Checklist
Windows enrollment error 0x80180018 and its neighbours: what to check, and where
Based on the article: Windows enrollment error 0x80180018 and its neighbours: what to check, and where · 5 min read
A user joins a Windows device to Microsoft Entra ID or adds a work account, and instead of landing in Intune the device stops with "Something went wrong" and a code such as 80180018. The codes in the 0x8018xxxx range all come from the MDM enrollment client, and Microsoft publishes what each one means. In this post I'll map the common ones to the tenant setting that usually causes them, show where to check each setting, and explain how to confirm the fix from the device's enrollment log.
Symptoms to confirm
- During OOBE, or in Settings › Accounts › Access work or school, enrollment stops with a dialog that ends in "contact your system administrator with the error code 80180018" (the dialog usually drops the
0xprefix). - The on-screen wording varies. You may see "This user isn't authorized to enroll" or "There was an error with your license". Microsoft's reference table ties
0x80180018itself to the user's licence state, so work from the code, not the sentence. - The Entra join part often succeeds: the device appears in Entra ID, but it never shows up under Devices › Windows in the Intune admin center.
- For Group Policy auto-enrollment there's no dialog at all. Instead the DeviceManagement-Enterprise-Diagnostics-Provider › Admin event log records event 76, "Auto MDM Enroll: Failed", with the code in the message.
Likely causes
Windows reports a specific MENROLL_E_* value for each enrollment failure, and Microsoft documents them in the Windows client management reference.
| Code | Documented meaning | Where to look first |
|---|---|---|
0x80180018 | MENROLL_E_USERLICENSE: the user's licence is in a state that blocks enrollment | The enrolling user's licences and the Intune service plan |
0x80180013 | MENROLL_E_DEVICECAPREACHED: the user has already enrolled too many devices | Intune device limit restrictions; the user's existing device records |
0x801c000E | Entra device registration quota exceeded ("too many devices or users for this account") | Entra ID device settings, Maximum number of devices |
0x8018000A | MENROLL_E_DEVICE_ALREADY_ENROLLED: the device is already enrolled | Another account's work or school connection on the same device |
0x80180014 | MENROLL_E_DEVICENOTSUPPORTED: platform or version not supported; in Intune this is usually Windows (MDM) blocked by a platform restriction | Device platform restrictions |
0x80180003 | MENROLL_E_DEVICE_AUTHORIZATION_ERROR: the user isn't authorized to enroll | Who is enrolling: MDM user scope, restrictions, licence |
0x8018002b | "Auto MDM Enroll: Failed" for Group Policy enrollment: the UPN uses an unverified or non-routable domain, or the MDM user scope is None | UPN suffix; automatic enrollment settings |
0x80180010 | MENROLL_E_CONNECTIVITY: a network error such as DNS failure or a timeout | Proxy and firewall rules for the Intune endpoints |
- Two licence-related messages don't come with a code. "This account is not allowed on this phone" means the user has no valid Intune licence.
Checklist
- 1
Get the exact code from the device
If the dialog is gone, open Event Viewer and go to Applications and Services Logs › Microsoft › Windows › DeviceManagement-Enterprise-Diagnostics-Provider › Admin. Event 75 is a successful automatic enrollment; event 76 is a failed one and carries the code. To collect everything for later, run:
cmdmdmdiagnosticstool.exe -area DeviceEnrollment;DeviceProvisioning -cab C:\enrollment.cab - 2
0x80180018: fix the licenceIn the Intune admin center open Users › All users, select the user and review Licenses (or use the Microsoft 365 admin center). The user needs a licence that includes Intune, and the Microsoft Intune service plan inside that licence must be turned on, not just the parent SKU.
- 3
0x80180013and0x801c000E: check both device limitsIntune's limit lives at Devices › Device onboarding › Enrollment › Device limit restrictions and can be set from 1 to 15; it applies to user-driven enrollments only. Compare it with the count under Users › All users › the user › Devices and retire or delete records the user no longer uses.
- 4
0x8018000A: remove the other connectionSign in to Windows as the account that originally enrolled or joined the device, remove its connection in Settings › Accounts › Access work or school, sign back in as the intended user and enroll again.
- 5
0x80180014: allow Windows (MDM)Under Devices › Device onboarding › Enrollment › Device platform restriction, confirm that every restriction that can apply to the user allows Windows (MDM), including the default one.
- 6
0x8018002band0x80180003: check automatic enrollment and the UPNGo to Devices › Device onboarding › Enrollment › Windows › Automatic Enrollment. Set MDM user scope to All, or Some with a group that contains the user, keep the three MDM URLs at their defaults and don't put the same users in the MAM (WIP) scope, because for personal devices the MAM scope wins.
- 7
Retry
On a hybrid joined device, run
gpupdate /forceor start the task Schedule created by enrollment client for automatically enrolling in MDM from Microsoft Entra ID under Microsoft › Windows › EnterpriseMgmt in Task Scheduler; it otherwise retries every 5 minutes for a day. For OOBE, restart the flow after the tenant change has had time to apply.
Tip: The Microsoft 365 admin center has a self-help diagnostic for exactly this. Open Help & support, describe the problem ("I need help enrolling Windows devices"), enter the user's address and select Run tests. It checks licence, scope and restriction settings for that user without changing anything.
Verify
- The DeviceManagement-Enterprise-Diagnostics-Provider › Admin log shows event 75 for the user, and no new event 76.
dsregcmd /statuson the device reportsAzureAdJoined : YESand a populatedMdmUrlpointing atenrollment.manage.microsoft.com.- The device appears under Devices › Windows with a current last check-in, and the Entra device record shows Microsoft Intune in the MDM column.
Prevent it next time
- Use group-based licensing and make the same group the Some scope for automatic enrollment, so a user is never in scope without a licence.
- Size device limits for how people actually work, and retire old records when hardware is replaced instead of raising the limit.
- Keep the default enrollment restrictions permissive for Windows (MDM) and apply blocks through targeted, higher-priority restrictions.
- Fix non-routable UPN suffixes before you enable Group Policy auto-enrollment, not after the first failure.