Search all guides & tools⌘ / Ctrl KReader Hub
LAlite£14.99 · Buy on Gumroad ↗

Intune Support Centre · 203 support scenarios

Find the failed control plane.

Windows and macOS deployment, enrolment, compliance, updates, applications, security and new-user access—organised by symptom for school IT teams worldwide.

Search the catalogue ↓
ScopeEvidenceControlRepairVerify

Interactive Intune action map

See the action before opening the portal.

Select one stage. The portal route, control-plane flow, verification and stop condition remain together within one working panel.

01

Prepare

Make the tenant ready

Confirm identity, licensing, MDM authority and a protected pilot group before assigning policy.
01Entra identity
02Intune licence
03MDM scope
04Pilot group
Microsoft Intune admin centre
Intune admin centre → Tenant administration → Tenant status
First action

Verify the MDM authority, Intune licence, administrator role and Microsoft Entra MDM scope.

Evidence of success

A licensed pilot user is in scope and a test device can reach the Microsoft enrolment endpoints.

Why this stage matters

Confirm identity, licensing, MDM authority and a protected pilot group before assigning policy.

Stop condition

Do not begin with a production-wide assignment or remove an existing management authority.

Open the detailed route →
Do not reset first

Record the device identity, join and enrolment state, assignments, failed stage, recent change and logs. A wipe can remove evidence without correcting the tenant, licence, group, policy or network fault.

New: visual Apple device guides →

Novice deployment guides

Choose the platform, then follow one controlled route.

Windows

Move from MDT or SCCM to Intune

Tenant setup, Autopilot, policy translation, Dell and HP registration, safe PowerShell and troubleshooting.

Open Windows deployment →
iOS · iPadOS · macOS

Manage Apple devices without prior Intune experience

Visual guides for iPhone and iPad management, Mac enrolment choices, Company Portal, Microsoft Entra and Platform SSO.

Open Apple device guides →
01

Enrolment and management

When a device will not enrol, check in, synchronise or receive management.

24 scenarios →
02

Autopilot deployment

Registration, profiles, OOBE, TPM, ESP, pre-provisioning and reset failures.

34 scenarios →
03

Compliance and access

Find the failed compliance setting before changing Conditional Access.

26 scenarios →
04

Windows Update

Update rings, feature, quality, driver, restart and reporting failures.

23 scenarios →
05

Apps, scripts and remediations

Assignments, detection, installation, Company Portal, scripts and remediations.

28 scenarios →
06

Configuration and security

Policy conflicts, BitLocker, Defender, LAPS, certificates, Wi-Fi and VPN.

25 scenarios →
07

New-user onboarding

Accounts, licences, groups, Teams, mailboxes, access and support permissions.

43 scenarios →

Symptom finder

Start with what failed.

Search the complete catalogue, then open the relevant runbook. A matching result is a route to evidence—not permission to wipe, delete or weaken a security control.

203 scenarios
001User is not licensed for IntuneEnrolment

Start here: Check licence assignment, enabled service plans and propagation.

Primary control: Intune / Entra

Open this scenario in the runbook →
002User is outside automatic MDM enrolment scopeEnrolment

Start here: Check Entra Mobility/MDM user scope and group membership.

Primary control: Intune / Entra

Open this scenario in the runbook →
003Windows enrolment is blocked by a platform restrictionEnrolment

Start here: Review the permitted platform, version and ownership settings.

Primary control: Intune / Entra

Open this scenario in the runbook →
004Personal device enrolment is blockedEnrolment

Start here: Confirm whether the device should be corporate before changing ownership.

Primary control: Intune / Entra

Open this scenario in the runbook →
005User has reached the device-enrolment limitEnrolment

Start here: Review existing devices and both Intune and Entra device limits.

Primary control: Intune / Entra

Open this scenario in the runbook →
006Device joins Entra but does not enrol in IntuneEnrolment

Start here: Check MDM scope, licence, scheduled tasks and MDM discovery URLs.

Primary control: Intune / Entra

Open this scenario in the runbook →
007Device appears in Entra but not IntuneEnrolment

Start here: Distinguish registered, joined, hybrid joined and MDM-enrolled states.

Primary control: Intune / Entra

Open this scenario in the runbook →
008Device appears in Intune but has stopped checking inEnrolment

Start here: Check last contact, connectivity, MDM certificate, time and services.

Primary control: Intune / Entra

Open this scenario in the runbook →
009MDM certificate is missing or expiredEnrolment

Start here: Inspect the device certificate store and EnterpriseMgmt scheduled tasks.

Primary control: Intune / Entra

Open this scenario in the runbook →
010Device was enrolled into the wrong tenantEnrolment

Start here: Confirm tenant identity and follow an authorised removal and re-enrolment route.

Primary control: Intune / Entra

Open this scenario in the runbook →
011Duplicate or stale device records existEnrolment

Start here: Map the Entra, Intune and Autopilot objects before deleting anything.

Primary control: Intune / Entra

Open this scenario in the runbook →
012Corporate or personal ownership is incorrectEnrolment

Start here: Correct ownership only after confirming the school asset record.

Primary control: Intune / Entra

Open this scenario in the runbook →
Showing 12 of 203

Escalation boundary

Not every failure belongs to Intune.

These symptoms depend on hardware, networks, identity data, licensing, suppliers or organisational decisions. The support route should say so clearly.

Failed SSD, memory, battery, motherboard or display

Use hardware repair or manufacturer warranty.

Failed or defective TPM

Use BIOS or firmware remediation and manufacturer support.

No internet, failed switch port, VLAN or DHCP

Follow the network troubleshooting route.

Captive portal during Autopilot

Provide a supported deployment network.

Tenant-wide Microsoft service incident

Check Microsoft 365 service health and support.

Device registered to another organisation

Contact the previous tenant, reseller or manufacturer.

OEM failed to register purchased devices

Escalate to Dell, HP, reseller or the relevant OEM.

Broken third-party installer or application

Escalate to the software supplier or developer.

Unsupported Windows edition or hardware

Upgrade, replace or approve a documented exception.

Failed NDES, certificate authority or RADIUS

Escalate to the PKI or network service owner.

Incorrect authoritative HR identity data

Correct it with HR or the directory-data owner.

Missing paid licences

Escalate to procurement or the licensing administrator.

Windows feature-update safeguard hold

Investigate compatibility; do not bypass it automatically.

Legal, safeguarding or retention decision

Escalate to leadership, the DPO or safeguarding lead.

Search LAlite

A guide, a scenario or a checklist. Find it here.