Office 365 Click to run is not compatible with UAC

LessThan50characters 0 Reputation points
2026-09-25T09:00:25.5933333+00:00

Identical architecture migration succeeds when initiated from an elevated interactive Administrator command prompt but fails when initiated through Microsoft Intune's Microsoft 365 Apps deployment mechanism. Deployment configuration, architecture settings, and Office prerequisites have been validated.

We are observing a real difference between an elevated interactive admin token and whatever context Microsoft's Office deployment mechanism is using. The challenge for us is proving exactly where the handoff breaks and that requires the Microsoft developers to conduct internal testing and monitoring on their own systems.

The UAC setting "Run all administrators in Admin Approval Mode" is of no affected but the behaviour appears to be the split token handoff is not being performed correctly by Click to run and following actions in the chain, so there could realistically be a defect in the bootstrapper.

As of now, a secure device following Microsoft's Secure Score guidance is not compatible with Intune being used to manage Office 365 installations. Please send this on to the relevant teams for urgent testing and resolution. There is no need for a service request and other users need visibility of the issues\resolution.

Microsoft 365 and Office | Install, redeem, activate | For business | Windows
0 comments No comments

1 answer

Sort by: Oldest
  1. Jayden-P 3,045 Reputation points Independent Advisor
    2026-09-25T09:51:31.4+00:00

    Hi @LessThan50characters

    First, I'd like to clarify that this is a user-to-user public forum and not an official Microsoft support channel. I am a forum user and do not have the ability to initiate, or request internal engineering investigations on Microsoft's behalf. The information I conducted are based on publicly available documentation, and my own research.

    Based on the information provided, I cannot confirm that the cause is specifically a split-token handoff issue, Click-to-Run defect, or bootstrapper problem. These remain possible hypotheses and would require appropriate diagnostic data and investigation to establish.

    The observation that the migration succeeds from an elevated interactive Administrator session but fails when deployed through Intune does indicate that the two execution paths are behaving differently. However, Intune-managed application deployments commonly run in a different security context than an interactive administrator session, so a difference in behavior by itself does not identify the specific component responsible for the failure.

    Regarding Secure Score, Microsoft does document that Secure Score for Devices currently has only partial Intune support. As a result, configurations set through Intune may appear as misconfigured in Secure Score even when the actual device configuration is correct. This is an assessment/reporting limitation and does not establish that the security configuration is incompatible with Intune or Microsoft 365 Apps deployment.

    Ref: Microsoft Secure Score for Devices - Microsoft Defender Vulnerability Management | Microsoft Learn

    Determining whether the reported Office migration failure represents a product defect or an expected limitation would require review of the relevant Intune and Click-to-Run diagnostic data.

    If you do not wish to open a support request, I recommend file a feedback via Feedback portal.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.