Runbook 01 · 24 scenarios
Enrolment and management
When a device will not enrol, check in, synchronise or receive management.
The “start here” text identifies the first control plane and evidence to inspect. It does not replace change approval, safeguarding requirements, backup or a tested rollback route.
User is not licensed for Intune
Start hereCheck licence assignment, enabled service plans and propagation.
Intune / EntraUser is outside automatic MDM enrolment scope
Start hereCheck Entra Mobility/MDM user scope and group membership.
Intune / EntraWindows enrolment is blocked by a platform restriction
Start hereReview the permitted platform, version and ownership settings.
Intune / EntraPersonal device enrolment is blocked
Start hereConfirm whether the device should be corporate before changing ownership.
Intune / EntraUser has reached the device-enrolment limit
Start hereReview existing devices and both Intune and Entra device limits.
Intune / EntraDevice joins Entra but does not enrol in Intune
Start hereCheck MDM scope, licence, scheduled tasks and MDM discovery URLs.
Intune / EntraDevice appears in Entra but not Intune
Start hereDistinguish registered, joined, hybrid joined and MDM-enrolled states.
Intune / EntraDevice appears in Intune but has stopped checking in
Start hereCheck last contact, connectivity, MDM certificate, time and services.
Intune / EntraMDM certificate is missing or expired
Start hereInspect the device certificate store and EnterpriseMgmt scheduled tasks.
Intune / EntraDevice was enrolled into the wrong tenant
Start hereConfirm tenant identity and follow an authorised removal and re-enrolment route.
Intune / EntraDuplicate or stale device records exist
Start hereMap the Entra, Intune and Autopilot objects before deleting anything.
Intune / EntraCorporate or personal ownership is incorrect
Start hereCorrect ownership only after confirming the school asset record.
Intune / EntraPrimary user is incorrect or missing
Start hereReview ownership and change the primary user where the platform supports it.
Intune / EntraCompany Portal cannot sign in
Start hereCheck app version, account state, licence and Conditional Access results.
Intune / EntraDevice sync remains pending or fails
Start hereCheck online status, notification services and the device sync report.
Intune / EntraIntune Management Extension is missing
Start hereConfirm eligibility and that a Win32 app, script or remediation is assigned.
Intune / EntraIntune Management Extension is stopped
Start hereCheck the service state and extension logs before reinstalling anything.
Intune / EntraHybrid Entra join never completes
Start hereCheck directory sync, service connection point, DNS and device registration.
Intune / EntraCo-managed device receives policy from the wrong authority
Start hereCheck Configuration Manager workload ownership and pilot collection.
Intune / EntraDevice Enrolment Manager account fails
Start hereCheck DEM licence, supported enrolment method and published limits.
Intune / EntraProxy, TLS inspection or firewall blocks management traffic
Start hereTest documented service endpoints, DNS and certificate trust.
Intune / EntraIncorrect date or time breaks authentication
Start hereRestore reliable time synchronisation before repeating enrolment.
Intune / EntraDevice object has been disabled in Entra
Start hereConfirm the reason and owner before restoring the object.
Intune / EntraEnrolment works for colleagues but not one user
Start hereCompare licence, scope, restrictions, device count and failure report.
Intune / Entra