Enrollment Status Page timing out during Autopilot: a step-by-step troubleshooting guide
Find the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.
Troubleshooting guides, how-tos, deep dives and certification study plans for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online.
Showing all 117 articles
Find the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.
0x87D1041C means the installer finished but the detection rule found nothing. The usual causes (bitness, install context, version drift) and how to test detection on the device.
A reused Autopilot device fails MDM enrollment with 0x80180014. Why it happens, and the documented fixes: unblock or remove the stale Intune record and check enrollment restrictions.
What each Intune Management Extension log records, how to read them with CMTrace, what to search for, how to force a check-in, and how to collect the logs remotely.
Why devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.
Silent BitLocker not starting? Check TPM, UEFI, Secure Boot and WinRE, the required policy settings, startup authentication conflicts and recovery key backup to Microsoft Entra ID.
Set up Windows LAPS end to end: enable it in Microsoft Entra ID, build the Intune account protection profile, retrieve and rotate passwords, and check the LAPS event log.
Set up Intune Remediations end to end: licensing and tenant attestation, the exit-code contract, run context, schedules, on-demand runs and reading the results.
Settings stuck on Conflict in Intune? Find the competing policies, confirm what the device received with the MDM diagnostic report and event log, and rule out Group Policy.
Feature update policy assigned but nothing offered? Check licensing, join type, telemetry, update ring deferrals, WSUS and Group Policy, hardware readiness and safeguard holds.
Outlook on iOS or Android ignoring your Intune app protection policy? Check targeting, licensing, the signed-in account, broker apps, check-in timing, reports and Edge diagnostics.
Why Apple ADE devices don't appear in Intune or enroll without the right policy: device assignment, token sync limits and renewal, default policies, and why a reset is needed.
A practical checklist for failed Android personally owned work profile enrollments: Managed Google Play, restrictions, licences, device requirements, existing profiles and logs.
A staged way to switch co-management workloads to Intune: what each slider really controls, pilot collections, the client logs to watch, rollback caveats and a sensible order.
Export your Intune device inventory to CSV with the Microsoft Graph PowerShell SDK, spot stale and noncompliant devices, and run it unattended with certificate-based app-only sign-in.
How Intune device cleanup rules work per platform, what they hide and what they leave behind, and how to pair them with a safe Entra ID stale-device routine that spares Autopilot.
Windows MDM enrollment fails with 0x80180018 or a nearby 0x8018 code. What Microsoft documents for each code, which tenant setting is behind it, and how to confirm the fix in the enrollment event log.
A Windows device shows a stale last check-in in Intune and policies stop arriving. How check-in works, what to inspect on the device (service, tasks, certificate, network) and when to re-enroll.
An Intune platform script reports Failed or never runs. How the Intune Management Extension executes scripts, what the three script settings change, how retries and re-runs work, and where to look.
Apple Business Manager apps assigned in Intune stay pending or fail on iPhones and iPads. How location (VPP) tokens and licences work, what the 0x87D13B error codes mean, and what to check in order.
How to wrap an installer with the Win32 Content Prep Tool, choose silent install and uninstall commands, set install behaviour, return codes, requirement and detection rules, and pilot the app.
Set up Windows Autopilot end to end: tenant prerequisites, collecting and importing hardware hashes, group tags and dynamic groups, a user-driven Entra join profile, an Enrollment Status Page and the first test device.
Prerequisites, the update ring settings and their ranges, a pilot/broad ring design, expedite and driver update policies, the Intune and Windows Update for Business reports, and how to check a device locally.
What each Intune policy type is for, how conflicts between them are resolved and reported, a recommended layering for a new tenant, and naming and assignment hygiene with filters.
A five-stage plan for Exam MD-102 and the Endpoint Administrator Associate certification: the current skills-measured domains, the Microsoft Learn paths to follow, lab exercises and exam-day tips.
Why a Windows device fails "Require the device to be at or under the machine risk score", and how to check the connector, onboarding, device identity and active alerts in the right order.
Some Windows 11 24H2 devices ship without the Sense client, so Intune's EDR policy errors and the device never reaches Defender. How to detect it at scale with Remediations and add the capability.
Intune will evaluate BitLocker, Secure Boot and code integrity compliance through Microsoft Azure Attestation. Which endpoints to allow, how to test from a device, and how to find affected policies.
After the September 2026 Windows 11 updates some domain-joined devices lose their secure channel because Machine Identity Isolation is now honoured. How to find the policy, roll it back and verify.
Microsoft Entra hybrid join Autopilot deployments can time out with 0x80004005 on older Windows 11 builds. How to confirm the known issue, which KBs fix it and how to get devices onto a fixed build.
Autopilot pre-provisioning for hybrid join fails in the technician flow when a policy such as a User Rights setting needs a domain controller. How to read the 0x800706FD event and fix the scoping.
Configuring the Intune Connector for AD with your own gMSA can fail on the SeLogonAsServicePrivilege pre-check. The June 2026 known issue, the SkipByoMsaPrivilegeCheck fix and how to verify it.
A walkthrough of the Windows Autopilot known issues page as of October 2026: open and fixed items, deeper guidance on the January 2026 entries, and how to subscribe so new issues reach you first.
What trips admins up in Autopilot device preparation, the known issues and their status as of October 2026, how to read the deployment status report, and the documented steps for a failed deployment.
Which 2011 Secure Boot certificates expire and when, the Settings catalog Secure Boot settings, model-based filters for a staged rollout, and the Intune report and remediation that track progress.
Read UEFICA2023Status, the AvailableUpdates bitmask and TPM-WMI events 1795 to 1808 to see where a Secure Boot certificate update is stuck, interpret the Intune report, and clear the common blockers.
How 26H2 installs as an enablement package, the Intune feature update policy and rollout options to deploy it, the known issues listed at launch, how safeguard holds show up, and how to verify a device.
Five items Microsoft currently lists as Active on the Intune known issues page, what each looks like, what to tell users, how to work around it, and how to track the page and escalate properly.
Why some Macs dropped out of Intune during MDM identity certificate renewal, Apple's fix in macOS 26.4, how to find and re-enroll affected devices, and how this differs from an expired Apple MDM push certificate.
A 10-minute checklist to rule out a service incident, a documented known issue or a gradual service release before you troubleshoot your tenant, plus what to collect for a support case and how to subscribe.
Intune's new Deployments experience (preview): staging Win32 and Enterprise App Catalog apps, settings catalog and endpoint security policies across rings, permissions, how rings advance, and a ring design.
What device association writes to UEFI, the Windows 11 and TPM 2.0 requirements, exporting the DeviceLink CSV and pre-associating in Intune, lifecycle and removal, and how it coexists with classic Autopilot.
Autopatch groups and quality update policies, the per-update-type automatic or manual approvals, deferrals and pausing rolling out in autumn 2026, quick machine recovery approvals, the reports, and migration tips.
Add a prepackaged Win32 app from the Enterprise App Catalog, understand the prefilled install and detection settings, choose between auto-update and guided supersedence, and troubleshoot failed installs.
Build a two-tier Microsoft Cloud PKI hierarchy in Intune, deploy the trusted certificate and SCEP profiles, bind the certificate to Wi-Fi or VPN profiles, monitor and revoke, and fix the common SCEP errors.
Deploy Intune Endpoint Privilege Management: the elevation settings policy, elevation rules by hash or certificate, the user experience, the elevation reports, and how to troubleshoot rules that don't match.
Set up Remote Help end to end: check licensing, enable the tenant settings, grant least-privilege helper roles, deploy the Windows app, handle Conditional Access, and fix sessions that won't connect.
Extend Intune compliance with your own checks: write a discovery script that returns compressed JSON, define rules in the JSON schema, upload both, and troubleshoot error codes 65007 to 65010.
How Intune roles, role assignments and scope tags fit together, three delegation designs that work, the pitfalls that leak visibility, and how to audit and test what an admin can really do.
A Cloud PC shows Provisioning failed in the Intune admin center. How provisioning works, what the Azure network connection health checks test, the documented failure reasons, and when to retry or reprovision.
Configure single-app and multi-app kiosks with the Intune Kiosk template or Assigned Access XML, set up Shared PC mode, pair with Autopilot self-deploying mode, and fix kiosks that won't launch.
What the Company Portal Sync button really does, why the app says a device isn't set up or belongs to another user, how the primary user drives it, and where the logs are.
Trace a stuck Wi-Fi or VPN profile back through the certificate chain: trusted root, SCEP/PKCS profile, Certificate Connector and NDES, using the logs and event IDs Microsoft documents.
Deploy OneDrive Known Folder Move through the Intune settings catalog, roll it out at a safe pace, read the sync health dashboard, and fix the documented reasons a folder refuses to move.
Build a locked-down Android kiosk with Intune: dedicated device enrollment tokens, multi-app kiosk mode with Managed Home Screen, Entra shared device mode sign-in, and fixes for missing apps.
What AADSTS53000, 53001 and 53003 actually mean, how to find the blocking policy in the sign-in logs, and how to fix compliance and browser device-identity gaps.
Read dsregcmd /status for hybrid join failures, check the SCP and Entra Connect sync, use the User Device Registration log and clear devices stuck in Pending.
How the Primary Refresh Token powers single sign-on on Windows, how to check it with dsregcmd and the AAD event logs, and how to fix a missing or stale PRT.
Use report-only mode, the sign-in logs, the insights workbook and the What If tool to prove a Conditional Access policy behaves as expected before you turn it on.
Enable the Temporary Access Pass policy, issue passes in the portal or with Graph PowerShell, and use them to register passkeys, Authenticator and Windows Hello for Business.
Working dynamic device rules for Autopilot, group tags, OS version, ownership and enrollment profiles, plus licensing, processing time, rule validation and when filters fit better.
What the MFA-related AADSTS codes mean, how to read the Authentication details and Conditional Access tabs of a sign-in, and how to fix legacy clients, unregistered users and authentication strength mismatches.
How to read Entra Connect export errors such as AttributeValueMustBeUnique, InvalidSoftMatch and LargeObject, fix matching problems with ms-DS-ConsistencyGuid, and find objects that filtering keeps out of Entra ID.
The core Conditional Access policies to deploy first, how they map to Microsoft's templates and Microsoft-managed policies, and how to roll them out in report-only mode without locking anyone out.
Why cloud Kerberos trust is the recommended Windows Hello for Business model for hybrid tenants, how to create the Entra Kerberos server object, configure the Intune policy, and verify with dsregcmd and klist.
A six-stage study plan for exam SC-300, mapped to the official Microsoft Learn learning paths, with hands-on labs for Conditional Access, authentication methods, PIM, access reviews, apps and Entra Connect.
Sign-ins requesting only openid, profile, email or User.Read are now subject to All resources policies with exclusions: who is affected, how to find the apps in sign-in logs, how to fix them, and the timeline.
What mandatory MFA enforcement covers, the failures it causes for user-based automation and admin sign-ins, how to verify who is ready, moving scripts to workload identities, and MFA-capable break-glass accounts.
Why a hybrid joined PC also shows as Entra registered, what Pending really means, and how to clean up duplicates with dsregcmd, BlockAADWorkplaceJoin and Graph PowerShell.
Configure the Passkey (FIDO2) policy and a passkey profile for Authenticator, pick the right registration flow, roll out in rings and fix the registration and sign-in failures users report.
Set up PIM for Microsoft Entra roles: role settings, eligible assignments, activation and approvals, PIM for Groups, alerts, access reviews, and the activation problems you'll hit.
How access reviews and entitlement management fit together in Microsoft Entra ID Governance: licensing, creating reviews, catalogs and access packages, and a starter plan you can run this quarter.
User risk vs sign-in risk, the detections behind them, risk-based Conditional Access that lets users fix their own risk, and how to investigate, dismiss or confirm the false positives.
SSPR prerequisites, password writeback through Connect Sync or Cloud Sync, the documented SSPR_00xx portal errors, the Windows sign-in screen Reset password link, and the event IDs behind writeback failures.
The four sign-in log types, the fields that matter, how to trace one failed sign-in end to end, KQL against the SigninLogs table, export and retention by licence, and the misreads that waste hours.
Architecture differences, the Learn feature comparison, when each sync tool fits, and the documented pilot-OU migration from Connect Sync to Cloud Sync with cloudNoFlow and JoinNoFlow rules.
Connect Intune to Microsoft Defender for Endpoint, onboard Windows devices with an EDR policy, then prove it worked on the device, in the Defender portal and with a detection test.
A phased plan for attack surface reduction rules in Intune: standard rules straight to Block, the rest in Audit, measured with advanced hunting, narrow exclusions, then enforce.
Intune says the antivirus policy succeeded but the device disagrees. Check the management channel, conflicts, passive mode, tamper protection and exclusion behaviour to find out why.
What Inactive, Impaired communications and No sensor data mean in the Defender device inventory, and how to check the sensor, onboarding state, proxy and duplicate device records.
Find the message, read why it was quarantined, release it, and report it through Submissions so a scoped, expiring allow entry replaces risky mail flow rule bypasses.
A field guide to Defender for Endpoint onboarding failures: onboarding script error codes, SENSE Operational event IDs, Intune error codes, and the registry and service checks that show where it broke.
How Defender for Endpoint security settings management pushes Intune endpoint security policies to devices not enrolled in Intune: prerequisites, enforcement scope, synthetic registration and pitfalls.
Eight short KQL queries for the Defender portal using documented tables: OS builds, sensor health, app versions, CVE exposure, antivirus posture, who ran a tool, ASR audit hits and network destinations.
What Built-in protection, Standard and Strict presets enforce, how they outrank custom threat policies, what you still have to configure for impersonation protection, and how to verify which policy handled a message.
A stage-by-stage study plan for exam SC-200 (Security Operations Analyst Associate): the current skills-measured domains, the Microsoft Learn paths to follow, hands-on labs and exam-day tips.
A device is onboarded to Defender but never shows up as MDE-managed in Intune. Read HKLM\SOFTWARE\Microsoft\SenseCM\EnrollmentStatus, map the code to its cause and fix it.
What *.endpoint.security.microsoft.com replaces and what it doesn't, the sensor prerequisites, how to migrate onboarded devices, EDR and antivirus proxy settings, and how to prove it worked.
What the monthly KB4052623 platform and engine updates are, how to assign Intune update channels in rings, how to read versions with Get-MpComputerStatus, and how to roll back with MpCmdRun.
How automated investigation and response decides what to remediate, how device groups and automation levels control it, and how to approve, reject or undo an action in the Action center.
How exposure score, recommendations, software inventory and weaknesses fit together, and how a Request remediation in the Defender portal becomes a security task an Intune admin can close.
Device control concepts (groups, rules, entries, access masks), the Intune Device Control profile with reusable settings, audit before block, printers, hunting queries and fixes when a USB stick stays writable.
What tamper protection locks, the four places it can be managed and their precedence, how to see which one controls a device, and how to fix settings that won't apply or exclusions that aren't protected.
How Safe Links rewriting and time-of-click checks work, what the Safe Attachments actions do, how to find out why a click was blocked, and how to allow a legitimate URL without weakening protection.
The Intune deployment for Defender for Endpoint on Mac in the documented order: system extensions, Full Disk Access, network filter, background services, the app, the onboarding package, mdatp checks and fixes.
Enable network protection from Intune, turn on web content filtering, build category policies scoped to device groups, add allow indicators, and read blocks in reports, Event Viewer and advanced hunting.
Run a message trace in the Exchange admin center or with Get-MessageTraceV2, read the delivery status and events, and pull older data from downloadable reports.
Publish one correct SPF record, turn on DKIM signing in the Defender portal, then move DMARC from p=none to p=reject without blocking your own legitimate mail.
Why Exchange Online blocks automatic forwarding to external addresses with 5.7.520, and how to allow it only for the mailboxes that need it instead of for everyone.
How automapping really works, why group-based Full Access never automaps, how to switch it off per user, and how to keep sent items in the shared mailbox.
Check licensing and the one-way switch, enable auto-expanding archiving org-wide or per user, make sure items actually move, and confirm extra storage was provisioned.
Why Exchange Online rejects mail with 550 5.4.1 at the perimeter, how Directory-Based Edge Blocking and the accepted domain type cause it, and how to fix each common cause.
What error 5.7.57 means, how SMTP AUTH client submission, SMTP relay and Direct Send differ, how to fix each cause, and where Basic authentication for SMTP AUTH stands.
Install the ExchangeOnlineManagement module, connect interactively or with app-only certificate authentication, and run five quick reports with the fast Get-EXO cmdlets.
How Exchange Online evaluates mail flow rules, why the native External tag beats a subject-prefix rule, and how to test, order and audit rules without punching holes in EOP.
A six-stage MS-102 study plan built on the official Microsoft Learn paths, with extra Exchange Online practice, lab ideas and what the November 2026 retirement of the exam means for you.
Exchange Web Services is being disabled in Exchange Online from October 2026. What changes, how EwsEnabled and EwsAllowedAppIDs work, how to find what still uses EWS and how to buy time safely.
Why senders get 554 5.2.2 mailbox full, how to measure a mailbox and its hidden Recoverable Items folder, and the fix for each cause: user data, holds, calendar logging or the wrong licence.
A methodical way to troubleshoot hybrid free/busy and calendar sharing: direction, Autodiscover, the OAuth trust and dedicated hybrid app, connectors and relationships, with cmdlets for each hop.
Microsoft's response order for a compromised mailbox, cmdlets that find malicious inbox rules and forwarding across every mailbox, what to read in sign-in and audit logs, and how to harden afterwards.
Purview retention policies vs retention labels vs Exchange MRM tags vs litigation hold: what each does, what wins in a conflict, licensing, how to set them up and how to prove a mailbox is really on hold.
How a remote move batch works, what Syncing, Synced and Completing really mean, the documented errors (SMTP proxy, MRS Proxy 401, skipped items) and how to finish the cutover cleanly.
How classic Outlook finds Exchange Online, how to read Test E-mail AutoConfiguration and the Remote Connectivity Analyzer, and the usual culprits: DNS, stale on-premises Autodiscover, old clients and broken profiles.
A capability-by-capability comparison of distribution groups, dynamic groups, Microsoft 365 Groups and shared mailboxes, when to choose each, how to upgrade a DL and the PowerShell to answer the usual questions.
Read the X-Forefront-Antispam-Report header (CAT, SFV, BCL, compauth) to see why a good message was junked, then fix it the supported way: submissions, Tenant Allow/Block List, sender authentication, not bypass rules.
Create room and equipment mailboxes, tune Set-CalendarProcessing (auto-accept, conflicts, booking window, delegates), build room lists and Set-Place metadata for Room Finder, and fix the usual booking complaints.
What the Microsoft MVP Award recognises, how nominations and reviews work, which contributions count (and which don't), and a simple log template to track your community work.
Try a different keyword, or .
Tell me what you're troubleshooting or which feature you'd like a guide for, and it may become the next article.