Overview Windows Apple Enrolment Autopilot & ESP Compliance Updates Apps & scripts Security Skip to main content Intune Support Centre · 203 support scenarios
Find the failed control plane. Windows and macOS deployment, enrolment, compliance, updates, applications, security and new-user access—organised by symptom for school IT teams worldwide.
Search the catalogue ↓ Book reference 4.4 — Standardised builds, Intune and the hybrid estate Start with the durable first-line checks in the book, then use this centre for current console paths and failure scenarios.
Scope → Evidence → Control → Repair → Verify
Enrol macOS devices Enrol iPads macOS + Entra ID / Platform SSO Interactive Intune action map
See the action before opening the portal. Select one stage. The portal route, control-plane flow, verification and stop condition remain together within one working panel.
01 Prepare Make the tenant ready 02 Enrol Choose one enrolment route 03 Configure Layer settings deliberately 04 Protect Connect compliance to access 05 Deliver Deploy applications in rings 06 Prove Troubleshoot the failed stage 01 Prepare
Make the tenant ready Confirm identity, licensing, MDM authority and a protected pilot group before assigning policy. 01 Entra identity →
02 Intune licence →
03 MDM scope →
04 Pilot group
Microsoft Intune admin centre
Intune admin centre → Tenant administration → Tenant status
First action Verify the MDM authority, Intune licence, administrator role and Microsoft Entra MDM scope.
Evidence of success A licensed pilot user is in scope and a test device can reach the Microsoft enrolment endpoints.
Why this stage matters Confirm identity, licensing, MDM authority and a protected pilot group before assigning policy.
Stop condition Do not begin with a production-wide assignment or remove an existing management authority.
Open the detailed route → Do not reset first Record the device identity, join and enrolment state, assignments, failed stage, recent change and logs. A wipe can remove evidence without correcting the tenant, licence, group, policy or network fault.
New: visual Apple device guides → 01 Enrolment and management When a device will not enrol, check in, synchronise or receive management.
24 scenarios → 02 Autopilot deployment Registration, profiles, OOBE, TPM, ESP, pre-provisioning and reset failures.
34 scenarios → 03 Compliance and access Find the failed compliance setting before changing Conditional Access.
26 scenarios → 04 Windows Update Update rings, feature, quality, driver, restart and reporting failures.
23 scenarios → 05 Apps, scripts and remediations Assignments, detection, installation, Company Portal, scripts and remediations.
28 scenarios → 06 Configuration and security Policy conflicts, BitLocker, Defender, LAPS, certificates, Wi-Fi and VPN.
25 scenarios → 07 New-user onboarding Accounts, licences, groups, Teams, mailboxes, access and support permissions.
43 scenarios → Symptom finder
Start with what failed. Search the complete catalogue, then open the relevant runbook. A matching result is a route to evidence—not permission to wipe, delete or weaken a security control.
203 scenarios
001 User is not licensed for Intune Enrolment 002 User is outside automatic MDM enrolment scope Enrolment 003 Windows enrolment is blocked by a platform restriction Enrolment 004 Personal device enrolment is blocked Enrolment 005 User has reached the device-enrolment limit Enrolment 006 Device joins Entra but does not enrol in Intune Enrolment 007 Device appears in Entra but not Intune Enrolment 008 Device appears in Intune but has stopped checking in Enrolment 009 MDM certificate is missing or expired Enrolment 010 Device was enrolled into the wrong tenant Enrolment 011 Duplicate or stale device records exist Enrolment 012 Corporate or personal ownership is incorrect Enrolment Show 12 more Showing 12 of 203
Escalation boundary
Not every failure belongs to Intune. These symptoms depend on hardware, networks, identity data, licensing, suppliers or organisational decisions. The support route should say so clearly.
Failed SSD, memory, battery, motherboard or display Use hardware repair or manufacturer warranty.
Failed or defective TPM Use BIOS or firmware remediation and manufacturer support.
No internet, failed switch port, VLAN or DHCP Follow the network troubleshooting route.
Captive portal during Autopilot Provide a supported deployment network.
Tenant-wide Microsoft service incident Check Microsoft 365 service health and support.
Device registered to another organisation Contact the previous tenant, reseller or manufacturer.
OEM failed to register purchased devices Escalate to Dell, HP, reseller or the relevant OEM.
Broken third-party installer or application Escalate to the software supplier or developer.
Unsupported Windows edition or hardware Upgrade, replace or approve a documented exception.
Failed NDES, certificate authority or RADIUS Escalate to the PKI or network service owner.
Incorrect authoritative HR identity data Correct it with HR or the directory-data owner.
Missing paid licences Escalate to procurement or the licensing administrator.
Windows feature-update safeguard hold Investigate compatibility; do not bypass it automatically.
Legal, safeguarding or retention decision Escalate to leadership, the DPO or safeguarding lead.