Fix it now
These codes are the deployment engine refusing on environment grounds rather than on anything wrong with the package. 0x80073D0A is specific and often misread: it means the Windows Firewall service is not running. Read the exact code from the deployment log and fix the condition it names.
Get-AppxLog
Get-Service mpssvc
Start-Service mpssvc
Get-Volume
Get-AppxVolume
- Take the code from
Get-AppxLogor from AppXDeployment-Server, Operational, not from whatever generic failure your deployment tool displayed. - 0x80073D0A: start the Windows Firewall service and try again. Microsoft’s remedy is exactly that, and it is common on machines where a third-party firewall was installed and the inbox service was turned off.
- 0x80073CF4: free space on the volume that holds the package repository, then retry. Staging needs room for the payload plus working space.
- 0x80073CF5: copy the package to a local folder such as
C:\tempand install from there rather than from a share, a mapped drive or a URL. - 0x80073D0D: the target volume is offline.
Get-AppxVolumelists package volumes andMount-AppxVolume -Volume <volume>brings one back.
0x80073D10 is the architecture refusal, not 0x80073D0A. If the log gives you 0x80073D10 you need a different build of the package, and nothing on this machine will change that.
If the condition it named is now satisfied and the package installs, stop here. Otherwise the next section takes the five codes apart.
Why it happens
Before a byte of payload is written, the engine confirms the operation can succeed in this environment. It picks the applicable package out of a bundle for the processor architecture, works out how much space staging needs on the target volume, confirms the source is readable, and confirms the services it depends on are available. Each of those failing produces its own code, and each has a different fix. They are not interchangeable.
0x80073D0A is the one people misfile. Microsoft publishes it as ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING, with the text “the package couldn’t be installed because the Windows Firewall service isn’t running. Enable the Windows Firewall service and try again.” It has nothing to do with the processor architecture. That is 0x80073D10, ERROR_INSTALL_WRONG_PROCESSOR_ARCHITECTURE, a separate code that means the package targets an architecture this device does not run.
The firewall dependency surprises people because disabling the inbox firewall service is a routine step when a third-party product takes over. Packaged apps declare firewall rules in their manifest, so the deployment path expects that service to be there to write them. Turn it off and every MSIX deployment on the machine stops, weeks after whoever disabled it has moved on.
The Windows Firewall service is not running
You have this one if 0x80073D0A, on a machine running a third-party firewall or one that has been through a hardening script.
Get-Service mpssvcto read the state, thenStart-Service mpssvcto start it. Microsoft refers to it as the Windows Defender Firewall Service (mpssvc).- Set it back to automatic start if a script disabled it, or the next reboot puts you back here.
- If policy is what stops it, fix that at the policy rather than locally, or it will be reverted at the next refresh.
Running the Windows Firewall service is not the same as filtering with it. It can be running with all profiles set to allow while another product does the filtering, which is what most third-party firewalls expect anyway.
Not enough disk space on the target volume
You have this one if 0x80073CF4, ERROR_INSTALL_OUT_OF_DISK_SPACE. Microsoft’s text is ‘there isn’t enough disk space on your computer. Free some space and try again.’
- Measure free space on the volume that holds the package repository, which is the system drive unless someone moved it.
- Allow for more than the package size. Staging needs working space as well as the payload.
Get-Volumegives the sizes;Get-AppxVolumetells you which volume packages are actually going to.
The package source cannot be read
You have this one if 0x80073CF5, ERROR_INSTALL_NETWORK_FAILURE, ‘the package can’t be downloaded’. Common when installing from a UNC path, a mapped drive or a URL.
- Copy the package to a local folder and install from there. That removes the network from the equation entirely.
- If it must come from a share, confirm the account running the deployment can read it – a per-machine deployment does not use your interactive credentials.
- For a download that was interrupted, delete the partial file rather than retrying over it.
The bundle has no package for this processor architecture
You have this one if 0x80073D10, or 0x80073CF3 where validation as a whole failed and architecture was the reason.
- Check the device’s processor architecture and compare it with what the vendor says the package supports.
- Ask for a build that covers that architecture. Nothing you configure on the device changes what is inside the bundle.
- Microsoft lists ‘the package doesn’t support the correct processor architecture’ under 0x80073CF3 as well, so an architecture problem can surface under either code.
The package volume is offline
You have this one if 0x80073D0D, ERROR_INSTALL_VOLUME_OFFLINE, on a machine configured to install packages to a drive other than C:.
Get-AppxVolumelists the package volumes and whether each is online.Mount-AppxVolume -Volume <volume>brings one back online.- For an update, Microsoft notes the volume means the installed volume of all package versions – so an old version sitting on a removed drive blocks the update even though the new one would go elsewhere.
Full reference
The five codes, side by side
| Code | Symbolic name | What Microsoft says |
|---|---|---|
0x80073D0A |
ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING | The package couldn’t be installed because the Windows Firewall service isn’t running |
0x80073CF4 |
ERROR_INSTALL_OUT_OF_DISK_SPACE | There isn’t enough disk space on your computer |
0x80073CF5 |
ERROR_INSTALL_NETWORK_FAILURE | The package can’t be downloaded |
0x80073D10 |
ERROR_INSTALL_WRONG_PROCESSOR_ARCHITECTURE | The deployment operation failed because the package targets the wrong processor architecture |
0x80073D0D |
ERROR_INSTALL_VOLUME_OFFLINE | The deployment operation failed because the volume is offline |
Package volumes
Windows can be configured to install packaged applications somewhere other than the system drive. When it is, the deployment engine works against a package volume rather than a plain drive letter, and the volume has to be present and mounted for anything to happen. The cmdlets are small and worth knowing before you need them.
| Command | What it does |
|---|---|
Get-AppxVolume |
Lists the package volumes on the machine and their state |
Mount-AppxVolume -Volume <volume> |
Brings a package volume back online |
Get-Volume |
The ordinary storage view: sizes, free space, file systems |
Add-AppxPackage -Path <file> -Volume <volume> |
Stages the package into a specific package volume |
A removable drive that was set up as a package volume and then unplugged produces 0x80073D0D for packages that have nothing to do with it, because for an update the volume Microsoft refers to is the installed volume of every version of the package.
Working out which condition applies without guessing
- Run
Get-AppxLogimmediately after the failure, or open AppXDeployment-Server, Operational in Event Viewer and read the most recent entry. - Match the code against the table above before doing anything on the machine.
- For a service problem, check the service state rather than assuming –
Get-Service mpssvctakes a second and rules it in or out. - For a space problem, check the volume the package repository is on, not whichever drive has least free space.
- For an architecture problem, stop working on the device. The answer is a different package.
Architecture, and why emulation does not save you
A bundle contains separate packages for different processor architectures and the engine selects the applicable one. If nothing in the bundle applies, the deployment stops. Emulation does not change that: whether the device can run code of a given architecture is a separate question from whether the bundle declares a package the device will accept. Check the vendor’s supported platform list rather than assuming a bundle that installed elsewhere will install here.
When none of the five conditions is present
- Confirm the code you are working from came from the deployment log rather than from a wrapper. Deployment tools routinely collapse several of these into one generic message.
- Check the component store:
DISM /Online /Cleanup-Image /RestoreHealth, thensfc /scannow. Deployment depends on servicing. - Look for a policy block instead. 0x80073CFF and 0x80073D01 are deployment policy refusals and read as environment failures until you see the code.
- Test the same package on a machine of the same build and architecture. If it installs there, you are looking at machine state, not the package.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x80073D0A |
ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING: the package could not be installed because the Windows Firewall service is not running. Enable the service and try again | Microsoft Learn |
0x80073CF4 |
ERROR_INSTALL_OUT_OF_DISK_SPACE: there is not enough disk space on the computer | Microsoft Learn |
0x80073CF5 |
ERROR_INSTALL_NETWORK_FAILURE: the package cannot be downloaded | Microsoft Learn |
0x80073D10 |
ERROR_INSTALL_WRONG_PROCESSOR_ARCHITECTURE: the deployment failed because the package targets the wrong processor architecture | Microsoft Learn |
0x80073D0D |
ERROR_INSTALL_VOLUME_OFFLINE: the deployment failed because the volume is offline. For an update the volume means the installed volume of all package versions | Microsoft Learn |
Confirm the fix worked
Get-Service mpssvcreports Running, and its startup type is not Disabled.Get-AppxVolumeshows the package volume online.- The package installs from a local path with no code returned.
Get-AppxLogfor the successful attempt records staging and registration completing.
Questions people ask about this
Does 0x80073D0A mean my package is built for the wrong CPU?
No. That is 0x80073D10. 0x80073D0A is ERROR_INSTALL_FIREWALL_SERVICE_NOT_RUNNING, and Microsoft’s remedy is to enable the Windows Firewall service and try again.
I run a third-party firewall. Do I have to turn the Windows one back on?
The service has to be running for MSIX deployment to succeed, because packaged apps declare firewall rules the deployment writes. Running the service is not the same as filtering with it, and most third-party products expect it to stay running anyway.
How much free space does staging actually need?
More than the package size, because the payload is expanded and validated as it is staged. Microsoft does not publish a multiplier, so treat a volume with only the package’s own size free as insufficient and clear real headroom.
Why does installing from a network share fail when the same file installs from C:?
0x80073CF5 is the source being unreadable at the moment the engine needs it. The deployment does not necessarily run with your interactive credentials, so a share you can browse is not necessarily a share it can read. Copy locally and the question disappears.
