oeltayeb.com · Intune Troubleshooting Toolkit

Checklist

Windows enrollment error 0x80180018 and its neighbours: what to check, and where

Based on the article: Windows enrollment error 0x80180018 and its neighbours: what to check, and where · 5 min read

A user joins a Windows device to Microsoft Entra ID or adds a work account, and instead of landing in Intune the device stops with "Something went wrong" and a code such as 80180018. The codes in the 0x8018xxxx range all come from the MDM enrollment client, and Microsoft publishes what each one means. In this post I'll map the common ones to the tenant setting that usually causes them, show where to check each setting, and explain how to confirm the fix from the device's enrollment log.

Symptoms to confirm

  • During OOBE, or in Settings › Accounts › Access work or school, enrollment stops with a dialog that ends in "contact your system administrator with the error code 80180018" (the dialog usually drops the 0x prefix).
  • The on-screen wording varies. You may see "This user isn't authorized to enroll" or "There was an error with your license". Microsoft's reference table ties 0x80180018 itself to the user's licence state, so work from the code, not the sentence.
  • The Entra join part often succeeds: the device appears in Entra ID, but it never shows up under Devices › Windows in the Intune admin center.
  • For Group Policy auto-enrollment there's no dialog at all. Instead the DeviceManagement-Enterprise-Diagnostics-Provider › Admin event log records event 76, "Auto MDM Enroll: Failed", with the code in the message.

Likely causes

Windows reports a specific MENROLL_E_* value for each enrollment failure, and Microsoft documents them in the Windows client management reference.

CodeDocumented meaningWhere to look first
0x80180018MENROLL_E_USERLICENSE: the user's licence is in a state that blocks enrollmentThe enrolling user's licences and the Intune service plan
0x80180013MENROLL_E_DEVICECAPREACHED: the user has already enrolled too many devicesIntune device limit restrictions; the user's existing device records
0x801c000EEntra device registration quota exceeded ("too many devices or users for this account")Entra ID device settings, Maximum number of devices
0x8018000AMENROLL_E_DEVICE_ALREADY_ENROLLED: the device is already enrolledAnother account's work or school connection on the same device
0x80180014MENROLL_E_DEVICENOTSUPPORTED: platform or version not supported; in Intune this is usually Windows (MDM) blocked by a platform restrictionDevice platform restrictions
0x80180003MENROLL_E_DEVICE_AUTHORIZATION_ERROR: the user isn't authorized to enrollWho is enrolling: MDM user scope, restrictions, licence
0x8018002b"Auto MDM Enroll: Failed" for Group Policy enrollment: the UPN uses an unverified or non-routable domain, or the MDM user scope is NoneUPN suffix; automatic enrollment settings
0x80180010MENROLL_E_CONNECTIVITY: a network error such as DNS failure or a timeoutProxy and firewall rules for the Intune endpoints
  • Two licence-related messages don't come with a code. "This account is not allowed on this phone" means the user has no valid Intune licence.

Checklist

  1. 1

    Get the exact code from the device

    If the dialog is gone, open Event Viewer and go to Applications and Services Logs › Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin. Event 75 is a successful automatic enrollment; event 76 is a failed one and carries the code. To collect everything for later, run:

    cmd
    mdmdiagnosticstool.exe -area DeviceEnrollment;DeviceProvisioning -cab C:\enrollment.cab
  2. 2

    0x80180018: fix the licence

    In the Intune admin center open Users › All users, select the user and review Licenses (or use the Microsoft 365 admin center). The user needs a licence that includes Intune, and the Microsoft Intune service plan inside that licence must be turned on, not just the parent SKU.

  3. 3

    0x80180013 and 0x801c000E: check both device limits

    Intune's limit lives at Devices › Device onboarding › Enrollment › Device limit restrictions and can be set from 1 to 15; it applies to user-driven enrollments only. Compare it with the count under Users › All users › the user › Devices and retire or delete records the user no longer uses.

  4. 4

    0x8018000A: remove the other connection

    Sign in to Windows as the account that originally enrolled or joined the device, remove its connection in Settings › Accounts › Access work or school, sign back in as the intended user and enroll again.

  5. 5

    0x80180014: allow Windows (MDM)

    Under Devices › Device onboarding › Enrollment › Device platform restriction, confirm that every restriction that can apply to the user allows Windows (MDM), including the default one.

  6. 6

    0x8018002b and 0x80180003: check automatic enrollment and the UPN

    Go to Devices › Device onboarding › Enrollment › Windows › Automatic Enrollment. Set MDM user scope to All, or Some with a group that contains the user, keep the three MDM URLs at their defaults and don't put the same users in the MAM (WIP) scope, because for personal devices the MAM scope wins.

  7. 7

    Retry

    On a hybrid joined device, run gpupdate /force or start the task Schedule created by enrollment client for automatically enrolling in MDM from Microsoft Entra ID under Microsoft › Windows › EnterpriseMgmt in Task Scheduler; it otherwise retries every 5 minutes for a day. For OOBE, restart the flow after the tenant change has had time to apply.

Tip: The Microsoft 365 admin center has a self-help diagnostic for exactly this. Open Help & support, describe the problem ("I need help enrolling Windows devices"), enter the user's address and select Run tests. It checks licence, scope and restriction settings for that user without changing anything.

Verify

  • The DeviceManagement-Enterprise-Diagnostics-Provider › Admin log shows event 75 for the user, and no new event 76.
  • dsregcmd /status on the device reports AzureAdJoined : YES and a populated MdmUrl pointing at enrollment.manage.microsoft.com.
  • The device appears under Devices › Windows with a current last check-in, and the Entra device record shows Microsoft Intune in the MDM column.

Prevent it next time

  • Use group-based licensing and make the same group the Some scope for automatic enrollment, so a user is never in scope without a licence.
  • Size device limits for how people actually work, and retire old records when hardware is replaced instead of raising the limit.
  • Keep the default enrollment restrictions permissive for Windows (MDM) and apply blocks through targeted, higher-priority restrictions.
  • Fix non-routable UPN suffixes before you enable Group Policy auto-enrollment, not after the first failure.

Microsoft Learn references