Packaging Win32 apps for Intune: detection rules and return codes
Most Win32 app failures in Intune come down to two things: a detection rule that doesn't match reality, and return codes Intune doesn't understand.
On this page
Wrapping the app
Intune deploys Win32 apps as .intunewin files created with the Microsoft Win32 Content Prep Tool:
IntuneWinAppUtil.exe -c C:\Packages\7zip -s 7z-x64.msi -o C:\Packages\OutputEverything in the source folder is included, so keep it tidy: the installer, any transforms and scripts, nothing else.
Install and uninstall commands
Both must run silently, with no user interaction:
msiexec /i "7z-x64.msi" /qn /norestart
msiexec /x {23170F69-40C1-2702-0000-000001000000} /qn /norestartDetection rules decide everything
After installing, Intune runs your detection rule. If it doesn't find the app, the install is marked as failed, even if it worked perfectly. Choose the most reliable signal:
- MSI product code: best for MSIs. It can check the version too.
- File or folder: check a file exists, optionally with a minimum version. Watch for 32-bit apps on 64-bit Windows, and tick the 32-bit option if needed.
- Registry: an uninstall key or a value the installer writes.
- Script: for complex cases. The app counts as detected if the script exits 0 and writes something to standard output.
Return codes
Intune needs to know what each installer exit code means. The defaults cover the common ones:
| Code | Meaning |
|---|---|
| 0 | Success |
| 1707 | Success |
| 3010 | Soft reboot: success, restart needed |
| 1641 | Hard reboot: the installer started a restart |
| 1618 | Retry: another installation is in progress |
Vendor installers often have their own codes. Check the vendor's documentation and add them.
Testing
Test the install and uninstall commands as SYSTEM before uploading, for example using PsExec with -s. Then assign to a test device and check the logs in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs.
Supersedence and dependencies
- Supersedence replaces an older app with a newer one. You can choose to uninstall the old version first or update in place.
- Dependencies install another Win32 app first, such as a runtime the main app needs.
Common failures
| Symptom | Usual cause |
|---|---|
| Installs, but shows as failed | Detection rule doesn't match what the installer actually wrote |
| Stuck on "Installing" | The installer is waiting for input. The command isn't really silent |
| Error 0x87D1041C | The app was detected as not installed after the install ran |
| Works on some devices only | 32-bit versus 64-bit paths, or a missing dependency |