Inside MSIX

Demystifying MSIX Architecture, Development, Deployment and Troubleshooting

Latest posts

Image
Oct 6, 2026
Post comments count 0
Post likes count 1

Is it MSIX? Part 2: Finding Package Identity with APIs

Image
Howard Kapustein

We previously determined how to tell if a process is packaged or unpackaged using Task Manager. Now let's find its package and application identity in code. Windows provides APIs to retrieve package and application identity for a process: If you prefer WinRT: Kernel mode What about kernel mode? Nearly all MSIX APIs require a user-mode caller. The Windows Driver Kit (WDK) provides RtlQueryPackageIdentity() and RtlQueryPackageIdentityEx() for querying package identity from a token. Tools? What about tools to do the same? Onward to Part 3... 1 returns but provides only the Package-Relative Application...

Image
Sep 29, 2026
Post comments count 0
Post likes count 3

Is it MSIX? Part 1: How to Tell if a Process Is Packaged

Image
Howard Kapustein

Overheard in a recent conversation: Enterprise Administrator: "The ***redacted*** application is awesome, but it really should be an MSIX package." Microsoft Developer: "Ummm, it already is." That sparked another question: How can you tell if an application is packaged or unpackaged? Turns out there's a few simple ways to check. The key difference between packaged and unpackaged processes is whether they have package identity. Task Manager provides a convenient way to quickly see this: The list of processes now shows Package name: For example: In this example, ...

Image
Sep 22, 2026
Post comments count 0
Post likes count 1

Footprint vs Payload files

Image
Howard Kapustein

Payload files Payload files are files stored in and delivered by the package. This includes your code, assets, and data, such as executables, DLLs, images, configuration files, and resources. For example: Content files The term content is sometimes used in MSIX-related APIs and documentation, but it does not provide as clean a classification as payload and footprint. For example, the Packaging API associates a content type with payload files. To avoid ambiguity, we'll use payload file when referring to files stored in the package. Footprint files Footprint files are package metadata and infrastructur...

Image
Sep 15, 2026
Post comments count 2
Post likes count 1

PackageType: Main, Framework, Resource, Optional, Bundle

Image
Howard Kapustein

Every MSIX package is one of four package types: MSIX also supports Bundle packages. Bundles are somewhat different from those four package types: a Bundle is a container for one or more MSIX packages. Windows APIs nevertheless expose Bundle alongside the other package types when identifying packages. Each package type has its own behaviors, nuances, and rationale worthy of a dedicated discussion. We'll take a brief whirlwind tour of MSIX package types here and explore them in greater detail in future blog posts. What does imply? What does actually mean? MSIX packages have various properties and beh...

Image
Sep 8, 2026
Post comments count 0
Post likes count 1

MSIX PackageVolume: How Package Storage Works

Image
Howard Kapustein

An MSIX package can be staged in several ways and locations: By far the most common is PackageVolume. We'll dig into the rest in future posts, but for now let's focus on MSIX PackageVolume. In the beginning... When MSIX first appeared in Windows 81 packages would be staged to a unique directory under . More specifically, packages were placed in a subdirectory named with the package's full name. For example: Every package has a unique package full name, and thus is staged to a unique subdirectory within its package volume. This is commonly referred to as a pkgdir. This illustrates one of MSIX's ...

Image
Sep 1, 2026
Post comments count 0
Post likes count 1

Servicing While In Use and ERROR_PACKAGES_IN_USE

Image
Howard Kapustein

How does MSIX service a package while it's in use? Simple: It doesn't. A core principle of MSIX servicing is: Do not service a package while it's in use. Deployment provides several ways to deal with that constraint. Options range from terminating applications to deferring servicing until the package is no longer in use. How hard can it be? 'Servicing a package' means any deployment activity modifying software, including update, remove, repair and other operations. Altering installed software can be highly disruptive if the software is in use. Executables and DLLs may be mapped into running processes. File...

Image
Aug 25, 2026
Post comments count 0
Post likes count 2

What Kind of Packaged Process Is It?

Image
Howard Kapustein

As previously discussed, we can divide processes into the two broad categories of packaged vs unpackaged, based on if the process HAS or LACKS package identity. Packaged processes can be divided into three broad categories: All three have package identity, but they make different tradeoffs between compatibility and modern packaged behavior. RuntimeBehavior Packages specify how an application process is created and runs via multiple properties in . The RuntimeBehavior attribute clearly expresses this: is a Universal app. It was first introduced in Windows 81. New lingo appeared with it, initially ref...

Image
Aug 18, 2026
Post comments count 0
Post likes count 2

What’s a PFN?

Image
Howard Kapustein

What's a PFN? MSIX introduced Package identity in Windows 8. While the familiar package identity "5-tuple" was functional, it wasn't especially convenient to pass through APIs or embed in resources such as files, registry keys, URLs, or XML documents. To address this, Windows defined an opaque string representation known as a Package Moniker. Windows called a related identifier derived from a package's Name and Publisher the Package Family Moniker. These were commonly abbreviated as PM and PFM. As development progressed, Windows quite sensibly required new APIs to pass through API Design Review. The review tea...

Image
Aug 11, 2026
Post comments count 2
Post likes count 3

Remove and Package Lifetime

Image
Howard Kapustein

MSIX uses a Garbage Collection (GC) design for staged package lifetime and destaging. Throughout this article: Package Core Principles A staged package can't be destaged while any references to it exist. This is a direct consequence of MSIX's core architectural principles: Consequently, removing a package's payload from disk is not a direct result of a single API call. Instead, package payloads are automatically destaged when they are no longer needed. Even then, destaging may not occur immediately. Some actions that remove a reference don't directly trigger Deployment activity. In these cases,...