IntuneDeep dive

Reading Intune Management Extension logs: IME, AppWorkload and AgentExecutor explained

What each Intune Management Extension log records, how to read them with CMTrace, what to search for, how to force a check-in, and how to collect the logs remotely.

When a Win32 app, platform script or remediation misbehaves on Windows, the admin center usually tells you that it failed. The Intune Management Extension (IME) logs tell you why. In this deep dive I'll map out the log folder, explain what each file records, and show a repeatable way to read them, on the device or from a remote diagnostics collection.

How this guide is organised: How it works → What each log records → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. What each log records. 3. Step-by-step (4 steps: Use a proper viewer; Find the right lines; Trigger a fresh check-in; Collect the logs remotely). 4. Verify. 5. Tips and gotchas. Toolbox: AppWorkload.log, IntuneManagementExtension.log, dsregcmd /status, …\Microsoft\IntuneManagementExtension, Settings › Sync.1How it works2What each logrecords3Step-by-step4Verify5Tips andgotchas1Use a proper viewer2Find the right lines3Trigger a fresh check-in4Collect the logs remotelyTOOLBOXAppWorkload.logIntuneManagementExtension.logdsregcmd /status…\Microsoft\IntuneManagementExten…Settings › SyncHow this guide is organised: How it works → What each log records → Step-by-step → Verify → Tips and gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. What each log records. 3. Step-by-step (4 steps: Use a proper viewer; Find the right lines; Trigger a fresh check-in; Collect the logs remotely). 4. Verify. 5. Tips and gotchas. Toolbox: AppWorkload.log, IntuneManagementExtension.log, dsregcmd /status, …\Microsoft\IntuneManagementExtension, Settings › Sync.1How it works2What each log records3Step-by-step1Use a proper viewer2Find the right lines3Trigger a fresh check-in4Collect the logs remotely4Verify5Tips and gotchasTOOLBOXAppWorkload.logIntuneManagementExtension.logdsregcmd /status…\Microsoft\IntuneManagementExtensionSettings › Sync
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

How it works#

The IME is the Intune agent for work the built-in Windows MDM client can't do on its own. Intune installs it automatically when you assign something that needs it, including Win32 apps, Microsoft Store apps, PowerShell platform scripts, Remediations and custom compliance discovery scripts. It runs as the IntuneManagementExtension service and checks in with Intune every 8 hours, independently of the MDM check-in. It also looks for new app assignments as soon as the Enrollment Status Page or Autopilot device preparation finishes.

Everything it does is logged to C:\ProgramData\Microsoft\IntuneManagementExtension\Logs. ProgramData is hidden by default, so type the path into File Explorer.

Note: Configuration profiles and LOB MSI apps are delivered by the Windows MDM client, not the IME, so you won't find them here. For those, use the DeviceManagement-Enterprise-Diagnostics-Provider event log or the advanced diagnostic report under Settings › Accounts › Access work or school.

What each log records#

LogWhat it recordsOpen it when
IntuneManagementExtension.logThe main log: check-ins, policy requests, policy processing and reportingNothing reaches the device, or you need proof a check-in happened
AppWorkload.logWin32 app deployment activity: download, install and detectionA Win32 app fails, hangs or reports the wrong state
AppActionProcessor.logDetection and applicability checks for assigned appsAn app is never attempted or shows as not applicable
AgentExecutor.logExecution of PowerShell scripts deployed by IntuneA script returns an unexpected exit code or output
HealthScripts.logRemediations that run on a scheduleA remediation didn't run when you expected
ClientHealth.logHealth checks of the IME agent itselfThe agent seems stuck or isn't checking in

You'll also find ClientCertCheck.log (device client certificate checks), DeviceHealthMonitoring.log, NotificationInfra.log, Sensor.log (Endpoint analytics data collection) and Win32AppInventory.log (app inventory). They're rarely the first stop for deployment problems.

Step-by-step: reading the logs#

1. Use a proper viewer#

The IME writes in the same format as Configuration Manager, so CMTrace is the natural choice. The Configuration Manager client installs it as C:\Windows\CCM\CMTrace.exe, and it ships in SMSSETUP\Tools on the site server. On Intune-only devices, copy it over or open the logs from your workstation. Three features earn their keep:

  • Merge selected files in the Open dialog interleaves IntuneManagementExtension.log and AppWorkload.log into one timeline.
  • Highlight and Filter on the Tools menu isolate the lines for one app or script.
  • Error Lookup translates a numeric error code into its message.

Support Center OneTrace works in a similar way. For a quick live view with no extra tools, PowerShell is enough:

PowerShell
Get-Content -Path "$env:ProgramData\Microsoft\IntuneManagementExtension\Logs\AppWorkload.log" -Tail 40 -Wait

2. Find the right lines#

Apps, scripts and remediations appear in the logs by their ID. Open the object in the admin center, copy the GUID from the browser address bar, and search for it. Once you're in the right area, these terms help:

  • The app or script name, if the GUID gives you too many hits.
  • error, fail and exception for the obvious failures.
  • exit code to see what an installer or script returned.
  • detection and applicability for "why wasn't it installed" questions. Win32 app lines in AppWorkload.log are tagged [Win32App].
  • download for content problems.

Exact message wording changes between IME releases, so GUIDs and timestamps are better anchors than memorized strings.

3. Trigger a fresh check-in#

Rather than waiting up to eight hours, start a check-in and watch the logs. Settings › Sync in Company Portal, Sync in the Windows Settings app, or the Sync device action in the admin center all trigger both an MDM and an IME check-in. Restarting the service from an elevated prompt does the same for the IME:

PowerShell
Restart-Service -Name IntuneManagementExtension

4. Collect the logs remotely#

For corporate-owned Windows devices, go to Devices › All devices, open the device, select Collect diagnostics and confirm with Collect data. Track progress under Monitor › Device diagnostics in the device's menu, then use Download when it completes. The zip contains the whole IME Logs folder, plus registry exports such as HKLM\SOFTWARE\Microsoft\IntuneManagementExtension and command output like dsregcmd /status. Worth knowing:

  • The device must be online, and you need the Help Desk Operator or School Administrator role, or a custom role with Remote tasks › Collect diagnostics.
  • Collections are kept for 28 days, up to 10 per device, and the action also runs in bulk on up to 25 devices.
  • The feature is on by default and can be turned off under Tenant administration › Device diagnostics.

Verify: what good looks like#

  • After a sync, IntuneManagementExtension.log shows new check-in and policy activity with current timestamps.
  • For a healthy Win32 app, AppWorkload.log shows the download, the install command, the installer's exit code, and a detection result saying the app is present.
  • For a script, AgentExecutor.log shows the run and the exit code you expected.
  • The status in the admin center catches up once the IME has reported back.

Tips and gotchas#

  • When a log fills up, the IME starts a new file and keeps the old one with a date stamp in its name. Check those too if the event you need is older.
  • Devices need IME version 1.58.103.0 or later to keep receiving Win32 apps, scripts and remediations. If nothing arrives, check the agent version early.
  • Install commands that call powershell.exe run in 32-bit PowerShell, which explains many "but it worked when I ran it" puzzles.
  • No IME on a device usually means nothing that needs it is assigned, the device can't reach Intune, or Windows is in S mode.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)