Search all guides & tools⌘ / Ctrl KReader Hub
LAlite£14.99 · Buy on Gumroad ↗

Runbook 01 · 24 scenarios

Enrolment and management

When a device will not enrol, check in, synchronise or receive management.

Use these as diagnostic routes

The “start here” text identifies the first control plane and evidence to inspect. It does not replace change approval, safeguarding requirements, backup or a tested rollback route.

001

User is not licensed for Intune

Start hereCheck licence assignment, enabled service plans and propagation.

Intune / Entra
002

User is outside automatic MDM enrolment scope

Start hereCheck Entra Mobility/MDM user scope and group membership.

Intune / Entra
003

Windows enrolment is blocked by a platform restriction

Start hereReview the permitted platform, version and ownership settings.

Intune / Entra
004

Personal device enrolment is blocked

Start hereConfirm whether the device should be corporate before changing ownership.

Intune / Entra
005

User has reached the device-enrolment limit

Start hereReview existing devices and both Intune and Entra device limits.

Intune / Entra
006

Device joins Entra but does not enrol in Intune

Start hereCheck MDM scope, licence, scheduled tasks and MDM discovery URLs.

Intune / Entra
007

Device appears in Entra but not Intune

Start hereDistinguish registered, joined, hybrid joined and MDM-enrolled states.

Intune / Entra
008

Device appears in Intune but has stopped checking in

Start hereCheck last contact, connectivity, MDM certificate, time and services.

Intune / Entra
009

MDM certificate is missing or expired

Start hereInspect the device certificate store and EnterpriseMgmt scheduled tasks.

Intune / Entra
010

Device was enrolled into the wrong tenant

Start hereConfirm tenant identity and follow an authorised removal and re-enrolment route.

Intune / Entra
011

Duplicate or stale device records exist

Start hereMap the Entra, Intune and Autopilot objects before deleting anything.

Intune / Entra
012

Corporate or personal ownership is incorrect

Start hereCorrect ownership only after confirming the school asset record.

Intune / Entra
013

Primary user is incorrect or missing

Start hereReview ownership and change the primary user where the platform supports it.

Intune / Entra
014

Company Portal cannot sign in

Start hereCheck app version, account state, licence and Conditional Access results.

Intune / Entra
015

Device sync remains pending or fails

Start hereCheck online status, notification services and the device sync report.

Intune / Entra
016

Intune Management Extension is missing

Start hereConfirm eligibility and that a Win32 app, script or remediation is assigned.

Intune / Entra
017

Intune Management Extension is stopped

Start hereCheck the service state and extension logs before reinstalling anything.

Intune / Entra
018

Hybrid Entra join never completes

Start hereCheck directory sync, service connection point, DNS and device registration.

Intune / Entra
019

Co-managed device receives policy from the wrong authority

Start hereCheck Configuration Manager workload ownership and pilot collection.

Intune / Entra
020

Device Enrolment Manager account fails

Start hereCheck DEM licence, supported enrolment method and published limits.

Intune / Entra
021

Proxy, TLS inspection or firewall blocks management traffic

Start hereTest documented service endpoints, DNS and certificate trust.

Intune / Entra
022

Incorrect date or time breaks authentication

Start hereRestore reliable time synchronisation before repeating enrolment.

Intune / Entra
023

Device object has been disabled in Entra

Start hereConfirm the reason and owner before restoring the object.

Intune / Entra
024

Enrolment works for colleagues but not one user

Start hereCompare licence, scope, restrictions, device count and failure report.

Intune / Entra

Search LAlite

A guide, a scenario or a checklist. Find it here.