EXE or MSI vs MSIX on the Microsoft Store, and how to convert an installer
The Microsoft Store takes Win32 apps in two forms. You can submit your EXE or MSI installer by URL, and you sign it, host it and update it yourself. Or you package the app as an MSIX, and Microsoft signs it, hosts it and delivers updates through the Store. If you only have an installer, the MSIX Packaging Tool can turn it into an MSIX by recording what it installs.
If you don't own a code signing certificate or don't want to run your own updates, ship an MSIX. If your app needs a driver or already has a signed installer and updater you're happy with, the EXE or MSI route is less work.
- Microsoft calls MSIX the recommended format, and it comes with free code signing, hosting and Store updates.
- An EXE or MSI keeps your existing installer and updater, but you need a trusted certificate and a versioned URL for every release.
- The MSIX Packaging Tool converts an installer without the source code by capturing what it does on a clean machine.
- StoreFast publishes MSIX updates. EXE and MSI apps are coming, not available yet.
How the two routes differ
| Feature | MSIX | EXE or MSI |
|---|---|---|
| Partner Center product type | MSIX or PWA app | EXE or MSI app |
| Code signing certificate | Not neededMicrosoft re-signs it | Requiredfrom a Trusted Root Program CA |
| Hosting | Microsoft | Your versioned HTTPS URL |
| Updates for existing users | Through the Storeonly changed blocks download | Your own updaterthe Store doesn't update them |
| Silent install | No switches to supply | Requiredyou give the switches for an EXE |
| Clean uninstall | YesMicrosoft guarantees it | Up to your installerpolicy 10.2.7 requires it |
| Games | Yes | Nopolicy 10.2.9 is for non-gaming products |
| Updates through StoreFast | Yes | Nocoming, not available yet |
What Microsoft requires for an EXE or MSI
Store policy 10.2.9 and the MSI/EXE package requirements set the rules. You submit a direct HTTPS link to the installer instead of uploading a file.
- The installer can only be an .msi or an .exe, and it has to be a standalone installer. A web installer or downloader stub that fetches files when it runs isn't allowed.
- The installer and every Portable Executable file in it have to be signed with a code signing certificate that chains up to a CA in the Microsoft Trusted Root Program. The Store doesn't re-sign EXE or MSI files.
- The URL has to be versioned, like https://www.contoso.com/downloads/1.1/setup.exe, and the file behind it can't change after you submit it. Microsoft says the Store keeps copies of your most recent packages, and if the file at the URL is swapped without a submission, it downloads the new one and certifies it again.
- The install has to be silent, though a User Account Control prompt is allowed. For an MSI, the Store runs it with /qn. For an EXE, you enter the switch your installer needs, like /s, in the Installer parameters field.
- For an EXE, you can also map your installer's return codes to cases like reboot required, disk full or already installed, so the Store can show customers the right message. Microsoft highly recommends it.
- You manage version numbers in your installer. The Store doesn't track them for Win32 packages.
Updates are your job. Microsoft's update page for EXE and MSI apps says the Store lets existing users install in-app updates if your installer supports them, and that it doesn't provide those updates itself. It still recommends submitting each new version with a new versioned URL so new customers get the latest installer. Policy 10.4.4 adds that the download can't take an unreasonable amount of time and the install success rate can't be unreasonably low.
What changes with an MSIX
Microsoft's MSIX package requirements say you don't need a CA-trusted certificate, a .pfx file or a hardware token for a Store submission, because the Store replaces any signature with a Microsoft certificate after certification. The same page lists free code signing and CDN hosting, easier updates, and features like flighting as reasons to pick MSIX.
You upload the .msix, .msixbundle or .msixupload file to Partner Center, and the Store installs and updates it. Microsoft's MSIX overview says an update only downloads the 64 KB blocks that changed, and that MSIX guarantees a clean uninstall with no leftover files or registry entries.
There are rules to work with. The package needs a four-part version with the last part left at 0, and its Name and Publisher have to match Product identity in Partner Center. The MSIX update guide covers those. Packaged apps also behave differently. Writes to AppData and the registry are redirected to a private per-app location, the install folder is protected, and drivers aren't supported at all.
How to convert an EXE or MSI to MSIX
If you build the app yourself, packaging the build output directly is usually cleaner. The Tauri guide does it with a manifest and MakeAppx, and the Electron guide uses electron-builder. If you only have an installer, use the MSIX Packaging Tool. It works without the source code because it runs your installer and records the files and registry changes it makes.
- 1
Check the installer will convert
Microsoft's Know your installer page lists what to fix first. Drivers can't be packaged. Services can, but installing them needs admin rights. An app that writes logs next to its .exe, relies on the working directory from a shortcut, or loads runtimes from the Windows side-by-side folder needs changes or a Package Support Framework fixup.
- 2
Prepare a clean machine
Install the tool from the Store or with winget. Microsoft recommends converting on a clean virtual machine, because the tool captures everything that happens during the install, including other apps and services that happen to be running. Match the architecture you're shipping, and take a checkpoint so you can go back to a clean state for the next version.
winget install "MSIX Packaging Tool" - 3
Fill in the package information
Choose Application package, pick your installer and add any installer arguments. For an MSI the tool reads the package details from the file, and for an EXE you type them in. For the Store, enter Package name and Publisher exactly as Product identity in Partner Center shows them, and use a version that ends in .0.
You don't need your own certificate for the copy you upload, since Microsoft re-signs it. To install it on your own machine first, sign a test copy, because the tool notes that an unsigned MSIX can't be installed.
- 4
Run the install and first launch
The tool starts your installer and you click through it while it captures the changes. Then launch the app at least once from the first launch page so the tool picks up anything the app sets up on first run, and remove entry points you don't want.
- 5
Create the package and test it
Save the .msix, open it in the package editor if you need to change the manifest, and install a signed copy to test it. Run the Windows App Certification Kit before you submit. For the next version, you can save a conversion template and run the conversion from an admin prompt.
MsixPackagingTool.exe create-package --template C:\conversion\ConversionTemplate.xml -v
runFullTrust and other restricted capabilities
A converted Win32 app runs as a full trust app, and Microsoft's capability reference says those apps have to declare the runFullTrust restricted capability. When Partner Center detects a restricted capability in your upload, the Submission options page asks you to explain how your app uses it, and Microsoft says that review can add time to certification. You generally don't go through it again on updates unless you declare new restricted capabilities.
How to choose
- Pick MSIX if you don't have a code signing certificate, don't want to host installers, or want the Store to deliver updates. It's also the only route for games.
- Pick EXE or MSI if your app needs a driver or system-wide changes that MSIX doesn't allow, or if you already sign your installer, host it and ship updates through your own updater.
- If you're unsure, try the conversion on a clean VM. If the packaged app runs and passes the certification kit, MSIX saves you work on every release after that.
Where StoreFast fits
StoreFast publishes MSIX updates today. You make the first submission in Partner Center, then drop each new .msix on your app's page and StoreFast checks the name and version, writes What's new in every listing language and submits it. EXE and MSI apps are coming, not available yet.
Who it's for
StoreFast is a good fit if
- You ship your app to the Store as an MSIX, or you plan to convert to one.
- Your listing has several languages and you want What's new in all of them.
- You release from GitHub Actions or a coding agent.
Look elsewhere if
- You submit an EXE or MSI installer by URL. That support is coming, not available yet.
- Your app isn't in the Store yet. Make the first submission in Partner Center.
Questions
- Can I submit an EXE to the Microsoft Store?
- Yes, if it isn't a game. Microsoft has accepted EXE and MSI installers since June 2021. You host the installer at a versioned HTTPS URL, sign it with a certificate from a CA in the Microsoft Trusted Root Program, and make sure it installs silently without downloading anything while it runs.
- Does the Store update an EXE or MSI app for me?
- No. Microsoft's docs say the Store doesn't provide updates to existing users of an EXE or MSI app, automatically or manually. Your app has to update itself. You still submit each new version with a new versioned URL so that new customers get the latest installer.
- Do I need a code signing certificate for an MSIX?
- Not for the Store. Microsoft re-signs MSIX packages with its own certificate after they pass certification. You only need your own certificate to install the package on your own machines or to distribute it outside the Store.
- Can the MSIX Packaging Tool convert any installer?
- It takes MSI, EXE, ClickOnce, App-V and script installers, but some apps won't work once packaged. Microsoft says MSIX doesn't support drivers, and apps that write to their own install folder or share data with other apps through AppData or the registry need changes first.
- Can StoreFast publish my EXE or MSI app?
- Not yet. StoreFast publishes MSIX updates today. EXE and MSI apps are coming, but they aren't available yet.
Publish your next MSIX update
Make your first submission in Partner Center, connect it to StoreFast and drop the next .msix on the page. Try it free for 7 days, no card needed.
Sources
Facts about Microsoft's tools were checked against these pages on October 5, 2026.
- App package requirements for MSI/EXE app
- Upload app packages for MSI/EXE app
- Publish update to your MSI/EXE app
- App package requirements for MSIX app
- Microsoft Store policies
- What is MSIX?
- MSIX Packaging Tool overview
- Create an MSIX package from any desktop installer
- Know your installer
- Prepare your environment for conversion
- Create a package using the command line
- App capability declarations