Several devices not able to enroll into Intune.

Joseph Martinez 0 Reputation points
2026-08-05T16:56:27.4366667+00:00

We have several devices that are able to enroll into Intune. No user is able to enroll. Not an admin. Not a DEM. No one. I have dsregcmd /leave multiple times and same result.

What I have been able to determine is that the Enterprise Management scheduled tasks and services are not found on the devices. This started a little over two weeks ago. We were able to get one device enrolled, but thru much nashing of teeth and timeing (hours of un/re-enrolling). Two other devices in this same timeline were pushed into Intune via MDE. One was device enrolled instead of user enrolled.

What would be the next step in resolving this? BTW, all the steps in the AI answer have already been done.

20260805_111114-DSRegTool.txt

20260805_110910-Test-DeviceRegConnectivity.txt

dsregcmd-20260801-194609.txt

Screenshot 2026-08-04 172203.png

Screenshot 2026-08-04 140734.png

Microsoft Security | Intune | Enrollment

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-05T16:56:52.2433333+00:00

    Based on the symptoms, the next step is to validate tenant-side enrollment configuration first, then check the common blockers that stop Windows enrollment for all users.

    1. Run the built-in Intune enrollment diagnostics as an administrator.
      • In the Microsoft 365 admin center, go to Show all > Support > Help & support.
      • Enter a description such as I need help enrolling Windows devices.
      • For an affected user, enter the user identity and select Run tests.
      • If the diagnostic finds a configuration issue, apply the recommended fix and rerun the diagnostic.
      • This is the fastest next step when multiple users and devices are affected.
    2. Check whether users have hit the Intune device enrollment limit.
      • In the Microsoft Intune admin center, go to Devices > Enrollment restrictions > Device limit restrictions and note the Device limit.
      • Then go to Users > All users > select an affected user > Devices and compare the enrolled device count.
      • If users are at the limit, remove unused devices or increase the limit.
      • To increase the limit for all users: Devices > Enrollment restrictions > Default under Device limit restrictions > Properties > Edit next to Device limit > increase the value, then Review + Save.
    3. Check whether Windows enrollment is blocked by device type restrictions.
      • In the Microsoft Intune admin center, go to Devices > Enrollment restrictions.
      • Open the Default restriction under Device Type Restrictions.
      • Select Platforms and confirm Windows (MDM) is set to Allow.
      • If it already shows Allow, change it to Block, save, then change it back to Allow and save again. This resets the enrollment setting.
      • Wait about 15 minutes, then retry enrollment.
    4. Check Microsoft Entra device join settings.
      • In the Azure portal, go to Microsoft Entra ID > Devices > Device Settings.
      • Confirm Users may join devices to Microsoft Entra ID is set to All.
      • If it is set to None, Windows enrollment can fail for new users.
    5. Check for the known Windows auto-enrollment blocker if Group Policy-based auto-enrollment is being used.
      • Event ID 76 with Auto MDM Enroll: Failed can occur when:
        • the user UPN uses an unverified or non-routable suffix such as .local, or
        • MDM user scope is set to None.
      • If affected users have a .local or other unverified UPN suffix, update the UPN suffix in Active Directory Users and Computers to a valid verified suffix.
    6. Collect the minimum troubleshooting data before the next retry.
      • Exact error message
      • Where the error appears
      • Whether enrollment ever worked before
      • Whether all users and all devices are affected
      • Enrollment method being used
      • MDM authority
    7. Also verify the device clock.
      • Restart the device.
      • Make sure date and time are correct and within about ±12 hours of GMT for the user’s time zone.
      • If Company Portal is being used, uninstall and reinstall it before retrying.

    If the issue began suddenly across multiple users about two weeks ago, the highest-value checks are:

    • Intune enrollment diagnostics
    • Windows (MDM) device type restriction
    • Users may join devices to Microsoft Entra ID
    • device cap
    • MDM user scope and user UPN suffix validity

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.