Autopilot ESP troubleshooting checklist
Find the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.
Checklists, log references and decision trees distilled from the guides on this site — free for the Microsoft community. Every resource links back to the full article it came from, so you can trust the steps and go deeper when you need to.
Checklists for the enrollment, Win32 app, compliance, BitLocker, script and device-sync problems that fill an Intune admin's week, plus the Intune Management Extension log reference and an enrollment decision tree — each distilled from a full guide on this site.
12 checklists · 2 references · 1 decision tree
Find the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.
0x87D1041C means the installer finished but the detection rule found nothing. The usual causes (bitness, install context, version drift) and how to test detection on the device.
A reused Autopilot device fails MDM enrollment with 0x80180014. Why it happens, and the documented fixes: unblock or remove the stale Intune record and check enrollment restrictions.
Windows MDM enrollment fails with 0x80180018 or a nearby 0x8018 code. What Microsoft documents for each code, which tenant setting is behind it, and how to confirm the fix in the enrollment event log.
Why devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.
A practical checklist for failed Android personally owned work profile enrollments: Managed Google Play, restrictions, licences, device requirements, existing profiles and logs.
Why Apple ADE devices don't appear in Intune or enroll without the right policy: device assignment, token sync limits and renewal, default policies, and why a reset is needed.
A Windows device shows a stale last check-in in Intune and policies stop arriving. How check-in works, what to inspect on the device (service, tasks, certificate, network) and when to re-enroll.
Silent BitLocker not starting? Check TPM, UEFI, Secure Boot and WinRE, the required policy settings, startup authentication conflicts and recovery key backup to Microsoft Entra ID.
An Intune platform script reports Failed or never runs. How the Intune Management Extension executes scripts, what the three script settings change, how retries and re-runs work, and where to look.
Microsoft Entra hybrid join Autopilot deployments can time out with 0x80004005 on older Windows 11 builds. How to confirm the known issue, which KBs fix it and how to get devices onto a fixed build.
Export your Intune device inventory to CSV with the Microsoft Graph PowerShell SDK, spot stale and noncompliant devices, and run it unattended with certificate-based app-only sign-in.
What each Intune Management Extension log records, how to read them with CMTrace, what to search for, how to force a check-in, and how to collect the logs remotely.
Settings stuck on Conflict in Intune? Find the competing policies, confirm what the device received with the MDM diagnostic report and event log, and rule out Group Policy.
Start from what you see on the device and follow the branches to the guide that fixes it — 9 enrollment and Autopilot failures on one printable page.
Onboarding, antivirus policy, attack surface reduction, tamper protection and sensor-health checklists for Microsoft Defender for Endpoint on Windows and macOS, including the Sense event IDs you need when onboarding goes wrong.
7 checklists
Connect Intune to Microsoft Defender for Endpoint, onboard Windows devices with an EDR policy, then prove it worked on the device, in the Defender portal and with a detection test.
Intune says the antivirus policy succeeded but the device disagrees. Check the management channel, conflicts, passive mode, tamper protection and exclusion behaviour to find out why.
A phased plan for attack surface reduction rules in Intune: standard rules straight to Block, the rest in Audit, measured with advanced hunting, narrow exclusions, then enforce.
What Inactive, Impaired communications and No sensor data mean in the Defender device inventory, and how to check the sensor, onboarding state, proxy and duplicate device records.
A field guide to Defender for Endpoint onboarding failures: onboarding script error codes, SENSE Operational event IDs, Intune error codes, and the registry and service checks that show where it broke.
What tamper protection locks, the four places it can be managed and their precedence, how to see which one controls a device, and how to fix settings that won't apply or exclusions that aren't protected.
The Intune deployment for Defender for Endpoint on Mac in the documented order: system extensions, Full Disk Access, network filter, background services, the app, the onboarding package, mdatp checks and fixes.
Conditional Access, Primary Refresh Token, hybrid join and PIM checklists, walkthroughs for the AADSTS errors users actually report, Entra Connect sync errors, and a reference for reading sign-in logs like an engineer.
7 checklists · 1 reference
The core Conditional Access policies to deploy first, how they map to Microsoft's templates and Microsoft-managed policies, and how to roll them out in report-only mode without locking anyone out.
How the Primary Refresh Token powers single sign-on on Windows, how to check it with dsregcmd and the AAD event logs, and how to fix a missing or stale PRT.
Read dsregcmd /status for hybrid join failures, check the SCP and Entra Connect sync, use the User Device Registration log and clear devices stuck in Pending.
Set up PIM for Microsoft Entra roles: role settings, eligible assignments, activation and approvals, PIM for Groups, alerts, access reviews, and the activation problems you'll hit.
What AADSTS53000, 53001 and 53003 actually mean, how to find the blocking policy in the sign-in logs, and how to fix compliance and browser device-identity gaps.
What the MFA-related AADSTS codes mean, how to read the Authentication details and Conditional Access tabs of a sign-in, and how to fix legacy clients, unregistered users and authentication strength mismatches.
How to read Entra Connect export errors such as AttributeValueMustBeUnique, InvalidSoftMatch and LargeObject, fix matching problems with ms-DS-ConsistencyGuid, and find objects that filtering keeps out of Entra ID.
The four sign-in log types, the fields that matter, how to trace one failed sign-in end to end, KQL against the SigninLogs table, export and retention by licence, and the misreads that waste hours.
Mail-flow checklists for message trace, SPF/DKIM/DMARC, the NDRs admins meet most often, compromised-mailbox investigation and anti-spam tuning, plus the SMTP AUTH relay reference for printers and apps.
6 checklists · 1 reference
Run a message trace in the Exchange admin center or with Get-MessageTraceV2, read the delivery status and events, and pull older data from downloadable reports.
Publish one correct SPF record, turn on DKIM signing in the Defender portal, then move DMARC from p=none to p=reject without blocking your own legitimate mail.
Why Exchange Online blocks automatic forwarding to external addresses with 5.7.520, and how to allow it only for the mailboxes that need it instead of for everyone.
Why Exchange Online rejects mail with 550 5.4.1 at the perimeter, how Directory-Based Edge Blocking and the accepted domain type cause it, and how to fix each common cause.
Microsoft's response order for a compromised mailbox, cmdlets that find malicious inbox rules and forwarding across every mailbox, what to read in sign-in and audit logs, and how to harden afterwards.
Read the X-Forefront-Antispam-Report header (CAT, SFV, BCL, compauth) to see why a good message was junked, then fix it the supported way: submissions, Tenant Allow/Block List, sender authentication, not bypass rules.
What error 5.7.57 means, how SMTP AUTH client submission, SMTP relay and Direct Send differ, how to fix each cause, and where Basic authentication for SMTP AUTH stands.
Tell me which problem you keep solving by hand — the next checklist, log reference or decision tree may come from your suggestion.