The Intune Management Extension (IME) Health Evaluation is a Windows scheduled task that launches ClientHealthEval.exe to check selected parts of the IME agent’s service health and, in some cases, correct them. It can help with a missing, stopped, or misconfigured IME service; it is not a general repair tool for failed Win32 app deployments.
On many devices, the task appears in Task Scheduler under Task Scheduler Library > Microsoft > Intune, and the executable is commonly installed at C:Program Files (x86)Microsoft Intune Management ExtensionClientHealthEval.exe. Verify both paths on the device: IME updates automatically, and internal task details can change between versions.
What the Intune Management Extension does
IME supplements Windows’ native mobile device management (MDM) channel. Microsoft uses it for Windows management workloads that require an agent, including Win32 apps, PowerShell scripts, Microsoft Store apps, custom compliance settings, and remediations. It is not required for every Intune policy or operation.
| Component | Primary role |
|---|---|
| Windows MDM channel | Configuration profiles, many policy settings, and standard MDM operations. |
| Intune Management Extension | Agent-based workloads such as Win32 applications, scripts, and remediations. |
| Company Portal | User-facing app and device experience. |
| Intune service | Cloud policy, assignment, orchestration, and reporting. |
Microsoft says IME installs automatically when a device meets the applicable prerequisites and a qualifying workload is assigned. Its IME overview describes supported workload triggers and agent behavior.
#1 Best Overall
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
Check prerequisites before diagnosing the task
A missing IME task does not, by itself, prove that an enrolled Windows device is broken. IME is installed in the context of qualifying workloads, not necessarily on every Intune-enrolled device. Check the device’s enrollment and assignment before treating the absence of the extension as a fault.
- Confirm the device is enrolled and active in Intune and that the intended user or device group receives the workload.
- Confirm the Windows edition and enrollment scenario meet the workload’s requirements. Windows Home is excluded from the standard Win32 app path. Windows S mode has a standard limitation, with a separately documented specialized method for enabling Win32 apps.
- Microsoft’s current IME documentation lists version
1.58.103.0or later as the minimum for supported configurations and updates that depend on IME. Treat this as the minimum stated in the documentation at the time of writing, not a permanent threshold. IME updates automatically on managed devices when they can sync with Intune. - For Win32 apps, Microsoft lists a maximum app size of 30 GB and additional enrollment, Windows edition, and Microsoft Entra registration or join requirements. Consult the Win32 app requirements for the applicable scenario.
Microsoft notes that Windows 10 reached end of support on October 14, 2025. Intune documentation may still list Windows 10 versions for particular management scenarios, but that does not mean the operating system continues to receive normal Microsoft servicing. See Microsoft’s Win32 app and S mode guidance for its related Windows 10 qualification.
Find the health-evaluation task and inspect it
Open Task Scheduler and navigate to Task Scheduler Library > Microsoft > Intune. The task is commonly named Intune Management Extension Health Evaluation. Its presence is evidence that the task is registered, not proof that IME is healthy or that an assigned app will install.
Use an elevated PowerShell session to query its state and definition:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteRank #2
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
- 4GB DDR4 System Memory; 128GB Solid State Drive
- 11.6" HD (1366 x 768) Multi-Touch Display
- Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
- Windows 11 Pro
$taskPath = 'MicrosoftIntune'
$taskName = 'Intune Management Extension Health Evaluation'
$task = Get-ScheduledTask -TaskPath $taskPath -TaskName $taskName -ErrorAction SilentlyContinue
$task | Format-List *
$task.Actions | Format-List *
$task.Triggers | Format-List *
$task.Principal | Format-List *
$task.Settings | Format-List *
Then check its run history summary:
Get-ScheduledTaskInfo -TaskPath $taskPath -TaskName $taskName -ErrorAction SilentlyContinue |
Select-Object LastRunTime, NextRunTime, LastTaskResult, NumberOfMissedRuns
Review whether the task is enabled, its action points to the expected executable, which account it uses, and what its trigger and settings specify. An HTMD report of April 23, 2026 describes a device with a trigger around 8:02 AM; another technical report describes a daily trigger with a randomized one-hour delay. Those are observations, not a guaranteed schedule for every endpoint. Inspect the local trigger rather than expecting a fixed tenant-wide run time. A device that was asleep or powered off, a delayed trigger, a disabled task, or an incomplete installation can all affect when it runs.
Verify ClientHealthEval.exe and the IME service
The commonly reported evaluator path is C:Program Files (x86)Microsoft Intune Management ExtensionClientHealthEval.exe. Verify that the file exists and inspect its metadata rather than assuming the path or version is identical on every device:
$imePath = 'C:Program Files (x86)Microsoft Intune Management Extension'
$healthEval = Join-Path $imePath 'ClientHealthEval.exe'
Test-Path $healthEval
Get-Item $healthEval -ErrorAction SilentlyContinue |
Select-Object FullName, Length, @{Name='FileVersion';Expression={$_.VersionInfo.FileVersion}},
@{Name='ProductVersion';Expression={$_.VersionInfo.ProductVersion}}
Check the signature as well. A missing or invalid signature, or an executable with an unexpected publisher, is a security concern; do not treat it as a routine repair issue.
Get-AuthenticodeSignature $healthEval
The signer should be Microsoft. Confirm the actual IME agent version separately if needed:
Rank #3
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
Get-Item (Join-Path $imePath 'Microsoft.Management.Services.IntuneWindowsAgent.exe') `
-ErrorAction SilentlyContinue |
Select-Object FullName, @{Name='FileVersion';Expression={$_.VersionInfo.FileVersion}},
@{Name='ProductVersion';Expression={$_.VersionInfo.ProductVersion}}
Check whether the service exists, is running, and has an appropriate startup configuration:
Get-Service -Name IntuneManagementExtension -ErrorAction SilentlyContinue |
Select-Object Name, DisplayName, Status, StartType
sc.exe qc IntuneManagementExtension
A service can exist but still be unhealthy. Distinguish a missing service, a disabled or stopped service, a service that starts and immediately stops, a running service that cannot communicate with Intune, and a running service that cannot process a particular app policy. Those conditions call for different follow-up.
What the health evaluator checks
An HTMD analysis published April 23, 2026 describes a sample IME HealthCheck.xml with four areas: whether the IME service exists, its startup type, its running status, and IME process memory use. The sample names the service IntuneManagementExtension and the process Microsoft.Management.Services.IntuneWindowsAgent. It shows remediation behavior for startup type and service status, and a service restart when configured memory conditions are exceeded. These are observed implementation details from a sample configuration, not a promise that every IME version uses the same rules. See the HTMD health-evaluation analysis.
The sample includes a memory threshold of 200, but that value should not be treated as a universal limit or compared directly with a Task Manager figure without knowing the build’s units and measurement method. A threshold in an observed configuration does not establish that IME has a memory leak or that every device will restart at the same value.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
You can inspect the process independently when investigating a resource concern:
Get-Process -Name Microsoft.Management.Services.IntuneWindowsAgent -ErrorAction SilentlyContinue |
Select-Object Name, Id, CPU, WorkingSet, StartTime
Run the evaluation and read its result
Use the registered scheduled task rather than launching the executable with undocumented switches. First confirm the task exists, then start it and inspect the result and log:
Start-ScheduledTask -TaskPath 'MicrosoftIntune' `
-TaskName 'Intune Management Extension Health Evaluation'
Start-Sleep -Seconds 10
Get-ScheduledTaskInfo -TaskPath 'MicrosoftIntune' `
-TaskName 'Intune Management Extension Health Evaluation'
Ten seconds is only a brief wait before checking; it is not a guaranteed completion time. Review the log after the run and allow for it to update:
$logPath = 'C:ProgramDataMicrosoftIntuneManagementExtensionLogs'
Get-Content "$logPathClientHealth.log" -Tail 200 -ErrorAction SilentlyContinue
If the task cannot start, examine its action and permissions, verify the executable exists, review Task Scheduler events, and check whether security software blocked it. A successful task result indicates the scheduled task ran; it does not establish that all Intune communication, policy, or application processing is working.
Recommended Free Tools
Best Value
- WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
- 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
- 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
- CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
- LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.
Use the right logs for the problem
Microsoft documents the typical IME log directory as C:ProgramDataMicrosoftIntuneManagementExtensionLogs. Its IME troubleshooting documentation describes log collection and the agent’s role.
| Log | Best use |
|---|---|
ClientHealth.log |
Health-evaluator activity and checks. |
IntuneManagementExtension.log |
IME check-ins, policy requests, processing, and reporting. |
AppWorkload.log |
Win32 app deployment activity; Microsoft specifically recommends it for app-management analysis. |
AppActionProcessor.log |
Application detection and applicability processing. |
AgentExecutor.log |
PowerShell script execution. |
HealthScripts.log |
Remediation health-script activity. |
DeviceHealthMonitoring.log |
Device health and inventory-related collectors. |
List recent logs and search the health log for relevant events:
Get-ChildItem $logPath -File -ErrorAction SilentlyContinue |
Sort-Object LastWriteTime -Descending |
Select-Object Name, Length, LastWriteTime
Select-String -Path "$logPathClientHealth.log" `
-Pattern 'HealthCheck|Pass|Fail|Remediat|error|exception|restart' `
-CaseSensitive:$false
For task launch or scheduling failures, also inspect Event Viewer > Applications and Services Logs > Microsoft > Windows > TaskScheduler. Historical examples of the task and IME logs are described by SMSAgent’s client-side log guide; historical details should not be assumed to match every current build.
Separate IME health from Win32 app failure
A healthy IME service does not guarantee a successful app deployment. The health evaluator checks selected agent-service conditions; it does not inherently correct app content, installer behavior, or assignment mistakes. Microsoft’s Win32 app guidance covers requirements, dependencies, detection rules, and related deployment configuration, while its packaging documentation explains package creation and silent installation requirements.
| Finding | What it suggests | Next check |
|---|---|---|
| Task missing | IME may not be installed because no qualifying workload was assigned, or installation may be incomplete or changed. | Verify enrollment, prerequisites, workload assignment, and IME installation. |
| Executable missing | Installation may be incomplete or damaged. | Review IME installation evidence and use supported enrollment or repair paths; do not substitute an unofficial executable. |
| Service missing | IME may not be installed correctly or service registration may be damaged. | Check enrollment, assigned workload, installation, and service registration. |
| Service stopped | Could be transient or indicate a service failure. | Review service state and IME logs; restart only when appropriate. |
| Startup type differs from expectation | Could be configuration drift or tampering. | Determine what changed it and review supported remediation. |
| Memory check fails | The observed build may have crossed its configured threshold. | Review process behavior and logs; do not infer a leak solely from the check. |
| Task runs, but a Win32 app fails | Often points to app content, requirements, detection, install command, dependencies, context, or return-code handling rather than IME service health. | Review AppWorkload.log, app-specific status in Intune, and the app’s configuration. |
| Health log passes, but policy does not arrive | The checked local service conditions may be sound while enrollment, communication, assignment, or tenant processing is not. | Check IME check-in, MDM diagnostics, network access, assignment scope, and Intune status. |
For an app failure, investigate the install command and silent behavior, package download and extraction, detection and requirement rules, dependency order, installer return codes, timeouts, reboot handling, user-versus-system context, and available disk space. These are app deployment paths, not failures that a service health task can be expected to repair.
Recover without making the installation harder to diagnose
- Capture evidence first. Record task state and last result, service state, executable signature and version, and relevant log timestamps.
- Run the registered health task. Check whether it starts and whether
ClientHealth.logrecords the evaluation. - Restart the IME service only when appropriate. This can interrupt active policy or app processing and does not prove the root cause is fixed:
Restart-Service -Name IntuneManagementExtension -Force - Check synchronization and assignment. Confirm the device is active, the intended workload is assigned, and the endpoint can communicate with Intune.
- Use supported installation mechanisms. Allow the managed extension to update or reinstall through the supported enrollment and workload path. If the service or executable is damaged, investigate that installation rather than repeatedly rerunning a task that cannot function.
- Escalate with logs when the fault persists. Repeated service restarts, a missing executable, an invalid signature, or damaged service registration warrant broader security or installation investigation. Preserve logs and task evidence before making changes.
Avoid deleting the scheduled task or IME folder, manually unregistering the service, or using generic cleanup utilities as a first response. Those actions can remove evidence, interfere with updates, and complicate recovery.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




