# Review catalog installer overrides again for each superseding app

> Will a customized Enterprise App Catalog installer survive the next app version correctly?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-149-review-catalog-installer-overrides-again-for-each-superseding-app/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:27+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Will a customized Enterprise App Catalog installer survive the next app version correctly?

## Potentially affected

Apply this review only where a catalog app genuinely needs an installer override. Identify the chosen package, architecture, version, and the approved customization rather than assuming catalog defaults authorize every local change.

## DSE recommendation

Keep the override and its purpose under version review alongside the catalog package.

## Article

## Source facts

Enterprise App Catalog permits a PowerShell installer to replace its standard command. Intune still uses detection rules to determine installation success. When creating a superseding app, the script is not transferred automatically and a new script is needed. Microsoft warns that custom install logic can break installation or updating; scripts must not contain secrets. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/deployment/add-enterprise-catalog-app).

## Applicability

Apply this review only where a catalog app genuinely needs an installer override. Identify the chosen package, architecture, version, and the approved customization rather than assuming catalog defaults authorize every local change.

## DSE recommendation

Keep the override and its purpose under version review alongside the catalog package. For each superseding app, compare the new default installation behavior with the customization and decide whether the override is still necessary. Recreate and test the script deliberately instead of assuming the prior version follows the app. Review actual approval coverage for script changes rather than relying on the presence of an approval feature.

## Verification

Exercise a clean installation, an update from the supported predecessor, and an approved removal in a test population. Inspect the app’s actual state as well as detection results and script output. Confirm that the new package invokes the intended installer and that no sensitive value is embedded in the script or logs. Preserve the reviewed override and test outcomes with that specific app version before expanding assignment.

## Official references

[Microsoft Learn: Add an Enterprise App Catalog App to Microsoft Intune](https://learn.microsoft.com/en-us/intune/app-management/deployment/add-enterprise-catalog-app).

## Primary reference

- Name: Add an Enterprise App Catalog App to Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/app-management/deployment/add-enterprise-catalog-app
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review catalog installer overrides again for each superseding app,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-149-review-catalog-installer-overrides-again-for-each-superseding-app/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
