Deploy Orb on Windows using Microsoft Intune

This guide walks you through deploying Orb across a Windows fleet using Microsoft Intune. The guide covers:

  1. Choosing between the Orb sensor and the Orb app
  2. Building an Intune package and keeping your Deployment Token out of logs
  3. Creating the Win32 app, its install commands and its detection rule
  4. Assigning, verifying, updating and uninstalling

Requirements:

  1. An Orb Cloud subscription
  2. Microsoft Intune with Win32 app deployment, and administrative access to the Microsoft Intune admin center
  3. Windows 10 version 1607 or later, 64-bit, enrolled in Intune
  4. A Deployment Token for your Space

Which should I deploy?

Orb offers two Windows deliverables. They behave very differently under managed deployment, so choose deliberately.

Orb sensor Orb app
Runs as Windows service (LocalSystem) User-session desktop app with a tray icon
Starts Automatically at boot, before any user logs in At user logon, once a startup entry exists
Needs a logged-in user No Yes
Installer Windows Installer package (.msi) Orb-installer.exe
Best for Unattended fleet monitoring, kiosks, point of sale, servers Devices where a person wants the Orb UI
Info

For most managed deployments the sensor is the better fit. It runs as a service, starts before login, reports continuously without anyone signing in, and ships as an MSI that Intune can detect and uninstall without any scripting.

Warning

The sensor and the app register with Orb Cloud separately, so a device running both appears twice in your Space, under the same hostname. Deploy one or the other unless you specifically want both.

Before you start

Create a Deployment Token

Create a token in the Orchestration section of Orb Cloud. A Deployment Token links each Orb to your Space automatically, with no user interaction.

Use a dedicated, revocable token per deployment so you can attribute devices and revoke access without disrupting other rollouts.

Download the Win32 Content Prep Tool

Intune delivers both Orb packages as Win32 apps, which are built with Microsoft's Win32 Content Prep Tool.

  1. Download IntuneWinAppUtil.exe from the Microsoft Win32 Content Prep Tool repository
  2. Extract it somewhere convenient, for example C:\Intune

Deploy the Orb sensor

Prepare the package

Create a source folder containing the sensor MSI and your token, and an empty output folder:

C:\Intune\
  IntuneWinAppUtil.exe
  OrbSensor\
    orb-sensor.msi
    deployment_token.txt
  Output\

deployment_token.txt contains only your token, with no trailing newline:

orb-dt1-yourdeploymenttoken678

Build the package:

.\IntuneWinAppUtil.exe -c "OrbSensor" -s "orb-sensor.msi" -o "Output" -q

This produces Output\orb-sensor.intunewin. Everything in the source folder is included in the package, so the token file travels with the MSI.

Info

Ship the token as a file in the package rather than on the install command line. Intune records the install command line in IntuneManagementExtension.log on every device and shows it in the app's properties in the console. The MSI keeps a token passed by file out of its own log as well.

Create the Win32 app

  1. Sign in to the Microsoft Intune admin center.

  2. Go to Apps → Windows → Windows apps, select Create, choose app type Windows app (Win32), and select Select.

    Selecting the Windows app (Win32) app type

  3. On App information, select Select app package file and upload orb-sensor.intunewin.

    Intune reads the MSI and shows what it found, including the product version and that the package installs per machine.

    Intune reading the MSI package

    Select OK. The name (Orb Sensor), publisher and version are filled in from the package. Add a description, then select Next.

  4. On Program, set:

    Install command

    msiexec /i "orb-sensor.msi" /qn /norestart DEPLOYMENTTOKENFILE=deployment_token.txt

    Uninstall command

    msiexec /x "{ProductCode}" /qn /norestart

    Replace {ProductCode} with the product code shown on the Detection rules page, including the braces. Intune pre-fills both commands from the MSI; add the DEPLOYMENTTOKENFILE property to the install command as above.

    • Install behavior: System — locked, because the package installs per machine
    • Device restart behavior: No specific action — the MSI does not require a restart
    • Return codes: leave the defaults

    Install and uninstall commands

  5. On Requirements, set the operating system architecture to x64 and Minimum operating system to Windows 10 1607, then select Next.

    Architecture and minimum operating system

  6. On Detection rules, choose Manually configure detection rules, select Add, and set Rule type to MSI. The MSI product code is filled in from the package. Leave MSI product version check set to No unless you want to pin a minimum version, then select OK.

    MSI product code detection rule

    Note

    MSI product code detection is the reason the sensor is packaged as an MSI. Do not use a file-based rule: Orb.exe carries no Windows file version resource, so a rule of the form file exists and version is at least X never matches, and Intune would reinstall the app on every evaluation.
    :::

  1. Skip Dependencies. On Supersedence, leave it empty for a first deployment — see Update Orb.

  2. On Assignments, add your device group under Required, then select Next.

  3. Review and select Create.

The service installs and links to your Space with no user interaction and without anyone logging in.

The app's Properties page afterwards shows the detection rule and the assignment, which is the quickest way to confirm the deployment is configured as intended:

Detection rule and assignment on the app's properties

Configuration properties

Set any of these as PROPERTY=value pairs on the install command. They are persisted so that they survive upgrades.

Property Effect
DEPLOYMENTTOKENFILE Path to a token file in the package content. Relative paths resolve against the package.
DEPLOYMENTTOKEN The token itself. Kept out of the MSI log, but recorded in the Intune install command — prefer the file.
ORB_DEVICE_NAME_OVERRIDE Name the device reports in your Space. Quote values containing spaces.
AUTOUPDATE 1 lets the sensor update itself on a schedule. Defaults to 0 when installed from the MSI, which is what you want when Intune manages versions.
PURGEDATA Uninstall only. 1 also removes C:\ProgramData\Orb — see Uninstall Orb.

Other sensor options from Orb Configuration are available as properties of the same name, including ORB_FIRSTHOP_DISABLED, ORB_BANDWIDTH_DISABLED, ORB_EPHEMERAL_MODE, ORB_MEASURE_SERVER_ENABLED and ORB_MEASURE_SERVER_PORT.