Intune Enrollment Eligibility Checker Fast answers for working admins
Windows Autopilot user-driven enrollment
Answer: Requires a registered Autopilot device, supported Windows edition, network access, and an eligible licensed user in the intended tenant.
Administrator playbook

Decide, verify, and document

Use the curated answer as a starting point, then prove the outcome against the target tenant or device.

1

What it means

  • Deployment profile must be assigned
  • Device identity must exist in the correct tenant
2

What to check next

  1. Verify hardware hash and profile status
  2. Check licensing, MDM scope, and enrollment restrictions
3

Verify success

  1. Confirm a new device record appears in the intended tenant and ownership state.
  2. Verify the device checks in, receives policy, and reports compliant or the expected transitional state.
  3. Capture a fresh successful enrollment timestamp and remove obsolete duplicate records.
4

Escalate when

  • Multiple known-good users or devices fail at the same enrollment stage.
  • The failure persists after scope, restriction, licensing, and stale-object checks.
  • You can provide sanitized enrollment logs, UTC time, tenant, and correlation identifiers.
Copyable admin briefAnswer, next checks, source, and review date
Inspect join and registration state
dsregcmd /status

Read-only. Review Device State, Tenant Details, and SSO State; redact tenant and user identifiers before sharing.

Collect enrollment diagnostics
mdmdiagnosticstool.exe -area "DeviceEnrollment;DeviceProvisioning;Autopilot" -zip "C:\Users\Public\Documents\MDMDiagReport.zip"

Creates a local ZIP. Review and redact identifiers before sharing it.

Evidence to preserve

  • Platform, ownership, and OS version
  • User license and MDM scope
  • Enrollment restriction and device limit
  • UTC failure time and enrollment error