oeltayeb.com · Intune Troubleshooting Toolkit

Reference

IME log reference

Based on the article: Reading Intune Management Extension logs: IME, AppWorkload and AgentExecutor explained · 4 min read

When a Win32 app, platform script or remediation misbehaves on Windows, the admin center usually tells you that it failed. The Intune Management Extension (IME) logs tell you why. In this deep dive I'll map out the log folder, explain what each file records, and show a repeatable way to read them, on the device or from a remote diagnostics collection.

How it works

The IME is the Intune agent for work the built-in Windows MDM client can't do on its own. Intune installs it automatically when you assign something that needs it, including Win32 apps, Microsoft Store apps, PowerShell platform scripts, Remediations and custom compliance discovery scripts. It runs as the IntuneManagementExtension service and checks in with Intune every 8 hours, independently of the MDM check-in. It also looks for new app assignments as soon as the Enrollment Status Page or Autopilot device preparation finishes.

Everything it does is logged to C:\ProgramData\Microsoft\IntuneManagementExtension\Logs. ProgramData is hidden by default, so type the path into File Explorer.

Note: Configuration profiles and LOB MSI apps are delivered by the Windows MDM client, not the IME, so you won't find them here. For those, use the DeviceManagement-Enterprise-Diagnostics-Provider event log or the advanced diagnostic report under Settings › Accounts › Access work or school.

What each log records

LogWhat it recordsOpen it when
IntuneManagementExtension.logThe main log: check-ins, policy requests, policy processing and reportingNothing reaches the device, or you need proof a check-in happened
AppWorkload.logWin32 app deployment activity: download, install and detectionA Win32 app fails, hangs or reports the wrong state
AppActionProcessor.logDetection and applicability checks for assigned appsAn app is never attempted or shows as not applicable
AgentExecutor.logExecution of PowerShell scripts deployed by IntuneA script returns an unexpected exit code or output
HealthScripts.logRemediations that run on a scheduleA remediation didn't run when you expected
ClientHealth.logHealth checks of the IME agent itselfThe agent seems stuck or isn't checking in

You'll also find ClientCertCheck.log (device client certificate checks), DeviceHealthMonitoring.log, NotificationInfra.log, Sensor.log (Endpoint analytics data collection) and Win32AppInventory.log (app inventory). They're rarely the first stop for deployment problems.

Step-by-step: reading the logs

1. Use a proper viewer

The IME writes in the same format as Configuration Manager, so CMTrace is the natural choice. The Configuration Manager client installs it as C:\Windows\CCM\CMTrace.exe, and it ships in SMSSETUP\Tools on the site server. On Intune-only devices, copy it over or open the logs from your workstation. Three features earn their keep:

Support Center OneTrace works in a similar way. For a quick live view with no extra tools, PowerShell is enough:

powershell
Get-Content -Path "$env:ProgramData\Microsoft\IntuneManagementExtension\Logs\AppWorkload.log" -Tail 40 -Wait

2. Find the right lines

Apps, scripts and remediations appear in the logs by their ID. Open the object in the admin center, copy the GUID from the browser address bar, and search for it. Once you're in the right area, these terms help:

Exact message wording changes between IME releases, so GUIDs and timestamps are better anchors than memorized strings.

3. Trigger a fresh check-in

Rather than waiting up to eight hours, start a check-in and watch the logs. Settings › Sync in Company Portal, Sync in the Windows Settings app, or the Sync device action in the admin center all trigger both an MDM and an IME check-in. Restarting the service from an elevated prompt does the same for the IME:

powershell
Restart-Service -Name IntuneManagementExtension

4. Collect the logs remotely

For corporate-owned Windows devices, go to Devices › All devices, open the device, select Collect diagnostics and confirm with Collect data. Track progress under Monitor › Device diagnostics in the device's menu, then use Download when it completes. The zip contains the whole IME Logs folder, plus registry exports such as HKLM\SOFTWARE\Microsoft\IntuneManagementExtension and command output like dsregcmd /status. Worth knowing:

Verify: what good looks like

Tips and gotchas

References