Problem Statement: WinCC Setup Halts on Missing MSMQ Component
During installation of Siemens WinCC V7.x (including V7.0, V7.3, V7.4, and V7.4 SP1) the setup routine detects that Microsoft Message Queuing (MSMQ) is not present on the target operating system and aborts with a blocking dialog. On Windows XP SP3, Windows 7, Windows Server 2008 R2, and some Windows 10 builds, an attempt to add MSMQ through Control Panel → Add or Remove Programs → Windows Components fails with the Microsoft error code 0x42C and the descriptive text "The dependency service or group failed to start." Until the MSMQ subsystem is operational, WinCC Setup cannot continue because MSMQ is a hard prerequisite for internal WinCC component communication, redundancy synchronization, and OPC channel services.
From WinCC V8 onward the setup installs MSMQ (and IIS when WebOptions are selected) automatically. The information below is therefore most relevant to WinCC V7.0 / V7.3 / V7.4 / V7.4 SP1 running on legacy Windows platforms, although the manual remediation steps also apply to clean Windows 10 / 11 installations where the MSMQ feature is corrupted.
Error 0x42C Technical Details
Error code 0x42C equals decimal 1068 in Windows. The canonical Windows error text is:
- Win32 error 1068 (0x42C): The dependency service or group failed to start.
- Source: Distributed Transaction Coordinator (MSDTC) or RPCSS-related dependency chain.
-
Visible in:
setupapi.dev.log,msmqinst.log(located in%WINDIR%\infand%WINDIR%\security\logs).
The MSMQ service (MQAC, MSMQ, MSMQTriggers, MSMQManagement) depends on a chain that includes the Distributed Transaction Coordinator (MSDTC), RPCSS, NT LM Security Support Provider, and the Server / Workstation services. If any link in the chain is disabled, set to Manual with no start trigger, or configured to run under an account without Log on as a service rights, MSMQ installation rolls back with 0x42C.
Root Cause Analysis
The most common cause observed on field installations is that the MSDTC service is configured to run under the LocalSystem account but its account context has been corrupted, removed from the local security policy, or its registry hive is damaged. A second common cause is that the NT LM Security Support Provider (NtLmSsp) is disabled, which breaks the MSMQ installer when it tries to enumerate the local machine account.
Verify the MSDTC account with the command:
sc qc msdtc
Confirm the output line START_TYPE is DEMAND_START or AUTO_START and the binary path includes %SystemRoot%\system32\msdtc.exe. If START_TYPE shows DISABLED, change it with:
sc config msdtc start= auto
sc sdset msdtc D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)
Pre-Installation Prerequisites
Before attempting any MSMQ install path, ensure the following Windows components are present and started:
- RPCSS (
RpcSs) — automatic, running. - DCOM Server Process Launcher (
DcomLaunch) — automatic, running. - Distributed Transaction Coordinator (
MSDTC) — automatic, running. - NT LM Security Support Provider (
NtLmSsp) — manual, enabled. - TCP/IP NetBIOS Helper — manual or automatic.
Confirm state on a single screen:
sc query RpcSs | findstr STATE
sc query DcomLaunch | findstr STATE
sc query msdtc | findstr STATE
sc query NtLmSsp | findstr STATE
Method 1: Enable MSMQ via Windows Features (Recommended First Path)
This is the procedure documented in the official Siemens support article for How to Install MS Message Queuing — WinCC V7.4 SP1:
- Open the Start Menu and navigate to Control Panel → Programs and Features.
- Select Turn Windows features on or off on the left menu.
- Locate the Microsoft Message Queue (MSMQ) Server node and expand it.
- Enable all four sub-features:
- MSMQ HTTP Support
- MSMQ Triggers (optional but recommended for WinCC redundancy)
- MSMQ Active Directory Domain Services Integration (only if the machine is domain-joined and you need AD-integrated queues)
- Multicasting Support (required for some WinCC event notifications)
- Click OK and allow Windows to apply the feature.
- Reboot if prompted.
- Verify the MSMQ service is registered and started.
Quick verification commands after the feature is enabled:
sc query MSMQ | findstr STATE
sc query MQCS | findstr STATE
netstat -an | findstr 1801
A listener on UDP port 1801 confirms the MSMQ kernel driver is loaded.
Method 2: Repair the MSDTC Service (0x42C Workaround)
When Method 1 returns error 0x42C, the MSDTC service hive is the prime suspect. Run the following from an elevated command prompt in the order shown:
net stop msdtc
msdtc -uninstall
reg delete "HKLM\Software\Microsoft\MSDTC" /f
msdtc -install
net start msdtc
Re-attempt the MSMQ feature installation after the service starts cleanly. If the service still refuses to start, dump its current security descriptor and reset it using sc sdset as shown earlier. Confirm with:
sc qc msdtc
msdtc -resetlog
The msdtc -resetlog step regenerates the transaction log under %WINDIR%\System32\Msdtc and often resolves the 0x42C trigger when the original log is corrupt.
Method 3: Enable NT LM Security Support Provider
On Windows XP SP3 and many Windows 7 installations, MSMQ setup fails silently if NtLmSsp is disabled. This is a frequently-missed root cause because the MSMQ installer does not always name the dependency that actually failed.
- Press Start, click Run.
- Type
services.mscand press Enter. - Scroll to NT LM Security Support Provider.
- Right-click, select Properties.
- Set Startup type to Manual (it should not be set to Disabled).
- Click Start, confirm the service state changes to Started.
- Click OK and re-run the MSMQ install from Windows Features.
NT AUTHORITY\NetworkService account has been removed from the local security policy. Re-add it under Local Policies → User Rights Assignment → Log on as a service or use secpol.msc to repair the default assignments.
Method 4: Windows 10 and WinCC V8 Automatic Installation
For WinCC V8 / WinCC V8.0 + SP1 / WinCC V8.1 the Message Queuing subsystem is provisioned automatically by the WinCC setup routine; the same is true for IIS when the WebOptions / WebNavigator component is selected. Manual installation of MSMQ is no longer required before the WinCC setup is started.
However, on Windows 10 builds newer than 1909 you may still encounter MSMQ installation failure on machines joined to a domain. The official guidance from Microsoft is to open a support request under Windows 10 → Windows Update or Security Update and provide the failure log. As a workaround, the machine can be removed from the domain, MSMQ installed with local administrator credentials, and the machine re-joined afterwards. The same pattern is documented in the Siemens TIA Portal help for Installing Microsoft Message Queuing (MSMQ) with WinCC WebNavigator RT Professional:
- Remove the computer from the domain.
- Log on locally as administrator.
- Install MSMQ (and SQL Server if not yet present).
- Install WinCC / WinCC WebNavigator.
- Rejoin the domain.
WinCC Version Compatibility Matrix
| WinCC Version | MSMQ Auto-Install | IIS Auto-Install | Manual MSMQ Prerequisite | Notes |
|---|---|---|---|---|
| V7.0 | No | No | Yes — manual install required | XP SP3 / Server 2003 supported, 0x42C common |
| V7.3 | No | No | Yes — manual install required | Windows 7 / Server 2008 R2 |
| V7.4 / V7.4 SP1 | No | No | Yes — manual install required | Windows 7 SP1 / Server 2012 R2 / Win 10 pre-1909 |
| V7.5 | No (partial) | No | Recommended pre-install | Windows 10 / Server 2016 / 2019 |
| V8.0 / V8.0 SP1 | Yes | Yes (when WebOptions) | No | Setup handles feature enablement |
| V8.1 / Unified | Yes | Yes (when WebOptions) | No | Modern Windows only |
Verification Procedure
After any of the four remediation methods above, perform the following sequence before relaunching the WinCC setup:
- Confirm MSMQ kernel driver loaded:
netstat -an | findstr 1801shows UDP 0.0.0.0:1801. - Confirm MSMQ service state:
sc query MSMQshows RUNNING. - Confirm MSDTC service state:
sc query msdtcshows RUNNING. - Confirm a public queue can be created:
powershell -command "[System.Messaging.MessageQueue]::Create('.\private$\wincc_test')"returns without error. - Delete the test queue:
powershell -command "[System.Messaging.MessageQueue]::Delete('.\private$\wincc_test')". - Re-launch the WinCC setup. The "MSMQ required" dialog should no longer appear.
Troubleshooting Matrix
| Symptom | Likely Cause | Remediation |
|---|---|---|
| 0x42C during Windows Features MSMQ install | MSDTC dependency broken | Apply Method 2 (msdtc reinstall + registry delete) |
| 0x42C on Windows XP SP3 | NtLmSsp disabled or removed | Apply Method 3 |
| MSMQ installs but service will not start | Corrupt MSDTC log |
msdtc -resetlog then net start msdtc
|
| 0x42C on domain-joined Windows 10 | MSMQ AD Integration feature fails on patched OS | Remove from domain, install locally, rejoin |
| MSMQ installs but WinCC setup still complains | Triggers feature not enabled | Re-open Windows Features, enable MSMQ Triggers |
| MSMQ installs, MSDTC fails to start with 5 (Access Denied) | Local security policy corrupted | Reset policy via secedit /configure /cfg %windir%\inf\defltwk.inf /db defltwk.sdb /verbose
|
| Setup log shows "0x80070643" during WinCC install | MSMQ Windows installer rollback failure | Repair .NET 3.5 / 4.x, then retry MSMQ install |
| WebNavigator cannot publish after install | IIS not installed or not configured | Add IIS role with ASP.NET and Windows Authentication |
Edge Cases and Field-Proven Caveats
-
Corrupted MSDTC registry hive: Deleting
HKLM\Software\Microsoft\MSDTCis supported on legacy platforms but on Windows 10 2004+ it is recreated on the nextmsdtc -install. Always take a registry backup first viareg export "HKLM\Software\Microsoft\MSDTC" msdtc_backup.reg. - Security-softened images: SCADA workstations delivered as golden images sometimes ship with NtLmSsp set to Disabled as part of a hardening script. Always re-check on first install.
- Domain-trust issues: The MSMQ Active Directory integration feature will fail (not always with 0x42C — sometimes with 0x80005000) if the workstation cannot reach a writable domain controller during the install. Either skip the AD integration feature or remove from the domain first.
- Windows 10 1909+ MSMQ bug: Microsoft has documented cases where MSMQ install fails on fully patched Windows 10 because the MSMQ-HTTP feature depends on KB components that are not present in newer cumulative updates. Use the official Microsoft support path referenced earlier if all four methods above fail.
-
WinCC V7.4 SP1 + Windows Server 2019: Some V7.4 SP1 builds ship setup routines that pre-check for MSMQ and exit cleanly even if the feature is missing on Server 2019, because MSMQ must be installed as a Windows feature (Add Roles and Features) rather than via Control Panel on Server SKUs. Use
Install-WindowsFeature -Name MSMQ-Server,MSMQ-Triggers,MSMQ-Multicastingin PowerShell. - Re-arm of MSDTC after group policy change: Group policy pushed via Computer Configuration → Windows Settings → Security Settings → System Services can re-disable MSDTC after remediation. Lock the workstation or apply a WMI filter to the GPO excluding the SCADA node.
Quick-Reference Command List
sc qc msdtc
sc config msdtc start= auto
net stop msdtc
msdtc -uninstall
reg delete "HKLM\Software\Microsoft\MSDTC" /f
msdtc -install
msdtc -resetlog
net start msdtc
sc query MSMQ
netstat -an | findstr 1801
Install-WindowsFeature -Name MSMQ-Server,MSMQ-Triggers,MSMQ-Multicasting :: Server SKUs only
What does WinCC error 0x42C actually mean?
Error 0x42C is Windows error 1068 ("The dependency service or group failed to start"). It is raised by the Windows MSMQ installer when the MSMQ service dependency chain — typically MSDTC, RPCSS, DCOMLaunch, or NtLmSsp — is not in a startable state. It is not generated by the WinCC installer itself.
Does WinCC V7.0 require MSMQ to be pre-installed?
Yes. WinCC V7.0, V7.3, V7.4, and V7.4 SP1 all require Microsoft Message Queuing to be present on the target Windows installation before setup is started. The setup cannot enable the feature itself on these versions; you must install MSMQ manually first.
Why does installing MSMQ fail with 0x42C on Windows 10?
The most common reason is that the Distributed Transaction Coordinator (MSDTC) service is in a broken state. Run msdtc -uninstall, delete the HKLM\Software\Microsoft\MSDTC registry key, run msdtc -install, and re-attempt the feature install. On domain-joined machines, removing the workstation from the domain, installing MSMQ locally, and rejoining is the cleanest workaround.
How do I confirm MSMQ is actually running after install?
Run sc query MSMQ to confirm the service state is RUNNING, and netstat -an | findstr 1801 to confirm the MSMQ kernel listener is bound to UDP 1801. A successful PowerShell queue creation via [System.Messaging.MessageQueue]::Create also proves the subsystem is healthy.
Is MSMQ still required for WinCC V8 and later?
Yes, MSMQ is still used internally by WinCC V8 for redundancy and event distribution, but the WinCC V8 setup installs MSMQ automatically. You no longer need to enable the Windows feature manually before launching the setup, and the same applies to IIS when WebOptions are selected.