GuideInformationBusiness ContinuityIT

Choose the IME log that matches the failed Windows workload

Which Intune Management Extension evidence should be examined for the failing workload?

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsGuide · 2 min read
Executive summary

What you need to know

Which Intune Management Extension evidence should be examined for the failing workload?

Potentially affected

Use this investigation for an IME-dependent Windows workload on a supported device. Identify the failing assignment and installed agent version before deciding which log is relevant.

DSE recommendation

Start with the main extension log for check-in and processing context.

Source facts

The Windows Intune Management Extension checks installations independently of MDM on an eight-hour cycle. Microsoft requires IME 1.58.103.0 or later for dependent configurations and updates. Its logs separate core check-ins, PowerShell execution, app applicability, and Win32 deployment activity. Automatic installation during Intune synchronization is the only supported installation method described by Microsoft. Microsoft Learn.

Applicability

Use this investigation for an IME-dependent Windows workload on a supported device. Identify the failing assignment and installed agent version before deciding which log is relevant.

DSE recommendation

Start with the main extension log for check-in and processing context. For a script failure, inspect AgentExecutor; for app detection, inspect AppActionProcessor; for Win32 deployment, inspect AppWorkload. Correlate the selected records with the assignment and failure time rather than collecting unrelated log lines. Do not repackage or manually install the agent as an improvised repair.

Verification

Confirm that the evidence belongs to the affected device and current attempt. Separate absence of a check-in from an applicability decision or an execution error. Reproduce the authorized workload once on a test endpoint and compare the resulting log sequence with the requested outcome. Preserve the agent version, assignment identity, timestamps, and sanitized failure details so escalation can follow the same path without treating a generic sync status as a complete diagnosis.

Official references

Microsoft Learn: Understand Microsoft Intune Management Extension.

Primary reference

Review the official source

Understand Microsoft Intune Management Extension - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE