# Choose the IME log that matches the failed Windows workload

> Which Intune Management Extension evidence should be examined for the failing workload?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-307-choose-the-ime-log-that-matches-the-failed-windows-workload/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:49+00:00
- Modified: 2026-09-10T01:40:02+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Which Intune Management Extension evidence should be examined for the failing workload?

## Potentially affected

Use this investigation for an IME-dependent Windows workload on a supported device. Identify the failing assignment and installed agent version before deciding which log is relevant.

## DSE recommendation

Start with the main extension log for check-in and processing context.

## Article

## Source facts

The Windows Intune Management Extension checks installations independently of MDM on an eight-hour cycle. Microsoft requires IME 1.58.103.0 or later for dependent configurations and updates. Its logs separate core check-ins, PowerShell execution, app applicability, and Win32 deployment activity. Automatic installation during Intune synchronization is the only supported installation method described by Microsoft. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-management/tools/management-extension-windows).

## Applicability

Use this investigation for an IME-dependent Windows workload on a supported device. Identify the failing assignment and installed agent version before deciding which log is relevant.

## DSE recommendation

Start with the main extension log for check-in and processing context. For a script failure, inspect AgentExecutor; for app detection, inspect AppActionProcessor; for Win32 deployment, inspect AppWorkload. Correlate the selected records with the assignment and failure time rather than collecting unrelated log lines. Do not repackage or manually install the agent as an improvised repair.

## Verification

Confirm that the evidence belongs to the affected device and current attempt. Separate absence of a check-in from an applicability decision or an execution error. Reproduce the authorized workload once on a test endpoint and compare the resulting log sequence with the requested outcome. Preserve the agent version, assignment identity, timestamps, and sanitized failure details so escalation can follow the same path without treating a generic sync status as a complete diagnosis.

## Official references

[Microsoft Learn: Understand Microsoft Intune Management Extension](https://learn.microsoft.com/en-us/intune/device-management/tools/management-extension-windows).

## Primary reference

- Name: Understand Microsoft Intune Management Extension - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-management/tools/management-extension-windows
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose the IME log that matches the failed Windows workload,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-307-choose-the-ime-log-that-matches-the-failed-windows-workload/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
