Additional settings-related features and issues within Microsoft Teams for business
Hi,
It looks like the Microsoft Store restriction and the non-admin app installation restriction can be handled separately for this scenario. Microsoft documents a way for managed endpoints to keep BlockNonAdminUserInstall enabled while allowing the SlimCore MSIX packages to install.
For the current split MSIX architecture, I would check these areas:
1/ Check the Windows build and required updates.
Microsoft documents support for SlimCore installation with BlockNonAdminUserInstall enabled after applying the applicable cumulative update:
- Windows 11 23H2 / 22H2: KB5052094
- Windows 11 24H2: KB5052093
- Windows 10 22H2: KB5055612
- or a later cumulative update
These updates introduce the Allowed package family names for non-admin user install policy, which can be used to allow the SlimCore packages without broadly allowing non-admin users to install packaged apps.
For the new split MSIX architecture, Microsoft lists these SlimCore package families:
- Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe
- Microsoft.Teams.SlimCoreVdiFwk.<version>_8wekyb3d8bbwe
Microsoft also documents a regex-based allow-list option: New VDI solution for Teams - Microsoft Teams | Microsoft Learn
2/ If the endpoints are Intune-managed, check whether the following policy can be configured in your environment:
./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/AllowedNonAdminPackageFamilyNameRules
Microsoft documents this as an option for allowing matching package family names even when BlockNonAdminUserInstall is enabled: ApplicationManagement Policy CSP | Microsoft Learn
3/ Verify the other MSIX-related policies.
Microsoft identifies these settings as possible blockers for SlimCore installation:
- BlockNonAdminUserInstall
- AllowAllTrustedApps
- AllowDevelopmentWithoutDevLicense
Your screenshot currently shows Allow All Trusted Apps as Explicit allow unlock, so I would verify the effective policy on an affected endpoint rather than changing this setting immediately.
4/ Also check AppLocker or WDAC.
Microsoft notes that AppLocker or Windows Defender Application Control can block SlimCore MSIX installation. If either is being used, check whether there is a rule preventing the SlimCore Host or Framework packages from being installed or registered.
5/ If the policy configuration looks correct, check the endpoint logs for the actual deployment failure.
On the affected endpoint, review: Applications and Services Logs > Microsoft > Windows > AppxPackagingOM > Microsoft-Windows-AppxPackaging/Operational
and Applications and Services Logs > Microsoft > Windows > AppXDeployment-Server > Microsoft-Windows-AppXDeploymentServer/Operational
These logs should help distinguish a policy restriction from another MSIX deployment or registration issue.
Could you also provide the following details from one affected endpoint?
- Windows version/build
- Whether the device is managed by Intune, Group Policy, or both
- The exact Teams/SlimCore error code, if one is shown
- Whether the screenshot represents the current effective policy or the configuration after your testing
For reference, Microsoft specifically documents error 16389 as commonly associated with BlockNonAdminUserInstall, while error 15615 is associated with MSIX installation policy issues such as AllowAllTrustedApps. (Troubleshooting the VDI 2.0 solution for Teams - Microsoft Teams | Microsoft Learn)