Most Windows Autopilot error codes map to a short list of documented causes: 0x80180014 means a self-deploying or pre-provisioned device must be unblocked or Windows (MDM) enrollment is blocked by a platform restriction; 0x800705b4 and 0x801c03ea are TPM attestation failures, usually because the device lacks a usable physical TPM 2.0; and 80180018 or the "MDM terms of use" error point to licensing or the user's device limit. Collect the Autopilot diagnostics first, match the code or event ID against the tables below, and apply the documented fix rather than resetting the device repeatedly.
Who this is for and what you will have
This reference is for Intune and endpoint administrators handling failed Windows Autopilot deployments in user-driven, self-deploying, pre-provisioning or Microsoft Entra hybrid join scenarios. It only lists codes and fixes that Microsoft documents. At the end you will have:
- A repeatable way to collect logs from a failed device, in OOBE or remotely.
- A lookup table for enrollment, TPM attestation, hybrid join and registration errors.
- The Event Viewer IDs and registry values that confirm each diagnosis.
If the device is not failing with a code but is stuck on the Enrollment Status Page, see Intune Enrollment Status Page stuck instead.
Prerequisites
- Intune Administrator, or a role with Windows Autopilot device and enrollment permissions, in the Microsoft Intune admin center.
- Physical or remote access to the failing device. In OOBE on a non-S mode device, Shift+F10 opens a command prompt.
- A USB drive if you want users to export logs from the device.
Step 1: Collect the evidence
Don't start with a reset. The failure screen, the event log and the registry usually identify the cause.
On the device
On Windows 11 user-driven deployments, the Autopilot diagnostics page opens with Ctrl+Shift+D or the View Diagnostics button, provided the ESP profile has Show app and profile configuration progress and Turn on log collection and diagnostics page for end users set to Yes. It shows network connectivity, Autopilot settings and enrollment status, and has an Export logs button.
From a command prompt (Shift+F10 in OOBE), collect a cab file. Use the first command for user-driven deployments and the second for self-deploying, pre-provisioning or any physical-device scenario where TPM attestation is involved:
mdmdiagnosticstool.exe -area Autopilot -cab C:\Diagnostics\Autopilot.cab
mdmdiagnosticstool.exe -area Autopilot;TPM -cab C:\Diagnostics\AutopilotTPM.cabTo summarize a cab file on an admin workstation, use Microsoft's Get-AutopilotDiagnostics script from the PowerShell Gallery:
Install-Script -Name Get-AutopilotDiagnostics -Force
Get-AutopilotDiagnostics -CABFile C:\Diagnostics\Autopilot.cabRemotely
Intune collects diagnostics automatically when an Autopilot deployment fails, and keeps them for 28 days. For the upload to work, lgmsapeweu.blob.core.windows.net must not be blocked. You can also select a device under Devices > All devices and choose Collect diagnostics.
What to read
- Event Viewer: Application and Services Logs > Microsoft > Windows > ModernDeployment-Diagnostics-Provider > Autopilot.
- Registry:
HKLM\SOFTWARE\Microsoft\Provisioning\Diagnostics\Autopilot.CloudAssignedTenantDomainandCloudAssignedTenantIdare blank if the device isn't registered.IsAutopilotDisabledset to1means the device isn't registered or the profile couldn't be downloaded because of network, firewall or timeout problems.TenantMatchedset to0means the user signed in to a different tenant from the one the device is registered to.
Quick lookup table
| Code or message | Where you see it | Documented cause | Fix |
|---|---|---|---|
0x80180014 | Redeploying a device | Self-deploying or pre-provisioning one-time limit, or Windows (MDM) blocked | Unblock or delete the device record; allow Windows (MDM) |
80180018 | "Something went wrong" page | Missing license or device enrollment limit | Assign a license with Intune; check device limits |
| "Can't connect to the URL of your organization's MDM terms of use" | OOBE | User has no Intune, EMS or Microsoft 365 license | License the user |
0x80180022 | Enrollment | Device runs Windows Home | Upgrade to Pro or higher |
8018000a | Enrollment | Device already enrolled or joined by another user | Remove the other work or school account |
0x800705b4 | "Securing your hardware" | Timeout; no physical TPM 2.0 | Use supported hardware |
0x801c03ea | "Registering your device for mobile management" | TPM attestation failed | Upgrade TPM to 2.0; check duplicate profile assignments |
0x81039001 | "Securing your hardware" | TPM attestation retries exceeded | Retry provisioning |
0x81039023 | Windows 11 attestation | Fixed in KB5013943 for 21H2 | Update Windows |
0x81039024 | Windows 11 attestation | Known TPM vulnerabilities detected | Update TPM firmware |
0x80070490 | AMD fTPM attestation | AMD ASP fTPM firmware issue | Update firmware |
0xc1036501 | Self-deploying | Multiple MDM configurations in Entra ID | Leave one MDM configuration |
0x801C03F3 | Pre-provisioning | Entra device object deleted | Deregister and re-register |
0x80070774 | Hybrid join | Domain mismatch, Assign user, or deleted Entra object | See hybrid section |
0x80004005 | Hybrid join timeouts | Windows issue | Install the listed KB |
Enrollment and licensing errors
0x80180014
Microsoft documents two causes.
The device was previously deployed with self-deploying or pre-provisioning mode. Reusing or resetting such a device requires removing the block. In the Intune admin center, go to Devices > Windows > Enrollment > Windows Autopilot > Devices, select the device and select Unblock device, then redeploy. A success message might not appear, but the device is ready. Deleting the device record in Intune before redeploying also works. The ETW trace shows Enrollment blocked for AP device by SDM One Time Limit Check.
Windows MDM enrollment is blocked. On the same Enrollment page, select Device platform restriction, open each Windows restriction (starting with All Users), select Properties > Edit next to Platform settings, and make sure Windows (MDM) is set to Allow. A restriction assigned to a group the device or user belongs to can still block it. The user-facing message for this cause is Your organization does not support this version of Windows. (0x80180014).
80180018 and the MDM terms of use error
80180018 on a Something went wrong page usually means the user has no license that includes Intune or has enrolled too many devices. The message Can't connect to the URL of your organization's MDM terms of use has the same licensing root cause. If both MDM for Microsoft 365 and Intune are used in the tenant, also check Microsoft Entra ID > Mobility (MDM and MAM) > Microsoft Intune, select Restore default MDM URLs, and confirm the MDM terms of use URL is https://portal.manage.microsoft.com/TermsofUse.aspx.
The Microsoft Entra per-user device limit defaults to 50 and is configurable. Users who exceed it get join errors.
0x80180022 and 8018000a
0x80180022 means the device runs Windows Home; Autopilot requires Pro or higher. 8018000a ("The device is already enrolled") means another user already enrolled or joined the device. Sign in as that user, remove the work or school account under Settings > Accounts, sign out, and enroll again.
TPM attestation errors
Self-deploying mode and pre-provisioning start with the Securing your hardware step, where the device completes TPM key attestation and receives a token from Microsoft Entra ID. User-driven mode skips this step. The attestation process needs HTTPS access to TPM provider URLs matching *.microsoftaik.azure.net. Firmware TPMs from Intel, AMD and Qualcomm also fetch certificates from the manufacturer on first use, so allow https://ekop.intel.com/ekcertservice, https://ftpm.amd.com/pki/aia or https://ekcert.spserv.microsoft.com/EKCertificate/GetEKCertificate/v1 as appropriate.
0x800705b4
The screen shows:
Securing your hardware (Failed: 0x800705b4)
Joining your organization's network (Previous step failed)
Registering your device for mobile management (Previous step failed)This general timeout usually means the device isn't TPM 2.0 capable: a virtual machine with a virtual TPM, or hardware with TPM 1.2. Those devices can't use self-deploying mode or pre-provisioning. Use a physical device with TPM 2.0, or switch the profile to user-driven mode for that hardware.
0x801c03ea
Registering your device for mobile management (Failed: 3, 0x801C03EA) means TPM attestation failed, so the device couldn't join Microsoft Entra ID with a device token. Microsoft's guidance is to upgrade a TPM that supports 2.0 but still runs an older version. If the error continues, check whether the device is in two groups that each have a different Autopilot profile assigned, and remove one assignment.
Other attestation codes
0x81039001(E_AUTOPILOT_CLIENT_TPM_MAX_ATTESTATION_RETRY_EXCEEDED) is intermittent; another provisioning attempt might succeed.0x81039023on Windows 11 21H2 is fixed by KB5013943 or later.0x81039024means known TPM vulnerabilities were detected. Update the TPM firmware from the PC manufacturer.0x80070490on AMD platforms with ASP firmware TPM is fixed in later AMD firmware.- "Something happened, and TPM attestation timed out" on Infineon SLB9672 TPMs with firmware 15.22 requires an OEM update.
- Event ID 171 (
AutopilotManager failed to set TPM identity confirmed) and 172 in the Autopilot event log accompany attestation failures.
Attestation can also fail, or the ESP can time out, when the device clock is off by several minutes or more. Boot to the start of OOBE, connect to the network, open a command prompt and resynchronize:
w32tm /resync /forceSelecting Reset after an ESP failure in pre-provisioning can also make TPM attestation fail on the retry.
0xc1036501 and 0x801C03F3
0xc1036501 in self-deploying mode means automatic MDM enrollment can't run because Microsoft Entra ID has more than one MDM configuration. 0x801C03F3 in the Microsoft-Windows-User Device Registration/Admin log during pre-provisioning means Microsoft Entra ID can't find the device object, usually because someone deleted it. Remove the device from Microsoft Entra ID, Intune and Windows Autopilot, then register it again, which recreates the object.
Microsoft Entra hybrid join errors
0x80070774
The message reads Something went wrong. Confirm you are using the correct sign-in information and that your organization uses this feature, typically before the first restart, when the device can't reach a domain controller or can no longer join the domain. Documented causes:
- Assign user is configured for a hybrid join deployment. Assign user performs a Microsoft Entra join at the initial sign-in screen, which leaves the device unable to join the on-premises domain. In Devices > Windows > Windows devices, select the device, choose Unassign user, and confirm the hybrid profile is assigned before retrying.
- The Intune Connector for Active Directory can't create the computer object. Event ID 30132 in the connector log with
Failed to get the ODJ Blob. The ODJ connector does not have sufficient privilegespoints to missing OU delegation. Delegate Create and Delete of computer objects, with Full Control, on the target OU to the connector's computer account. - Domain mismatch between where the connector is installed and where devices are configured. Configure the connector in the matching domain.
- The Autopilot object's Entra device was deleted. Delete the Autopilot object and reimport the hash.
0x80004005 timeouts
Hybrid join deployments timing out with 0x80004005 are resolved in KB5065789 or later for Windows 11 25H2, KB5065426 or later for 24H2 and KB5070312 or later for 23H2.
Profile and registration events
When the device shows the consumer OOBE instead of your company sign-in page, the Autopilot event log usually holds the answer:
| Event ID | Message | Fix |
|---|---|---|
| 807 | ZtdDeviceIsNotRegistered | Upload or fix the hardware hash and assign a profile |
| 809 | ZtdDeviceHasNoAssignedProfile - Assigned profile does not exist | Assign a different profile, then re-enroll |
| 815 | ZtdDeviceHasNoAssignedProfile - No profile assigned... | Assign a profile to the device's group |
| 908 | SerialNumberMismatch or ProductKeyIdMismatch | Reregister the device |
| 163 | Device already provisioned, download not required | Clean or reset the device |
Events 153 and 161 confirm a profile was found and downloaded. If you assigned a profile while the device sat at OOBE, it may have cached an empty profile; press Shift+F10 and run shutdown.exe /r /t 0 to restart and download again.
After a hardware change, the Autopilot devices list can show Fix pending or Attention required. Deregister and re-register the device. If a device shows as Microsoft Entra registered instead of joined, it was workplace-joined earlier; delete it from Intune, Microsoft Entra ID and Windows Autopilot, then register and deploy again.
CSV import does nothing
If selecting Import does nothing, the hash is probably unpadded Base64 and the service returns a 400 error. Test the hash with PowerShell. If it fails with Invalid length for a Base-64 char array or string, adjust the padding as Microsoft's troubleshooting FAQ describes (add up to two = characters at the end; if two are already there, replace them with one A and try again) until it decodes:
[System.Text.Encoding]::ascii.getstring([System.Convert]::FromBase64String("DEVICE HASH"))Edit CSV files in Notepad, not Excel, which can add characters that make the file invalid.
ESP application errors
Another installation is in progress, please try again later during the ESP means an LOB MSI and a Win32 app tried to install at the same time through TrustedInstaller. Repackage the LOB app as Win32, or move the population to Windows Autopilot device preparation, which can mix both types; see Autopilot device preparation vs classic Autopilot. An ESP that never leaves Identifying usually means the signed-in user has no Intune license.
Conditional Access blocking enrollment
If a Conditional Access policy blocks all apps except an exclusion list, and a second policy requires a compliant device for those apps, add Microsoft Intune Enrollment and Microsoft Intune to the exclusion list so the device can enroll. When a policy requires a compliant device for all cloud apps with no exclusion list, Microsoft Intune Enrollment is excluded by default. Policies that require Terms of Use must exclude the Intune Enrollment app. These exclusions keep device compliance usable as a signal in a Zero Trust access architecture without creating a circular dependency.
Closing checklist
- Collect
mdmdiagnosticstool.exe -area Autopilot(add;TPMfor self-deploying and pre-provisioning) before any reset. - Check the Autopilot event log for 807, 809, 815 and 908, and the registry for
IsAutopilotDisabledandTenantMatched. - For
0x80180014, unblock the device and confirm Windows (MDM) is allowed in every platform restriction. - For
80180018or the terms of use error, confirm the user's Intune license and device count. - For
0x800705b4and0x801c03ea, confirm physical TPM 2.0, current TPM firmware, correct clock and*.microsoftaik.azure.netaccess. - For
0x80070774, remove Assign user from hybrid deployments and verify connector OU delegation. - Never delete the Microsoft Entra device object that registration creates.