Decision tree
Enrollment & Autopilot troubleshooting decision tree
Based on the articles linked at each leaf.
Start from what you see on the device, follow the branch that matches, and open the guide at the leaf. Each leaf links to the full troubleshooting article on oeltayeb.com.
Device fails during enrollment / Autopilot — what do you see?
- During OOBE / Autopilot
- Enrollment Status Page times outEnrollment Status Page timing out during Autopilot: a step-by-step troubleshooting guideFind the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.
- Error 0x80180014 when redeploying a deviceWindows Autopilot error 0x80180014 when redeploying a device: cause and fixA reused Autopilot device fails MDM enrollment with 0x80180014. Why it happens, and the documented fixes: unblock or remove the stale Intune record and check enrollment restrictions.
- Enrollment error 0x80180018 (or a nearby 0x8018 code)Windows enrollment error 0x80180018 and its neighbours: what to check, and whereWindows MDM enrollment fails with 0x80180018 or a nearby 0x8018 code. What Microsoft documents for each code, which tenant setting is behind it, and how to confirm the fix in the enrollment event log.
- Hybrid join deployment times out with 0x80004005Hybrid join Autopilot deployments time out with 0x80004005: the 2026 known issue and the fixMicrosoft Entra hybrid join Autopilot deployments can time out with 0x80004005 on older Windows 11 builds. How to confirm the known issue, which KBs fix it and how to get devices onto a fixed build.
- Pre-provisioning hybrid join fails (0x800706FD)Pre-provisioning hybrid join fails when a policy needs a domain controller (0x800706FD)Autopilot pre-provisioning for hybrid join fails in the technician flow when a policy such as a User Rights setting needs a domain controller. How to read the 0x800706FD event and fix the scoping.
- Device is enrolled, but…
- Device not checking in / stopped syncingIntune device not checking in: diagnosing a Windows device that stopped syncingA Windows device shows a stale last check-in in Intune and policies stop arriving. How check-in works, what to inspect on the device (service, tasks, certificate, network) and when to re-enroll.
- Company Portal: Sync fails, device not enrolled or assigned to someone elseCompany Portal for Windows: Sync fails, device not enrolled or assigned to someone elseWhat the Company Portal Sync button really does, why the app says a device isn't set up or belongs to another user, how the primary user drives it, and where the logs are.
- Apps and compliance after enrollment
- Win32 app installed but Intune can't detect it (0x87D1041C)Win32 app error 0x87D1041C: the app installed but Intune can't detect it0x87D1041C means the installer finished but the detection rule found nothing. The usual causes (bitness, install context, version drift) and how to test detection on the device.
- Noncompliant on the Default Device Compliance PolicyNoncompliant on the Default Device Compliance Policy? The three built-in checks explainedWhy devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.
How to use this tree
- Confirm the symptom on the device before you act: the leaf text is the wording used in the matching article.
- If two leaves fit, start with the one that happens earliest in the deployment (OOBE first, then check-in, then apps and compliance).
- Each linked article has a Verify section — tick it off before you close the ticket.