You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Intune Win32应用创建HKLM注册表项失败,检测报错0x87D1041C

问题描述

需创建注册表项隐藏Windows 11欢迎屏幕上的本地管理员账户sysadmin,同时保留所有AzureAD用户显示。本地通过elevated命令提示符运行安装、卸载及检测脚本均正常,但经IntuneWinAppUtil.exe打包为Intune Win32应用部署至所有设备时失败,报错:The application was not detected after installation completed successfully (0x87D1041C)。

Intune Win32应用配置

  • 安装命令:powershell -executionpolicy bypass -file Install-HideUserWelcomeScreen.ps1
  • 卸载命令:powershell -executionpolicy bypass -file Uninstall-HideUserWelcomeScreen.ps1
  • 所需安装时间:60分钟
  • 允许卸载:否
  • 安装行为:系统
  • 设备重启行为:应用安装可能强制设备重启

检测规则配置

  • 规则格式:自定义检测脚本
  • 在64位客户端上以32位进程运行脚本:否
  • 强制执行脚本签名检查并静默运行脚本:否

关联脚本

Install-HideUserWelcomeScreen.ps1

$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
$registryKey = "sysadmin"
$registryValue = 0

if (-not (Test-Path $registryPath)) {
New-Item -Path $registryPath -Force
}

New-ItemProperty -Path $registryPath -Name $registryKey -PropertyType DWord -Value $registryValue -Force

Uninstall-HideUserWelcomeScreen.ps1

$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
$registryKey = "sysadmin"

Remove-ItemProperty -Path $registryPath -Name $registryKey -Force -ErrorAction SilentlyContinue

Detection-HideUserWelcomeScreen.ps1

$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
$registryKey = "sysadmin"
$registryValue = 0

$exists = Get-ItemProperty -path $registryPath -name $registryKey -ErrorAction SilentlyContinue
 
if ($exists.$registryKey -eq $registryValue)
    {
        Write-Output "Registry Key Present"
        Exit 0
    }
ELSE
    {
        Write-Output "Registry Key Missing"
        Exit 1603
    }

解决方案

1. 修复检测脚本逻辑缺陷

原检测脚本在注册表路径不存在或键值缺失时,$exists会返回$null,此时$exists.$registryKey会触发静默错误并直接进入失败分支。修改后的脚本先验证路径,再精准判断键值:

$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList"
$registryKey = "sysadmin"
$registryValue = 0

# 先确认注册表路径存在
if (-not (Test-Path -Path $registryPath)) {
    Write-Output "Registry path not found"
    Exit 1603
}

# 获取目标键值,缺失时返回$null
$currentValue = Get-ItemPropertyValue -Path $registryPath -Name $registryKey -ErrorAction SilentlyContinue

# 验证键值是否符合要求
if ($currentValue -eq $registryValue) {
    Write-Output "Registry key is correctly configured"
    Exit 0
}
else {
    Write-Output "Registry key missing or value incorrect"
    Exit 1603
}

2. 确保安装脚本以64位上下文执行

尽管已配置禁用32位进程运行脚本,仍可在安装命令中明确指定使用64位PowerShell,避免注册表重定向:

powershell.exe -ExecutionPolicy Bypass -NoProfile -NonInteractive -File Install-HideUserWelcomeScreen.ps1

同时在安装脚本末尾添加验证逻辑,确保注册表项创建成功后再退出:

# 原安装代码...

# 验证注册表项是否创建成功
try {
    $createdValue = Get-ItemPropertyValue -Path $registryPath -Name $registryKey -ErrorAction Stop
    if ($createdValue -ne $registryValue) {
        Exit 1603
    }
}
catch {
    Exit 1603
}
Exit 0

3. 改用Intune内置注册表检测规则(推荐)

放弃自定义检测脚本,使用Intune原生的注册表检测规则,稳定性更高:

  • 规则格式:注册表
  • 项路径:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
  • 值名称:sysadmin
  • 检测方法:值等于
  • 值数据:0(选择DWORD类型)
  • 在64位系统上检查64位注册表:是

4. 检查脚本执行权限

确保所有脚本以系统权限运行,可在脚本开头添加权限校验:

$currentPrincipal = New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent())
if (-not $currentPrincipal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) {
    Write-Output "Script not running with elevated privileges"
    Exit 1603
}

内容的提问来源于stack exchange,提问作者ausip

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 00:17:17