IntuneTroubleshooting

Windows Autopilot known issues in 2026: what's open, what's fixed and how to stay informed

A walkthrough of the Windows Autopilot known issues page as of October 2026: open and fixed items, deeper guidance on the January 2026 entries, and how to subscribe so new issues reach you first.

The Windows Autopilot known issues page on Microsoft Learn is the first place I check when a deployment misbehaves in a way that doesn't match the usual suspects. It's a long page, though, and the status of each entry changes over time. In this post I'll summarise where things stand as of early October 2026, go deeper on the two issues added in January 2026, and show how to read the dates and subscribe so you hear about new entries before your users do.

How this guide is organised: What's on the page right now → Local Autopilot Reset blocked by "Deny access to this computer from the network" → Quality updates skipped during hybrid joined deployments → How to read the dates on the page → How to stay informed → Key takeawaysFlow diagram of the article's sections in reading order: 1. What's on the page right now. 2. Local Autopilot Reset blocked by "Deny access to this computer from the network". 3. Quality updates skipped during hybrid joined deployments. 4. How to read the dates on the page. 5. How to stay informed. 6. Key takeaways. Toolbox: 0x80004005, 0x800706FD, 0x80070032, reagentc.exe, Devices › All devices.1What's on the page right now2Local Autopilot Reset blockedby "Deny access to this compu…3Quality updates skipped duringhybrid joined deployments4How to read the dates on thepage5How to stay informed6Key takeawaysTOOLBOX0x800040050x800706FD0x80070032reagentc.exeDevices › All devicesHow this guide is organised: What's on the page right now → Local Autopilot Reset blocked by "Deny access to this computer from the network" → Quality updates skipped during hybrid joined deployments → How to read the dates on the page → How to stay informed → Key takeawaysFlow diagram of the article's sections in reading order: 1. What's on the page right now. 2. Local Autopilot Reset blocked by "Deny access to this computer from the network". 3. Quality updates skipped during hybrid joined deployments. 4. How to read the dates on the page. 5. How to stay informed. 6. Key takeaways. Toolbox: 0x80004005, 0x800706FD, 0x80070032, reagentc.exe, Devices › All devices.1What's on the page right now2Local Autopilot Reset blocked by "Denyaccess to this computer from the network"3Quality updates skipped during hybrid joineddeployments4How to read the dates on the page5How to stay informed6Key takeawaysTOOLBOX0x800040050x800706FD0x80070032reagentc.exeDevices › All devices
At a glance: how this guide is organised · 6 sections · 5 key tools

Status (October 2026): this roundup reflects the Windows Autopilot known issues page as last updated by Microsoft on 8 September 2026. The newest entry is dated 1 September 2026 (hybrid join pre-provisioning and domain controller connectivity). Several 2026 entries are already resolved by Windows updates or connector builds; two are open. Always re-check the official page, because statuses change without a new blog post from anyone.

What's on the page right now#

These are the entries added from 2024 onwards, newest first, with the status Microsoft gives. Older items (2022 and 2023, plus a tail of undated entries) are mostly TPM attestation firmware notes, report quirks and by-design behaviours such as duplicate device objects in hybrid deployments.

Date addedIssueStatus on the page
1 Sep 2026Pre-provisioning fails for hybrid join when a policy conflict needs a domain controller (0x800706FD)Known limitation. Don't assign such policies in the technician flow, or pre-provision with line of sight to a DC.
18 Jun 2026ODJ Connector configuration fails with a SeLogonAsServicePrivilege error when using your own gMSAResolved in connector build 6.2604.2000.3 via the opt-in SkipByoMsaPrivilegeCheck key.
9 Feb 2026Hybrid join Autopilot deployments time out with 0x80004005Resolved in KB5065789 (25H2), KB5065426 (24H2), KB5070312 (23H2) or later.
16 Jan 2026Local Autopilot Reset can't be triggered by the local administrator when "Deny access to this computer from the network" is setUnder investigation. Workaround: remove the setting for the local account or exclude the devices.
13 Jan 2026 (updated 8 Sep 2026)Devices don't get quality updates during hybrid joined deployments when Allow OOBE Updates is configuredAffects KB5041571 and later. Resolved in KB5079473 and later.
13 Aug 2025Deployment duration in the Autopilot deployment report includes lock-screen sign-in timeDocumented behaviour; no fix listed.
1 Aug 2025ESP Account setup phase not shown for FIDO2 (YubiKey) sign-in in self-deploying mode with Shared PCBeing investigated.
9 May 2025TPM attestation fails on some ST Micro and Nuvoton RSA 3072 TPMsMicrosoft says the OEM has resolved it; Lenovo customers should work with Lenovo support.
8 Apr 2025Intune Connector for AD 6.2501.2000.5 errors (MSA not valid, service logon failure, constraint violation)"MSA not valid" resolved in 6.2504.2001.8; others point to the troubleshooting FAQ.
4 Apr 2025Automatic keyboard configuration doesn't update the keyboard languageUse KB5072033 or later.
9 Dec 2024LAPS policy isn't applied during the technician flowApplies when the user phase begins.
4 Dec 2024Deployment report and AutopilotEvents Graph API return 50 records at a timeUse skipToken paging or the export API with AutopilotV1DeploymentStatus.
9 Oct 2024DFCI enrollment fails for Windows 11 24H2 Professional editionsInstall KB5046740 or later after provisioning, or step up to Enterprise during OOBE.
29 Aug 2024Deployment report doesn't support column sortingTo be addressed in the future.
21 Aug 2024 (updated Dec 2025)Kiosk profile auto logon lost after unexpected OOBE rebootsFixed in 24H2 with KB5058411 or later.
8 Jul 2024BitLocker defaults to 128-bit when 256-bit is configured (unregistered devices, race condition)Being investigated. Register devices for Autopilot if you need 256-bit.
17 May 2024Required apps aren't shown on the ESP after an Autopilot ResetApps install after the user signs in instead.

Note the BitLocker entry: the separate device preparation known issues page was updated on 14 September 2026 to say that issue is resolved in KB5124012 and later for device preparation deployments, while the classic Autopilot page still shows it under investigation. Read the page that matches your deployment type.

Local Autopilot Reset blocked by "Deny access to this computer from the network"#

What Microsoft says. When an Intune policy sets Deny access to this computer from the network for the local account, the local Windows administrator account can't start a local Autopilot Reset, whether from the sign-in screen or after signing in locally. The workaround is to remove that setting for the local account or exclude the devices that need local reset from the policy; after the device syncs the updated policy, the reset works. The issue is under investigation.

How to recognise it. Local reset is only available when Autopilot Reset is set to Allow in a device restrictions profile (the CredentialProviders/DisableAutomaticReDeploymentCredentials policy). The trigger is Ctrl+Win+R at the lock screen followed by local admin credentials. If that sign-in doesn't start the reset, check whether a settings catalog, baseline or custom profile configures the UserRights/DenyAccessFromNetwork setting with the local account or a group containing it. On the device, secedit /export /cfg C:\secpol.cfg shows the effective list under SeDenyNetworkLogonRight.

Rule out the other reasons local reset fails. Autopilot Reset isn't supported on Microsoft Entra hybrid joined devices at all, and it requires the Windows Recovery Environment: if WinRE is disabled the reset fails immediately with ERROR_NOT_SUPPORTED (0x80070032), which reagentc.exe /enable fixes.

Alternative. A remote Autopilot Reset from the Microsoft Intune admin center (Devices › All devices, select the device, Autopilot Reset) doesn't depend on the local account signing in, so it's the simplest way to keep resetting devices while you keep the deny setting for security reasons.

Quality updates skipped during hybrid joined deployments#

What Microsoft says. When the Allow OOBE Updates policy is configured in the ESP profile, the scan for quality updates during OOBE can time out on hybrid joined deployments, so devices don't get the updates during OOBE. It impacts devices with KB5041571 (the August 2024 update for 24H2) and later, and is resolved in KB5079473 (March 2026) and later.

How to recognise it. In the ESP profile the setting appears as Install Windows quality updates (might restart the device). It defaults to Yes in new profiles and No in profiles created before the setting existed, until you edit them. A hybrid device that finishes OOBE and reaches the desktop still on the build it shipped with, while a cloud-native device from the same batch arrives patched, is the pattern to look for. Compare winver on the device with the current month's build.

What to do. The fix lives in Windows, so the device has to be on KB5079473 or later when OOBE runs for the setting to work. Until your images reach that level, decide deliberately: either set the ESP setting to No for hybrid profiles and let your update rings or an expedited quality update policy patch the device after enrollment, or keep it on and accept that hybrid devices may skip it. Don't rely on it for compliance on day one.

How to read the dates on the page#

  • Date added is when Microsoft first published the entry, not when the problem started. The hybrid join 0x80004005 issue was added in February 2026 but is fixed by updates from September 2025.
  • Date updated usually marks a status change, most often a resolution or a new KB. The quality update entry carries a date updated of 8 September 2026, so that's when its text last changed.
  • The Last updated on stamp in the page footer reflects any edit to the whole page, which is a quick way to see if anything moved since your last visit.
  • Entries without a date predate the dating convention and are mostly long-standing guidance (Conditional Access exclusions, provisioning package caveats, time sync).

How to stay informed#

  1. Subscribe to the page's RSS feed. The tip box at the top of the known issues page gives a search-based RSS URL that returns the page whenever it changes:
    Text
    https://learn.microsoft.com/api/search/rss?search=%22Be+informed+about+known+issues+that+might+occur+during+Windows+Autopilot+deployment.%22&locale=en-us&%24filter=
    Paste it into any RSS reader, or into an Outlook RSS subscription. The locale parameter is required; change en-us to your locale if you prefer. The device preparation known issues page and both "What's new" pages publish their own feeds in the same way, and the Intune "How to use the docs" article explains the mechanism.
  2. Watch Windows release health too. Most 2026 Autopilot fixes arrive in Windows cumulative updates, and the per-version Known issues and Resolved issues pages on the Windows release health site, plus the "Known issues in this update" section of each KB article, often describe an OOBE or enrollment problem before the Autopilot page does.
  3. Add the Intune side. The "What's new in Microsoft Intune" and "In development" pages carry RSS feeds as well, and Message center posts in the Microsoft 365 admin center are where planned changes with deadlines appear.

Key takeaways#

  • Of the five 2026 entries, three are resolved (by Windows updates or a connector build) and two remain open: the local Autopilot Reset block and the pre-provisioning domain controller limitation, which Microsoft treats as by design.
  • Every hybrid-only issue on the page is one more argument for Microsoft's own recommendation to deploy new devices as cloud-native Microsoft Entra joined.
  • Check the build at OOBE, not the build after the first update ring, when you decide whether a Windows fix applies to your deployment.
  • Subscribe once, and you stop depending on someone else's blog post, including this one.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)