second console, no separate source of truth and no migration.

Microsoft controls how often a device checks in, while the organization's own update rings control how fast a version reaches production. Devicie shortens the time it takes for an application to become ready for deployment while leaving device check-in and production rollout to Microsoft Intune and the customer's own policies.

Automation at speed requires trust

Every installer must arrive over HTTPS from a domain belonging to the publisher; mirrors, third parties and shortened links are rejected. The file's cryptographic hash is calculated from the installer itself and compared again at each stage.

Every package is scanned for malware, then installed, detected and removed on a clean machine across every architecture and installation scope it supports. AI accelerates Devicie's ability to monitor, package and test applications, but it does not replace these deterministic controls. If validation fails, the process stops before the package reaches the customer tenant.

How many of your applications are covered?

Devicie has published a free calculator that allows organizations to compare their Intune application estate against Devicie's managed coverage and estimate the operational time currently spent managing applications.

Exporting an application list from Intune shows how much of the estate Devicie already covers, which applications have no catalog match and an estimate of the hours per year that work is consuming. Matching runs in the browser; no account or email address is required, and nothing is uploaded.

Check your application coverage → https://devicie.com/intune-roi-calculator

Devicie manages Windows and macOS end-user devices; servers are out of scope.

About Devicie

Devicie is an Intune management and automation platform that automates the ongoing endpoint operations required to configure, secure and maintain Windows and macOS environments in Microsoft Intune. It connects to an organization's Microsoft Intune tenant through a secure Microsoft Entra enterprise application and deploys tested security baselines, including CIS benchmarks and ACSC Essential Eight, alongside automated application management and structured update rings. Every managed policy is checked hourly and returned to its intended state if it drifts.

Devicie is a member of the Microsoft Intelligent Security Association, holds SOC 2 Type II and SOC 3 certifications, and is GDPR compliant. Infrastructure runs on Microsoft Azure. Compliance documentation is available through the Devicie Trust Center.

For more information, press only:
Miluse Najmr, Head of Global Marketing
+1 (617) 640-3802
miluse.najmr@devicie.com

FAQs

What is automated application management in Microsoft Intune

Automated application management removes the manual work required to monitor software publishers for new releases, package and test applications, and make new versions ready for deployment through Microsoft Intune. Devicie automates this process while Intune remains the organization’s device management platform and control plane.

How many applications does Devicie manage?

Devicie automatically manages more than 1,500 Windows and macOS applications, with new applications added continuously based on customer usage and market monitoring. Organizations can also automate their own line-of-business and in-house applications through the same platform.

How quickly are new application versions available in Devicie?

New application versions are typically packaged, tested and made ready within Microsoft Intune within hours of publisher release. Actual deployment timing remains controlled by Microsoft Intune, the organization’s update rings and its own policies.

Does Devicie replace Microsoft Intune?

No. Devicie works with an organization’s existing Microsoft Intune environment. Intune remains the control plane and source of truth, while Devicie automates many of the recurring operational tasks required to configure, secure and maintain the environment.

Can Devicie manage custom or line-of-business applications?

Yes. Devicie can manage line-of-business applications, internally developed software and vendor applications with complex installers alongside applications in the Devicie catalog, at no additional charge.

How does Devicie validate application updates before they reach Intune

Installers must originate over HTTPS from a publisher-owned domain. Devicie calculates and validates cryptographic hashes, scans packages for malware and tests installation, detection and removal on clean machines across supported architectures and installation scopes. If validation fails, the package does not proceed to the customer tenant.

Can application updates be rolled back?

Yes. Devicie retains the current application version and the two preceding versions in the customer tenant, allowing organizations to step back if a new application version creates an issue.

Does Devicie support macOS application management through Intune?

Yes. Devicie supports application management for both Windows and macOS through the same platform, allowing organizations with mixed device fleets to manage applications natively through Microsoft Intune without introducing a separate macOS application management vendor.