Skip to content
Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script

Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script

Written By Anoop C Nair
Last Updated May 12, 2026
Posted In Intune
SHARE

Key Takeaways

  • Microsoft Tunnel version 20260129.1 has a confirmed upgrade issue
  • Affected servers may appear healthy even when upgrades fail
  • Microsoft fixed the issue in version 20260330.1
  • A new remediation script simplifies recovery for impacted servers

In this post, we are discussing Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script. Microsoft has shared details about a known upgrade problem affecting some Microsoft Tunnel servers running version 20260129.1. Due to this issue, certain servers may fail to complete updates and remain stuck on the older release.

Table of Contents

Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script

Microsoft also shared some administrators might still see the server status as healthy inside the Microsoft Intune admin center, even when the upgrade process does not finish correctly. In some environments, the server may also return to the previous version automatically after the failed update.

What Is the Issue?

Microsoft has identified an upgrade issue affecting Microsoft Tunnel deployments running version 20260129.1. Due to this problem, some Tunnel servers may get stuck during the upgrade process and fail to install newer builds successfully. Even though the server health status may continue to appear normal in the Microsoft Intune admin center, the upgrade itself may not complete correctly.

Symptoms Reported by Administrators
Servers remain on version 20260129.1
Upgrade banners display errors in Intune
Server health still appears as healthy despite failed upgrades
Tunnel servers roll back to the older version because of configuration mismatches
Automatic upgrades fail to complete successfully
Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script -Table.1
Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script -Fig.1
Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script -Fig.1

Workaround

Microsoft recommends updating affected Microsoft Tunnel servers to version 20260330.1 or later to resolve the upgrade problem. For administrators facing failed or stuck upgrades, Microsoft has provided a new remediation script named mstunnel-patch-2602.sh that can repair impacted servers without requiring a complete reinstall. Before using the script, administrators should have access to the Linux virtual machine hosting the Tunnel server, sudo permissions, and the downloaded patch script available on the server.

Patch My PC

Use the following hash to identify whether your deployment is on this version:

Agent: sha256:abbdcd854aa5ac376aed32c828e4c84917e776a701855cd1e3febed18a3e4dae

Server: sha256:ad57d6a7ffe21f64fc1577713063ae9b180914cf65bc70b4e49be21299cfc1d3

When to Use the Script

Microsoft recommends using the remediation script for Microsoft Tunnel environments experiencing upgrade-related problems with version 20260129.1. Administrators may need the script if the Tunnel server stays on the affected build, fails to update to newer releases, or repeatedly rolls back after upgrade attempts. In some cases, the Microsoft Intune admin center may still display the server status as healthy even though upgrade errors continue to appear because of version mismatches.

Running the Patch Script

After downloading the remediation script, administrators may first need to enable execution permissions before running it with elevated privileges. Once started, the script automatically checks affected build versions, creates backup configurations, stops Tunnel services, updates configuration hashes, downloads the corrected release, and installs the updated Tunnel version using mst-cli.

  • After the process completes successfully, affected Tunnel servers should upgrade properly to version 20260330.1 and no longer experience rollback or upgrade failure issues.
Run the script
Info
Step 1: Enable execution permissionschmod +x mstunnel-patch-2602.sh
Step 2: Run the scriptsudo ./mstunnel-patch-2602.sh
Fix Upgrade Issues in Specific Microsoft Intune Tunnel Versions using mstunnel-patch-2602 Script -Table.2

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the WhatsApp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair is a Workplace Technology solution architect with 25+ years of experience. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He is a blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, and Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Entra, and Microsoft Security.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read