When you click the tile of a Microsoft Store App, the App begins to start, and then Windows just returns to the start screen. No on-screen error is displayed.
Microsoft-Windows-Immersive-Shell event 5961 is logged under the Applications and Services Logs\Microsoft\Windows\Apps\Microsoft-Windows-TWinUI/Operational event log path:
Log Name: Microsoft-Windows-TWinUI/Operational
Date: 1/3/2013 3:03:17 PM
Event ID: 5961
Task Category: (5961)
Activation of the app <app name> for the Windows.Launch contract failed with error: The app didn't start.
Note: The app portion of the example event, "<app name>", will change depending on the application that fails to start.
Possible values for <app name> include but are not limited to:
Prefixes for other built-in Microsoft Store Apps include:
You cannot start a Microsoft Store App, open Start screen, and use Search in Windows. Additionally, you receive the following event log in Application logs:
Log Name: Application
Source: Application Error
Event ID: 1000
Task Category: (100)
Faulting application name: xxxx.exe, version: 10.1605.1606.6002, time stamp: 0x5755acef
Faulting module name: xxxxxx.dll, version: 10.0.14393.1198, time stamp: 0x5902836c
Exception code: 0xc000027b
Fault offset: 0x00000000006d5eab
Faulting process id: 0x29c4
0xc000027b: An application-internal exception has occurred. This error occurs when an access denied error happens during app initialization that is fatal and cause an exception that leads to the crash.
If you use Process Monitor to track Apps' executables or related files, you receive the following access denied logs pointing to the missing permission for the user account that you log on to:
- For keys like below and its subkeys with permission missing for currently logged in user:
For file subsystem :
Program Files - Read, Read and Execute, List folder Contents
Windows - Read, Read and Execute, List folder Contents
Users\<userName>\AppData\Local\Microsoft\Windows\WER - Special Permissions (List folder / read data, Create Folders /Append Data)
For issue 1
Registry and or file system permissions may have been changed from their defaults.
The "All Application Packages" group (a well known group with a predefined SID) must have specific access to certain locations of the registry and file system for Microsoft Store Apps to function properly.
For issue 2
This issue occurs because the read permission is missing from any or all the keys. Therefore, 0xc000027b is logged. This error without exception is missing permission for ALL APPLICATION PACKAGES at registry location or file subsystem locations.
Registry and File System permission must be reverted to a state that will allow Microsoft Store App to function
Warning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.
Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.
Only change the permission of the registry keys that are known to cause the access denied error. Incorrectly changing registry keys' permission might cause serious problems or unintentionally weaken security settings.
Extensive permission changes that are propagated throughout the registry and file system cannot be undone. Microsoft will provide commercially reasonable efforts in line with your support contract. However, you cannot currently roll back these changes. We can guarantee only that you can return to the recommended out-of-the-box settings by reformatting the hard disk drive and by reinstalling the operating system.
If you use Group Policy to manage permissions, or if you are unsure whether Group Policy is used to manage permissions, follow these steps:
- Unjoin the computer from the domain or put the computer in a test OU with block policy inheritance enabled. This prevents the domain-based Group Policy from reapplying the permission changes and breaking the modern applications again after you have fixed them.
- Add permissions where they are required per the following details.
- Edit the Group Policy that manages to permissions so that it no longer breaks modern application.
Registry and File System permission must be reverted back to a state that will allow Microsoft Store App to function. Follow this method to resolve the issue
- Determine if file system permissions have been changed. If not see the "More Information" section below
- If so how were they changed? Manually or with Group Policy?
- Determine if registry permissions have been changed If not see the "More Information" section below
- If so how were they changed? Manually or with Group Policy?
- Verify secpol and GPPs specifically.
Determining if File System permissions have been changed
Check the folders listed below. Determine if the All Application Packages group has the access indicated. Most but not all sub directories of Windows, Program Files and WER also grant permissions to the All Application Packages group.
- Program Files - Read, Read and Execute, List folder Contents
- Windows - Read, Read and Execute, List folder Contents
- Users\<userName>\AppData\Local\Microsoft\Windows\WER - Special Permissions (List folder / read data, Create Folders /Append Data)
Determining if registry permissions have changed
Check the registry keys listed below. Make sure the All Applications Packages group has the Read permissions to the following registry paths:
Most but not all of the subkeys of the registry keys listed above will grant the "All Application Packages" group read access.
Determining if Group Policy is being used to manage permissions
- Logon to a PC as a user experiencing the problem
- Open an administrative command prompt then run the following command:
> gpresult /h <path>\gpreport.html
- Open the file gpreport.html and expand the following path:
Computer Settings -> Policies\Windows Settings\Security Settings. look for "File System" and Registry. If these exist then GP is assigning permission. You must edit the GP to include the necessary permissions for the All Application Packages group.
Steps to fix the problem
Depending on how the file system permissions were changed will determine how to recover from the problem. The most common ways permissions are changed are manually and by Group Policy.
Important Note - Make sure that you test your resolution in a lab before widely deploying. Always backup any important data before changing registry and file system permissions.
Fixing file system permissions that have been changed manually
- Open File Explorer
- Browse to "c:\Program Files "
- Right click and select properties
- Select the "Security" tab
- Click the "Advanced" button
- Click the "Change permissions" button
- Click the Add button
- Click "Select a principal" link
- Click the locations button and select the local computer
- Add the All Applications Packages group name and click ok
- Make sure that Type = allow and Applies to = This folder, subfolder and files.
- Check Read & Execute, List folder contents and Read.
- Check the box Replace all child object permissions with inheritable permission entries from this object
- Click Apply and OK.
- Repeat for c:\Windows
- Repeat for c:\Users but grant the "All Application Packages" group Full Control.
- Click Apply and Ok.
Fixing file system permissions changed by Group Policy
Have a Group Policy administrator do the following:
You will need to wait for the Group policy change to replicate to all Domain Controller s and for all clients to update their Group Policy settings.
Note: Processing the File System changes will incur some logon delay the first time this policy is processed. Subsequent logons will not be impacted unless changes are made to the policy. As an alternative you can use a script that is called post logon by the user is run as a scheduled task.
Fixing registry permissions that have been changed manually
- Open regedit.exe
- Right click on HKEY_Users and select properties
- Make sure that All Application Packages has Read
- Repeat for HKEY_CLASSES_ROOT
- Expand HKEY_LOCAL_MACHINE. Check the subkeys HARDWARE, SAM,SOFTWARE,SYSTEM. Make sure that All Application Packages has the Read permission.
Fixing Registry Permissions that have been changed by Group Policy
Have a Group Policy administrator do the following:
For more information, refer to the following articles:
And refer to the following article and its "File system and registry access control list modifications" section:
File system and registry access control list modifications
Windows XP and later versions of Windows have significantly tightened permissions throughout the system. Therefore, extensive changes to default permissions should not be necessary.
Additional discretionary access control list (DACL) changes may invalidate all or most of the application compatibility testing that is performed by Microsoft. Frequently, changes such as these have not undergone the thorough testing that Microsoft has performed on other settings. Support cases and field experience have shown that DACL edits change the fundamental behavior of the operating system, frequently in unintended ways. These changes affect application compatibility and stability and reduce functionality, with regard to both performance and capability.
Because of these changes, we do not recommend that you modify file system DACLs on files that are included with the operating system on production systems. We recommend that you evaluate any additional ACL changes against a known threat to understand any potential advantages that the changes may lend to a specific configuration. For these reasons, our guides make only very minimal DACL changes and only to Windows 2000. For Windows 2000, several minor changes are required. These changes are described in the Windows 2000 Security Hardening Guide.
Extensive permission changes that are propagated throughout the registry and file system cannot be undone. New folders, such as user profile folders that were not present at the original installation of the operating system, may be affected. Therefore, if you remove a Group Policy setting that performs DACL changes, or you apply the system defaults, you cannot roll back the original DACLs.
Changes to the DACL in the %SystemDrive% folder may cause the following scenarios:
- The Recycle Bin no longer functions as designed, and files cannot be recovered.
- A reduction of security that lets a non-administrator view the contents of the administrator’s Recycle Bin.
- The failure of user profiles to function as expected.
- A reduction of security that provides interactive users with read access to some or to all user profiles on the system.
- Performance problems when many DACL edits are loaded into a Group Policy object that includes long logon times or repeated restarts of the target system.
- Performance problems, including system slowdowns, every 16 hours or so as Group Policy settings are reapplied.
- Application compatibility problems or application crashes.
To help you remove the worst results of such file and registry permissions, Microsoft will provide commercially reasonable efforts in line with your support contract. However, you cannot currently roll back these changes. We can guarantee only that you can return to the recommended out-of-the-box settings by reformatting the hard disk drive and by reinstalling the operating system.
For example, modifications to registry DACLs affect large parts of the registry hives and may cause systems to no longer function as expected. Modifying the DACLs on single registry keys poses less of a problem to many systems. However, we recommend that you carefully consider and test these changes before you implement them. Again, we can guarantee only that you can return to the recommended out-of-the-box settings if you reformat and reinstall the operating system.