Additional settings-related features and issues within Microsoft Teams for business
Yes. SlimCore can be enabled while keeping Microsoft Store access restricted, but the endpoint policies must allow the SlimCore MSIX packages to install.
The key points are:
- BlockNonAdminUserInstall is the most likely cause of SlimCore failing to install or activate. This commonly surfaces as Error 16389 / E_FAIL, with the underlying AppX failure often being 0x80070005 Access Denied.
- Keeping Store restricted is possible. The documented approach is to keep the restrictive policy and allow-list the SlimCore package family names using the new policy Allowed package family names for non-admin user install.
- For the new split MSIX package architecture, both package families must be allow-listed:
-
Microsoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe -
Microsoft.Teams.SlimCoreVdiFwk.*_8wekyb3d8bbwe
-
Microsoft.Teams.SlimCoreVdi*.*_8wekyb3d8bbwe
-
- On Intune-managed endpoints, this can be set with the OMA-URI:
-
./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/AllowedNonAdminPackageFamilyNameRules
<enabled/> <data id="AllowedNonAdminPackageFamilyNameRules" value="Microsoft.Teams.SlimCoreVdi*.*_8wekyb3d8bbwe"/> -
- Required Windows updates matter. Managed endpoints/thin clients with BlockNonAdminUserInstall enabled can still allow SlimCore packages to install after applying these updates or later:
- KB5052094 for Windows 11 23H2 and 22H2
- KB5052093 for Windows 11 24H2
- KB5055612 for Windows 10 22H2
- AllowAllTrustedApps must not be disabled. If AllowAllTrustedApps is disabled, the new media engine MSIX installation fails.
- Also verify that AppLocker or WDAC is not blocking the SlimCore MSIX packages. If AppLocker is used, add an exception for SlimCore packages. AppLocker cannot process trailing wildcards, so exclusions can rely on the PublisherID
8wekyb3d8bbwe. The new Host package family name isMicrosoft.Teams.SlimCoreVdiHost.win-x64_8wekyb3d8bbwe. - After policy changes, verify optimization on the endpoint:
- Check whether MsTeamsVdi.exe is running on the endpoint.
- For Azure Virtual Desktop/Windows 365, it appears as a child of msrdc.exe.
- In Teams, hover over the Optimized banner to confirm whether SlimCore optimization is active.
- If not optimized, use Optimize virtual desktop and restart from the Teams menu to trigger a repair attempt.
Recommended path for the current scenario:
- Keep Microsoft Store restricted for users.
- Apply the required Windows cumulative update for the endpoint OS.
- Configure Allowed package family names for non-admin user install for the SlimCore package families.
- Ensure AllowAllTrustedApps is enabled.
- Check AppLocker/WDAC for blocking rules and add SlimCore exceptions if needed.
- Restart Teams and validate optimization status on the endpoint.
If the environment is currently showing windows_error_16389, this strongly matches the documented BlockNonAdminUserInstall policy issue.