A user joins a Windows device to Microsoft Entra ID or adds a work account, and instead of landing in Intune the device stops with "Something went wrong" and a code such as 80180018. The codes in the 0x8018xxxx range all come from the MDM enrollment client, and Microsoft publishes what each one means. In this post I'll map the common ones to the tenant setting that usually causes them, show where to check each setting, and explain how to confirm the fix from the device's enrollment log.
Symptoms#
- During OOBE, or in Settings › Accounts › Access work or school, enrollment stops with a dialog that ends in "contact your system administrator with the error code 80180018" (the dialog usually drops the
0xprefix). - The on-screen wording varies. You may see "This user isn't authorized to enroll" or "There was an error with your license". Microsoft's reference table ties
0x80180018itself to the user's licence state, so work from the code, not the sentence. - The Entra join part often succeeds: the device appears in Entra ID, but it never shows up under Devices › Windows in the Intune admin center.
- For Group Policy auto-enrollment there's no dialog at all. Instead the DeviceManagement-Enterprise-Diagnostics-Provider › Admin event log records event 76, "Auto MDM Enroll: Failed", with the code in the message.
Why it happens#
Windows reports a specific MENROLL_E_* value for each enrollment failure, and Microsoft documents them in the Windows client management reference. The table below lists the ones I see most, what Microsoft says they mean, and where in the tenant the cause normally lives.
| Code | Documented meaning | Where to look first |
|---|---|---|
0x80180018 | MENROLL_E_USERLICENSE: the user's licence is in a state that blocks enrollment | The enrolling user's licences and the Intune service plan |
0x80180013 | MENROLL_E_DEVICECAPREACHED: the user has already enrolled too many devices | Intune device limit restrictions; the user's existing device records |
0x801c000E | Entra device registration quota exceeded ("too many devices or users for this account") | Entra ID device settings, Maximum number of devices |
0x8018000A | MENROLL_E_DEVICE_ALREADY_ENROLLED: the device is already enrolled | Another account's work or school connection on the same device |
0x80180014 | MENROLL_E_DEVICENOTSUPPORTED: platform or version not supported; in Intune this is usually Windows (MDM) blocked by a platform restriction | Device platform restrictions |
0x80180003 | MENROLL_E_DEVICE_AUTHORIZATION_ERROR: the user isn't authorized to enroll | Who is enrolling: MDM user scope, restrictions, licence |
0x8018002b | "Auto MDM Enroll: Failed" for Group Policy enrollment: the UPN uses an unverified or non-routable domain, or the MDM user scope is None | UPN suffix; automatic enrollment settings |
0x80180010 | MENROLL_E_CONNECTIVITY: a network error such as DNS failure or a timeout | Proxy and firewall rules for the Intune endpoints |
Two licence-related messages don't come with a code. "This account is not allowed on this phone" means the user has no valid Intune licence. "Looks like the MDM Terms of Use endpoint is not correctly configured" appears when a tenant uses both basic mobility for Microsoft 365 and Intune and the user has no valid licence, or when the MDM terms of use URL in the Mobility settings is blank or wrong.
How to fix it#
- Get the exact code from the device. If the dialog is gone, open Event Viewer and go to Applications and Services Logs › Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin. Event 75 is a successful automatic enrollment; event 76 is a failed one and carries the code. To collect everything for later, run:
Command Prompt
mdmdiagnosticstool.exe -area DeviceEnrollment;DeviceProvisioning -cab C:\enrollment.cab 0x80180018: fix the licence. In the Intune admin center open Users › All users, select the user and review Licenses (or use the Microsoft 365 admin center). The user needs a licence that includes Intune, and the Microsoft Intune service plan inside that licence must be turned on, not just the parent SKU. If the user was licensed a moment ago, give the change a few minutes before retrying. If you deliberately don't license some users and only want them Entra joined, keep them out of the MDM user scope so Windows doesn't attempt enrollment for them.0x80180013and0x801c000E: check both device limits. Intune's limit lives at Devices › Device onboarding › Enrollment › Device limit restrictions and can be set from 1 to 15; it applies to user-driven enrollments only. Compare it with the count under Users › All users › the user › Devices and retire or delete records the user no longer uses. Entra joined, Autopilot, Group Policy, co-management, bulk and device enrollment manager enrollments aren't subject to the Intune limit; for those the cap is Maximum number of devices in the Entra admin center under Entra ID › Devices › Device settings (default 50, up to 100, or Unlimited; it doesn't apply to hybrid joined devices).0x8018000A: remove the other connection. Sign in to Windows as the account that originally enrolled or joined the device, remove its connection in Settings › Accounts › Access work or school, sign back in as the intended user and enroll again.0x80180014: allow Windows (MDM). Under Devices › Device onboarding › Enrollment › Device platform restriction, confirm that every restriction that can apply to the user allows Windows (MDM), including the default one.0x8018002band0x80180003: check automatic enrollment and the UPN. Go to Devices › Device onboarding › Enrollment › Windows › Automatic Enrollment. Set MDM user scope to All, or Some with a group that contains the user, keep the three MDM URLs at their defaults and don't put the same users in the MAM (WIP) scope, because for personal devices the MAM scope wins. Automatic enrollment needs Microsoft Entra ID P1 or P2. If the tenant shows both Microsoft Intune and Microsoft Intune Enrollment under Mobility, the settings must be on Microsoft Intune. For hybrid joined devices, the user's UPN must use a verified, routable domain: a.localsuffix fails, so fix the UPN suffix in Active Directory and run a delta sync.- Retry. On a hybrid joined device, run
gpupdate /forceor start the task Schedule created by enrollment client for automatically enrolling in MDM from Microsoft Entra ID under Microsoft › Windows › EnterpriseMgmt in Task Scheduler; it otherwise retries every 5 minutes for a day. For OOBE, restart the flow after the tenant change has had time to apply.
Tip: The Microsoft 365 admin center has a self-help diagnostic for exactly this. Open Help & support, describe the problem ("I need help enrolling Windows devices"), enter the user's address and select Run tests. It checks licence, scope and restriction settings for that user without changing anything.
Verify the fix#
- The DeviceManagement-Enterprise-Diagnostics-Provider › Admin log shows event 75 for the user, and no new event 76.
dsregcmd /statuson the device reportsAzureAdJoined : YESand a populatedMdmUrlpointing atenrollment.manage.microsoft.com.- The device appears under Devices › Windows with a current last check-in, and the Entra device record shows Microsoft Intune in the MDM column.
Prevent it next time#
- Use group-based licensing and make the same group the Some scope for automatic enrollment, so a user is never in scope without a licence.
- Size device limits for how people actually work, and retire old records when hardware is replaced instead of raising the limit.
- Keep the default enrollment restrictions permissive for Windows (MDM) and apply blocks through targeted, higher-priority restrictions.
- Fix non-routable UPN suffixes before you enable Group Policy auto-enrollment, not after the first failure.