how to push software to a single device via jamf or intune
Deploys software to one specific device through Jamf Pro or Intune without affecting the fleet. Covers scoped policies, direct assignment, and verification. Use for one-off installs and troubleshooting. Not for fleet-wide deployment.
TL;DR
Scope a policy or app assignment to just that device (Jamf: policy scoped to the single computer; Intune: app assigned to a group containing only that device or user), trigger a check-in, and verify installation. Remove the one-off scope afterward so it does not linger.
The error
(Deployment request; no error.)Steps
- Jamf: create a policy with the package, scoped to the single computer (Computers > the device). Intune: assign the app to an Entra group containing only the target user or device. Expected: scope limited to one.
- Set the trigger: Jamf "check-in" or Self Service; Intune "available" or "required". Expected: configured. For urgent needs use required/push; otherwise Self Service avoids surprise installs.
- Trigger a client check-in: Jamf
sudo jamf policyon the Mac, or Company Portal sync for Intune. Expected: policy runs. - Verify: Jamf inventory shows the app installed, or Intune app install status is succeeded. Expected: confirmed. Do not trust "assigned" alone.
- Clean up: remove the one-off scope or delete the single-use policy. Expected: no lingering targeted policies. Lingering scopes cause confusion later.
When to use
- One user needs software now
- Testing a package before fleet rollout
When not to use
- Fleet deployments (use proper group scoping)
- Recurring installs (make it a standard policy)
Compatibility
- Jamf Pro (macOS), Microsoft Intune (Windows/macOS/mobile)
Variants
App must install without user interaction
Use required/push assignment, but warn the user first.
Test before fleet
Scope to a pilot group, verify, then widen.
Why it happens
MDM deployment is scope-driven. One-off requests need the same machinery as fleet rollouts, just scoped to one target, and the cleanup matters because forgotten scopes accumulate.
Edge cases
- Name one-off policies clearly (ONEOFF-username-app-date) so they are findable.
- Some apps need a reboot; warn the user.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_yrR2CiKTDjanfe6Dpi9f0g
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.