Intune Enrollment Eligibility Checker Fast answers for working admins
Windows Autopilot self-deploying mode
Answer: Self-deploying mode is a corporate-owned, userless Autopilot flow that requires a registered device, assigned profile, supported TPM attestation, network access, and an appropriate device-management licensing model.
Administrator playbook

Decide, verify, and document

Use the curated answer as a starting point, then prove the outcome against the target tenant or device.

1

What it means

  • Designed for kiosks, shared devices, and userless scenarios
  • TPM attestation is central to the flow
  • No user credentials are entered during provisioning
2

What to check next

  1. Confirm hardware hash, profile assignment, and device ownership
  2. Validate TPM 2.0 attestation and firmware readiness
  3. Check network access to required Microsoft endpoints
3

Verify success

  1. Confirm a new device record appears in the intended tenant and ownership state.
  2. Verify the device checks in, receives policy, and reports compliant or the expected transitional state.
  3. Capture a fresh successful enrollment timestamp and remove obsolete duplicate records.
4

Escalate when

  • Multiple known-good users or devices fail at the same enrollment stage.
  • The failure persists after scope, restriction, licensing, and stale-object checks.
  • You can provide sanitized enrollment logs, UTC time, tenant, and correlation identifiers.
Copyable admin briefAnswer, next checks, source, and review date
Inspect join and registration state
dsregcmd /status

Read-only. Review Device State, Tenant Details, and SSO State; redact tenant and user identifiers before sharing.

Collect enrollment diagnostics
mdmdiagnosticstool.exe -area "DeviceEnrollment;DeviceProvisioning;Autopilot" -zip "C:\Users\Public\Documents\MDMDiagReport.zip"

Creates a local ZIP. Review and redact identifiers before sharing it.

Evidence to preserve

Platform
Windows
Ownership
Corporate
User affinity
None
Reset
Required for the OOBE flow
  • Platform, ownership, and OS version
  • User license and MDM scope
  • Enrollment restriction and device limit
  • UTC failure time and enrollment error