Win10 Hybrid AD Joined Computers Unable to install apps from Company Portal

%3CLINGO-SUB%20id%3D%22lingo-sub-1589827%22%20slang%3D%22en-US%22%3EWin10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1589827%22%20slang%3D%22en-US%22%3E%3CP%3EAll%20of%20our%20Windows%2010%20machines%20are%20unable%20to%20install%20any%20application%20from%20the%20Intune%20Company%20Portal.%20When%20trying%20to%20install%20an%20application%20from%20Company%20Portal%2C%20it%20almost%20immediately%20says%20%22it's%20taking%20a%20little%20longer%20than%20usual%20to%20install%20this%20app.%20Try%20to%20install%20it%20again%22%20and%20then%20presents%20a%20Retry%20button.%20.MSI%2C%20Windows%20Store%20for%20Business%2C%20and%20even%20the%20Microsoft-created%20Office%20and%20new%20Edge%20packages%20all%20do%20the%20same%20thing.%20Also%20doesn't%20matter%20if%20application%20is%20set%20as%20required%20install%20or%20just%20made%20available%20in%20Intune%20Portal.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20our%20Windows%20machines%20are%20Hybrid%20AD%20joined%20to%20Azure%20AD%20and%20enrolled%20in%20Intune%20via%20GPO.%20They%20show%20up%20as%20%22compliant%22%20in%20the%20device%20management%20portal%20and%20do%20get%20updated%20config%2Fcompliance%20policies.%20The%20devices%20don't%20show%20as%20requesting%20the%20application%20for%20install%20when%20you%20look%20at%20the%20Intune%20portal%20either.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEvent%20Viewer%20logs%20in%20Applications%20%26gt%3B%20Windows%20%26gt%3B%20DeviceManagement-Enterprise-Diagnostics-Provider%20show%20several%20error%20entries%20like%20the%20below%3A%3C%2FP%3E%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%22MDM%20ConfigurationManager%3A%20Command%20failure%20status.%20Configuration%20Source%20ID%3A%20(CCADB38D-B155-4CAA-820F-52B368E2EEE4)%2C%20Enrollment%20Name%3A%20(MDMDeviceWithAAD)%2C%20Provider%20Name%3A%20(Policy)%2C%20Command%20Type%3A%20(Add%3A%20from%20Replace%20or%20Add)%2C%20CSP%20URI%3A%20(.%2FDevice%2FVendor%2FMSFT%2FPolicy%2FConfigOperations%2FADMXInstall%2FReceiver%2FProperties%2FPolicy%2FFakePolicy%2FVersion)%2C%20Result%3A%20(The%20system%20cannot%20find%20the%20file%20specified.).%22%3C%2FP%3E%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eand%3A%3C%2FP%3E%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%22MDM%20PolicyManager%3A%20Set%20policy%20int%2C%20Policy%3A%20(RequireRetrieveHealthCertificateOnBoot)%2C%20Area%3A%20(Security)%2C%20EnrollmentID%20requesting%20set%3A%20(CCADB38D-B155-4CAA-820F-52B368E2EEE4)%2C%20Current%20User%3A%20(Device)%2C%20Int%3A%20(0x1)%2C%20Enrollment%20Type%3A%20(0x6)%2C%20Scope%3A%20(0x0)%2C%20Result%3A(0x80004005)%20Unspecified%20error.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20thoughts%20on%20how%20to%20resolve%20and%20get%20our%20applications%20back%20to%20installing%3F%20Even%20setting%20up%20blank%2C%20new%20machines%20and%20enrolling%20yields%20the%20same%20errors.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1589827%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESoftware%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1591982%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1591982%22%20slang%3D%22en-US%22%3EWhat%20version%20of%20Windows%20are%20you%20using%3F%3CBR%20%2F%3E%3CBR%20%2F%3EMoe%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1591993%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1591993%22%20slang%3D%22en-US%22%3EHi%20Moe.%20We%20are%20all%20on%202004.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1593761%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1593761%22%20slang%3D%22en-US%22%3EDo%20you%20have%20SCCM%20configured%20in%20your%20environment%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1594914%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1594914%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3Bno%20SCCM.%20PCs%20are%20auto%20joined%20to%20Azure%20AD%20and%20enrolled%20in%20Intune%20via%20GPO.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1595747%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1595747%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F24652%22%20target%3D%22_blank%22%3E%40Seth%20Tate%3C%2FA%3E%26nbsp%3BThe%20Fakepolicy%20event%20can%20be%20ignored.%20Don%60t%20know%20exactly%20why%20the%20event%20is%20logged%2C%20but%20MS%20support%20confirmed%20there%20is%20no%20issue%20when%20you%20see%20the%20event.%3CBR%20%2F%3E%3CBR%20%2F%3EWhen%20deploying%20win32%20apps%20have%20a%20look%20at%20this%20log%20file%20C%3A%5CProgramData%5CMicrosoft%5CIntuneManagementExtension%5CLogs%5CIntuneManagementExtension.log%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20logs%20everything%20related%20to%20the%20app%20deployments%20when%20using%20win32%20app%20deployment%2C%20but%20also%20Edge%20should%20be%20logged%20in%20this%20file.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1595826%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1595826%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3194%22%20target%3D%22_blank%22%3E%40Peter%20Klapwijk%3C%2FA%3EI%20don%E2%80%99t%20have%20any%20Win32%20apps%20that%20I%20packaged%20myself.%20We%20are%20only%20trying%20to%20push%2Fmake%20available%20MSI%20installers%20and%20Windows%20Store%20for%20Business%20apps%20in%20addition%20to%20the%20Microsoft-provided%20Office%20and%20Edge%20bundles.%20None%20of%20them%20install%20on%20any%20Windows%2010%20machine%20-%20leaving%20manual%20install%20the%20only%20option%20for%20us%20to%20get%20by.%20When%20we%20were%20troubleshooting%2C%20the%20management%20extension%20didn%E2%80%99t%20even%20create%20any%20logs%20until%20a%20couple%20of%20days%20ago%20and%20this%20has%20been%20going%20on%20for%20almost%202%20months.%20All%20seems%20related%20to%20to%20the%20Company%20Portal.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1598002%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1598002%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F24652%22%20target%3D%22_blank%22%3E%40Seth%20Tate%3C%2FA%3E%26nbsp%3BThe%20recommended%20way%20to%20go%20for%20installing%20LOB%20apps%20is%20win32%2C%20even%20if%20these%20are%20MSI%20files.%3CBR%20%2F%3EWin32%20provides%20more%20control%20and%20better%20logging.%20I%20recommend%20to%20at%20least%20wrap%20one%20MSI%20into%20win32%20package%20to%20test.%20As%20far%20as%20I%20know%20MSI%20isn%60t%20tracked%20(anymore)%20during%20ESP.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20Intune%20management%20extension%20only%20handles%20win32%20apps%20and%20PowerShell%20scripts%2C%20that%20is%20probably%20the%20reason%20you%20don%60t%20see%20logging.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1599831%22%20slang%3D%22en-US%22%3ERe%3A%20Win10%20Hybrid%20AD%20Joined%20Computers%20Unable%20to%20install%20apps%20from%20Company%20Portal%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1599831%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3194%22%20target%3D%22_blank%22%3E%40Peter%20Klapwijk%3C%2FA%3E%26nbsp%3B%20I%20agree%20the%20logging%20is%20better%20with%20win32%20apps.%20However%2C%20none%20of%20our%20apps%20are%20setup%20that%20way%2C%20nor%20is%20that%20an%20option.%20Some%20apps%20are%20Windows%20Store%20for%20Business%20apps%20that%20sync%20with%20Intune.%20I%20think%20our%20problem%20has%20something%20to%20do%20with%20our%20tenant%20because%20it%20immediately%20fails%20when%20you%20try%20to%20install%20an%20application.%20It%20doesn't%20even%20download%20the%20install%20files.%20Intune%20device%20management%20portal%20shows%20no%20status%20that%20a%20device%20has%20requested%20install%20either.%20While%20I%20don't%20have%20a%20win32%20app%20already%20setup%20in%20Intune%20to%20test%2C%20I%20have%20a%20strong%20feeling%20they%20would%20have%20the%20same%20behavior%20as%20Windows%20Store%20and%20MSI%20apps.%20Have%20you%20ever%20run%20into%20the%20Company%20Portal%20saying%20%22it's%20taking%20longer%20than%20usual%20to%20install%20this%20app%22%20immediately%20after%20clicking%20the%20install%20button%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

All of our Windows 10 machines are unable to install any application from the Intune Company Portal. When trying to install an application from Company Portal, it almost immediately says "it's taking a little longer than usual to install this app. Try to install it again" and then presents a Retry button. .MSI, Windows Store for Business, and even the Microsoft-created Office and new Edge packages all do the same thing. Also doesn't matter if application is set as required install or just made available in Intune Portal.

 

All our Windows machines are Hybrid AD joined to Azure AD and enrolled in Intune via GPO. They show up as "compliant" in the device management portal and do get updated config/compliance policies. The devices don't show as requesting the application for install when you look at the Intune portal either.

 

Event Viewer logs in Applications > Windows > DeviceManagement-Enterprise-Diagnostics-Provider show several error entries like the below:

"MDM ConfigurationManager: Command failure status. Configuration Source ID: (CCADB38D-B155-4CAA-820F-52B368E2EEE4), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI: (./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Receiver/Properties/Policy/FakePolicy/Version), Result: (The system cannot find the file specified.)."

 

and:

"MDM PolicyManager: Set policy int, Policy: (RequireRetrieveHealthCertificateOnBoot), Area: (Security), EnrollmentID requesting set: (CCADB38D-B155-4CAA-820F-52B368E2EEE4), Current User: (Device), Int: (0x1), Enrollment Type: (0x6), Scope: (0x0), Result:(0x80004005) Unspecified error."

 

Any thoughts on how to resolve and get our applications back to installing? Even setting up blank, new machines and enrolling yields the same errors.

10 Replies
What version of Windows are you using?

Moe
Do you have SCCM configured in your environment?

@Thijs Lecomte no SCCM. PCs are auto joined to Azure AD and enrolled in Intune via GPO.

@Seth Tate The Fakepolicy event can be ignored. Don`t know exactly why the event is logged, but MS support confirmed there is no issue when you see the event.

When deploying win32 apps have a look at this log file C:\ProgramData\Microsoft\IntuneManagementExtension\Logs\IntuneManagementExtension.log

It logs everything related to the app deployments when using win32 app deployment, but also Edge should be logged in this file.

@Peter KlapwijkI don’t have any Win32 apps that I packaged myself. We are only trying to push/make available MSI installers and Windows Store for Business apps in addition to the Microsoft-provided Office and Edge bundles. None of them install on any Windows 10 machine - leaving manual install the only option for us to get by. When we were troubleshooting, the management extension didn’t even create any logs until a couple of days ago and this has been going on for almost 2 months. All seems related to to the Company Portal.

@Seth Tate The recommended way to go for installing LOB apps is win32, even if these are MSI files.
Win32 provides more control and better logging. I recommend to at least wrap one MSI into win32 package to test. As far as I know MSI isn`t tracked (anymore) during ESP.

The Intune management extension only handles win32 apps and PowerShell scripts, that is probably the reason you don`t see logging.

@Peter Klapwijk  I agree the logging is better with win32 apps. However, none of our apps are setup that way, nor is that an option. Some apps are Windows Store for Business apps that sync with Intune. I think our problem has something to do with our tenant because it immediately fails when you try to install an application. It doesn't even download the install files. Intune device management portal shows no status that a device has requested install either. While I don't have a win32 app already setup in Intune to test, I have a strong feeling they would have the same behavior as Windows Store and MSI apps. Have you ever run into the Company Portal saying "it's taking longer than usual to install this app" immediately after clicking the install button?

Hello, do you still have this issue? This could be related to conditional access policy and MFA.

//Nicklas
Hi, Not experiencing this issue anymore. Microsoft fixed/addressed something on their end and we were able to deploy apps again. No changes to MFA or conditional access required on my side. Thanks.