“MSI detection method failed” usually means the installer finished but Configuration Manager or Intune could not verify the application afterward. It is not, by itself, proof that msiexec.exe failed. First establish the installer’s return code and resulting files or registry entries, then correct the ProductCode, execution context, registry view, rule logic, or timing that prevents detection.
Error 0x87D00324 is documented by Microsoft as “the application was not detected after installation completed.” Configuration Manager administrators should begin with AppEnforce.log and AppDiscovery.log; Intune Win32 apps use the Intune Management Extension and its configured detection rules.
Identify which Microsoft product is reporting the error
Configuration Manager (SCCM)
The exact error code and logs most often refer to a Configuration Manager application deployment. The client evaluates detection, runs the install command when the application appears absent, and evaluates detection again. If the second check still reports “not installed,” the deployment is marked failed. Configuration Manager MSI detection checks whether the configured MSI ProductCode is installed. See Microsoft’s application evaluation reference and application error reference.
Intune Win32 apps
Intune has similar detection concepts but different management components and rules. A Win32 app can use an MSI ProductCode, file or folder, registry value, or custom detection script. When multiple manual rules are configured, every rule must be satisfied; one stale additional rule can make a correctly installed app appear absent. The current rule behavior is documented in Microsoft’s Win32 app deployment documentation.
#1 Best Overall
- VERSATILE CABLE TESTING: Cable tester for data (RJ45) terminated cables and patch cords, ensuring comprehensive testing capabilities
- LARGE BACKLIT LCD: Backlit LCD display enables easy reading of pin-to-pin wiremap results, even in low-lit areas
- COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, Split-Pair faults, Cross-over, and Shield, providing thorough fault detection
- INTUITIVE USER INTERFACE: User-friendly interface with three buttons and simple, easy-to-identify test responses, ensuring a smooth testing experience
- MULTIPLE TONE GENERATOR STYLES: Tone on a single wire, wire pair, or all 8 conductor wires using the multiple style tone generator (solid/warble); requires probe Cat. No. VDV500-123 (sold separately)
Confirm whether the MSI really installed
Do this before changing detection. Reproduce the exact command used by the deployment, including transforms, properties, silent switches, reboot handling, and execution context, while creating a verbose log:
msiexec.exe /i "C:PathApp.msi" /qn /norestart /L*V "C:WindowsTempApp-install.log"
For an uninstall test:
msiexec.exe /x "{PRODUCT-CODE-GUID}" /qn /norestart /L*V "C:WindowsTempApp-uninstall.log"
Inspect the final MSI return code and the verbose log for rollback, prerequisite, permission, transform, timeout, or reboot conditions. A successful MSI return code still does not prove that the management system’s separate detection rule will succeed.
Check installed metadata and artifacts
Targeted registry queries are generally safer for routine diagnosis than Win32_Product. The latter can be slow and may trigger Windows Installer consistency checks, so use it only when appropriate:
Get-CimInstance Win32_Product |
Select-Object Name, Version, IdentifyingNumber, LocalPackage
IdentifyingNumber is normally the MSI ProductCode in GUID form. To inspect common uninstall locations across machine and user contexts:
$paths = @(
'HKLM:SOFTWAREMicrosoftWindowsCurrentVersionUninstall*',
'HKLM:SOFTWAREWOW6432NodeMicrosoftWindowsCurrentVersionUninstall*',
'HKCU:SOFTWAREMicrosoftWindowsCurrentVersionUninstall*'
)
Get-ItemProperty $paths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -like '*Application Name*' } |
Select-Object DisplayName, DisplayVersion, UninstallString, PSPath
Also verify the executable, service, configuration, and version that the application is expected to create. An absent artifact points to an installation problem; present artifacts with a failed deployment point toward detection.
Validate the MSI ProductCode
ProductCode, PackageCode, UpgradeCode, product name, and filename are different values:
Rank #2
- VERSATILE CABLE TESTING: Cable tester tests voice (RJ11/12), data (RJ45), and video (coax F-connector) terminated cables, providing clear results for comprehensive testing on unenergized Ethernet cables (not designed to test PoE)
- EXTENDED CABLE LENGTH MEASUREMENT: Measure cable length up to 2000 feet (610 m), allowing for precise cable length determination
- COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, or Split-Pair faults, ensuring thorough fault detection and identification
- BACKLIT LCD DISPLAY: Backlit LCD screen displays cable length, wiremap, cable ID, and test results, ensuring easy readability in various lighting conditions
- EFFICIENT CABLE TRACING: Trace cables, wire pairs, and individual conductor wires using the multiple style tone generator (requires analog probe Cat. No. VDV500-123, sold separately), simplifying cable tracing tasks
- ProductCode identifies the installed MSI product and is the normal MSI detection identifier.
- PackageCode identifies a particular MSI package build.
- UpgradeCode groups related products and is not normally used for MSI detection.
- Product name is human-readable and is not a reliable unique identifier.
Open the exact MSI being deployed in Orca or another MSI database tool and inspect its Property table. Compare that ProductCode with the uninstall registration on the target device:
$productCode = '{00000000-0000-0000-0000-000000000000}'
Get-ChildItem `
'HKLM:SOFTWAREMicrosoftWindowsCurrentVersionUninstall',
'HKLM:SOFTWAREWOW6432NodeMicrosoftWindowsCurrentVersionUninstall',
'HKCU:SOFTWAREMicrosoftWindowsCurrentVersionUninstall' `
-ErrorAction SilentlyContinue |
ForEach-Object { Get-ItemProperty $_.PSPath -ErrorAction SilentlyContinue } |
Where-Object { $_.PSChildName -eq $productCode }
Do not assume the filename, display version, and ProductCode change together. A major upgrade may change the ProductCode while retaining a similar name, or separate x86 and x64 MSIs may have different codes. A bootstrapper may also install a child MSI whose ProductCode differs from the wrapper’s name. Intune’s MSI rule requires a valid ProductCode and can optionally compare its version.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsMatch the installation and detection context
Ask four questions: Is the deployment assigned to a device or a user? Does the install behavior run as System or User? Is the MSI authored per-machine or per-user? Does the detection rule inspect HKLM, HKCU, files, services, or MSI registration?
System versus user
A required Configuration Manager application commonly installs as SYSTEM. A per-user MSI may register under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionUninstall, which is the signed-in user’s profile—not the SYSTEM profile. Conversely, a user-targeted install may not create the HKLM data checked by a computer-targeted rule. Applications installed during a task sequence can also use a different context from a later user deployment. A community report describes these context-dependent symptoms, but it is field experience rather than confirmation of a universal product defect: community discussion.
Test as SYSTEM
An elevated administrator session is not equivalent to SYSTEM. With Sysinternals PsExec and suitable local privileges, launch a test shell:
psexec.exe -i -s powershell.exe
Run the same registry, file, and script checks from that shell. This reveals whether the detector can see the same profile and registry view as the deployment client.
Rank #3
- Multifunctional NOYAFA NF-8508 Network Cable Tester: There are nine features to meet your needs. Continuity Testing, Cable Scan, Port Flash, Length Measurement, POE Power Supply Test, QC testing, Optical Power Meter, VFL and NVC function.It is perfectly suited for various engineering cabling projects, network troubleshooting, network equipment maintenance and testing scenarios. Its precise cable scanning and fault localization capabilities help you effortlessly pinpoint the root cause of issues.
- 7 WAVELENGTHS OPTICAL POWER METER: NF-8508 network cable tester can measure 7 standard wavelengths, 850/1300/1310/1490/1550/1625/1650, power detecting range(dBm): -70 ~ +10. Its power detection range spans from -70 dBm to +10 dBm, supporting FC/SC/ST connectors. It enables precise fiber optic power measurement, helping users efficiently assess fiber signal strength and ensure healthy fiber link operation. It effortlessly detects attenuation issues within fibers, thereby safeguarding fiber network stability.
- High Efficiency Visual Fault Locator: Easy identification of fiber breakpoints, poor connections, bending or cracking. Excellent for finding the right fiber to splice or quickly finding a break. Emmiting Energy: standard wavelenth: 650nm. Fast flashing, slow flashing, high precison.The built-in self-calibration ensures stable long-term performance, and Class IIIa laser (output<5mW) ensures safe daily operation.
- PORT FLASHING:The indicator light on the connection port in the NF-8508 device flashes to help accurately locate the cable. Displays port information, including operating speed, duplex mode, and negotiation settings. Port lights flash on the same screen to show the port's operating speed, making it easy to pinpoint lines and ports.
- PoE Testing and Cable Length Test: PoE testing can check cable mapping polarity and voltage of PoE network switches, withstand 60VDC. Automatically detects and switches between 10M/100M/1000M modes, Includes cable tracking, short circuit test, interruption of circuit test and etc The RJ45 cable tester can quickly measure the length of the cable with a range of 200m. Not only network cables, but also phone lines and BNC cables.
Check 32-bit and 64-bit registry views
On 64-bit Windows, 32-bit applications commonly register under:
HKLMSOFTWAREWOW6432NodeMicrosoftWindowsCurrentVersionUninstall
64-bit applications commonly register under:
HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall
Test both views explicitly:
$base = 'HKLM:SOFTWAREMicrosoftWindowsCurrentVersionUninstall'
$wow = 'HKLM:SOFTWAREWOW6432NodeMicrosoftWindowsCurrentVersionUninstall'
Get-ItemProperty "$base*" -ErrorAction SilentlyContinue
Get-ItemProperty "$wow*" -ErrorAction SilentlyContinue
Intune’s registry rule includes an option to associate the rule with a 32-bit application on 64-bit clients; that setting controls which view is searched. A custom PowerShell detector can also be affected by whether the host process is 32-bit or 64-bit, so deliberately handle the intended view.
Audit every detection clause
One incorrect additional condition is enough to fail detection. Check for:
- A stale file, registry path, or value left from an earlier package.
- An exact version comparison when vendor servicing changes the version.
- A requirement for a value the installer never creates.
- AND logic where either of two valid states was intended, or an OR model that does not match the platform’s rule behavior.
- Rules mixing per-user and per-machine locations.
- A ProductCode belonging to a superseded MSI.
- A folder-only rule where the folder survives uninstall.
For Intune, Microsoft states that all configured detection conditions must be met. Configuration Manager connectors and clauses require equally deliberate testing; do not copy Intune’s behavior assumptions into a ConfigMgr rule. A Microsoft Q&A case reports intermittent results with multiple registry clauses and an OR connector, but that is case-specific: Q&A discussion.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Allow for delayed registration
Detection can run while a wrapper’s child process is still finishing, MSI registration is being written, a service is starting, or a first-launch file is being created. A Microsoft Q&A response suggests adding a delay for timing-related cases; treat that as a workaround, not proof that a fixed delay is universally required: Q&A example.
Preserve the installer’s exit code before checking the post-install condition:
Rank #4
- Automatically runs all tests and checks for continuity, open, shorted and crossed wire pairs. Visible LED status display.
- Cable state testing (2-wire): Line DC detecting, anode and cathode determination,Ringing signal detecting open, short and cross circuit testing
- Cable Type: RJ11 Telephone cable and RJ45 LAN cable
- Connectors: Ethernet Cat 5, Ethernet Cat 5e, Ethernet Cat 6, Ethernet Cat 7, RJ11 6P and RJ45 8P
- Power Source: DC9V Battery Required (not included)
Start-Process msiexec.exe `
-ArgumentList '/i "C:PathApp.msi" /qn /norestart' `
-Wait `
-PassThru
$msiExitCode = $LASTEXITCODE
Start-Sleep -Seconds 15
exit $msiExitCode
A deterministic wait is better than an arbitrary sleep:
$deadline = (Get-Date).AddSeconds(60)
$installed = $false
do {
$installed = Test-Path 'C:Program FilesVendorAppApp.exe'
if ($installed) { break }
Start-Sleep -Seconds 5
} while ((Get-Date) -lt $deadline)
if ($installed) { exit 0 }
exit 1
Use a condition that represents a completed installation, such as a versioned executable or running service, rather than merely waiting longer.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Choose a less fragile detection method
| Method | Best fit | Main risk |
|---|---|---|
| MSI ProductCode | Conventional per-machine MSI with stable metadata | Major upgrades, wrappers, context, or architecture can change what is registered |
| Registry value | Stable vendor key and explicit version value | Wrong hive, view, value, or stale key |
| File and version | Known executable or DLL reliably installed and updated | Relocated files, per-user paths, or unchanged files after uninstall |
| Custom script | Several valid ProductCodes, architectures, or combined checks | Context, host architecture, encoding, and script output errors |
Registry or file detection
A vendor-specific rule might check HKLMSOFTWAREVendorProduct, value Version, with a “greater than or equal to 4.2.0” comparison. A file rule might check C:Program FilesVendorProductProduct.exe and its product version. Choose a path that uniquely identifies the required product and installation state.
Intune custom script
For Intune, exit code 0 indicates successful script execution and output to STDOUT indicates detection. A nonzero exit code means not installed. Output to STDERR causes the result to be evaluated as not installed even if STDOUT and the exit code otherwise indicate success. Microsoft recommends UTF-8 with BOM encoding. Example:
$minimumVersion = [version]'4.2.0'
$file = 'C:Program FilesVendorProductProduct.exe'
if (-not (Test-Path -LiteralPath $file)) { exit 1 }
try {
$actualVersion = [version](Get-Item $file).VersionInfo.ProductVersion
} catch {
exit 1
}
if ($actualVersion -ge $minimumVersion) {
Write-Output "Detected Product version $actualVersion"
exit 0
}
exit 1
Keep diagnostic output controlled and do not write errors to STDERR.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Read the right logs
Configuration Manager log order
- AppEnforce.log: confirms that the command launched, shows execution context, return code, timeout, and reboot behavior.
- AppDiscovery.log: shows the detection method, searched location or ProductCode, and whether the deployment type was detected.
- AppIntentEval.log: shows applicability, requirements, dependencies, and supersedence decisions.
- CIAgent.log: shows configuration-item and application evaluation activity.
These log roles are listed in Microsoft’s Configuration Manager log reference. Search for the application name, deployment type, ProductCode, or deployment type unique ID. “Command completed” in AppEnforce followed by “did not detect app deployment type” in AppDiscovery indicates a detection problem, not necessarily an MSI failure.
Recommended Free Tools
Best Value
- Multi-Function Network Cable Tester: Supports RJ45 (CAT5, CAT5e, CAT6, CAT6A, CAT7) and RJ11 telephone cables. Quickly detects continuity, short circuits, open wires, miswiring, and cable shielding status, ensuring your LAN or phone lines are correctly wired and ready to use.
- Fast/Slow Mode with LED Indicators: Switch between fast and slow scan speeds to identify wiring issues more precisely. LED lights on both master and remote units show wire order, making it easy to spot errors like open pairs or misaligned pins at a glance.
- Split-Type Design for Long-Distance Testing: Master and remote units can be detached and used separately, allowing you to test both ends of a long cable run, ideal for wall-mounted ports, long runs, or structured cabling. Perfect for home, office, or professional IT setups.
- Compact, Lightweight & Durable: Ergonomically designed with sturdy ABS housing, this pocket-sized tester is ideal for on-the-go network engineers, DIYers, and electricians. It’s your go-to toolkit for cable maintenance, upgrades, or new installations.
- Safe & Easy to Use: Simple one-button operation makes testing quick and hassle-free. LED indicators clearly show wiring status, while the G light instantly identifies shielded (FTP/STP) or unshielded (UTP) cables. Supports safe testing of telephone lines with typical voltages under 48-72V, ideal for both home and professional use.
Intune logs
For Win32 apps, inspect the Intune Management Extension logs, especially:
C:ProgramDataMicrosoftIntuneManagementExtensionLogsIntuneManagementExtension.log
C:ProgramDataMicrosoftIntuneManagementExtensionLogsAppWorkload.log
Use these to correlate the install command, detection evaluation, script output, and retry behavior. Do not substitute Intune logs for ConfigMgr logs when the deployment is managed by Configuration Manager.
What to do after correcting detection
- Save the revised deployment type or Win32 app configuration.
- Confirm that policy replication or Intune synchronization has completed.
- Trigger the relevant machine-policy and application-evaluation cycle.
- Review the new detection entries in AppDiscovery.log or the Intune Management Extension logs.
- Use Retry only after the rule is corrected.
A detection-only change does not automatically mean MSI content must be redistributed. A Microsoft Q&A discussion recommends reviewing policy and agent logs instead of treating content redistribution as mandatory: Q&A guidance. Avoid repeatedly reinstalling an application that is already present.
Printable troubleshooting checklist
- Identify whether the deployment is Configuration Manager or Intune Win32.
- Read the installer return code and verbose MSI log.
- Verify the expected executable, service, registry entry, and version.
- Confirm the exact ProductCode from the deployed MSI, not its filename or UpgradeCode.
- Check for major-upgrade or x86/x64 ProductCode changes.
- Match device/user targeting with System/User installation behavior.
- Test HKLM and HKCU in the correct security context.
- Test both 32-bit and 64-bit registry views.
- Review every detection clause, comparison, path, and connector.
- Check for delayed child processes, service startup, or registration.
- Read AppEnforce and AppDiscovery first for ConfigMgr; use Intune Management Extension logs for Intune.
- Refresh policy and retry only after the detector is deterministic.
Frequently Asked Questions
Does 0x87D00324 prove that the MSI failed?
No. It means the application was not detected after installation completed. Prove an installer failure from the MSI return code and verbose log; otherwise investigate detection.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Why does the application install manually but fail through Configuration Manager?
Manual testing may use your administrator profile and a different 32-bit/64-bit process. Reproduce the deployment’s System/User context, registry view, command line, and reboot behavior.
Should I add a delay after msiexec?
Only when logs and testing indicate delayed registration or a child process race. A deterministic wait for a file, version, or service is more reliable than a blind sleep.
Do I need to redistribute MSI content after changing detection?
Not normally for a detection-only change. Refresh policy, allow the revised rule to arrive, and verify a new evaluation in the appropriate logs.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

