Thx for sharing your experience! I think I will try WAU tomorrow. In the meantime I have read, it has block/allow lists, too.
At my institution GPO/intune is not allowed; we have on-premis ActiveDirectory, and my access is restricted to the clients I need to manage.
So far, I could preinstall almost all apps with the --silent flag. I assume that this also means, that they will update gracefully as SYSTEM user managed by WAU. Having the updates only applied when any normal AD user without admin rights logs on, is not an issue, as long as it works.
There is only one specific app to install user certificates; this can stay a manual task after first logon, because it requires user credentials anyway. (:











No, thx, I’ll check it out.