# Check every app relationship's install context on multi-session desktops

> Why can a system-context Intune app still fail to install on an Azure Virtual Desktop multi-session VM?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:57+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Why can a system-context Intune app still fail to install on an Azure Virtual Desktop multi-session VM?

## Potentially affected

Apply this check to Intune-managed Azure Virtual Desktop Windows Enterprise multi-session VMs that meet the documented prerequisites. Intune's multi-session support does not extend to Citrix DaaS or VMware Horizon Cloud.

## DSE recommendation

Review the complete app relationship graph before changing the parent assignment.

## Article

## Source facts

Intune requires apps for Windows Enterprise multi-session to install in system or device context and target devices. Only Required and Uninstall assignment intents are supported, not Available. A system-context Win32 app will not install if a dependency or supersedence relationship points to a user-context app. Microsoft recommends a separate system-context instance or making all dependencies system-context. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session).

## Applicability

Apply this check to Intune-managed Azure Virtual Desktop Windows Enterprise multi-session VMs that meet the documented prerequisites. Intune’s multi-session support does not extend to Citrix DaaS or VMware Horizon Cloud.

## DSE recommendation

Review the complete app relationship graph before changing the parent assignment. List each dependency and superseded app with its configured install context. Identify the intended device group and assignment intent. If a user-context relationship is present, design and test the supported system-context package arrangement with the application owner. Do not assume that changing only the parent app’s context resolves its linked packages or preserves the intended application behavior.

## Verification

In an approved multi-session test pool, confirm the effective assignments and the context of every linked app before checking installation results. Exercise the application with the intended users and retain the dependency outcomes, not only the parent’s status. Keep any separate package instance clearly identified in the handoff. If an app still fails, investigate its actual relationship and installation evidence before widening its target population.

## Official references

[Microsoft Learn: Using Azure Virtual Desktop multi-session with Microsoft Intune](https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session).

## Primary reference

- Name: Using Azure Virtual Desktop multi-session with Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/solutions/azure-virtual-desktop-multi-session
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check every app relationship's install context on multi-session desktops,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-419-check-every-app-relationship-s-install-context-on-multi-session-desktops/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
