Hello @tim.wilkinson
Thanks for clarifying. For a Windows 11 deployment through Microsoft Intune, the suggestion is to build the Intune Win32 app from a fresh Adobe Reader enterprise/volume distribution installer and include the latest matching Continuous-track update MSP in the same deployment package.
Please note that you have to apply for the redistributing Reader across your estate needs Adobe's free Reader Distribution License Agreement: https://adobe.ly/4frKgBt
The version difference you saw can happen when the installer media you packaged is not at the same patch level as the latest update that is available from the Acrobat Enterprise Release Notes. In this case, 26.001.21662 was the June planned/security update level, while 26.001.21691 is a later planned update. If the EXE you packaged installs 26.001.21662, Intune will deploy that build unless the package also applies the newer 26.001.21691 update, or the Acrobat/Reader updater is allowed to bring it current after installation. See the release notes for more information: https://adobe.ly/44DIj03
Download a fresh Acrobat Reader enterprise installer from Adobe’s Reader distribution page: https://adobe.ly/4frKgBt
Download the latest matching Reader update MSP from the Acrobat Enterprise Release Notes, Windows 64-bit Reader MSP, or the MUI MSP if you are deploying the MUI package: https://adobe.ly/44DIj03
Package the installer and the MSP together as an Intune Win32 app. For details, check this article on: Deploy Adobe packages on Windows using Microsoft Intune.
Run the base Reader install and apply the MSP as part of the same Intune install workflow.
Configure your Intune detection rule to check that the installed Reader/Acrobat build is 26.001.21691 or later before marking the deployment successful.
Also confirm that Acrobat/Reader updates are not disabled by policy. If your organization disables automatic updates, then the latest MSP should be deployed through Intune, SCCM, or your normal software update process each time Adobe publishes a new planned or security update.
So, either MSI or EXE can work for Intune, but the key point is: do not deploy only the base installer if you need the endpoint to be current immediately. Include and apply the latest Reader MSP in the same deployment package.
And, if you have Acrobat Enterprise licenses, then you may also get in touch with the Enterprise support team to get assistance on this.
I hope this helps, and let us know if you need any assistance.
Regards,
Anand Sri.