Settings Reference · Chapter 1 of 1

Required settings

MAS ships with sensible defaults for almost everything. Two settings have to be configured explicitly before the pipeline can complete: an active profile and, optionally but frequently, a code-signing certificate. Everything else can wait.

4 min read
Applies to v2.0+
Last updated 2026-07-19
PUBLISHED

MAS ships with sensible defaults for almost everything. Two settings have to be configured explicitly before the pipeline can complete: an active profile and, optionally but frequently, a code-signing certificate. Everything else can wait.


The single required setting: an active profile #

Without a profile, Rollout has no target. Capture and Build work in their absence, but the Ship button stays disabled.

Create a profile via Settings → Profiles → New. A profile bundles connection details for one deployment target. A profile can hold both SCCM and Intune configuration simultaneously — one profile covers a hybrid environment.

For SCCM #

Field Meaning Example
Site server FQDN Fully qualified name of the SMS Provider (usually the primary site server or a SMS Provider machine). sccm01.contoso.internal
Site code Three-character ConfigMgr site code. P01
DP group (optional) Distribution-Point Group to push content to. If empty, MAS distributes to the site's default DP. All Content DPs
Default collection (optional) Device or user collection to create a deployment against. If empty, MAS creates the Application but no deployment. DEV - Test Machines
Application folder (optional) Console folder to place the Application under, for tidiness. Applications\Third-Party

MAS uses the ConfigMgr PowerShell provider from the SCCM Admin Console. That means the console has to be installed on the packaging workstation, and the current user has to have Application Author + Distribution Point Full Control rights on the site.

For Intune #

Field Meaning Notes
Tenant ID Azure AD tenant GUID. Found in Entra ID → Overview.
Client ID App-registration ID of the MAS Intune app. Must be registered in Entra ID; needs the DeviceManagementApps.ReadWrite.All Graph permission.
Client Secret (if not using device-code) The registered app's client secret. Never leaves the workstation; stored in Windows DPAPI.
Auth mode DeviceCode (interactive, browser popup) or ClientSecret (headless). DeviceCode is default; suits interactive packagers.
Default assignments (optional) JSON snippet describing intent + target group per new package. Applied on every Ship if the checkbox is enabled.

The registered-app requirements are covered end to end in docs/20-konzepte/Konzept-Intune-Integration.md for reference — the user does not need to read that document to use MAS; the packager sets up the app registration once, hands the Tenant/Client IDs to MAS, and never revisits it.

Activating the profile #

MAS 2.0 tracks a single ActiveProfileId (the pre-2026-07-18 split of ActiveSccmProfileId and ActiveIntuneProfileId was consolidated in Roadmap Punkt 7). Set the active profile via the profile dropdown at the top of the Rollout drawer or via Settings → Profiles → Set active. Field presence — HasSccmConfig / HasIntuneConfig — drives which target tabs light up on the Rollout page, so a single profile can cover both platforms without any switching.


Optional but common: code-signing certificate #

If the organisation signs PSADT scripts, add the cert at Settings → Signing. MAS accepts:

  • A PFX file with a password. MAS reads it into a X509Certificate2 in memory; the password is stored via DPAPI.
  • A certificate installed in Cert:\CurrentUser\My. Selected by thumbprint; the private key stays where Windows put it.
  • A HSM-backed certificate. Same selection flow — MAS uses CNG behind the scenes so any provider that surfaces the cert to the cert store works transparently.

With a cert configured, the Pre-Ship page shows Signing armed. Unarm per-package via the Sign-Scripts toggle if a specific package should not be signed.


Everything else is optional #

None of the following blocks Ship — they are quality-of-life tweaks:

Setting When to touch it
General → Language To switch to German (de-DE).
General → Theme Light / Dark / System. Dark is the default.
Naming convention To match the organisation's package-name convention. Default is {Product} {Version} {Architecture}.
PSADT template path Only if using a bespoke fork of the PSADT template instead of the embedded v4.1.8. Path to a folder with a valid PSADT layout.
Preview themes Code-editor colour scheme for the Build preview. Cosmetic.
Updates → Channel Only stable is publicly-published. Preview and Dev channels are internal build streams.
Diagnose → Include workspaces For diagnostics ZIPs that need to reproduce a specific package failure. Off by default (workspaces can be large).

Verifying the setup #

Once the profile is active, the Welcome page's Ready for Ship indicator turns green and the Ship button becomes clickable on any new capture. If the indicator stays yellow, hover it — the tooltip explains the exact field that's missing.


  • Vocabulary — profiles, Ship queue, active-profile semantics.
  • Workflow steps — Rollout uses the settings this chapter configures.
  • Common issues — SCCM warm-up failures, Intune sign-in cache flushes.
Up next · PSADT Integration
Template basics
MAS instantiates the PSADT template on every Build. This chapter covers the template's shape, which files the packager typically customises, and where custom scripts are supposed to live so they survi…
→