Microsoft Teams SlimCore optimization is not installing or activating successfully on endpoint laptops as we have the Microsoft Store block policy

Nair, Aneesh 20 Reputation points
2026-09-28T06:14:04.12+00:00

Microsoft Teams SlimCore optimization is not installing or activating successfully on endpoint laptops as we have the Microsoft Store block policy.

Context

Microsoft Teams SlimCore optimization is not installing or activating successfully on endpoint laptops. The request is to validate and enable SlimCore on laptops used for Teams VDI. The goal is to improve call quality and reduce resource consumption inside the VDI.

Current Policy Settings:
User's image

Tried to tweek the MS Store configuration policy and found that The Slimcore Optimization is only working if we allow the Non Admin Install option in the above policy.

After extensive testing and evaluation of potential solutions, the most effective recommended approach is outlined below.

This is more restrictive, but there is an important production-support limitation. Microsoft documents a policy named: Allowed package family names for non-admin user install It can bypass Prevent non-admin users from installing packaged Windows apps for matching package family names. Microsoft’s Teams guidance recommends these values for the current split package architecture: Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe

Microsoft.Teams.SlimCoreVdiFwk.*_8wekyb3d8bbwe As of 30 July 2026, the Microsoft ApplicationManagement CSP reference still marks as applicable to Windows Insider Preview for MDM/CSP deployment.

Any Suggestions to achieve our result by keeping the Microsoft Store Restricted for users, but need the Slimcore activaion done.

Microsoft Teams | Microsoft Teams for business | Settings | Other
0 comments No comments

2 answers

Sort by: Most helpful
  1. Ana Le 2,615 Reputation points Independent Advisor
    2026-09-28T07:03:31.3266667+00:00

    Hi,

    It looks like the Microsoft Store restriction and the non-admin app installation restriction can be handled separately for this scenario. Microsoft documents a way for managed endpoints to keep BlockNonAdminUserInstall enabled while allowing the SlimCore MSIX packages to install.

    For the current split MSIX architecture, I would check these areas:

    1/ Check the Windows build and required updates.

    Microsoft documents support for SlimCore installation with BlockNonAdminUserInstall enabled after applying the applicable cumulative update:

    • Windows 11 23H2 / 22H2: KB5052094
    • Windows 11 24H2: KB5052093
    • Windows 10 22H2: KB5055612
    • or a later cumulative update

    These updates introduce the Allowed package family names for non-admin user install policy, which can be used to allow the SlimCore packages without broadly allowing non-admin users to install packaged apps.

    For the new split MSIX architecture, Microsoft lists these SlimCore package families:

    • Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe
    • Microsoft.Teams.SlimCoreVdiFwk.<version>_8wekyb3d8bbwe

    Microsoft also documents a regex-based allow-list option: New VDI solution for Teams - Microsoft Teams | Microsoft Learn

    2/ If the endpoints are Intune-managed, check whether the following policy can be configured in your environment:

    ./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/AllowedNonAdminPackageFamilyNameRules

    Microsoft documents this as an option for allowing matching package family names even when BlockNonAdminUserInstall is enabled: ApplicationManagement Policy CSP | Microsoft Learn

    3/ Verify the other MSIX-related policies.

    Microsoft identifies these settings as possible blockers for SlimCore installation:

    • BlockNonAdminUserInstall
    • AllowAllTrustedApps
    • AllowDevelopmentWithoutDevLicense

    Your screenshot currently shows Allow All Trusted Apps as Explicit allow unlock, so I would verify the effective policy on an affected endpoint rather than changing this setting immediately.

    4/ Also check AppLocker or WDAC.

    Microsoft notes that AppLocker or Windows Defender Application Control can block SlimCore MSIX installation. If either is being used, check whether there is a rule preventing the SlimCore Host or Framework packages from being installed or registered.

    5/ If the policy configuration looks correct, check the endpoint logs for the actual deployment failure.

    On the affected endpoint, review: Applications and Services Logs > Microsoft > Windows > AppxPackagingOM > Microsoft-Windows-AppxPackaging/Operational

    and Applications and Services Logs > Microsoft > Windows > AppXDeployment-Server > Microsoft-Windows-AppXDeploymentServer/Operational

    These logs should help distinguish a policy restriction from another MSIX deployment or registration issue.

    Could you also provide the following details from one affected endpoint?

    • Windows version/build
    • Whether the device is managed by Intune, Group Policy, or both
    • The exact Teams/SlimCore error code, if one is shown
    • Whether the screenshot represents the current effective policy or the configuration after your testing

    For reference, Microsoft specifically documents error 16389 as commonly associated with BlockNonAdminUserInstall, while error 15615 is associated with MSIX installation policy issues such as AllowAllTrustedApps. (Troubleshooting the VDI 2.0 solution for Teams - Microsoft Teams | Microsoft Learn)

    Was this answer helpful?


  2. AI answer

    2026-09-28T06:14:27.8933333+00:00

    Yes. SlimCore can be enabled while keeping Microsoft Store access restricted, but the endpoint policies must allow the SlimCore MSIX packages to install.

    The key points are:

    1. BlockNonAdminUserInstall is the most likely cause of SlimCore failing to install or activate. This commonly surfaces as Error 16389 / E_FAIL, with the underlying AppX failure often being 0x80070005 Access Denied.
    2. Keeping Store restricted is possible. The documented approach is to keep the restrictive policy and allow-list the SlimCore package family names using the new policy Allowed package family names for non-admin user install.
    3. For the new split MSIX package architecture, both package families must be allow-listed:
      • Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe
      • Microsoft.Teams.SlimCoreVdiFwk.*_8wekyb3d8bbwe
      Regex form:
      • Microsoft.Teams.SlimCoreVdi*.*_8wekyb3d8bbwe
    4. On Intune-managed endpoints, this can be set with the OMA-URI:
      • ./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/AllowedNonAdminPackageFamilyNameRules
      Value:
         <enabled/>
         <data id="AllowedNonAdminPackageFamilyNameRules" value="Microsoft.Teams.SlimCoreVdi*.*_8wekyb3d8bbwe"/>
      
    5. Required Windows updates matter. Managed endpoints/thin clients with BlockNonAdminUserInstall enabled can still allow SlimCore packages to install after applying these updates or later:
      • KB5052094 for Windows 11 23H2 and 22H2
      • KB5052093 for Windows 11 24H2
      • KB5055612 for Windows 10 22H2
    6. AllowAllTrustedApps must not be disabled. If AllowAllTrustedApps is disabled, the new media engine MSIX installation fails.
    7. Also verify that AppLocker or WDAC is not blocking the SlimCore MSIX packages. If AppLocker is used, add an exception for SlimCore packages. AppLocker cannot process trailing wildcards, so exclusions can rely on the PublisherID 8wekyb3d8bbwe. The new Host package family name is Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe.
    8. After policy changes, verify optimization on the endpoint:
      • Check whether MsTeamsVdi.exe is running on the endpoint.
      • For Azure Virtual Desktop/Windows 365, it appears as a child of msrdc.exe.
      • In Teams, hover over the Optimized banner to confirm whether SlimCore optimization is active.
      • If not optimized, use Optimize virtual desktop and restart from the Teams menu to trigger a repair attempt.

    Recommended path for the current scenario:

    1. Keep Microsoft Store restricted for users.
    2. Apply the required Windows cumulative update for the endpoint OS.
    3. Configure Allowed package family names for non-admin user install for the SlimCore package families.
    4. Ensure AllowAllTrustedApps is enabled.
    5. Check AppLocker/WDAC for blocking rules and add SlimCore exceptions if needed.
    6. Restart Teams and validate optimization status on the endpoint.

    If the environment is currently showing windows_error_16389, this strongly matches the documented BlockNonAdminUserInstall policy issue.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.