azureblog.co.uk
← cd ~/posts

Packaging Win32 apps for Intune: detection rules and return codes

Most Win32 app failures in Intune come down to two things: a detection rule that doesn't match reality, and return codes Intune doesn't understand.

2 min read✓ checked 13 May 2026Intune · Windows
On this page
  1. Wrapping the app
  2. Install and uninstall commands
  3. Detection rules decide everything
  4. Return codes
  5. Testing
  6. Supersedence and dependencies
  7. Common failures

Wrapping the app

Intune deploys as .intunewin files created with the Microsoft Win32 Content Prep Tool:

IntuneManagement extensionInstallerApp assigned to device1Runs detection: alreadyinstalled?Not detected: run installcommand3Return code (0, 3010…)4Runs detection againDetected: Installed. Notdetected: Failed6
What Intune does when it installs a Win32 app.
shell
IntuneWinAppUtil.exe -c C:\Packages\7zip -s 7z-x64.msi -o C:\Packages\Output

Everything in the source folder is included, so keep it tidy: the installer, any transforms and scripts, nothing else.

Install and uninstall commands

Both must run silently, with no user interaction:

shell
msiexec /i "7z-x64.msi" /qn /norestart
msiexec /x {23170F69-40C1-2702-0000-000001000000} /qn /norestart

Detection rules decide everything

After installing, Intune runs your detection rule. If it doesn't find the app, the install is marked as failed, even if it worked perfectly. Choose the most reliable signal:

  • MSI product code: best for MSIs. It can check the version too.
  • File or folder: check a file exists, optionally with a minimum version. Watch for 32-bit apps on 64-bit Windows, and tick the 32-bit option if needed.
  • Registry: an uninstall key or a value the installer writes.
  • Script: for complex cases. The app counts as detected if the script exits 0 and writes something to standard output.
What kind of installer is it?
MSIMSI product code (optionally with version)
EXE that writes a normal uninstall keyRegistry: the uninstall key and DisplayVersion
Portable app or custom setupFile or folder, with a version check
Anything complicatedDetection script that outputs text and exits 0
Choosing a detection rule.

Return codes

Intune needs to know what each installer exit code means. The defaults cover the common ones:

CodeMeaning
0Success
1707Success
3010Soft reboot: success, restart needed
1641Hard reboot: the installer started a restart
1618Retry: another installation is in progress

Vendor installers often have their own codes. Check the vendor's documentation and add them.

Testing

Test the install and uninstall commands as SYSTEM before uploading, for example using PsExec with -s. Then assign to a test device and check the logs in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs.

Supersedence and dependencies

  • Supersedence replaces an older app with a newer one. You can choose to uninstall the old version first or update in place.
  • Dependencies install another Win32 app first, such as a runtime the main app needs.

Common failures

SymptomUsual cause
Installs, but shows as failedDetection rule doesn't match what the installer actually wrote
Stuck on "Installing"The installer is waiting for input. The command isn't really silent
Error 0x87D1041CThe app was detected as not installed after the install ran
Works on some devices only32-bit versus 64-bit paths, or a missing dependency
Next in Intune for Windows, start to finish · part 2 of 6Intune Remediations: find and fix problems before users notice →