IntuneTroubleshooting

Windows enrollment error 0x80180018 and its neighbours: what to check, and where

Windows MDM enrollment fails with 0x80180018 or a nearby 0x8018 code. What Microsoft documents for each code, which tenant setting is behind it, and how to confirm the fix in the enrollment event log.

A user joins a Windows device to Microsoft Entra ID or adds a work account, and instead of landing in Intune the device stops with "Something went wrong" and a code such as 80180018. The codes in the 0x8018xxxx range all come from the MDM enrollment client, and Microsoft publishes what each one means. In this post I'll map the common ones to the tenant setting that usually causes them, show where to check each setting, and explain how to confirm the fix from the device's enrollment log.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x80180018, 0x80180013, 0x801C000E, gpupdate /force, dsregcmd /status.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttimeTOOLBOX0x801800180x801800130x801C000Egpupdate /forcedsregcmd /statusHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: 0x80180018, 0x80180013, 0x801C000E, gpupdate /force, dsregcmd /status.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it next timeTOOLBOX0x801800180x801800130x801C000Egpupdate /forcedsregcmd /status
At a glance: how this guide is organised · 5 sections · 5 key tools

Symptoms#

  • During OOBE, or in Settings › Accounts › Access work or school, enrollment stops with a dialog that ends in "contact your system administrator with the error code 80180018" (the dialog usually drops the 0x prefix).
  • The on-screen wording varies. You may see "This user isn't authorized to enroll" or "There was an error with your license". Microsoft's reference table ties 0x80180018 itself to the user's licence state, so work from the code, not the sentence.
  • The Entra join part often succeeds: the device appears in Entra ID, but it never shows up under Devices › Windows in the Intune admin center.
  • For Group Policy auto-enrollment there's no dialog at all. Instead the DeviceManagement-Enterprise-Diagnostics-Provider › Admin event log records event 76, "Auto MDM Enroll: Failed", with the code in the message.

Why it happens#

Windows reports a specific MENROLL_E_* value for each enrollment failure, and Microsoft documents them in the Windows client management reference. The table below lists the ones I see most, what Microsoft says they mean, and where in the tenant the cause normally lives.

CodeDocumented meaningWhere to look first
0x80180018MENROLL_E_USERLICENSE: the user's licence is in a state that blocks enrollmentThe enrolling user's licences and the Intune service plan
0x80180013MENROLL_E_DEVICECAPREACHED: the user has already enrolled too many devicesIntune device limit restrictions; the user's existing device records
0x801c000EEntra device registration quota exceeded ("too many devices or users for this account")Entra ID device settings, Maximum number of devices
0x8018000AMENROLL_E_DEVICE_ALREADY_ENROLLED: the device is already enrolledAnother account's work or school connection on the same device
0x80180014MENROLL_E_DEVICENOTSUPPORTED: platform or version not supported; in Intune this is usually Windows (MDM) blocked by a platform restrictionDevice platform restrictions
0x80180003MENROLL_E_DEVICE_AUTHORIZATION_ERROR: the user isn't authorized to enrollWho is enrolling: MDM user scope, restrictions, licence
0x8018002b"Auto MDM Enroll: Failed" for Group Policy enrollment: the UPN uses an unverified or non-routable domain, or the MDM user scope is NoneUPN suffix; automatic enrollment settings
0x80180010MENROLL_E_CONNECTIVITY: a network error such as DNS failure or a timeoutProxy and firewall rules for the Intune endpoints

Two licence-related messages don't come with a code. "This account is not allowed on this phone" means the user has no valid Intune licence. "Looks like the MDM Terms of Use endpoint is not correctly configured" appears when a tenant uses both basic mobility for Microsoft 365 and Intune and the user has no valid licence, or when the MDM terms of use URL in the Mobility settings is blank or wrong.

How to fix it#

  1. Get the exact code from the device. If the dialog is gone, open Event Viewer and go to Applications and Services Logs › Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin. Event 75 is a successful automatic enrollment; event 76 is a failed one and carries the code. To collect everything for later, run:
    Command Prompt
    mdmdiagnosticstool.exe -area DeviceEnrollment;DeviceProvisioning -cab C:\enrollment.cab
  2. 0x80180018: fix the licence. In the Intune admin center open Users › All users, select the user and review Licenses (or use the Microsoft 365 admin center). The user needs a licence that includes Intune, and the Microsoft Intune service plan inside that licence must be turned on, not just the parent SKU. If the user was licensed a moment ago, give the change a few minutes before retrying. If you deliberately don't license some users and only want them Entra joined, keep them out of the MDM user scope so Windows doesn't attempt enrollment for them.
  3. 0x80180013 and 0x801c000E: check both device limits. Intune's limit lives at Devices › Device onboarding › Enrollment › Device limit restrictions and can be set from 1 to 15; it applies to user-driven enrollments only. Compare it with the count under Users › All users › the user › Devices and retire or delete records the user no longer uses. Entra joined, Autopilot, Group Policy, co-management, bulk and device enrollment manager enrollments aren't subject to the Intune limit; for those the cap is Maximum number of devices in the Entra admin center under Entra ID › Devices › Device settings (default 50, up to 100, or Unlimited; it doesn't apply to hybrid joined devices).
  4. 0x8018000A: remove the other connection. Sign in to Windows as the account that originally enrolled or joined the device, remove its connection in Settings › Accounts › Access work or school, sign back in as the intended user and enroll again.
  5. 0x80180014: allow Windows (MDM). Under Devices › Device onboarding › Enrollment › Device platform restriction, confirm that every restriction that can apply to the user allows Windows (MDM), including the default one.
  6. 0x8018002b and 0x80180003: check automatic enrollment and the UPN. Go to Devices › Device onboarding › Enrollment › Windows › Automatic Enrollment. Set MDM user scope to All, or Some with a group that contains the user, keep the three MDM URLs at their defaults and don't put the same users in the MAM (WIP) scope, because for personal devices the MAM scope wins. Automatic enrollment needs Microsoft Entra ID P1 or P2. If the tenant shows both Microsoft Intune and Microsoft Intune Enrollment under Mobility, the settings must be on Microsoft Intune. For hybrid joined devices, the user's UPN must use a verified, routable domain: a .local suffix fails, so fix the UPN suffix in Active Directory and run a delta sync.
  7. Retry. On a hybrid joined device, run gpupdate /force or start the task Schedule created by enrollment client for automatically enrolling in MDM from Microsoft Entra ID under Microsoft › Windows › EnterpriseMgmt in Task Scheduler; it otherwise retries every 5 minutes for a day. For OOBE, restart the flow after the tenant change has had time to apply.

Tip: The Microsoft 365 admin center has a self-help diagnostic for exactly this. Open Help & support, describe the problem ("I need help enrolling Windows devices"), enter the user's address and select Run tests. It checks licence, scope and restriction settings for that user without changing anything.

Verify the fix#

  • The DeviceManagement-Enterprise-Diagnostics-Provider › Admin log shows event 75 for the user, and no new event 76.
  • dsregcmd /status on the device reports AzureAdJoined : YES and a populated MdmUrl pointing at enrollment.manage.microsoft.com.
  • The device appears under Devices › Windows with a current last check-in, and the Entra device record shows Microsoft Intune in the MDM column.

Prevent it next time#

  • Use group-based licensing and make the same group the Some scope for automatic enrollment, so a user is never in scope without a licence.
  • Size device limits for how people actually work, and retire old records when hardware is replaced instead of raising the limit.
  • Keep the default enrollment restrictions permissive for Windows (MDM) and apply blocks through targeted, higher-priority restrictions.
  • Fix non-routable UPN suffixes before you enable Group Policy auto-enrollment, not after the first failure.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)