T The Triage ManualTechnical Guides for IT Emergencies
P3 · Microsoft 365 & Collaboration

Intune compliance / enrolment failure

Devices fail to enrol, drop out of compliance, or refuse company resource access. Intune diagnostics span Windows, Autopilot, OEM and Entra.

Indicators

Likely causes

Diagnostic steps

  1. On device: dsregcmd /status — confirm Entra-joined, Domain-joined, Workplace-joined states and tenant ID
  2. Event Viewer: Applications and Services Logs → Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider
  3. Intune portal: Devices → check enrolment status / failure reason for the specific device
  4. For Autopilot: review device hash registration and assigned profile
  5. For compliance: review the specific failing setting in the compliance policy + device's reported value
  6. Confirm user has Intune licence (P1/P2 or M365 BP/E3 with Intune)

Resolution path

Prevention

Tools

References

intuneautopilotcompliancemdmmicrosoft-365