Before you spend an afternoon pulling logs off a device, it's worth ten minutes checking whether Microsoft already knows about the problem. Intune, Windows Autopilot and Windows itself each have an official place where incidents, advisories and known issues are published, and the Intune service changes every month in a rollout that doesn't reach every tenant on the same day. In this post I'll give you a checklist to run through in order, how to tell a service incident from a tenant problem, what to collect before opening a case, and how to get this information pushed to you instead.
Where Microsoft publishes what#
Service health is tenant-specific and covers live incidents and advisories; it is the same data in the Microsoft 365 admin center and in the Intune admin center. The Message center carries planned changes and announcements. Known issues pages on Microsoft Learn describe product bugs with workarounds and fix status, and they aren't tenant-specific. What's new in Intune tells you which service release your tenant is on and what changed, and Windows release health covers Windows update problems and safeguard holds. Each one answers a different question, so the order matters.
The 10-minute checklist#
1. Service health (two minutes)#
In the Microsoft 365 admin center go to Health › Service health. The Overview tab shows every service with its health state, an Issues for your organization to act on section (only visible when there is something for you to do) and Active issues Microsoft is working on. An advisory means a problem affecting some users while the service stays available, often with a workaround; an incident means a critical issue where the service or a major function is unavailable. Statuses run from Investigating and Service degradation through Restoring service and Extended recovery to Service restored, False positive and Post-incident report published. Each issue has an ID; the Intune known issues page quotes one of them, IT393575, for the macOS unenrollment problem, which is the format you'll see for Intune items. Viewing this needs the Service Support Administrator or Helpdesk Administrator role.
The same information is in the Intune admin center under Tenant administration › Tenant status, on the Service health and message center tab, filtered to incidents that affect your tenant and with a section for issues in your environment that require action.
2. Message center (one minute)#
Still in the Microsoft 365 admin center, Health › Message center lists announcements and Plan for change posts. Planned maintenance is not shown in Service health, so a behaviour change that landed on a date is often explained here. Filter by the Intune service.
3. Intune known issues (two minutes)#
Open Known issues with Microsoft Intune. Each entry has a status such as Active or Resolved and often links to a longer Intune Customer Success blog post. At the time of writing it includes items like regional selection for Microsoft Store apps being temporarily unavailable and Configuration Manager apps loading slowly in Company Portal. If your symptom is listed, you have your answer and your workaround.
4. What's new and your tenant's service release (two minutes)#
Go to Tenant administration › Tenant status › Tenant details and note the service release number; it is a link to What's new in Microsoft Intune. That page carries an important note: each monthly service update rolls out gradually, validated internally first, then to a small set of datacenters, then worldwide over several days to a week, and some features keep rolling out for weeks. So a colleague's tenant can show a new blade or behaviour before yours, and a new behaviour that appeared "overnight" often lines up with your tenant moving to a new release. The In development page previews what is coming.
5. Windows Autopilot known issues (one minute)#
If the problem is a deployment, check Windows Autopilot known issues. Entries carry a Date added and the KB that fixes them, for example the hybrid join time-outs with error 0x80004005 resolved in KB5065789 (25H2) and KB5065426 (24H2), or the pre-provisioning hybrid join failure added on 1 September 2026.
6. Windows release health (two minutes)#
For update, upgrade or OS behaviour problems, open the public release health pages on Microsoft Learn or, with a Windows E3/E5 or A3/A5 licence, Health › Windows release health in the Microsoft 365 admin center, which shows more technical detail than the public page. The Known issues tab covers active issues and ones resolved in the last 30 days, History goes back six months, and statuses run from Reported and Investigating to Confirmed, Mitigated and Resolved (with External variants for third-party causes). Each issue has an advisory ID starting with WI, such as WI123456, which support will ask for.
7. Connector status (30 seconds)#
Back on Tenant status, the Connector status tab lists every connector and certificate. Unhealthy means a certificate or credential has expired or the last sync was three or more days ago; Warning means expiry within seven days or no sync for more than a day. An expired Apple MDM push certificate or a stale Autopilot sync explains a lot of "Intune is broken" tickets.
Service incident or tenant problem?#
None of this is in a Microsoft document; it's the pattern I'd apply. Scope: an incident hits many devices, users or sites at the same time and usually crosses platforms or features, while a tenant problem clusters around one group, one policy or one model. Timing: if it started at a precise time with no change on your side, suspect the service or a service release; if it started after you edited a policy, suspect the policy. Reproducibility: incidents are often intermittent and resolve without you doing anything; configuration errors reproduce every time. Community reports from other admins are a useful hint, but treat them as "reported by admins", not confirmation, until Microsoft posts.
What to collect before a support case#
- Tenant ID and the service release number from Tenant details.
- For each affected device: device name, Intune device ID and Microsoft Entra device ID, the primary user's UPN, OS version and the last check-in time.
- Exact timestamps with time zone for when it started, when it was last seen working and when you changed anything; a count of affected versus unaffected devices.
- Screenshots of the error, the exact error code or message, and the policy or app names involved.
- Any IDs you found above: the Service health issue ID, the WI advisory ID or the Autopilot known issue entry.
- Device logs. For Windows, use the Collect diagnostics remote action in Intune or run this on the device:
MdmDiagnosticsTool.exe -area DeviceEnrollment;DeviceProvisioning;Autopilot -cab C:\Temp\MDMDiag.cabOpen the case from Troubleshooting + support › Help and support in the Intune admin center. If you believe the problem is on Microsoft's side and nothing is posted yet, use Report an issue on the Service health page; Microsoft checks related data and reports from other organizations, and adds an incident or advisory if it originated in the service. Your report then appears on the Reported issues tab.
Subscribe instead of checking#
- Service health email: Customize › Email on the Service health page, up to two addresses per admin, with a choice of incidents or advisories and which services. You can also pick Manage notifications for this issue on a single active issue.
- Microsoft 365 Admin mobile app: push notifications for Service health.
- Windows release health email: Preferences › Email on the Windows release health page, up to two addresses and your choice of Windows versions; changes take up to eight hours to apply.
- Message center email: Message center preferences in the Microsoft 365 admin center, including a weekly digest; Intune's own tenant status page tells you to set these in the Microsoft 365 admin center.
- RSS: the Autopilot known issues page publishes an RSS link built on the Learn search API, and What's new in Intune notes that RSS is available for page updates, so a feed reader can watch both.
- X accounts: Microsoft points to @MSFT365status for service events and @WindowsUpdate for release health.
Tip: make the checklist a saved browser folder with the seven links in order. When a ticket comes in, open the folder, work top to bottom, and only then start on the device. Most of the time you'll still be troubleshooting your own configuration, but you'll do it knowing nothing upstream is on fire.