Intune Win32应用创建HKLM注册表项失败,检测报错0x87D1041C
问题描述
需创建注册表项隐藏Windows 11欢迎屏幕上的本地管理员账户sysadmin,同时保留所有AzureAD用户显示。本地通过elevated命令提示符运行安装、卸载及检测脚本均正常,但经IntuneWinAppUtil.exe打包为Intune Win32应用部署至所有设备时失败,报错:The application was not detected after installation completed successfully (0x87D1041C)。
Intune Win32应用配置
- 安装命令:
powershell -executionpolicy bypass -file Install-HideUserWelcomeScreen.ps1 - 卸载命令:
powershell -executionpolicy bypass -file Uninstall-HideUserWelcomeScreen.ps1 - 所需安装时间:60分钟
- 允许卸载:否
- 安装行为:系统
- 设备重启行为:应用安装可能强制设备重启
检测规则配置
- 规则格式:自定义检测脚本
- 在64位客户端上以32位进程运行脚本:否
- 强制执行脚本签名检查并静默运行脚本:否
关联脚本
Install-HideUserWelcomeScreen.ps1
$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" $registryKey = "sysadmin" $registryValue = 0 if (-not (Test-Path $registryPath)) { New-Item -Path $registryPath -Force } New-ItemProperty -Path $registryPath -Name $registryKey -PropertyType DWord -Value $registryValue -Force
Uninstall-HideUserWelcomeScreen.ps1
$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" $registryKey = "sysadmin" Remove-ItemProperty -Path $registryPath -Name $registryKey -Force -ErrorAction SilentlyContinue
Detection-HideUserWelcomeScreen.ps1
$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" $registryKey = "sysadmin" $registryValue = 0 $exists = Get-ItemProperty -path $registryPath -name $registryKey -ErrorAction SilentlyContinue if ($exists.$registryKey -eq $registryValue) { Write-Output "Registry Key Present" Exit 0 } ELSE { Write-Output "Registry Key Missing" Exit 1603 }
解决方案
1. 修复检测脚本逻辑缺陷
原检测脚本在注册表路径不存在或键值缺失时,$exists会返回$null,此时$exists.$registryKey会触发静默错误并直接进入失败分支。修改后的脚本先验证路径,再精准判断键值:
$registryPath = "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList" $registryKey = "sysadmin" $registryValue = 0 # 先确认注册表路径存在 if (-not (Test-Path -Path $registryPath)) { Write-Output "Registry path not found" Exit 1603 } # 获取目标键值,缺失时返回$null $currentValue = Get-ItemPropertyValue -Path $registryPath -Name $registryKey -ErrorAction SilentlyContinue # 验证键值是否符合要求 if ($currentValue -eq $registryValue) { Write-Output "Registry key is correctly configured" Exit 0 } else { Write-Output "Registry key missing or value incorrect" Exit 1603 }
2. 确保安装脚本以64位上下文执行
尽管已配置禁用32位进程运行脚本,仍可在安装命令中明确指定使用64位PowerShell,避免注册表重定向:
powershell.exe -ExecutionPolicy Bypass -NoProfile -NonInteractive -File Install-HideUserWelcomeScreen.ps1
同时在安装脚本末尾添加验证逻辑,确保注册表项创建成功后再退出:
# 原安装代码... # 验证注册表项是否创建成功 try { $createdValue = Get-ItemPropertyValue -Path $registryPath -Name $registryKey -ErrorAction Stop if ($createdValue -ne $registryValue) { Exit 1603 } } catch { Exit 1603 } Exit 0
3. 改用Intune内置注册表检测规则(推荐)
放弃自定义检测脚本,使用Intune原生的注册表检测规则,稳定性更高:
- 规则格式:注册表
- 项路径:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList - 值名称:
sysadmin - 检测方法:值等于
- 值数据:
0(选择DWORD类型) - 在64位系统上检查64位注册表:是
4. 检查脚本执行权限
确保所有脚本以系统权限运行,可在脚本开头添加权限校验:
$currentPrincipal = New-Object Security.Principal.WindowsPrincipal([Security.Principal.WindowsIdentity]::GetCurrent()) if (-not $currentPrincipal.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)) { Write-Output "Script not running with elevated privileges" Exit 1603 }
内容的提问来源于stack exchange,提问作者ausip
相关产品推荐
相关产品推荐

