Tool Detail

Smart Device Reboot Manager

Windows restart governance with recommended or required states, a local WPF interface, PreviewOnly test paths, exact Intune Win32 version detection, and a stable PowerShell Gallery module.

Smart Device Reboot Manager interface screenshot

Windows / Intune / PowerShell / WPF

First public standalone release

The public release exposes a clean standalone ZIP package, a clean Intune Win32 package, a stable PowerShell Gallery module, Authenticode-signed PowerShell scripts, and deployment flows that keep runtime configuration local.

RST

Recommended or required restart states

Use a local WPF restart workflow that clearly separates recommended restart prompts from required restart enforcement, with configurable postpone choices, user-visible state, and operator-controlled wording.

PRE

PreviewOnly and safe test launchers

Validate the restart experience before rollout with PreviewOnly test paths, dedicated launchers, cleaner logging, and support-friendly checks that do not force a reboot during validation.

WIN

Exact IntuneWin version detection

The Intune detection script records the exact installed version and source, validates the expected GUI files and scheduled task, and confirms that the optional Gallery updater is absent from the clean Intune package.

MOD

Stable Gallery module

The stable PowerShell Gallery package supports local install, update, and uninstall workflows, while automatic update remains opt-in instead of enabled by default.

Intune Win32 deployment

Supersedence-aware deployment without hidden auto-update behavior

The public Intune Win32 package is designed for clean tenant publication. Build from the release artifact, publish each version as a new app, use supersedence for in-place replacement, and assign the new version explicitly so Intune controls rollout, retry, reporting, and rollback.

The publication workflow supports exact version detection, preserves the existing runtime configuration during in-place upgrades, and can resume an interrupted publication with -ResumeAppId instead of creating another app object.

PowerShell Gallery stable package

Stable module for controlled local deployment

The public package SmartM365.DeviceRebootManager version 0.1.0 is published on PowerShell Gallery for controlled installation and update scenarios outside Intune packaging.

A standard install does not enable the automatic Gallery update task. Operators must opt in explicitly, which keeps the stable module predictable for support, pilot validation, and privacy-sensitive deployment baselines.

Requirements and privilege boundaries

Windows user experience, elevated deployment

The local interface requires Windows PowerShell 5.1 and WPF. The included Intune publication workflow targets x64 devices and declares Windows 10 version 1607 as its minimum supported operating system.

Direct preview and GUI launches run in the signed-in user session. Installation, update, and removal require elevation because they write to ProgramData and manage scheduled tasks; the Intune package runs those deployment actions as SYSTEM.

The deployed GUI task runs with limited user rights, not in session 0. A real restart remains subject to local Windows rights and policy, while PreviewOnly lets operators review the experience without restarting the device.

Security and confidentiality

Signed scripts and local runtime configuration

The public release links only the clean ZIP package, the clean Intune Win32 package, the published checksums, the stable Gallery module, and the source tag. It does not expose private runtime configuration or any older private bundle.

Shipped PowerShell files are Authenticode-signed, runtime JSON configuration stays local on the device, and the clean Intune packaging flow is built to avoid publishing tenant-specific or operator-specific data with the release artifacts.

The signatures use the self-signed workplacecloudhub.com certificate with thumbprint D70ECB7B00377EBFB76B304C08DFC6620584E114. Signature trust is not automatic on every endpoint and still depends on the local certificate stores and execution policy; verify both the expected signer and the published SHA-256 values before deployment.

ZIP SHA-256: AE8ADEDDE56CBBA2EFC0989A3255F50A71FEC81F9FFB1F82EE405E65C0720B49
IntuneWin SHA-256: 6386CA6C2CFF4318EBDCDACFDBC5B4B911800A3F456D3C9F9EAEC26E1A261296

Quick start

Download, verify, extract, and launch

1. Download the standalone ZIP package or the clean Intune Win32 package from GitHub Releases.

2. Verify the downloaded file against the published SHA-256 file and the expected ZIP or IntuneWin hash.

3. Extract the complete ZIP package to a local folder.

4. Run Start-SmartM365-DeviceRebootManager-GUI.cmd for the standard local workflow.

5. Use Start-SmartM365-DeviceRebootManager-GUI-Test.cmd or -PreviewOnly to validate required or recommended restart behavior before rollout.

6. For Intune publication, use the clean .intunewin artifact together with the detection script and supersedence-aware publication workflow.

Current source path

GitHub remains the source of truth.

The current GitHub code path is SmartM365/Devices/DeviceRebootManager. The public release tag is device-reboot-manager-v0.1.0, the published source commit is f3a6aa542cea572d792b60283ccdd1243a6e9aa0, the stable module is SmartM365.DeviceRebootManager 0.1.0, and the repository license is GPL-3.0-only. View source commit.