Seven minutes end to end, using 7-Zip as the running example. The walkthrough goes Capture → Build → Pre-Ship → Rollout and finishes with a deployable SCCM Application (or an Intune Win32App). If MAS was installed twenty minutes ago and one profile is defined, this chapter should just work.
Prerequisite: a profile that points at either a SCCM site or an Intune tenant. See Required settings.
What you need on disk #
7z2409-x64.msi(or any small MSI you already have — Firefox ESR, Notepad++, WinMerge all work identically).
That's it. No accompanying scripts, no manifest file, no pre-built folder — MAS derives everything from the installer.
Capture (~90 seconds) #
Open MAS. The Welcome page shows a large drop zone that says Drop an installer to begin.
Drag
7z2409-x64.msionto the drop zone.MAS switches to the Capture page. Within a couple of seconds the Capture summary card populates:
Field Filled from Product name MSI ProductNamepropertyVersion MSI ProductVersionPublisher MSI ManufacturerUpgradeCode MSI UpgradeCodepropertySilent switch MAS Catalog match (falls back to /qnfor MSI)Detection rule MAS Catalog match (falls back to MSI product code) A green Catalog-hit badge appears next to Silent switch if the entry came from the MAS Catalog rather than a plain default. For 7-Zip x64 the Catalog match is exact.
Click Continue → Build.
Everything captured is editable — click any field to override. The canonical use of Capture is to accept the Catalog defaults and move on.
Build (~2 minutes) #
- The Build page loads with a workspace pre-populated from the
captured metadata. Left rail: the file tree of the workspace
MAS is about to write. Right rail: a live preview of
Invoke-AppDeployToolkit.ps1. - The default script contains one Install step:
Start-ADTMsiProcess -Action Install -FilePath "$dirFiles\7z2409-x64.msi". The Uninstall and Repair branches are present but empty by default. - Leave every toggle at its default:
- Deferral policy:
AllowDefer = false(silent, unattended). - Close running apps: none.
- Reboot handling:
AllowRebootPassThru = false.
- Deferral policy:
- Click Build. MAS writes the workspace to
%LOCALAPPDATA%\MilochApplicationStudio\workspaces\7-Zip-24.09-x64\, copies the MSI intoFiles\, and confirms with a green Build succeeded toast.
Open the workspace folder from the toast to inspect. The folder
matches the PSADT v4 template: Invoke-AppDeployToolkit.ps1,
Invoke-AppDeployToolkit.exe, Files\, SupportFiles\,
AppDeployToolkit\.
Pre-Ship (~2 minutes) #
- Click Continue → Pre-Ship. The Pre-Ship page opens the Ship drawer.
- Package name defaults to
7-Zip 24.09 x64. The rename step ensures the SCCM Application (or Intune Win32App) carries the final display name that end users and admins will see; adjust the convention if the site uses one (e.g.IGEL - 7-Zip 24.09 x64). - Detection rules default to the MSI product-code rule captured earlier. Two others are prefilled if the MAS Catalog knows them (registry uninstall entry, executable version). Untick the ones the target platform doesn't need — SCCM requires at least one, Intune the same.
- Signing section: if a code-signing certificate is configured in Settings → Signing, MAS shows Signing armed. Skip this for a first run — an unsigned PSADT payload is a valid package.
- Preflight card shows green checkmarks for Workspace valid, Detection rules present, Package name unique on the target. Click Ship.
Rollout (~2 minutes) #
MAS' Ship queue picks up the job.
- For SCCM: MAS calls the ConfigMgr PowerShell provider to create
the Application with all captured properties in one
New-CMApplicationcall (this pattern lifts the CIVersion from 4 to 2 on a fresh app). Content is copied to the site server via UNC, the DP distribution is triggered, and (if the profile carries a default deployment collection) a deployment is created. - For Intune: MAS packages the workspace to
.intunewin, uploads it via the Microsoft Graph beta endpoint, and posts the assignments the profile carries by default (Available forAll Users, Required for a specific group, etc.).
The Ship drawer updates each stage — Renamed, Detection rules
attached, Content distributed, Assignments posted — with an
OK / Failed marker per stage. A green Completed toast fires
when every stage on every target finishes.
Verify the result in the SCCM Admin Console under Software Library → Application Management → Applications or in Intune under Apps → All apps. The new Application / Win32App carries the display name, detection rules and (if signing was armed) a signed payload.
What you have now #
- A packaged 7-Zip 24.09 available in the deployment platform.
- A workspace folder at
%LOCALAPPDATA%\MilochApplicationStudio\workspaces\7-Zip-24.09-x64\that can be re-opened from Home → Recent projects. - A Memory-DB row with the full audit trail for this run. The Recent Projects list shows a Reopen button that lands directly in the Rollout drawer.
The next installer follows the same path in less time — the muscle memory of Capture → Build → Pre-Ship → Rollout is the whole point of MAS.
Related chapters #
- Vocabulary — the terms used above, defined once.
- Workflow steps — the same steps at operator-reference depth.
- Common issues — when Ship doesn't succeed on the first try.