Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Yes—when GIMP is available in your tenant’s Enterprise App Catalog, you can deploy it to managed Windows devices as a prepackaged Win32 app. In Intune, create a Windows Enterprise App Catalog app, select the GIMP package that matches your requirements, review its prefilled settings, and assign it to a pilot group before wider deployment. The package version is tenant- and time-dependent: an HTMD Blog example published January 20, 2025 used GIMP 2.10.38.1 (en-US, x64), but that is a historical example, not a current-version recommendation.
This procedure is for managed 64-bit Windows devices. GIMP itself is cross-platform, but the Intune Enterprise App Catalog workflow described here is not a macOS or Linux deployment method.
What you are deploying
GIMP (GNU Image Manipulation Program) is a free, open-source raster image editor for photo retouching, compositing, drawing, and graphics work. It can suit organizations that need image-editing capability without a per-seat GIMP subscription. It is not a universal substitute for every creative workflow: teams that depend on Photoshop compatibility, integrated vector or page-layout tools, cloud asset libraries, or commercial vendor support may need other products.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallMicrosoft’s Enterprise App Catalog provides prepackaged Win32 applications for Intune. A catalog package generally includes installation metadata, requirements, and detection rules, reducing the work of building and maintaining a Win32 package yourself. It does not remove your organization’s responsibility to review software security, privacy, licensing, suitability, and update practices. Microsoft also cautions that changing catalog-provided commands can cause installation or update failures.
#1 Best Overall
Enterprise App Catalog is part of Enterprise App Management, an Intune Suite capability available through trial or purchase. GIMP may be free to use, but access to this Intune management capability may have a separate licensing implication. Confirm your tenant’s entitlement before planning a deployment.
Before you begin
- Confirm access: Your tenant must have access to Enterprise App Management / Enterprise App Catalog, and your administrator account needs permission to create and assign apps.
- Confirm device support: This catalog workflow supports managed 64-bit Windows devices. Do not infer macOS or Linux support from GIMP’s cross-platform availability.
- Choose a target: Decide whether GIMP should install automatically for a defined role or be offered in Company Portal for users who want it.
- Use a pilot group: Test on representative devices and user accounts before broad deployment. Include the Windows versions, network conditions, and privilege model you actually support.
- Check the package in your tenant: Record the selected package name, language, architecture, version, and the date you checked it. Catalog contents can change, and the latest GIMP release on GIMP’s website is not proof that the same version is already in Intune.
- Review governance: Apply your organization’s software approval, plugin, privacy, file-handling, and update policies. Open-source status alone is not an approval decision.
GIMP’s official download page listed version 3.2.4, released April 17, 2026, when checked for this guide. That is an upstream release reference, not confirmation that every Intune tenant offers 3.2.4 in its catalog. Check both the official GIMP downloads page and the package displayed in your own tenant.
Add GIMP from the Enterprise App Catalog
- Sign in to the Microsoft Intune admin center.
- Go to Apps > All Apps, select Create, choose the Windows platform, then select Enterprise App Catalog app and Select. Portal labels can change; Microsoft’s documented workflow uses this path.
- On App information, choose Search the Enterprise App Catalog and search for GIMP.
- Review the returned package choices. Select the intended package by name and verify its publisher, language, architecture, and version. Do not select an old screenshot’s package merely because its label looks familiar.
- Review the populated app information and select Next.
If GIMP does not appear, confirm your catalog access and search results, inspect available publisher, language, or architecture options, and check whether the app is currently present in your tenant’s catalog. Availability can differ or change. If no suitable package is offered, consider packaging the official Windows installer as a Win32 app under your organization’s normal process rather than claiming that the catalog universally contains a particular version.
Review each configuration page
App information
Catalog metadata is prepopulated, but review it before publishing. Check the app name, description, publisher, version, category, information URL, privacy URL, developer, owner, notes, and logo. Some fields are visible to users in Company Portal.
- Name: GIMP
- Description: For example, “Open-source image editor for photo retouching, image composition, and graphics creation.”
- Publisher: Preserve the value supplied by the catalog unless your governance process requires a documented change.
- Category: Choose Graphics & design if that category is available and appropriate in your tenant.
- Information URL: https://www.gimp.org/
- Privacy URL: Use official GIMP privacy information if required by your organization; do not guess a URL.
Do not assume that the publisher, logo, package name, or version in a 2025 article remains unchanged.
Rank #2
Program
For an ordinary catalog deployment, leave the recommended install and uninstall commands intact. Review them to confirm that they correspond to the package you selected, but do not replace them with commands for a separately downloaded installer unless you have a specific, tested requirement.
Also review installation behavior, install context, restart behavior, return codes, and timeout. The documented default installation timeout is 60 minutes, with a maximum of 1,440 minutes. Keep the default unless representative testing shows it is unsuitable. Check that the install is appropriately silent and will not cause an unexpected restart or user disruption.
Requirements
Review the prefilled architecture and minimum Windows version rather than clicking through without checking. Confirm the target devices meet the package’s requirements and that the x64 package is appropriate. Microsoft supports this Enterprise App Management scenario on managed 64-bit Windows devices; organizations with 32-bit devices should treat those as a separate packaging problem.
Add file, registry, or PowerShell requirement rules only when there is a real deployment need. Extra requirements can prevent an otherwise eligible device from receiving the app.
Detection rules
Intune uses detection to determine whether the app is installed and whether a Required deployment should be offered again. The catalog supplies detection configuration; preserve it unless testing shows it is incorrect. Microsoft supports detection approaches including MSI, file, registry, and custom PowerShell rules. When multiple configured detection conditions apply, all must be satisfied.
Rank #3
A successful installer process alone does not prove to Intune that GIMP is installed. If the portal reports failure or the app is repeatedly offered despite being present, inspect the actual installation path, registry or MSI evidence, selected architecture, and Intune Management Extension logs before changing detection. Avoid marking an app installed based only on an installer exit code.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Scope tags
Assign a scope tag if your role-based administration model uses them to limit which administrators can view or manage the app. Scope tags govern administrative visibility; they are not deployment targets. Skip this step only if your RBAC design does not require a tag.
Assignments: choose the intended experience
| Assignment intent | What users and devices experience | Typical use |
|---|---|---|
| Required | Intune installs the app for the targeted users or devices. | Standardized workstations or roles that need GIMP. |
| Available for enrolled devices | The app is offered in Company Portal so users can install it when needed. | Optional creative software or a mixed user population. |
| Uninstall | Intune removes the app from the targeted users or devices. | Retirement or remediation, with careful targeting and exclusions. |
Start with a pilot device or user group, choose Required or Available according to the intended user experience, then validate installation and removal behavior before expanding. Check assignment filters, exclusions, and group membership carefully, especially for Uninstall.
For user-targeted Win32 deployments, consider privilege requirements. Microsoft warns that apps requiring device administrator privileges can fail when assigned to users who are standard users. Test with the same account type and deployment context used in production.
Review + create
Before selecting Create, verify the package version, language and architecture; target group and assignment intent; install and uninstall commands; detection and requirement rules; restart behavior; scope tags; and user-facing metadata. Confirm that the package is suitable for your organization’s update and configuration policy. Create the app only after the pilot target and assignment are intentional.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #4
Monitor and verify the deployment
In the Intune admin center, open the app and review its overview and device and user install status. Check for failures, pending devices, assignment problems, and detection status. To see app versions, Microsoft documents using Apps > All Apps > Columns > Version. Compare the version reported by Intune with the version you selected and your deployment record.
For an Available assignment, verify the user experience on an enrolled test device:
- Open Company Portal using the account associated with the assignment.
- Search for GIMP and open its listing.
- Select Install and observe whether the state progresses to installed.
- Launch GIMP and confirm the installed version.
On the device, also check that GIMP appears in Installed apps, launches for a standard user if that is an expected scenario, and has the expected Start menu shortcut. Test opening and saving the image formats your organization permits, and check file associations if you intend to manage them. Confirm that installation did not trigger an unwanted reboot. Test uninstall if that is part of your assignment or lifecycle plan.
Do not promise an eight-hour installation window. An HTMD author reported that timing in a particular test environment; it is not a Microsoft guarantee. Assignment processing, device check-in, Company Portal synchronization, content download, network conditions, and detection all affect endpoint timing. A user-initiated sync can help prompt a check-in, but it does not guarantee immediate completion.
Troubleshooting
GIMP is missing from the catalog
- Confirm the tenant has Enterprise App Management / Enterprise App Catalog access and that your account can use it.
- Search for GIMP and inspect available package, publisher, language, and architecture results.
- Consider whether catalog availability or package naming has changed. Do not assume every tenant has the same listing.
- If there is no suitable package, use your organization’s tested Win32 packaging process with an approved official installer, or wait for catalog availability if that is your policy.
Intune reports failure, but GIMP is on the device
Check the catalog detection rule against the actual installed path or product data, the selected architecture, install context, installer exit code, and whether a reboot is pending. Also investigate incomplete content downloads, insufficient privileges, conflicting existing installations, and security software interference. Gather the device-side evidence before altering the catalog command or detection rule; changing defaults can introduce a second problem.
Best Value
Company Portal does not show the Available app
Verify that the device is enrolled, the correct user or device is in the assignment group, filters and exclusions do not remove it, and Company Portal is using the expected work account. Trigger a device or Company Portal sync and allow assignment processing. Check for another app with the same name: Microsoft notes that duplicate names can affect which app appears in Company Portal.
The app is pending or an update has not arrived
Separate catalog publication from endpoint delivery. Microsoft says most catalog app updates complete automated validation and become available within 24 hours; updates that require manual testing typically take up to seven days. These are catalog-update objectives, not guarantees that an assigned device will install an update within that interval. Endpoint check-in, assignment, download, and detection determine delivery timing.
When to use manual Win32 packaging instead
The catalog is attractive when it has a suitable package and you want Microsoft-provided install metadata, requirements, and detection without maintaining your own package. Manual packaging may be preferable if you need a specific version unavailable in the catalog, custom plugins or presets, bundled fonts or configuration, a nonstandard installation location, wrapper logic, or tighter control over the application baseline. Weigh that control against the ongoing work of testing and updating your own package.
For Windows Autopilot scenarios, Enterprise App Catalog apps can be used with supported enrollment experiences, including blocking apps in Enrollment Status Page and Device Preparation Page profiles. Test that provisioning path independently from ordinary post-enrollment deployment; a successful normal install does not by itself validate an Autopilot configuration.
Quick Recap
Deployment checklist
- ☐ Confirm Enterprise App Catalog entitlement, administrator permissions, and managed 64-bit Windows targets.
- ☐ Record the selected GIMP package, language, architecture, version, and the date checked.
- ☐ Review metadata, requirements, commands, detection, restart behavior, and scope tags.
- ☐ Assign to a pilot group with the intended Required, Available, or Uninstall behavior.
- ☐ Confirm Intune reports the expected detection and version, and GIMP launches on the pilot device.
- ☐ Validate Company Portal presentation, file behavior, update expectations, and uninstall if applicable.
- ☐ Expand deployment only after the pilot meets your organization’s security and support requirements.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

