Guides / Intune Company Portal: apps won't install or device pending
Last reviewed 5 Oct 2026
Intune Company Portal: apps won't install or device pending
Company Portal stuck on Pending, Required apps failing, or printers never appearing? User checks first, then Intune app and device status for admins.
Company Portal is the shop window for work apps, Wi-Fi profiles, VPN and sometimes printers. When it sits on Pending, shows a red error, or never offers the app the manager promised, the ticket lands as "Intune is broken". Usually the device never checked in, the assignment missed the user, or the installer never got a clear path to the content.
Is Microsoft Intune down?
Check Service health for Microsoft Intune / Endpoint Manager and the Microsoft 365 status page. A posted Intune incident can stop enrolments and app installs broadly. One PC pending while the rest of the team installs fine is local. Sign-in problems belong on the Entra ID page first.
User-level steps
- Confirm you are signed into Company Portal with the work account, not a personal Microsoft account. Wrong account is surprisingly common on shared PCs.
- Sync. In Company Portal open Settings and tap Sync. On Windows you can also open Settings → Accounts → Access work or school → the work account → Info → Sync.
- Wait on Pending — but not forever. A large Win32 app can sit on Pending while the content downloads. If it has not moved in an hour on a normal office connection, collect the error and stop hoping.
- Disk and power. Full disks and laptops on battery saver defer installs. Free space and plug in.
- Reboot once. Many required apps need a restart to finish detection. Do not reboot in a loop.
- Reinstall Company Portal from the Store only if the app itself will not open. Reinstalling Portal does not wipe Intune management.
Admin checks (Intune)
- Device check-in. In the Intune admin centre, open the device and note Last check-in. A device that has not checked in for days will not install anything new. Fix connectivity, sleep settings, or enrolment first.
- App status by device / by user. Open the app → Device install status / User install status. Read the error code.
0x80070005is access denied,0x87D1041Coften means the requirement rules did not match, and download failures often mean the content URI or network path is blocked. - Assignment. Confirm the app is assigned to a group that actually contains the user or device. Nested group delays and dynamic group lag cause "everyone else got it" tickets.
- Win32 content and detection. Wrong detection rules mark a failed install as success, or retry forever. Install in the SYSTEM context unless the app truly needs the user.
- Filters and applicability. Assignment filters for OS version or device ownership silently skip machines. Check why the device was excluded before repackaging.
- Printers and profiles. Printer deployments via Intune (Universal Print, Win32 print drivers, or configuration profiles) fail for the same reasons as apps: no check-in, bad assignment, or a driver that needs a reboot. See the printer guide once Company Portal health is clean.
Network gotchas
Delivery Optimisation and the Intune content CDN need outbound HTTPS. Guest Wi-Fi that intercepts SSL, or a proxy that authenticates only per-user, will stall SYSTEM-context downloads. Test on corporate Wi-Fi or Ethernet before blaming the package.
Enrolment versus app install
If Company Portal asks the user to enrol again, or Windows shows no work account under Access work or school, you do not have an app problem yet. Finish Entra join or automatic enrolment first. Apps assigned to devices never reach a PC that is not managed. Apps assigned to users still need a successful user token on that device.
When to escalate
Escalate to Microsoft when many devices across sites fail the same app with the same error, Service health is quiet, and your package installs cleanly from a manual SYSTEM run. Attach the app GUID, error codes, and device check-in times. For one PC that has not checked in since last month, fix enrolment first.
Related status pages
Related guides
- Conditional Access: device not compliant or not joining
- Work printer offline, stuck jobs, or Intune printer missing
- Microsoft 365 sign-in loop or 'More information required'
FAQ
- Why is Company Portal stuck on Pending?
- Usually the device has not checked in, the download is still running, assignment missed the user, or the installer cannot reach Intune content because of network or proxy rules. Sync, free disk space, then ask IT to read the app install status error.
- Does reinstalling Company Portal remove Intune?
- No. Company Portal is the storefront. Management stays on the device until you unenrol or wipe. Reinstall Portal only if the app itself will not open.
- How do I force an Intune sync on Windows?
- Settings → Accounts → Access work or school → your work account → Info → Sync. You can also sync from Company Portal settings. Then wait for the next check-in cycle.
- Is Intune down if one app will not install?
- Rarely. Check Service health for Intune. If other required apps install on the same device, the problem is that package, detection, or assignment — not the whole service.