Skip to main content
    All posts
    Intune
    Win32 App
    Exit Codes
    1603
    Troubleshooting

    Intune Exit Code 1603: Why Wrapped EXE Installers Fail and How to Find the Real Error

    Andrew MartyOctober 6, 20268 min read

    Intune reports 1603 and nothing else. No message, no hint about which step failed. For a wrapped EXE installer, 1603 is rarely the real error: it is the Windows Installer catch-all for "a fatal error occurred", or a wrapper script passing along whatever the vendor setup happened to return. The cause is in a log you have to know where to find.

    Here is what 1603 actually means, why EXE-based deployments produce it so often, and how to get a deterministic result instead of a guess.

    Fast Verdict Matrix

    Failure SourceLegacy EXE BehaviorNative MSI Behavior
    Where the real error livesVendor-specific log, if one exists at all. The exit code is often just the wrapper's own failure value.A standard verbose log from msiexec /l*v, with a searchable Return value 3 line at the failing action.
    Missing prerequisitesA VC++ runtime or .NET dependency is missing and the setup aborts with a generic code.Dependencies are resolved at conversion time and shipped in the package.
    Running installs and locked filesLocked files or a running instance cause a silent abort and a non-zero code.Windows Installer stages replacements and uses a pending-rename on locked files, so the install can complete.
    Result consistencySame app, different return codes depending on machine state.Documented codes only: 0, 3010, 1603, 1618.

    The Rule of Thumb

    • Never troubleshoot 1603 from the Intune portal. Run the install as SYSTEM with logging on and search the log for Return value 3; the lines just above it name the failing action.
    • A 1603 from an EXE is a symptom, not a diagnosis. Fix the cause once in the package instead of adding retry logic around it.

    The Fix: A Package That Reports Honestly

    The usual workaround is a PowerShell wrapper such as PSAppDeployToolkit that checks prerequisites, closes processes, retries the setup and rewrites exit codes. It can work, but you now own a script per app and a log format nobody else understands.

    InstallMage converts the EXE into a native MSI that Windows Installer runs directly. Prerequisites and payload are packaged, the install runs silently under SYSTEM, and failures produce a standard MSI log with a documented return value. No PSADT wrapper, no custom exit-code translation, and the same result on every device.

    Deep Dive

    What 1603 Actually Means

    1603 is ERROR_INSTALL_FAILURE. Windows Installer returns it when any action in the install sequence fails and rolls back, and it does not say which one. Common triggers are a custom action that returns an error, a file or registry write blocked by permissions, a pending reboot, or a prerequisite that is not present. For EXE installers, the setup bootstrapper may run an embedded MSI and relay its 1603, or hit its own fatal error and choose 1603 because it is a familiar number.

    Finding the Real Error in the Log

    Reproduce the install as SYSTEM and force verbose logging:

    psexec -i -s cmd.exe
    msiexec /i "package.msi" /qn /l*v "C:\Windows\Temp\install.log"
    findstr /n /c:"Return value 3" "C:\Windows\Temp\install.log"

    Open the log at the line number returned and read upward. The failing action is named just before the rollback begins, for example a custom action that could not launch an executable, or an Error 1920 for a service that failed to start. For a bootstrapper EXE, look for the vendor's own log in %TEMP% under the SYSTEM profile, which is usually C:\Windows\Temp. If the setup writes nothing there, the wrapper itself is the source and you are debugging the script, not the app. See the Intune Win32 app exit codes guide for the full mapping.

    Causes Specific to Wrapped EXEs

    Three patterns account for most wrapped-EXE 1603 failures. First, a missing runtime: the app needs a Visual C++ redistributable the vendor assumed was already present. Second, a running process holding files open, where the setup has no restart manager support and aborts. Third, a pending reboot from an earlier install, which makes the engine refuse the next one. Each passes on a freshly imaged test VM and fails on a production device with history, which is why the failure rate looks random. The reboot handling guide covers the pending-reboot case in detail, and the context guide covers permission-related variants.

    Frequently Asked Questions

    What does Intune error 1603 mean?

    It is the Windows Installer code for a fatal error during installation. Something in the install sequence failed and the install rolled back. The code does not identify what failed, so you need a verbose MSI log or the vendor log to find the cause.

    How do I get a log for a failed Intune Win32 install?

    For an MSI, add /l*v C:\Windows\Temp\install.log to the install command line. Intune's own client logs are in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs, but they only record the exit code. For an EXE, check the vendor log in the SYSTEM temp folder.

    Should I add 1603 as a retry code in Intune?

    Not as a fix. Retrying only helps when the cause is transient, such as 1618 (another install in progress). A 1603 usually repeats until the underlying cause, such as a missing prerequisite, is resolved.


    1603 costs time because it hides the cause. Log as SYSTEM, read upward from Return value 3, and package the fix so it only has to be solved once.

    Keep reading