oeltayeb.com · Intune Troubleshooting Toolkit

Checklist

Windows Autopilot error 0x80180014 when redeploying a device: cause and fix

Based on the article: Windows Autopilot error 0x80180014 when redeploying a device: cause and fix · 4 min read

You wipe or reset a Windows device that has been through Autopilot before, start the deployment again, and it stops at MDM enrollment with error 0x80180014. In this post I'll explain the two causes Microsoft documents for this error, how to tell them apart, and how to get the device through Autopilot again without touching its Autopilot registration.

Symptoms to confirm

The device downloads its Autopilot profile, but enrollment into Intune fails.

  • In self-deploying mode or the pre-provisioning technician flow, the device preparation phase of the Enrollment Status Page fails at Register your device for mobile management with 0x80180014.
  • In other enrollment paths the same code appears on an error page. For a manual Microsoft Entra join, Microsoft documents the message as "Your organization does not support this version of Windows. (0x80180014)".
  • The device enrolled fine the first time. The failure starts after it was wiped, reset, handed to someone else, or had its profile redeployed.
  • Event tracing (ETW) logs for MDM enrollment can show a DeviceNotSupported fault with the reason Enrollment blocked for AP device by SDM One Time Limit Check.

Likely causes

The Windows Autopilot troubleshooting FAQ describes two scenarios behind 0x80180014 on a previously enrolled device.

  • The old Intune device record blocks reuse. For self-deploying and pre-provisioning deployments, Intune requires the device record created by the previous enrollment to be cleared before the same hardware can enroll again. That applies whether the device is being reused, reset, or redeployed.
  • Windows MDM enrollment is blocked. If a device platform restriction that applies to the enrollment has Windows (MDM) set to Block, enrollment fails with the same code.

Checklist

  1. 1

    Rule out a platform block

    In the Microsoft Intune admin center, go to Devices › Windows › Enrollment › Device platform restriction. Open each Windows restriction, starting with All Users, select Properties, then Edit next to Platform settings.

  2. 2

    Unblock the device for reuse

    Go to Devices › Windows › Enrollment and, under Windows Autopilot, select Devices. Find the device by serial number, select it, and choose Unblock device in the toolbar.

  3. 3

    Alternatively, delete the stale Intune record

    The known-issues page documents deleting the device record in Intune and then redeploying. In Devices › Windows, open the old record, check the serial number so you remove the right one, and select Delete.

  4. 4

    Use the personally owned workaround only if you must

    Allowing personally owned Windows (MDM) devices in the restriction also clears the error, but it opens personal Windows enrollment for everyone that restriction covers. If you go this way, scope it narrowly and switch it back afterwards.

  5. 5

    Redeploy

    Reset the device and run the deployment again. For pre-provisioning, restart the technician flow by pressing the Windows key five times during OOBE.

Watch out: Don't "clean up" by also deleting the device from Windows Autopilot or from Microsoft Entra ID. If the Entra object that Autopilot created is deleted, the documented recovery is to delete and re-import the device as an Autopilot device, which costs far more time than the original error.

Verify

If the error comes back, collect logs before you change anything else.

  • The device gets past Register your device for mobile management and continues into device setup.
  • A new record shows up in Devices › Windows with the right serial number, Corporate ownership and a current last check-in time. Don't judge by the Enrolled date column: Microsoft lists a known issue where it shows the Autopilot registration date rather than the enrollment date.
  • The Autopilot deployment report under Devices › Monitor shows the new attempt as successful. The earlier failed attempt can stay in the report as a separate row.
cmd
mdmdiagnosticstool.exe -area Autopilot;TPM -cab C:\autopilot.cab

Prevent it next time

  • Make "unblock or delete the Intune record" a fixed step in your reuse runbook for self-deploying and pre-provisioned devices, done before the device boots back into OOBE.
  • Remove only the Intune object when you recycle hardware. Keep the Autopilot registration and its Entra device object so group tags, dynamic groups and profile assignment keep working.
  • Keep Windows (MDM) allowed in every restriction that can apply to Autopilot enrollments, and recheck restriction priority whenever you add a new one.
  • If personal Windows enrollment is blocked by design, fix reuse with unblock or delete rather than loosening the restriction.

Microsoft Learn references