msnugget
Intune By Jannik Reinhard & Florian Salzmann · Published · Updated

Retry Failed Win32 Apps on Demand with Intune Remediations

When a Win32 app fails to install, Intune does not retry immediately. The Intune Management Extension (IME) enters a Global Re-evaluation Schedule (GRS) and waits up to 24 hours before the next attempt. If you are actively troubleshooting or just fixed the root cause, that wait is unacceptable.

Why this matters

The GRS behaviour catches many admins off guard. After three consecutive failed attempts with five minute intervals, the IME locks the app into a 24 hour cooldown. Even if you update the app package, change the detection rule, or fix the install command in the portal, IME will not process the app again until GRS expires. It simply skips it during every hourly sync.

This means a single misconfigured app can sit in a failed state for a full day, and there is no built in button in Intune to force a retry.

The workaround is to remove the app’s registry keys under HKLM\SOFTWARE\Microsoft\IntuneManagementExtension\Win32Apps\{UserSID}\{AppID} and the corresponding GRS subkey, then restart the IME service. That clears the cooldown and lets IME re evaluate the app on the next sync.

Retry Failed Win32 Apps on Demand with Intune Remediations

When to use it

The best fit for this approach is combining it with Intune’s on demand remediation feature. Create a remediation package with a detection script that checks for failed Win32 app states in the registry and a remediation script that cleans up the relevant keys and restarts IME. You can then trigger it from the Intune portal on a per device basis without waiting for a schedule.

This is ideal during app packaging testing, after fixing a broken installer, or when a helpdesk technician needs to resolve a stuck deployment remotely without remoting into the device.

When NOT to use it

Do not use this as a permanent fix for apps that keep failing. If the same app enters GRS repeatedly, the problem is in the package, the detection rule, or a dependency. Clearing registry keys just resets the retry counter. It does not fix the underlying issue. Also keep in mind that on demand remediations require Windows Enterprise or Education licensing and the device must be online and reachable via WNS.

Example scenario

You update a Win32 app’s install command to fix a silent switch, but 200 devices already failed and are sitting in GRS. Instead of waiting 24 hours or manually touching each machine, you trigger the remediation on demand for the affected devices. IME picks up the corrected app within minutes.

Recommendation

Create a dedicated remediation package for retrying failed apps and keep it unassigned. That way it is always available for on demand use without running on a schedule across your fleet. The detection script checks for failed app states, the remediation script cleans up registry keys and restarts IME.

You can find ready to use detection and remediation scripts here:

Dowload RetryFailedApps on GitHub

Runbook notes for Retry Failed Win32 Apps on Demand with Intune Remediations

Retry Failed Win32 Apps on Demand with Intune Remediations deserves a little more operational context because the decision usually affects app recovery. The related items are Intune remediations, Win32 app retry, detection rules, on-demand action, helpdesk flow. Treat this Nugget as a starting point for a concrete tenant decision: who is in scope, which Microsoft portal or policy is touched, and what visible result should confirm that the configuration worked.

When validating Retry Failed Win32 Apps on Demand with Intune Remediations, keep the test narrow enough to understand the result. Select one representative user, device, workload or subscription, capture the current state, then apply the change and compare the outcome. This avoids guessing later when support sees a different enrollment state, access result, model response, update status or admin center signal.

The most useful documentation for Retry Failed Win32 Apps on Demand with Intune Remediations is practical rather than theoretical. Record the assignment logic, the owner, the expected monitoring view and the exception path. If the change affects users, include the wording support teams should use when they explain the behavior. If it affects devices or services, include the exact place where administrators can verify health.

For search consistency, keep the phrase Retry Failed Win32 Apps on Demand with Intune Remediations connected to the body text, the internal links and the category context. That helps readers understand why this Microsoft admin topic belongs with the surrounding Intune, Entra, Azure, Copilot, Security or automation Nuggets, and it gives AI search systems clearer signals about the real subject of the page.

Jannik Reinhard

Head of AI

Jannik brings deep expertise in AI integration, modern infrastructure, and enterprise transformation at scale.

Florian Salzmann

Leading Expert

Florian specializes in Intune, endpoint management, and security with extensive real-world enterprise experience.