The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Configuration Manager application groups let you deploy several existing applications as one Software Center item, with member applications installed in the order you set. The group coordinates deployment; it does not package the applications for you. Each member still needs working content, detection, requirements and deployment types.
What an application group does
An application group is a deployable object made from existing Configuration Manager applications. Users see its Software Center metadata as one item, while the client processes its member applications in the group’s defined order. You can deploy it to a user or device collection. It is not just an administrative folder or a single installer. Microsoft introduced the feature as pre-release in Configuration Manager current branch version 1906; it became generally available beginning with version 2111. Check your installed site version for exact console labels and available options. Microsoft’s application-group documentation describes the feature and version history.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
System Center 2012 R2 Configuration Manager: A Practical Handbook for Reporting | $55.00 | Buy on Amazon |
Use a group when related applications are normally delivered together—for example, a workstation bundle, department suite, runtime and business application, or host application and plug-in. It is a weaker fit when members need different approvals, licensing, maintenance schedules or target audiences.
Prepare the member applications and target
- Confirm your Configuration Manager current-branch site exposes Application Groups and that your account has permissions on the Application Groups object.
- Ensure every member already exists as a Configuration Manager application with a valid deployment type, tested content, an accurate detection method and requirements that match the intended devices.
- Test installation, detection and restart behavior for each member. Make sure the collection contains the intended users or devices, and prepare a pilot collection before broad deployment.
- Plan distribution points and boundary-group access. Before application deployment, the hierarchy needs at least one distribution point; clients must be able to reach an appropriate point that hosts the content. See application-management planning and distribution-point setup.
- Decide whether the group belongs to devices or users, whether it should be Available or Required, and how deadlines and restarts should behave.
Create the group in the Configuration Manager console
- Open the Configuration Manager console and go to Software Library > Application Management > Application Groups.
- Select Create Application Group in the ribbon.
- On General Information, enter the group name and administrative metadata.
- On Software Center, set the display information users need, such as description, publisher, version, support contact, documentation link, privacy URL, icon and keywords where available.
- On Application Group, select Add, choose the existing applications, then use Move Up and Move Down to set their installation order.
- Complete the wizard. Reopen the group’s properties to confirm its members, metadata and order before deployment.
Microsoft’s application-group instructions identify the wizard pages and member-selection workflow. The PowerShell cmdlet documentation specifies a maximum group name length of 256 characters and description length of 2,048 characters; use those as design limits for naming and descriptions. New-CMApplicationGroup reference.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsSet an order that reflects prerequisites
Order members by real technical dependency, not alphabetically. Put a required runtime before the application that uses it, a host before its plug-in, and a base product before its language pack when that is how the installers must run. Test the sequence on a clean device and on a device where some members are already present; detection and requirements can change what the client installs.
Treat the group as coordinated sequencing, not a guaranteed transaction. If a later member fails, inspect that member’s enforcement and detection results; do not assume earlier installations will be rolled back automatically. If you need explicit conditional logic, recovery or rollback, use a workflow designed for it rather than relying on the group alone.
Distribute member content
The group definition is not the application content. Distribute the content for each member to the distribution points or distribution point groups that serve the target devices, either during the deployment workflow or separately. In the console, select the relevant content and choose Distribute Content, then select the destinations and complete the wizard. Monitor Monitoring > Distribution Status > Content Status until the member content is successfully available.
Check that the clients’ boundary groups provide access to those distribution points. If you add a member to an existing group, distribute that new application’s content separately; if you modify a member application, redistribute its changed content. A client cannot install a member until it can access a distribution point holding its content. See application-group content guidance and New-CMApplicationGroupDeployment. For security, configure deployments to download content from distribution points and run locally rather than execute directly from a distribution point, so the client can verify the content hash; see application-management security guidance.
Deploy the group
- In Software Library > Application Management > Application Groups, select the group and choose Deploy.
- On General, choose the target user or device collection.
- On Content, select or confirm the distribution point or distribution point group.
- On Deployment Settings, set the action to Install and choose the purpose: Available for user-initiated self-service or Required for enforced installation.
- Set scheduling, deadline and notification behavior as appropriate; review the summary and finish the wizard.
- Check the group’s Deployments tab and deployment monitoring to confirm the assignment was created as intended.
Available is appropriate when users should choose whether to install from Software Center. Content is generally downloaded when they start installation, not simply because policy arrived. Required is appropriate for a standard build or mandatory suite; the client evaluates applicability and downloads content when the assignment is active and applicable. Actual timing depends on policy and client state, so do not promise an immediate appearance or installation. For the details, see Microsoft’s deployment download technical reference and Software Center planning.
Choose a device collection when the suite should follow a device regardless of who signs in. Choose a user collection when entitlement follows the person. User-available deployments have additional identity and infrastructure prerequisites, particularly for Microsoft Entra-joined, hybrid-joined or internet-based devices; review Microsoft’s user-available app prerequisites. Pilot shared-device and mixed user/device targeting to avoid unexpected installs.
Create and deploy with PowerShell
Use the Configuration Manager PowerShell module from the site drive. Replace the example names with objects and names that exist in your site, and confirm the cmdlet parameters available in your installed module.
Import-Module "$($ENV:SMS_ADMIN_UI_PATH)..ConfigurationManager.psd1"
Set-Location "ABC:"
$appNames = @(
"Contoso Runtime",
"Contoso Client",
"Contoso Office Add-in"
)
$group = New-CMApplicationGroup `
-Name "Contoso Workstation Suite" `
-AddApplication $appNames `
-Description "Standard Contoso workstation software" `
-Publisher "Contoso IT" `
-SoftwareVersion "1.0" `
-LocalizedName "Contoso Workstation Suite"
$collection = Get-CMCollection -Name "Pilot - Contoso Workstations"
New-CMApplicationGroupDeployment `
-InputObject $group `
-Collection $collection `
-DeployAction Install `
-DeployPurpose Available `
-DistributionPointGroupName "Regional Distribution Points" `
-DistributeContent
For mandatory installation, use -DeployPurpose Required. The -AddApplication parameter takes application names; if you supply application objects, use their LocalizedDisplayName values. The site drive, application names, collection, distribution-point group and permissions are environment-specific, so this is a pattern to adapt, not a universal copy-and-run script. Some properties may require Set-CMApplicationGroup after creation. References: New-CMApplicationGroup and New-CMApplicationGroupDeployment.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Verify the installation
- Confirm the test device or user is in the selected collection and the deployment is listed for the group.
- For immediate testing, trigger client policy retrieval, then check whether the group appears in Software Center. Software Center receives deployment information through policy from the management point; refresh timing depends on client settings. See Software Center planning.
- Start an Available deployment from Software Center, or observe the Required assignment according to its schedule.
- Check the status of each member application and confirm its detection method reports the expected installed state.
- Confirm content status remains successful on the distribution points the pilot clients can access.
Troubleshoot by symptom
The group does not appear in Software Center
- Check that the deployment targets the intended collection and that the client is a member.
- Verify that policy has reached the client and that the Software Center client is functioning.
- For a user-targeted assignment, verify user discovery and identity prerequisites; review management-point and, when relevant, cloud management gateway configuration.
- Check requirements and applicability, deployment visibility settings and boundary or management-point connectivity.
Content download fails
- Check distribution status for every member, not only the group.
- Verify distribution-point availability and boundary-group relationships, then check content validation and hashes.
- Check connectivity through firewalls and any required SMB, HTTP/HTTPS or CMG path, as well as client disk space.
- Confirm newly added or modified applications were distributed again.
A member is skipped or installation fails
- Review the member’s detection method: it may already be considered installed.
- Check requirements, deployment-type applicability for operating system and architecture, supersedence, unresolved dependencies and evaluation status.
- Use
AppGroupHandler.logfor group processing,AppEnforce.logfor application enforcement andSettingsAgent.logfor related settings activity. Follow the individual member’s status rather than treating the group as one opaque installer.
Restart or user-targeting behavior is unexpected
Test restart behavior on the site version you run. Microsoft documents a restart-related deployment failure warning for Configuration Manager version 2103 and earlier; that is a historical, version-specific caveat, not a universal statement about current releases. For user-available deployments, validate identity discovery, client settings and management-point configuration against the documented prerequisites.
Choose between a group and other deployment methods
| Method | Best fit | Trade-off |
|---|---|---|
| Application group | A user-facing bundle of existing applications that should be deployed together in a defined order. | Provides one deployment object, but does not add rollback or complex workflow logic. |
| Application dependency | A reusable prerequisite relationship, especially when the main application should be visible while prerequisites remain hidden. | Models application-to-application dependence rather than a whole user-facing suite. |
| Task sequence | Conditional branches, scripts between installs, explicit reboot control, OS deployment or broader provisioning. | More suitable for workflows than a simple ordered bundle. Microsoft documents that application groups cannot be used with the Install Application task-sequence step. |
| Wrapper application | Custom error handling, recovery, rollback, user experience or cross-application state. | Requires packaging and maintenance, and can make individual application status less transparent. |
| Package/program | Simple legacy command execution. | Lacks much of the application model’s detection, requirements, supersedence and user-centered Software Center behavior. |
Neither groups nor dependencies universally replace one another: use the construct that matches whether you are expressing a suite or a reusable prerequisite. Choose a task sequence or wrapper only when the workflow needs control that a group does not provide.
Version-specific limits and operating practices
Microsoft’s application-group documentation identifies feature and known-issue details by Configuration Manager version. The feature became generally available in version 2111. Microsoft also documents that deleting a member application could leave a broken reference in version 2107 and earlier; beginning with 2111, deletion of an application that belongs to a group is prevented. Microsoft lists alerts, phased deployment and repair among options that may not work with application groups. Because console behavior and limitations can change, validate these details against your installed current-branch release before using them in production.
Quick Recap
- Keep groups logically scoped, with clear naming, ownership and support information.
- Document why members are ordered as they are, and use change control when adding or reordering them.
- Test members independently, then test the complete group on a pilot ring before production.
- Monitor content replication and distribution status, especially when targeting many sites or boundary groups.
- Avoid duplicating applications just to form a bundle; maintain the member applications as reusable ConfigMgr objects where their lifecycle permits.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

