A user opens the Company Portal app on Windows, presses Sync or Check access, and gets nowhere: the device is missing from the list, the app says it belongs to someone else, or apps simply never appear. In most of these cases Intune itself is healthy; the mismatch is between the account in Company Portal, the enrollment on the device and the primary user recorded in Intune. In this post I'll walk through how to tell those apart and fix each one.
Symptoms#
- Company Portal shows the warning This device is already assigned to someone in your organization. Contact company support about becoming the primary device user. and most self-service actions are missing.
- The device tile carries a shared label, and Uninstall, Rename, Reset or Retire aren't offered.
- Available apps don't show up under Apps, even though the device appears enrolled.
- Sync from Company Portal seems to do nothing, while the device's last check-in time in the Intune admin center is hours or days old.
- When the user tries to add their work account in Settings, Windows reports Your device is already being managed by an organization.
Why it happens#
What Sync actually triggers#
Company Portal has two related actions. Settings › Sync asks the device to check in with Intune for new policies, requirements and apps. Devices › (device) › Check access does the same and then evaluates compliance, returning Can access company resources, Cannot access company resources or Can access company resources, but action required. Both are user-initiated check-ins, the same kind the admin center's Sync device action produces. The Windows Settings app offers an equivalent at Settings › Accounts › Access work or school › (work account) › Info › Sync; that path talks to the MDM client directly and doesn't depend on Company Portal being signed in correctly. If Settings sync works but Company Portal doesn't, the problem is in the app's view of the device, not in enrollment.
The primary user has to match#
Company Portal expects the signed-in account to be the device's primary user in Intune. The primary user is set during enrollment: for user-driven methods (Add work or school account, Microsoft Entra join during OOBE, Autopilot user-driven) it's the enrolling user; for hybrid join with the automatic enrollment Group Policy and for co-management it's the first user to sign in to Windows; for bulk enrollment and Autopilot self-deploying mode there is no primary user at all. When someone else signs in to Company Portal, the app shows the "already assigned" warning and limits functionality. When no primary user exists, Company Portal treats the device as shared: available apps can still be requested, but self-service actions are hidden.
Registered isn't enrolled#
A device can be Microsoft Entra registered or joined without being MDM-enrolled, for example when the user wasn't in the MDM user scope or enrollment was blocked by a platform restriction. Company Portal then has no managed device to show. The quick tell is in Settings: a managed work account shows an Info button under Access work or school; a registered-only account doesn't.
Apps need the device to be identified#
For available apps to appear in Company Portal on Windows, the user has to identify which enrolled device they're using. Microsoft's support article for this scenario points users to the Company Portal website, My Devices, and the prompt to select the current device.
How to fix it#
- Confirm the enrollment state on the device. Open Settings › Accounts › Access work or school. If the work account is listed with an Info button, the device is enrolled; select Info › Sync and watch for errors. If the account is missing, use Connect to add it again. If Windows answers Your device is already being managed by an organization, the device is enrolled in Intune or another MDM, possibly under a different account; check the Intune admin center before touching anything.
- Compare the Intune record with the user. In the Intune admin center go to Devices › All devices, open the device and read Primary user and Enrolled by on the overview. If the primary user is a departed colleague or an imaging technician, select Properties › Change primary user and pick the real user. This works for Microsoft Entra joined and hybrid joined Windows devices, not for registered-only devices; the new user must be licensed for Intune, you need the Managed devices Set primary user permission, and the change can take up to 10 minutes to show everywhere. Changing the primary user doesn't change Enrolled by or local group membership.
- Decide whether the device should be shared. If the device genuinely has no single owner, leave the primary user empty and tell users the shared label is expected. Assign the apps they need as required, or as available to the device group, so they still appear.
- Identify the device for apps. Have the user sign in to portal.manage.microsoft.com, open My Devices, and select the device they're on. Available apps should then appear in the app and on the website.
- Rule out the device limit. An enrollment attempt that fails with DeviceCapReached or a generic Company Portal Temporarily Unavailable message means the user has hit the device limit. Compare Devices › Enrollment restrictions › Device limit restrictions with the user's device count under Users › (user) › Devices and remove stale records.
- Check the known issues page. Microsoft's Intune known issues page lists active Company Portal problems; at the time of writing they include Azure enterprise applications not displaying in Company Portal for Windows and Configuration Manager apps loading slowly on the Windows apps page.
- Collect logs before escalating. In Company Portal, Help & support › Upload logs sends the app logs to Microsoft and opens an email template for your helpdesk. The same files sit in
%localappdata%\Packages\Microsoft.CompanyPortal_8wekyb3d8bbwe\LocalStateasLog_<n>.log. For the MDM side, Settings › Accounts › Access work or school › Export your management log files writes the report toC:\Users\Public\Public Documents\MDMDiagnostics.
Watch out: Don't retire or wipe a device just because Company Portal shows it as assigned to someone else. Fixing the primary user is a two-minute change; re-enrolling costs the user their apps and settings.
Verify the fix#
- In Company Portal, Devices lists the machine without the shared label, and Check access returns Can access company resources.
- Settings › Sync completes, and the device's Last check-in in the admin center updates within a few minutes.
- Available apps appear under Apps, and Troubleshooting + support for the user shows the expected assignments.
- The device overview shows the intended primary user.
Documented messages at a glance#
| Message | Meaning | Where to look |
|---|---|---|
| This device is already assigned to someone in your organization… | Signed-in user isn't the primary user | Device overview › Primary user |
| "shared" label on the device tile | No primary user; self-service actions disabled by design | Device overview, enrollment method |
| Your device is already being managed by an organization. | Device already enrolled in Intune or another MDM | Devices › All devices; MDM enrollment on the device |
| We couldn't auto-discover a management endpoint matching the username entered. | Account couldn't be verified against the management endpoint | Re-enter credentials; provide the enrollment URL if needed |
| It looks like you're not connected. | No network connection during account setup | Connectivity |
| DeviceCapReached / Company Portal Temporarily Unavailable | Device enrollment limit reached | Device limit restrictions; user's device list |
Prevent it next time#
- Don't let technicians enroll devices with their own accounts unless the process includes changing the primary user afterwards; use Autopilot user-driven mode or a device enrollment manager with a documented hand-over step.
- For kiosks and shared PCs, use enrollment methods that leave the primary user empty on purpose, and assign apps accordingly.
- Teach the helpdesk the order: enrollment state in Settings first, primary user second, Company Portal last.