Create .intunewin

Create a .intunewin file without IntuneWinAppUtil.exe

To upload a Win32 app to Microsoft Intune you first have to wrap it in the .intunewin format. The official way is Microsoft’s IntuneWinAppUtil.exe (the Content Prep Tool): download it, run it at a command line, point it at a source folder and a setup file, and wait for it to spit out a package. It works, but it is one more local tool to fetch and one more step between you and a deployment.

RFF’s free SwitchHunt tool builds the .intunewin for you, right in the browser. Drop a plain EXE or MSI and it hands back a real, Intune-ready .intunewin file - the exact same Win32 content format the Content Prep Tool produces - with no download and no command line.

Build a .intunewin now, free →


Nothing is uploaded, and you can prove it

This is the part that matters if the installer is a licensed vendor package or an internal line-of-business app. Most online “EXE to .intunewin” converters are upload-based: your installer leaves your machine, gets processed on someone else’s server, and sits on their infrastructure until they delete it. That is a supply-chain and licensing question you have to answer before you can use them, and “we delete it within 24 hours” is a promise you take on faith.

SwitchHunt does the packaging entirely in your browser. The installer bytes are zipped, AES-256-CBC encrypted, HMAC-SHA256 authenticated, and wrapped with the Detection.xml the format requires - all client-side, the same steps IntuneWinAppUtil.exe performs locally. Your file never touches a network. Open your browser’s developer tools and watch: there is no upload request, because there is nothing to upload to. That is a property you can verify in ten seconds, not a policy you have to trust.

What you get back

Drop an installer and SwitchHunt returns everything the Intune portal asks you for:

So the whole “prepare a Win32 app for Intune” chore - package, install string, uninstall string, detection rule - comes back from one drag-and-drop.

How to convert an EXE to .intunewin

  1. Open SwitchHunt in any modern browser. Nothing to install.
  2. Drag your .exe or .msi onto the page.
  3. Click Build .intunewin (in browser).
  4. Download the .intunewin, copy the install, uninstall, and detection text, and upload the package to Intune as a Win32 app.

That is the entire flow, and it never leaves the tab.

The honest limit

The in-browser builder holds a few full copies of the file in tab memory while it packages, so it caps at 512 MB. Above that, the browser is the wrong place to do the work and SwitchHunt will tell you to use Microsoft’s IntuneWinAppUtil.exe for that one file. Most application installers are comfortably under the cap; a handful of giant suites are not. We would rather say that plainly than have a 900 MB installer freeze your tab.

You may not need a .intunewin at all

Worth saying, since it is the honest answer: the .intunewin wrapper exists because Intune requires it. If your goal is simply to get software onto Windows machines, RFF deploys a plain EXE, MSI, PowerShell, or any script as-is - no packaging step, no Content Prep Tool, no wrapper. Agents enroll with one PowerShell line, and it is free for your first 100 endpoints. If part of your fleet lives on Intune, build the .intunewin here for that part and push the rest straight through RFF. More on that in the Intune alternative writeup.

Deploy to Windows without the wrapper, free →

FAQ

Can I create a .intunewin without IntuneWinAppUtil.exe? Yes. SwitchHunt builds a real, Intune-ready .intunewin in your browser - the same Win32 content format the Content Prep Tool produces - with no download and no command line.

Is my installer uploaded anywhere? No. The packaging happens entirely in your browser. The file never leaves your machine, and there is no server to delete it from afterward because it was never sent anywhere.

Is it actually a valid .intunewin, or just a renamed zip? It is the real format: a STORE zip containing the encrypted payload and the Detection.xml with the wrapping keys, exactly as IntuneWinAppUtil.exe produces. It uploads to Intune as a normal Win32 app.

Does it give me the install and detection commands too? Yes. Along with the package you get the silent install command, the uninstall command where one exists, and a detection rule to paste into the portal.

Is there a size limit? Yes, 512 MB, because the browser holds several copies of the file in memory while packaging. For larger installers, use Microsoft’s IntuneWinAppUtil.exe.

Is it free? Yes. SwitchHunt is a free browser tool from RFF, with nothing to sign up for.

Build your .intunewin now →