Resolving WinCC MSMQ Installation Error 0x42C on Windows

David Krause10 min read
SCADA ConfigurationSiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Statement: WinCC Setup Halts on Missing MSMQ Component

During installation of Siemens WinCC V7.x (including V7.0, V7.3, V7.4, and V7.4 SP1) the setup routine detects that Microsoft Message Queuing (MSMQ) is not present on the target operating system and aborts with a blocking dialog. On Windows XP SP3, Windows 7, Windows Server 2008 R2, and some Windows 10 builds, an attempt to add MSMQ through Control Panel → Add or Remove Programs → Windows Components fails with the Microsoft error code 0x42C and the descriptive text "The dependency service or group failed to start." Until the MSMQ subsystem is operational, WinCC Setup cannot continue because MSMQ is a hard prerequisite for internal WinCC component communication, redundancy synchronization, and OPC channel services.

From WinCC V8 onward the setup installs MSMQ (and IIS when WebOptions are selected) automatically. The information below is therefore most relevant to WinCC V7.0 / V7.3 / V7.4 / V7.4 SP1 running on legacy Windows platforms, although the manual remediation steps also apply to clean Windows 10 / 11 installations where the MSMQ feature is corrupted.

Field caveat: Error 0x42C is a Windows-level error originating inside the MSMQ installer service, not a WinCC installer error. The WinCC setup only surfaces it because it cannot proceed without MSMQ. Diagnose the Windows platform first; do not retry the WinCC installer until MSMQ is installed and started cleanly.

Error 0x42C Technical Details

Error code 0x42C equals decimal 1068 in Windows. The canonical Windows error text is:

  • Win32 error 1068 (0x42C): The dependency service or group failed to start.
  • Source: Distributed Transaction Coordinator (MSDTC) or RPCSS-related dependency chain.
  • Visible in: setupapi.dev.log, msmqinst.log (located in %WINDIR%\inf and %WINDIR%\security\logs).

The MSMQ service (MQAC, MSMQ, MSMQTriggers, MSMQManagement) depends on a chain that includes the Distributed Transaction Coordinator (MSDTC), RPCSS, NT LM Security Support Provider, and the Server / Workstation services. If any link in the chain is disabled, set to Manual with no start trigger, or configured to run under an account without Log on as a service rights, MSMQ installation rolls back with 0x42C.

Root Cause Analysis

The most common cause observed on field installations is that the MSDTC service is configured to run under the LocalSystem account but its account context has been corrupted, removed from the local security policy, or its registry hive is damaged. A second common cause is that the NT LM Security Support Provider (NtLmSsp) is disabled, which breaks the MSMQ installer when it tries to enumerate the local machine account.

Verify the MSDTC account with the command:

sc qc msdtc

Confirm the output line START_TYPE is DEMAND_START or AUTO_START and the binary path includes %SystemRoot%\system32\msdtc.exe. If START_TYPE shows DISABLED, change it with:

sc config msdtc start= auto
sc sdset msdtc D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)

Pre-Installation Prerequisites

Before attempting any MSMQ install path, ensure the following Windows components are present and started:

  1. RPCSS (RpcSs) — automatic, running.
  2. DCOM Server Process Launcher (DcomLaunch) — automatic, running.
  3. Distributed Transaction Coordinator (MSDTC) — automatic, running.
  4. NT LM Security Support Provider (NtLmSsp) — manual, enabled.
  5. TCP/IP NetBIOS Helper — manual or automatic.

Confirm state on a single screen:

sc query RpcSs | findstr STATE
sc query DcomLaunch | findstr STATE
sc query msdtc | findstr STATE
sc query NtLmSsp | findstr STATE

Method 1: Enable MSMQ via Windows Features (Recommended First Path)

This is the procedure documented in the official Siemens support article for How to Install MS Message Queuing — WinCC V7.4 SP1:

  1. Open the Start Menu and navigate to Control Panel → Programs and Features.
  2. Select Turn Windows features on or off on the left menu.
  3. Locate the Microsoft Message Queue (MSMQ) Server node and expand it.
  4. Enable all four sub-features:
    • MSMQ HTTP Support
    • MSMQ Triggers (optional but recommended for WinCC redundancy)
    • MSMQ Active Directory Domain Services Integration (only if the machine is domain-joined and you need AD-integrated queues)
    • Multicasting Support (required for some WinCC event notifications)
  5. Click OK and allow Windows to apply the feature.
  6. Reboot if prompted.
  7. Verify the MSMQ service is registered and started.

Quick verification commands after the feature is enabled:

sc query MSMQ | findstr STATE
sc query MQCS | findstr STATE
netstat -an | findstr 1801

A listener on UDP port 1801 confirms the MSMQ kernel driver is loaded.

Method 2: Repair the MSDTC Service (0x42C Workaround)

When Method 1 returns error 0x42C, the MSDTC service hive is the prime suspect. Run the following from an elevated command prompt in the order shown:

net stop msdtc
msdtc -uninstall
reg delete "HKLM\Software\Microsoft\MSDTC" /f
msdtc -install
net start msdtc

Re-attempt the MSMQ feature installation after the service starts cleanly. If the service still refuses to start, dump its current security descriptor and reset it using sc sdset as shown earlier. Confirm with:

sc qc msdtc
msdtc -resetlog

The msdtc -resetlog step regenerates the transaction log under %WINDIR%\System32\Msdtc and often resolves the 0x42C trigger when the original log is corrupt.

Method 3: Enable NT LM Security Support Provider

On Windows XP SP3 and many Windows 7 installations, MSMQ setup fails silently if NtLmSsp is disabled. This is a frequently-missed root cause because the MSMQ installer does not always name the dependency that actually failed.

  1. Press Start, click Run.
  2. Type services.msc and press Enter.
  3. Scroll to NT LM Security Support Provider.
  4. Right-click, select Properties.
  5. Set Startup type to Manual (it should not be set to Disabled).
  6. Click Start, confirm the service state changes to Started.
  7. Click OK and re-run the MSMQ install from Windows Features.
Tip: If the service start returns Access Denied, the NT AUTHORITY\NetworkService account has been removed from the local security policy. Re-add it under Local Policies → User Rights Assignment → Log on as a service or use
secpol.msc to repair the default assignments.

Method 4: Windows 10 and WinCC V8 Automatic Installation

For WinCC V8 / WinCC V8.0 + SP1 / WinCC V8.1 the Message Queuing subsystem is provisioned automatically by the WinCC setup routine; the same is true for IIS when the WebOptions / WebNavigator component is selected. Manual installation of MSMQ is no longer required before the WinCC setup is started.

However, on Windows 10 builds newer than 1909 you may still encounter MSMQ installation failure on machines joined to a domain. The official guidance from Microsoft is to open a support request under Windows 10 → Windows Update or Security Update and provide the failure log. As a workaround, the machine can be removed from the domain, MSMQ installed with local administrator credentials, and the machine re-joined afterwards. The same pattern is documented in the Siemens TIA Portal help for Installing Microsoft Message Queuing (MSMQ) with WinCC WebNavigator RT Professional:

  1. Remove the computer from the domain.
  2. Log on locally as administrator.
  3. Install MSMQ (and SQL Server if not yet present).
  4. Install WinCC / WinCC WebNavigator.
  5. Rejoin the domain.

WinCC Version Compatibility Matrix

WinCC Version MSMQ Auto-Install IIS Auto-Install Manual MSMQ Prerequisite Notes
V7.0 No No Yes — manual install required XP SP3 / Server 2003 supported, 0x42C common
V7.3 No No Yes — manual install required Windows 7 / Server 2008 R2
V7.4 / V7.4 SP1 No No Yes — manual install required Windows 7 SP1 / Server 2012 R2 / Win 10 pre-1909
V7.5 No (partial) No Recommended pre-install Windows 10 / Server 2016 / 2019
V8.0 / V8.0 SP1 Yes Yes (when WebOptions) No Setup handles feature enablement
V8.1 / Unified Yes Yes (when WebOptions) No Modern Windows only

Verification Procedure

After any of the four remediation methods above, perform the following sequence before relaunching the WinCC setup:

  1. Confirm MSMQ kernel driver loaded: netstat -an | findstr 1801 shows UDP 0.0.0.0:1801.
  2. Confirm MSMQ service state: sc query MSMQ shows RUNNING.
  3. Confirm MSDTC service state: sc query msdtc shows RUNNING.
  4. Confirm a public queue can be created: powershell -command "[System.Messaging.MessageQueue]::Create('.\private$\wincc_test')" returns without error.
  5. Delete the test queue: powershell -command "[System.Messaging.MessageQueue]::Delete('.\private$\wincc_test')".
  6. Re-launch the WinCC setup. The "MSMQ required" dialog should no longer appear.

Troubleshooting Matrix

Symptom Likely Cause Remediation
0x42C during Windows Features MSMQ install MSDTC dependency broken Apply Method 2 (msdtc reinstall + registry delete)
0x42C on Windows XP SP3 NtLmSsp disabled or removed Apply Method 3
MSMQ installs but service will not start Corrupt MSDTC log msdtc -resetlog then net start msdtc
0x42C on domain-joined Windows 10 MSMQ AD Integration feature fails on patched OS Remove from domain, install locally, rejoin
MSMQ installs but WinCC setup still complains Triggers feature not enabled Re-open Windows Features, enable MSMQ Triggers
MSMQ installs, MSDTC fails to start with 5 (Access Denied) Local security policy corrupted Reset policy via secedit /configure /cfg %windir%\inf\defltwk.inf /db defltwk.sdb /verbose
Setup log shows "0x80070643" during WinCC install MSMQ Windows installer rollback failure Repair .NET 3.5 / 4.x, then retry MSMQ install
WebNavigator cannot publish after install IIS not installed or not configured Add IIS role with ASP.NET and Windows Authentication

Edge Cases and Field-Proven Caveats

  • Corrupted MSDTC registry hive: Deleting HKLM\Software\Microsoft\MSDTC is supported on legacy platforms but on Windows 10 2004+ it is recreated on the next msdtc -install. Always take a registry backup first via reg export "HKLM\Software\Microsoft\MSDTC" msdtc_backup.reg.
  • Security-softened images: SCADA workstations delivered as golden images sometimes ship with NtLmSsp set to Disabled as part of a hardening script. Always re-check on first install.
  • Domain-trust issues: The MSMQ Active Directory integration feature will fail (not always with 0x42C — sometimes with 0x80005000) if the workstation cannot reach a writable domain controller during the install. Either skip the AD integration feature or remove from the domain first.
  • Windows 10 1909+ MSMQ bug: Microsoft has documented cases where MSMQ install fails on fully patched Windows 10 because the MSMQ-HTTP feature depends on KB components that are not present in newer cumulative updates. Use the official Microsoft support path referenced earlier if all four methods above fail.
  • WinCC V7.4 SP1 + Windows Server 2019: Some V7.4 SP1 builds ship setup routines that pre-check for MSMQ and exit cleanly even if the feature is missing on Server 2019, because MSMQ must be installed as a Windows feature (Add Roles and Features) rather than via Control Panel on Server SKUs. Use Install-WindowsFeature -Name MSMQ-Server,MSMQ-Triggers,MSMQ-Multicasting in PowerShell.
  • Re-arm of MSDTC after group policy change: Group policy pushed via Computer Configuration → Windows Settings → Security Settings → System Services can re-disable MSDTC after remediation. Lock the workstation or apply a WMI filter to the GPO excluding the SCADA node.

Quick-Reference Command List

sc qc msdtc
sc config msdtc start= auto
net stop msdtc
msdtc -uninstall
reg delete "HKLM\Software\Microsoft\MSDTC" /f
msdtc -install
msdtc -resetlog
net start msdtc
sc query MSMQ
netstat -an | findstr 1801
Install-WindowsFeature -Name MSMQ-Server,MSMQ-Triggers,MSMQ-Multicasting  :: Server SKUs only

What does WinCC error 0x42C actually mean?

Error 0x42C is Windows error 1068 ("The dependency service or group failed to start"). It is raised by the Windows MSMQ installer when the MSMQ service dependency chain — typically MSDTC, RPCSS, DCOMLaunch, or NtLmSsp — is not in a startable state. It is not generated by the WinCC installer itself.

Does WinCC V7.0 require MSMQ to be pre-installed?

Yes. WinCC V7.0, V7.3, V7.4, and V7.4 SP1 all require Microsoft Message Queuing to be present on the target Windows installation before setup is started. The setup cannot enable the feature itself on these versions; you must install MSMQ manually first.

Why does installing MSMQ fail with 0x42C on Windows 10?

The most common reason is that the Distributed Transaction Coordinator (MSDTC) service is in a broken state. Run msdtc -uninstall, delete the HKLM\Software\Microsoft\MSDTC registry key, run msdtc -install, and re-attempt the feature install. On domain-joined machines, removing the workstation from the domain, installing MSMQ locally, and rejoining is the cleanest workaround.

How do I confirm MSMQ is actually running after install?

Run sc query MSMQ to confirm the service state is RUNNING, and netstat -an | findstr 1801 to confirm the MSMQ kernel listener is bound to UDP 1801. A successful PowerShell queue creation via [System.Messaging.MessageQueue]::Create also proves the subsystem is healthy.

Is MSMQ still required for WinCC V8 and later?

Yes, MSMQ is still used internally by WinCC V8 for redundancy and event distribution, but the WinCC V8 setup installs MSMQ automatically. You no longer need to enable the Windows feature manually before launching the setup, and the same applies to IIS when WebOptions are selected.

Back to blog