Registering devices with Intune for management and policy enforcement
Based on the symptoms, the next step is to validate tenant-side enrollment configuration first, then check the common blockers that stop Windows enrollment for all users.
- Run the built-in Intune enrollment diagnostics as an administrator.
- In the Microsoft 365 admin center, go to Show all > Support > Help & support.
- Enter a description such as I need help enrolling Windows devices.
- For an affected user, enter the user identity and select Run tests.
- If the diagnostic finds a configuration issue, apply the recommended fix and rerun the diagnostic.
- This is the fastest next step when multiple users and devices are affected.
- Check whether users have hit the Intune device enrollment limit.
- In the Microsoft Intune admin center, go to Devices > Enrollment restrictions > Device limit restrictions and note the Device limit.
- Then go to Users > All users > select an affected user > Devices and compare the enrolled device count.
- If users are at the limit, remove unused devices or increase the limit.
- To increase the limit for all users: Devices > Enrollment restrictions > Default under Device limit restrictions > Properties > Edit next to Device limit > increase the value, then Review + Save.
- Check whether Windows enrollment is blocked by device type restrictions.
- In the Microsoft Intune admin center, go to Devices > Enrollment restrictions.
- Open the Default restriction under Device Type Restrictions.
- Select Platforms and confirm Windows (MDM) is set to Allow.
- If it already shows Allow, change it to Block, save, then change it back to Allow and save again. This resets the enrollment setting.
- Wait about 15 minutes, then retry enrollment.
- Check Microsoft Entra device join settings.
- In the Azure portal, go to Microsoft Entra ID > Devices > Device Settings.
- Confirm Users may join devices to Microsoft Entra ID is set to All.
- If it is set to None, Windows enrollment can fail for new users.
- Check for the known Windows auto-enrollment blocker if Group Policy-based auto-enrollment is being used.
- Event ID 76 with Auto MDM Enroll: Failed can occur when:
- the user UPN uses an unverified or non-routable suffix such as
.local, or - MDM user scope is set to None.
- the user UPN uses an unverified or non-routable suffix such as
- If affected users have a
.localor other unverified UPN suffix, update the UPN suffix in Active Directory Users and Computers to a valid verified suffix.
- Event ID 76 with Auto MDM Enroll: Failed can occur when:
- Collect the minimum troubleshooting data before the next retry.
- Exact error message
- Where the error appears
- Whether enrollment ever worked before
- Whether all users and all devices are affected
- Enrollment method being used
- MDM authority
- Also verify the device clock.
- Restart the device.
- Make sure date and time are correct and within about ±12 hours of GMT for the user’s time zone.
- If Company Portal is being used, uninstall and reinstall it before retrying.
If the issue began suddenly across multiple users about two weeks ago, the highest-value checks are:
- Intune enrollment diagnostics
- Windows (MDM) device type restriction
- Users may join devices to Microsoft Entra ID
- device cap
- MDM user scope and user UPN suffix validity
References: