Skip to content

Quickstart

Install

Pick one:

The latest AppImage from the GitHub Release, installed to ~/.local/bin as intune-container:

curl -fsSL https://raw.githubusercontent.com/magicabdel/intune-container/master/install.sh | sh
# or: wget -qO- https://raw.githubusercontent.com/magicabdel/intune-container/master/install.sh | sh

Override the location with DEST=/usr/local/bin, or pin a version with VERSION=v0.2.0. (AppImages need FUSE, which ships on most desktops.)

Grab the package for your distro from the latest release:

sudo apt install ./intune-container_*_amd64.deb     # Debian / Ubuntu
sudo dnf install ./intune-container-*.x86_64.rpm     # Fedora
just install      # builds the GUI and installs to ~/.local/bin (no sudo)

Needs Rust, Node.js + npm, and the WebKitGTK/GTK dev libraries.

Make sure ~/.local/bin is on your PATH. The same binary is both the graphical interface and the command-line tool: run it with no subcommand for the GUI, or with a subcommand for the CLI. The default container image is publicly hosted and already includes everything needed (including Xvfb for headless SSO), so there's nothing else to build — and no Docker/Podman is required, the image is pulled with a built-in OCI client.


Using the interface

Open the app (the default — no subcommand):

intune-container
  1. Enroll — click Enroll this device on the Console. It provisions the container (first run only), opens the Intune Portal; sign in and enroll, then close the window.
  2. Everyday actions live on the Console: Start/Stop the container (starting also makes browser SSO ready), Open portal, and Open Edge. The signed-in identity and live health checks are right there too.
  3. Other tabsShell (a terminal inside the container), Backup (back up / restore enrollment), Logs, and Destroy.
  4. Tray — single-click for a compact quick panel, double-click for the full window, right-click for a menu. The icon is tinted to the container's state (grey = stopped, teal = running, amber = display attached). Closing the window keeps the app in the tray; only Quit exits.

Tip

The portal window can take up to ~30s to appear the first time while the container finishes booting and its services come up.


Using the command line

The same binary is the CLI when given a subcommand.

Enroll your device

intune-container enroll

Provisions the container (first run only), boots it with your display forwarded, and opens the Intune Portal. Sign in, enroll, then close the windowenroll waits for that and reports success.

Seamless browser SSO (optional)

intune-container start

Starts the container headless and installs a native-messaging host for the linux-entra-sso extension. Then install the extension:

  • Firefox / Thunderbird — the signed .xpi from the releases page.
  • Chrome / Chromium / Brave — the Chrome Web Store (search linux-entra-sso).

Open teams.microsoft.com and it signs in automatically using the container's enrollment.

Start automatically on login and at boot (optional)

intune-container autostart enable

Installs a systemd --user service that runs start on login and stop on logout, and enables lingering so the container also comes up at boot before you log in. Check or undo it with:

intune-container autostart status
intune-container autostart disable

Open Microsoft Edge

intune-container edge      # add -v to run in the foreground with logs

Launches Edge inside the container with your display forwarded — handy for sites that require the managed/compliant device.

Daily use

intune-container status    # container + display + SSO state
intune-container doctor    # health checks across the stack
intune-container stop      # shut the container down

Keep the image up to date

The rootfs records the digest of the image it was extracted from. On every start, the registry is asked (one HEAD request) what :latest points to now; if the digest moved, the image is re-pulled and the rootfs rebuilt before boot. Your enrollment survives — device registration, tokens and the keyring live outside the rootfs.

intune-container update --check   # compare local vs registry digest, download nothing
intune-container update           # re-pull if the digest changed (restarts if running)
intune-container update --force   # re-pull unconditionally

To pin the rootfs and skip the check, set auto_update = false in ~/.local/share/intune-container/config.toml; update still works on demand.

Back up / restore enrollment

intune-container backup            # archive device registration + tokens
intune-container backup-inspect    # list archive contents
intune-container restore           # restore after a rebuild (container stopped)

Uninstall

intune-container destroy --purge   # remove container + all data + host integration
just uninstall                     # remove the binary

Build your own image (optional)

The default image is publicly hosted and already includes Xvfb, so you only need this if you want to customize the image or build it yourself. The committed Dockerfile derives from the base image and adds xvfb:

just build-image   # -> localhost/intune-container:local (base + xvfb)
intune-container init --force --image localhost/intune-container:local

To make a custom image the default, push it to a registry and set DEFAULT_IMAGE in src/backend.rs (or pass --image per run).