Intune reports 1603 and nothing else. No message, no hint about which step failed. For a wrapped EXE installer, 1603 is rarely the real error: it is the Windows Installer catch-all for "a fatal error occurred", or a wrapper script passing along whatever the vendor setup happened to return. The cause is in a log you have to know where to find.
Here is what 1603 actually means, why EXE-based deployments produce it so often, and how to get a deterministic result instead of a guess.
Fast Verdict Matrix
| Failure Source | Legacy EXE Behavior | Native MSI Behavior |
|---|---|---|
| Where the real error lives | Vendor-specific log, if one exists at all. The exit code is often just the wrapper's own failure value. | A standard verbose log from msiexec /l*v, with a searchable Return value 3 line at the failing action. |
| Missing prerequisites | A VC++ runtime or .NET dependency is missing and the setup aborts with a generic code. | Dependencies are resolved at conversion time and shipped in the package. |
| Running installs and locked files | Locked files or a running instance cause a silent abort and a non-zero code. | Windows Installer stages replacements and uses a pending-rename on locked files, so the install can complete. |
| Result consistency | Same app, different return codes depending on machine state. | Documented codes only: 0, 3010, 1603, 1618. |
The Rule of Thumb
- Never troubleshoot
1603from the Intune portal. Run the install as SYSTEM with logging on and search the log forReturn value 3; the lines just above it name the failing action. - A
1603from an EXE is a symptom, not a diagnosis. Fix the cause once in the package instead of adding retry logic around it.
The Fix: A Package That Reports Honestly
The usual workaround is a PowerShell wrapper such as PSAppDeployToolkit that checks prerequisites, closes processes, retries the setup and rewrites exit codes. It can work, but you now own a script per app and a log format nobody else understands.
InstallMage converts the EXE into a native MSI that Windows Installer runs directly. Prerequisites and payload are packaged, the install runs silently under SYSTEM, and failures produce a standard MSI log with a documented return value. No PSADT wrapper, no custom exit-code translation, and the same result on every device.
Deep Dive
What 1603 Actually Means
1603 is ERROR_INSTALL_FAILURE. Windows Installer returns it when any action in the install sequence fails and rolls back, and it does not say which one. Common triggers are a custom action that returns an error, a file or registry write blocked by permissions, a pending reboot, or a prerequisite that is not present. For EXE installers, the setup bootstrapper may run an embedded MSI and relay its 1603, or hit its own fatal error and choose 1603 because it is a familiar number.
Finding the Real Error in the Log
Reproduce the install as SYSTEM and force verbose logging:
psexec -i -s cmd.exe
msiexec /i "package.msi" /qn /l*v "C:\Windows\Temp\install.log"
findstr /n /c:"Return value 3" "C:\Windows\Temp\install.log"Open the log at the line number returned and read upward. The failing action is named just before the rollback begins, for example a custom action that could not launch an executable, or an Error 1920 for a service that failed to start. For a bootstrapper EXE, look for the vendor's own log in %TEMP% under the SYSTEM profile, which is usually C:\Windows\Temp. If the setup writes nothing there, the wrapper itself is the source and you are debugging the script, not the app. See the Intune Win32 app exit codes guide for the full mapping.
Causes Specific to Wrapped EXEs
Three patterns account for most wrapped-EXE 1603 failures. First, a missing runtime: the app needs a Visual C++ redistributable the vendor assumed was already present. Second, a running process holding files open, where the setup has no restart manager support and aborts. Third, a pending reboot from an earlier install, which makes the engine refuse the next one. Each passes on a freshly imaged test VM and fails on a production device with history, which is why the failure rate looks random. The reboot handling guide covers the pending-reboot case in detail, and the context guide covers permission-related variants.
Frequently Asked Questions
What does Intune error 1603 mean?
It is the Windows Installer code for a fatal error during installation. Something in the install sequence failed and the install rolled back. The code does not identify what failed, so you need a verbose MSI log or the vendor log to find the cause.
How do I get a log for a failed Intune Win32 install?
For an MSI, add /l*v C:\Windows\Temp\install.log to the install command line. Intune's own client logs are in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs, but they only record the exit code. For an EXE, check the vendor log in the SYSTEM temp folder.
Should I add 1603 as a retry code in Intune?
Not as a fix. Retrying only helps when the cause is transient, such as 1618 (another install in progress). A 1603 usually repeats until the underlying cause, such as a missing prerequisite, is resolved.
1603 costs time because it hides the cause. Log as SYSTEM, read upward from Return value 3, and package the fix so it only has to be solved once.