Troubleshooting Windows device enrollment problems in Microsoft Intune
What does this guide do?
Helps administrators understand and troubleshoot problems when enrolling Windows devices in Intune.
Who is it for?
Administrators who implement and oversee a Microsoft Intune environment.
How does it work?
This guide provides suggestions for troubleshooting and resolving some of the most common problems when you enroll Windows desktop and mobile devices in Intune.
Estimated time of completion:
10-20 minutes.
Collecting Initial Data
Before you start troubleshooting, it’s important to collect some basic information. This information can help you better understand the problem and reduce the time to find a resolution.
For example, any time that you encounter a Windows device enrollment problem, check the following first:
- Is a valid Intune license assigned to the user?
Before users can enroll their devices, they must have the necessary license assigned. - Is the latest update installed on the Windows device?
Some features in Intune only work with the latest version of Windows, and there are many fixes for known issues available through Windows Update. Applying all the latest updates often fix a Windows device enrollment problem.
Additionally, collect the following information about the problem:
- What is the exact error message?
- Where do you receive the error message?
- When did the problem start? Has enrollment ever worked?
- How many users are affected? Are all users affected or just some?
- How many devices are affected? Are all devices affected or just some?
- What is the MDM authority? If it's System Center Configuration Manager, what version of Configuration Manager are you using?
- How is enrollment being performed?
Now let's start troubleshooting based on the answers to these questions.
Select your problem:
Collecting Initial Data
Before you start troubleshooting, it’s important to collect some basic information. This information can help you better understand the problem and reduce the time to find a resolution.
For example, any time that you encounter a Windows device enrollment problem, check the following first:
- Is a valid Intune license assigned to the user?
Before users can enroll their devices, they must have the necessary license assigned. - Is the latest update installed on the Windows device?
Some features in Intune only work with the latest version of Windows, and there are many fixes for known issues available through Windows Update. Applying all the latest updates often fix a Windows device enrollment problem.
Additionally, collect the following information about the problem:
- What is the exact error message?
- Where do you receive the error message?
- When did the problem start? Has enrollment ever worked?
- How many users are affected? Are all users affected or just some?
- How many devices are affected? Are all devices affected or just some?
- What is the MDM authority? If it's System Center Configuration Manager, what version of Configuration Manager are you using?
- How is enrollment being performed?
Now let's start troubleshooting based on the answers to these questions.
Select your problem:
Error 0x801c0003 "This user is not authorized to enroll."
Symptom
When you try to enroll a Windows 10 computer, you receive the following error message:
This user is not authorized to enroll. You can try to do this again or contact your system administrator with the error code (0x801c0003).
Cause
This issue occurs if the user has already enrolled maximum number of devices allowed in Intune.
Resolution
To fix this issue, use one of the following methods:
- Method 1: Remove devices that were enrolled
To do this, follow these steps:- Sign in to the Azure Intune portal.
- Go to Users > All Users.
- Select the affected user account, and then click Devices.
- Select any unused or unwanted devices, and then click Delete.
- Method 2: Increase the device enrollment limit
Note This method increases the device enrollment limit for all users, not just the affected user.
To do this, follow these steps:- Sign in to the Azure Intune portal.
- Go to Device Enrollment > Enrollment Restrictions, and then select Device Limit Restrictions.
- Increase the value of Device Limit.
- Method 3: Configure a Device Enrollment Manager (DEM) account
To do this, follow Enroll devices using device enrollment manager.
Error 0x801c0003 "This user is not authorized to enroll."
Symptom
When you try to join a Windows 10 computer to Azure Active Directory, you receive the following error message:
This user is not authorized to enroll. You can try to do this again or contact your system administrator with the error code (0x801c0003).
Cause
This issue occurs if the user has already enrolled maximum number of devices allowed in Azure.
Resolution
To fix this issue, use one of the following methods:
- Method 1: Remove devices that were joined
To do this, follow these steps:
-
Sign in to the Azure portal.
-
Go to Azure Active Directory > Devices > All Devices.
-
Select any unused or unwanted devices of the affected user, and then click Delete.
-
- Method 2: Increase the maximum number of devices that a user can join
Note This method increases the device enrollment limit for all users, not just the affected user.
To do this, follow these steps:
-
Sign in to the Azure portal.
-
Go to Azure Active Directory > Devices > Device Settings.
-
Increase the value of Maximum number of devices per user.
-
Error 0x801c0003 "This user is not authorized to enroll."
Symptom
When you try to enroll a Windows 10 computer, you receive the following error message:
This user is not authorized to enroll. You can try to do this again or contact your system administrator with the error code (0x801c0003).
Cause
This issue occurs if the computer is running Windows 10 Home. Enrolling in Intune or joining Azure AD is only supported on Windows 10 Pro and higher editions.
Resolution
To fix this issue, upgrade Windows 10 Home to Windows 10 Pro or a higher edition.
Error 0x801c0003 "This user is not allowed to enroll."
Symptom
When you try to enroll a Windows 10 computer, you receive the following error message:
This user is not allowed to enroll. You can try again or contact your system administrator with the error code 801c0003.
Cause
This issue occurs if the Users may join devices to Azure AD setting is set to None. This prevents new users from joining their devices to Azure AD. Therefore Intune enrollment fails.
Resolution
To fix this issue, follow these steps:
- Sign in to the Azure portal as administrator.
- Go to Azure Active Directory > Devices > Device Settings.
- Set Users may join devices to Azure AD to All.
- Enroll the device again.
Error 8018000a "The device is already enrolled."
Symptom
When you try to enroll a Windows 10 computer, you receive the following error message:
Something went wrong.
The device is already enrolled. You can contact your system administrator with the error code 8018000a.
Cause
This issue occurs if a different user has already enrolled the device in Intune or joined the device to Azure AD.
To determine whether this is the case, go to Settings > Accounts > Work Access, then look for a message that's similar to the following:
Another user on the system is already connected to a work or school. Please remove that work or school connection and try again.
Resolution
To fix this issue, follow these steps:
- Sign out of Windows, then sign in by using the other account that has enrolled or joined the device.
- Go to Settings > Accounts > Work Access, then remove the work or school account.
- Sign out of Windows, then sign in by using your account.
- Enroll the device in Intune or join the device to Azure AD.
Error 8018000a "The device is already enrolled."
Symptom
When you try to enroll a Windows 10 computer, you receive the following error message:
Something went wrong.
The device is already enrolled. You can contact your system administrator with the error code 8018000a.
Cause
This issue occurs if the Configuration Manager client agent is installed on the computer.
Resolution
To fix this issue, remove the Configuration Manager client, and then enroll the device again.
Error "This account is not allowed on this phone."
Symptom
When you try to enroll a Windows Phone, you receive the following error message:
This account is not allowed on this phone. Make sure the information you provided is correct, and then try again or request support from your company.
Cause
This issue occurs if the user who tries to enroll the device doesn't have a valid Intune license.
Resolution
To fix this issue, assign a valid Intune license to the user, and then enroll the device.
Error "Looks like the MDM Terms of Use endpoint is not correctly configured"
Symptom
When you try to enroll a Windows 10 computer in Intune or join it to Azure AD, you receive the following error message:
Looks like the MDM Terms of Use endpoint is not correctly configured
Cause
This issue occurs if you use both Mobile Device Management (MDM) for Office 365 and Intune on the tenant, and the user who tries to enroll the device doesn't have a valid Intune license or an Office 365 license.
Resolution
To fix this issue, go to the Office 365 Admin Center, and then assign either an Intune or an Office 365 license to the user.
Error "Looks like the MDM Terms of Use endpoint is not correctly configured"
Cause
This issue occurs if the MDM terms and conditions in Azure AD is blank or doesn't contain the correct URL.
Resolution
To fix this issue, follow these steps:
- Sign in to the Azure portal, and then select Azure Active Directory.
- Select Mobility (MDM and MAM), and then click Microsoft Intune.
- Select Restore default MDM URLs, verify that the MDM terms of use URL is set to https://portal.manage.microsoft.com/TermsofUse.aspx.
- Click Save.
Error 80180026 when you join a device to Azure AD
Symptom
When you try to join a Windows 10 computer to Azure AD, you receive the following error message:
Something went wrong.
Confirm you are using the correct sign-in information and that your organization uses this feature. You can try to do this again or contact your system administrator with the error code 80180026.
Cause
This issue occurs when both of the following conditions are true:
- MDM automatic enrollment is enabled in Azure.
- Either the Intune PC client (Intune PC agent) or the Configuration Manager client agent is installed on the Windows 10 computer.
Resolution
To fix this issue, use one of the following methods:
- Disable MDM automatic enrollment in Azure.
To do this, follow these steps:- Sign in to the Azure portal.
- Go to Azure Active Directory > Mobility (MDM and MAM) > Microsoft Intune.
- Set MDM User scope to None, and then click Save.
- Uninstall the Intune PC client or Configuration Manager client agent from the computer.
Error "The software cannot be installed, 0x80cf4017."
Symptom
When you try to install the Intune client software on Windows PCs, you receive the following error message:
The software cannot be installed, 0x80cf4017.
Cause
This issue occurs if the client software is out of date.
Resolution
To fix this issue, follow these steps:
- Sign in to https://admin.manage.microsoft.com.
- Go to Admin > Client Software Download, and then click Download Client Software.
- Save the installation package, and then install the client software.
Error "The account certificate is not valid and may be expired, 0x80cf4017. "
Symptom
When you try to enroll a Windows computer by installing the Intune PC client software, you receive the following error message:
The account certificate is not valid and may be expired, 0x80cf4017.
Cause
This issue occurs if the client software is out of date.
Resolution
To fix this issue, follow these steps:
- Sign in to https://admin.manage.microsoft.com.
- Go to Admin > Client Software Download, and then click Download Client Software.
- Save the installation package, and then install the client software.
Error 0x80180014 "Your organization does not support this version of Windows."
Symptom
When you try to enroll a Windows 10 device, you receive the following error message:
There was a problem. Your organization does not support this version of Windows. (0x80180014)
Cause
This issue occurs if Windows MDM enrollment is disabled in your Intune tenant.
Resolution
To fix this issue in a stand-alone Intune environment, follow these steps:
- Sign in to the Azure portal as administrator.
- Select Intune on the left, and then go to Device enrollment > Enrollment restrictions.
- In Device Type Restrictions, click Platforms, and then select Allow for Windows (MDM).
- Click Save.
To fix this issue in hybrid MDM with Intune and Configuration Manager, follow these steps:
- Open the Configuration Manager console.
- Select Administration, and then select Cloud Services.
- Right-click Microsoft Intune Subscription, and then select Configure Platforms > Windows.
- Check Enable Windows Enrollment, click Apply, and then click OK.
Error "A setup failure has occurred" during bulk enrollment
Symptom
When you bulk enroll Windows devices by following Bulk enrollment for Windows devices, you receive the following error message during the Enrolls the device in management step:
A setup failure has occurred
Cause
This issue occurs if the Azure AD user accounts in the account package (Package_GUID) for the respective provisioning package aren't allowed to join devices to Azure AD. These Azure AD accounts are automatically created when you set up a provisioning package with Windows Configuration Designer (WCD) or the Set up School PCs app, and these accounts are then used to join the devices to Azure AD.
Resolution
To fix this issue, follow these steps:
- Sign in to the Azure portal as administrator.
- Go to Azure Active Directory > Devices > Device Settings.
- Set Users may join devices to Azure AD to All or Selected.
If you choose Selected, click Selected, and then click Add Members to add all users who can join their devices to Azure AD. Make sure that all Azure AD accounts for the provisioning package are added.
For more information about how to create a provisioning package for Windows Configuration Designer, see Create a provisioning package for Windows 10.
For more information about the Set up School PCs app, see Use the Set up School PCs app.
Congratulations
Congratulations! Your Intune enrollment problem is fixed.
If you’re still looking for a solution to another Windows enrollment problem, or you’re looking for more information about Intune, post a question in our Microsoft Intune forum here. Many support engineers, MVPs and members of our development team frequent the forums. So, there’s a good chance that you can find someone with the information you need.
For more information about the enrollment of Windows devices in Microsoft Intune, see the following:
- Enroll Windows devices – This article contains information for all aspects of Windows enrollment, including how to enable automatic MDM enrollment, CNAME registration, bulk enrollment of devices, and more.
- Enroll your Windows 10 devices in Intune – This article describes the end-user steps and experience for enrolling a Windows computer in Microsoft Intune.
For all the latest news, information and tech tips, visit our official Intune blogs:
Additional Information
Still searching for a solution to a Windows enrollment problem? Post a question in our Microsoft Intune forum here. Many of our support engineers, MVPs and members of our development team frequent the forums, so there’s a good chance you’ll find someone there with the information you’re after.
If all else fails and you want to open a support request with the Microsoft Intune product support team, you can find information on how to do that here:
How to get support for Microsoft Intune
If you’d like more information regarding the enrollment of Windows devices in Microsoft Intune, please see the following documentation:
- Enroll Windows devices – This article contains information for all aspects of Windows enrollment, including how to enable automatic MDM enrollment, CNAME registration, bulk enrollment of devices, and more.
- Enroll your Windows 10 devices in Intune – This article describes the end user steps and experience for enrolling a Windows computer in Microsoft Intune.
For all the latest news, information and tech tips on Microsoft Intune as well as all of our other Enterprise Mobility and Security offerings, please visit our Microsoft Enterprise Mobility and Security Blog.