SOLVED

Install Office after Autopilot

%3CLINGO-SUB%20id%3D%22lingo-sub-1334166%22%20slang%3D%22en-US%22%3EInstall%20Office%20after%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1334166%22%20slang%3D%22en-US%22%3E%3CP%3EHi.%20Working%20with%20a%20client%20to%20deploy%20Autopilot.%26nbsp%3B%20We%20are%20running%20into%20a%20problem%20where%20we%20would%20like%20to%20have%20Office%20installed%20but%20only%20after%20the%20desktop%20is%20released%20to%20the%20user.%20Meaning%2C%20on%20the%20Enrollment%20Status%20Page%2C%20we%20have%20selected%20the%20apps%20that%20must%20be%20installed%20before%20the%20user%20access%20the%20desktop.%26nbsp%3B%20These%20are%20typically%20security%20apps.%26nbsp%3B%20The%20client%20would%20like%20to%20have%20Office%20installed%20automatically%20too%20(so%20its%20assignment%20is%20%22Required%22%20and%20assigned%20to%20a%20user%20group).%20However%2C%20as%20long%20as%20Office%20is%20%22Required%22%20it%20always%20gets%20added%20to%20the%20list%20of%20apps%20to%20install%20while%20the%20device%20is%20blocked%20by%20the%20ESP%20page.%26nbsp%3B%20Is%20there%20anyway%20to%20have%20Office%20install%20after%20the%20desktop%20is%20released%3F%26nbsp%3B%20I%20have%20tested%20other%20apps%26nbsp%3B%20that%20are%20required%20and%20they%20install%20after%20the%20user%20gets%20to%20the%20desktop.%26nbsp%3B%20Why%20not%20Office%3F%26nbsp%3B%20Bug%3F%26nbsp%3B%20What%20have%20I%20configured%20wrong%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1334166%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1334452%22%20slang%3D%22en-US%22%3ERe%3A%20Install%20Office%20after%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1334452%22%20slang%3D%22en-US%22%3EI%20think%20it%E2%80%99s%20a%20bug%2C%20I%20have%20tried%20that%20policy%20last%20year%20and%20opened%20case%20with%20MSFT%2C%20they%20agreed%20about%20the%20issue%20but%20no%20fix.%20Surprised%20to%20see%20it%20still%20exists%20though!%3CBR%20%2F%3E%3CBR%20%2F%3EHere%20is%20evidence%20about%20the%20issue-%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fborncity.com%2Fwin%2F2018%2F12%2F09%2Fintune-autopilot-block-app-install-via-enrollment-status-page%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fborncity.com%2Fwin%2F2018%2F12%2F09%2Fintune-autopilot-block-app-install-via-enrollment-status-page%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EHope%20this%20helps%20and%20please%20keep%20us%20updated%20with%20your%20results!%3CBR%20%2F%3E%3CBR%20%2F%3EMoe%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1334965%22%20slang%3D%22en-US%22%3ERe%3A%20Install%20Office%20after%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1334965%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20think%20the%20issue%20is%20based%20on%20the%20following%20fact.%20As%20long%20as%20software%20is%20installed%20via%20Intune%20Management%20Extension%20(IME)%20Agent%20the%20IME%20can%20coordinate%20the%20behavior.%20This%20can%20also%20be%20seen%20in%20the%20log%20files%20like%20checking%20ESP%20phase%20etc.%3C%2FP%3E%0A%3CP%3EThe%20Office%20365%20ProPlus%20install%20is%20%3CU%3Enot%3C%2FU%3E%20driven%20by%20IME%20it%20is%20a%20separate%20Configuration%20Service%20Provider%20(CSP)%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Foffice-csp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Foffice-csp%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EThe%20Office%20CSP%20basically%20gets%20the%20XML%20definition%20by%20MDM%20channel%2C%20then%20uses%20the%20ODT%20to%20do%20the%20install%20and%20monitors%20everything%20to%20report%20on%20it.%20So%2C%20we%20are%20talking%20about%20a%20kind%20of%20side%20channel.%20The%20process%20how%20Windows%20and%20Intune%20is%20handling%20the%20enrollment%20is%20driven%20by%20no%20specific%20order%2C%20meaning%20there%20is%20no%20defined%20sequence%20like%20first%20install%20am%20then%20b%2C%20then%20c...%20This%20means%20the%20MDM%20driven%20instruction%20for%20the%20Office%20CSP%20does%20get%20the%20command%20to%20trigger%20Office%20install%20and%20the%20IME%20does%20have%20it's%20own%20channel%20to%20get%20the%20apps%20to%20install.%20IME%20does%20respect%20the%20ESP%20phase%20where%20the%20MDM%20Office%20CSP%20driven%20channel%20does%20not.%20This%20is%20why%20you%20especially%20with%20Office%20see%20this%20install%20during%20ESP.%20As%20the%20Office%20CSP%20will%20kick%20off%20the%20process%20as%20soon%20as%20he%20gets%20the%20MDM%20SyncML%20instructions.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20think%20there%20is%20no%20mechanism%20currently%20to%20coordinate%20this...%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1335481%22%20slang%3D%22en-US%22%3ERe%3A%20Install%20Office%20after%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1335481%22%20slang%3D%22en-US%22%3EThanks%20for%20the%20clarification%20Oliver!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1335765%22%20slang%3D%22en-US%22%3ERe%3A%20Install%20Office%20after%20Autopilot%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1335765%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F174439%22%20target%3D%22_blank%22%3E%40Oliver%20Kieselbach%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20the%20reply.%26nbsp%3B%20I%20guess%20this%20is%20supported%20by%20having%20Office%20%22required%22%20(processes%20immediately%20when%20target%20receives%20instructions)%20versus%20%22available%22%20(user%20driven).%3CBR%20%2F%3EThis%20also%20explains%20why%20I%20can%20see%20Firefox%20working%20correctly%20with%20the%20IME%20while%20Office%20does%20its%20own%20thing.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20wish%20this%20was%20more%20clear%20in%20the%20docs%20for%20installing%20Office%20through%20Intune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPaul%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hi. Working with a client to deploy Autopilot.  We are running into a problem where we would like to have Office installed but only after the desktop is released to the user. Meaning, on the Enrollment Status Page, we have selected the apps that must be installed before the user access the desktop.  These are typically security apps.  The client would like to have Office installed automatically too (so its assignment is "Required" and assigned to a user group). However, as long as Office is "Required" it always gets added to the list of apps to install while the device is blocked by the ESP page.  Is there anyway to have Office install after the desktop is released?  I have tested other apps  that are required and they install after the user gets to the desktop.  Why not Office?  Bug?  What have I configured wrong?

4 Replies
Highlighted
I think it’s a bug, I have tried that policy last year and opened case with MSFT, they agreed about the issue but no fix. Surprised to see it still exists though!

Here is evidence about the issue-

https://borncity.com/win/2018/12/09/intune-autopilot-block-app-install-via-enrollment-status-page/

Hope this helps and please keep us updated with your results!

Moe
Highlighted
Solution

Hi,

 

I think the issue is based on the following fact. As long as software is installed via Intune Management Extension (IME) Agent the IME can coordinate the behavior. This can also be seen in the log files like checking ESP phase etc.

The Office 365 ProPlus install is not driven by IME it is a separate Configuration Service Provider (CSP)

https://docs.microsoft.com/en-us/windows/client-management/mdm/office-csp

The Office CSP basically gets the XML definition by MDM channel, then uses the ODT to do the install and monitors everything to report on it. So, we are talking about a kind of side channel. The process how Windows and Intune is handling the enrollment is driven by no specific order, meaning there is no defined sequence like first install am then b, then c... This means the MDM driven instruction for the Office CSP does get the command to trigger Office install and the IME does have it's own channel to get the apps to install. IME does respect the ESP phase where the MDM Office CSP driven channel does not. This is why you especially with Office see this install during ESP. As the Office CSP will kick off the process as soon as he gets the MDM SyncML instructions.

 

I think there is no mechanism currently to coordinate this...

 

best,

Oliver

Highlighted
Thanks for the clarification Oliver!
Highlighted

@Oliver Kieselbach 

Thank you for the reply.  I guess this is supported by having Office "required" (processes immediately when target receives instructions) versus "available" (user driven).
This also explains why I can see Firefox working correctly with the IME while Office does its own thing.

 

I wish this was more clear in the docs for installing Office through Intune.

 

Paul