MSI install via GPO

I have created an MSI package that I want to deploy using Group Policy.

The policy have been created under User Configuration and I have linked the policy to the appropriate OU containing users.

When I logon with an account in that OU it seems like the package are installed. But there are no shortcuts or programfiles at all.

The GPO are "Assigned" and set to "Install this application at logon"

The MSI package are created with Wise Studio Package with SetupCapture. It works fine when I install the MSI manually.

How can it be?
Kasper KatzmannSeniorkonsulentAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Hi Kasper_K,

how do you know the program is installed?

Fatal_ExceptionSystems EngineerCommented:
Also, ck this article...

Packages Assigned to Computers with Group Policy Are Not Installed
Become a Microsoft Certified Solutions Expert

This course teaches how to install and configure Windows Server 2012 R2.  It is the first step on your path to becoming a Microsoft Certified Solutions Expert (MCSE).

Kasper KatzmannSeniorkonsulentAuthor Commented:
Jay Jay70:
I only see the information that says it is being installed during upstart. But nothing is there when the i chack.

The shortcuts are already "Advertised" but something is clearly missing :-(

The package are assigned to users, not computers.
Fatal_ExceptionSystems EngineerCommented:
My bad...

Not sure if this will help, but you can enable verbose msi logging using another GPO:

Enable Windows Installer logging with Group Policies
You can enable logging with Group Policies by editing the appropriate OU or Directory Group Policy. Under Group Policy, expand Computer Configuration, expand Administrative Templates, expand Windows Components, and then select Windows Installer.

Double-click Logging, and then click Enabled. In the Logging box, enter the options you want to log. The log file, Msi.log, appears in the Temp folder of the system volume.

For more information about MSI logging, please see Windows Help. To do so, search using the phrase "msi logging" and select "Managing options for computers through Group Policy".
mm logging will be good

also, does the software error at all or is just silently installed and thats it - anything in the event logs?
Kasper KatzmannSeniorkonsulentAuthor Commented:

I don't seem to get any log-file. I've tryed to log off and on (even after a gpupdate /force) and it still looks like it is being installed during startup but still no shortcuts of any kind and no log-file as well.

I enabled the logging in the GPO with the installation and I enabled everything possible.

Am I completely wrong when I say that the temp folder is "C:\windows\temp" ?
i personally prefer the c:\temp but it doesnt make a diff as long as you have write permissions to the windows folder....

maybe you need to have a look at the permissions on the directory you are trying to write to
Kasper, the temp folder may differ, use %temp% in your adress bar to find it.
Also, please supply the eventlog entries. In the application log, there will be some entries called "application management".
Call eventvwr

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Fatal_ExceptionSystems EngineerCommented:
Probably would have helped if I had located the link to the msi log KB article:

Windows Installer can use logging to help assist in troubleshooting issues with installing software packages. This logging is enabled by adding keys and values to the registry. After the entries have been added and enabled, you can retry the problem installation and Windows Installer will track the progress and post it to the Temp folder. The new log's file name is random, but begins with the letters "Msi" and end with a .log extension. To locate the Temp folder location, type the following line at a command prompt:
cd %temp%
Kasper KatzmannSeniorkonsulentAuthor Commented:
I think I have located the problem, but I can't figure out why it is a problem :-(

It seems like the installation job can't find the file. I am 100% sure the file is at the given place.

The .msi file is on a share witch I locate with the following adress: \\server\share$\folder\file.msi

Is there a problem with the way I adress the file?
Have you read and checked Fatal exceptions ?
Kasper KatzmannSeniorkonsulentAuthor Commented:
Yes I have. And just to be sure and for testing purpose, I have granted full control to the Authenticated Users group.
If you test, you would grant acces to everyone, not authenticated users. Maybe the group "domain computers" is missing, that's what the article says. MSIs placed in the computer section are installed using machine rights, i.e. the accounts aren't "authenticated users" but mypc$ for example, all members of "domain computers".
Kasper KatzmannSeniorkonsulentAuthor Commented:
But the MSI are placed in the user section, so shouldn't it be Auth. users?
oops, you said that in your first posting, sorry. Why don't you grant full rights to everyone for a test, so we can rule that out?
Fatal_ExceptionSystems EngineerCommented:
If you are running GPMC, you might want to check the GPO, and make sure your OU and users have the correct permissions also..  regardless, you need to make sure your users have Read and Apply permissions in that OU and GPO..

Also, I have never deployed using a hidden share, so you might want to test with one that is not hidden..  (should not make a difference, but..)

and run down this article to make sure you have followed the correct procedures..
Kasper KatzmannSeniorkonsulentAuthor Commented:
It helped looking in the log.

I changed the "share$" to "share" and thats the only difference I can see. But now it works and I am happy happy happy :-))

Is it possible to split the points? If it is I would have given Fatal_Exception a share as well.

Thanks to you all for your time and help.

Kasper K from Denamark (the country that doesn't apologize)
Fatal_ExceptionSystems EngineerCommented:
hmm..  yes, you should have split the points...  you can post a question in the support area, and a 'mod' will come in and make the adjustment for you...

Just be sure to post a link to this thread...

and, glad we could help!

Fatal_ExceptionSystems EngineerCommented:
Thanks!  and best to all!

(Thank you too, Netminder!)

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.