The Windows Autopilot known issues page on Microsoft Learn is the first place I check when a deployment misbehaves in a way that doesn't match the usual suspects. It's a long page, though, and the status of each entry changes over time. In this post I'll summarise where things stand as of early October 2026, go deeper on the two issues added in January 2026, and show how to read the dates and subscribe so you hear about new entries before your users do.
Status (October 2026): this roundup reflects the Windows Autopilot known issues page as last updated by Microsoft on 8 September 2026. The newest entry is dated 1 September 2026 (hybrid join pre-provisioning and domain controller connectivity). Several 2026 entries are already resolved by Windows updates or connector builds; two are open. Always re-check the official page, because statuses change without a new blog post from anyone.
What's on the page right now#
These are the entries added from 2024 onwards, newest first, with the status Microsoft gives. Older items (2022 and 2023, plus a tail of undated entries) are mostly TPM attestation firmware notes, report quirks and by-design behaviours such as duplicate device objects in hybrid deployments.
| Date added | Issue | Status on the page |
|---|---|---|
| 1 Sep 2026 | Pre-provisioning fails for hybrid join when a policy conflict needs a domain controller (0x800706FD) | Known limitation. Don't assign such policies in the technician flow, or pre-provision with line of sight to a DC. |
| 18 Jun 2026 | ODJ Connector configuration fails with a SeLogonAsServicePrivilege error when using your own gMSA | Resolved in connector build 6.2604.2000.3 via the opt-in SkipByoMsaPrivilegeCheck key. |
| 9 Feb 2026 | Hybrid join Autopilot deployments time out with 0x80004005 | Resolved in KB5065789 (25H2), KB5065426 (24H2), KB5070312 (23H2) or later. |
| 16 Jan 2026 | Local Autopilot Reset can't be triggered by the local administrator when "Deny access to this computer from the network" is set | Under investigation. Workaround: remove the setting for the local account or exclude the devices. |
| 13 Jan 2026 (updated 8 Sep 2026) | Devices don't get quality updates during hybrid joined deployments when Allow OOBE Updates is configured | Affects KB5041571 and later. Resolved in KB5079473 and later. |
| 13 Aug 2025 | Deployment duration in the Autopilot deployment report includes lock-screen sign-in time | Documented behaviour; no fix listed. |
| 1 Aug 2025 | ESP Account setup phase not shown for FIDO2 (YubiKey) sign-in in self-deploying mode with Shared PC | Being investigated. |
| 9 May 2025 | TPM attestation fails on some ST Micro and Nuvoton RSA 3072 TPMs | Microsoft says the OEM has resolved it; Lenovo customers should work with Lenovo support. |
| 8 Apr 2025 | Intune Connector for AD 6.2501.2000.5 errors (MSA not valid, service logon failure, constraint violation) | "MSA not valid" resolved in 6.2504.2001.8; others point to the troubleshooting FAQ. |
| 4 Apr 2025 | Automatic keyboard configuration doesn't update the keyboard language | Use KB5072033 or later. |
| 9 Dec 2024 | LAPS policy isn't applied during the technician flow | Applies when the user phase begins. |
| 4 Dec 2024 | Deployment report and AutopilotEvents Graph API return 50 records at a time | Use skipToken paging or the export API with AutopilotV1DeploymentStatus. |
| 9 Oct 2024 | DFCI enrollment fails for Windows 11 24H2 Professional editions | Install KB5046740 or later after provisioning, or step up to Enterprise during OOBE. |
| 29 Aug 2024 | Deployment report doesn't support column sorting | To be addressed in the future. |
| 21 Aug 2024 (updated Dec 2025) | Kiosk profile auto logon lost after unexpected OOBE reboots | Fixed in 24H2 with KB5058411 or later. |
| 8 Jul 2024 | BitLocker defaults to 128-bit when 256-bit is configured (unregistered devices, race condition) | Being investigated. Register devices for Autopilot if you need 256-bit. |
| 17 May 2024 | Required apps aren't shown on the ESP after an Autopilot Reset | Apps install after the user signs in instead. |
Note the BitLocker entry: the separate device preparation known issues page was updated on 14 September 2026 to say that issue is resolved in KB5124012 and later for device preparation deployments, while the classic Autopilot page still shows it under investigation. Read the page that matches your deployment type.
Local Autopilot Reset blocked by "Deny access to this computer from the network"#
What Microsoft says. When an Intune policy sets Deny access to this computer from the network for the local account, the local Windows administrator account can't start a local Autopilot Reset, whether from the sign-in screen or after signing in locally. The workaround is to remove that setting for the local account or exclude the devices that need local reset from the policy; after the device syncs the updated policy, the reset works. The issue is under investigation.
How to recognise it. Local reset is only available when Autopilot Reset is set to Allow in a device restrictions profile (the CredentialProviders/DisableAutomaticReDeploymentCredentials policy). The trigger is Ctrl+Win+R at the lock screen followed by local admin credentials. If that sign-in doesn't start the reset, check whether a settings catalog, baseline or custom profile configures the UserRights/DenyAccessFromNetwork setting with the local account or a group containing it. On the device, secedit /export /cfg C:\secpol.cfg shows the effective list under SeDenyNetworkLogonRight.
Rule out the other reasons local reset fails. Autopilot Reset isn't supported on Microsoft Entra hybrid joined devices at all, and it requires the Windows Recovery Environment: if WinRE is disabled the reset fails immediately with ERROR_NOT_SUPPORTED (0x80070032), which reagentc.exe /enable fixes.
Alternative. A remote Autopilot Reset from the Microsoft Intune admin center (Devices › All devices, select the device, Autopilot Reset) doesn't depend on the local account signing in, so it's the simplest way to keep resetting devices while you keep the deny setting for security reasons.
Quality updates skipped during hybrid joined deployments#
What Microsoft says. When the Allow OOBE Updates policy is configured in the ESP profile, the scan for quality updates during OOBE can time out on hybrid joined deployments, so devices don't get the updates during OOBE. It impacts devices with KB5041571 (the August 2024 update for 24H2) and later, and is resolved in KB5079473 (March 2026) and later.
How to recognise it. In the ESP profile the setting appears as Install Windows quality updates (might restart the device). It defaults to Yes in new profiles and No in profiles created before the setting existed, until you edit them. A hybrid device that finishes OOBE and reaches the desktop still on the build it shipped with, while a cloud-native device from the same batch arrives patched, is the pattern to look for. Compare winver on the device with the current month's build.
What to do. The fix lives in Windows, so the device has to be on KB5079473 or later when OOBE runs for the setting to work. Until your images reach that level, decide deliberately: either set the ESP setting to No for hybrid profiles and let your update rings or an expedited quality update policy patch the device after enrollment, or keep it on and accept that hybrid devices may skip it. Don't rely on it for compliance on day one.
How to read the dates on the page#
- Date added is when Microsoft first published the entry, not when the problem started. The hybrid join
0x80004005issue was added in February 2026 but is fixed by updates from September 2025. - Date updated usually marks a status change, most often a resolution or a new KB. The quality update entry carries a date updated of 8 September 2026, so that's when its text last changed.
- The Last updated on stamp in the page footer reflects any edit to the whole page, which is a quick way to see if anything moved since your last visit.
- Entries without a date predate the dating convention and are mostly long-standing guidance (Conditional Access exclusions, provisioning package caveats, time sync).
How to stay informed#
- Subscribe to the page's RSS feed. The tip box at the top of the known issues page gives a search-based RSS URL that returns the page whenever it changes:
Paste it into any RSS reader, or into an Outlook RSS subscription. TheText
https://learn.microsoft.com/api/search/rss?search=%22Be+informed+about+known+issues+that+might+occur+during+Windows+Autopilot+deployment.%22&locale=en-us&%24filter=localeparameter is required; changeen-usto your locale if you prefer. The device preparation known issues page and both "What's new" pages publish their own feeds in the same way, and the Intune "How to use the docs" article explains the mechanism. - Watch Windows release health too. Most 2026 Autopilot fixes arrive in Windows cumulative updates, and the per-version Known issues and Resolved issues pages on the Windows release health site, plus the "Known issues in this update" section of each KB article, often describe an OOBE or enrollment problem before the Autopilot page does.
- Add the Intune side. The "What's new in Microsoft Intune" and "In development" pages carry RSS feeds as well, and Message center posts in the Microsoft 365 admin center are where planned changes with deadlines appear.
Key takeaways#
- Of the five 2026 entries, three are resolved (by Windows updates or a connector build) and two remain open: the local Autopilot Reset block and the pre-provisioning domain controller limitation, which Microsoft treats as by design.
- Every hybrid-only issue on the page is one more argument for Microsoft's own recommendation to deploy new devices as cloud-native Microsoft Entra joined.
- Check the build at OOBE, not the build after the first update ring, when you decide whether a Windows fix applies to your deployment.
- Subscribe once, and you stop depending on someone else's blog post, including this one.