Cloud & infrastructure

Windows Autopilot error codes: fix 0x80180014, 0x800705b4 and more

Look up Windows Autopilot and Intune enrollment error codes, including 0x80180014, 0x800705b4, 0x801c03ea and 80180018, and apply the fix Microsoft documents for each.

12 min read
On this page

Most Windows Autopilot error codes map to a short list of documented causes: 0x80180014 means a self-deploying or pre-provisioned device must be unblocked or Windows (MDM) enrollment is blocked by a platform restriction; 0x800705b4 and 0x801c03ea are TPM attestation failures, usually because the device lacks a usable physical TPM 2.0; and 80180018 or the "MDM terms of use" error point to licensing or the user's device limit. Collect the Autopilot diagnostics first, match the code or event ID against the tables below, and apply the documented fix rather than resetting the device repeatedly.

Who this is for and what you will have

This reference is for Intune and endpoint administrators handling failed Windows Autopilot deployments in user-driven, self-deploying, pre-provisioning or Microsoft Entra hybrid join scenarios. It only lists codes and fixes that Microsoft documents. At the end you will have:

  • A repeatable way to collect logs from a failed device, in OOBE or remotely.
  • A lookup table for enrollment, TPM attestation, hybrid join and registration errors.
  • The Event Viewer IDs and registry values that confirm each diagnosis.

If the device is not failing with a code but is stuck on the Enrollment Status Page, see Intune Enrollment Status Page stuck instead.

Prerequisites

  • Intune Administrator, or a role with Windows Autopilot device and enrollment permissions, in the Microsoft Intune admin center.
  • Physical or remote access to the failing device. In OOBE on a non-S mode device, Shift+F10 opens a command prompt.
  • A USB drive if you want users to export logs from the device.

Step 1: Collect the evidence

Don't start with a reset. The failure screen, the event log and the registry usually identify the cause.

On the device

On Windows 11 user-driven deployments, the Autopilot diagnostics page opens with Ctrl+Shift+D or the View Diagnostics button, provided the ESP profile has Show app and profile configuration progress and Turn on log collection and diagnostics page for end users set to Yes. It shows network connectivity, Autopilot settings and enrollment status, and has an Export logs button.

From a command prompt (Shift+F10 in OOBE), collect a cab file. Use the first command for user-driven deployments and the second for self-deploying, pre-provisioning or any physical-device scenario where TPM attestation is involved:

mdmdiagnosticstool.exe -area Autopilot -cab C:\Diagnostics\Autopilot.cab
mdmdiagnosticstool.exe -area Autopilot;TPM -cab C:\Diagnostics\AutopilotTPM.cab

To summarize a cab file on an admin workstation, use Microsoft's Get-AutopilotDiagnostics script from the PowerShell Gallery:

Install-Script -Name Get-AutopilotDiagnostics -Force
Get-AutopilotDiagnostics -CABFile C:\Diagnostics\Autopilot.cab

Remotely

Intune collects diagnostics automatically when an Autopilot deployment fails, and keeps them for 28 days. For the upload to work, lgmsapeweu.blob.core.windows.net must not be blocked. You can also select a device under Devices > All devices and choose Collect diagnostics.

What to read

  • Event Viewer: Application and Services Logs > Microsoft > Windows > ModernDeployment-Diagnostics-Provider > Autopilot.
  • Registry: HKLM\SOFTWARE\Microsoft\Provisioning\Diagnostics\Autopilot. CloudAssignedTenantDomain and CloudAssignedTenantId are blank if the device isn't registered. IsAutopilotDisabled set to 1 means the device isn't registered or the profile couldn't be downloaded because of network, firewall or timeout problems. TenantMatched set to 0 means the user signed in to a different tenant from the one the device is registered to.

Quick lookup table

Code or messageWhere you see itDocumented causeFix
0x80180014Redeploying a deviceSelf-deploying or pre-provisioning one-time limit, or Windows (MDM) blockedUnblock or delete the device record; allow Windows (MDM)
80180018"Something went wrong" pageMissing license or device enrollment limitAssign a license with Intune; check device limits
"Can't connect to the URL of your organization's MDM terms of use"OOBEUser has no Intune, EMS or Microsoft 365 licenseLicense the user
0x80180022EnrollmentDevice runs Windows HomeUpgrade to Pro or higher
8018000aEnrollmentDevice already enrolled or joined by another userRemove the other work or school account
0x800705b4"Securing your hardware"Timeout; no physical TPM 2.0Use supported hardware
0x801c03ea"Registering your device for mobile management"TPM attestation failedUpgrade TPM to 2.0; check duplicate profile assignments
0x81039001"Securing your hardware"TPM attestation retries exceededRetry provisioning
0x81039023Windows 11 attestationFixed in KB5013943 for 21H2Update Windows
0x81039024Windows 11 attestationKnown TPM vulnerabilities detectedUpdate TPM firmware
0x80070490AMD fTPM attestationAMD ASP fTPM firmware issueUpdate firmware
0xc1036501Self-deployingMultiple MDM configurations in Entra IDLeave one MDM configuration
0x801C03F3Pre-provisioningEntra device object deletedDeregister and re-register
0x80070774Hybrid joinDomain mismatch, Assign user, or deleted Entra objectSee hybrid section
0x80004005Hybrid join timeoutsWindows issueInstall the listed KB

Enrollment and licensing errors

0x80180014

Microsoft documents two causes.

The device was previously deployed with self-deploying or pre-provisioning mode. Reusing or resetting such a device requires removing the block. In the Intune admin center, go to Devices > Windows > Enrollment > Windows Autopilot > Devices, select the device and select Unblock device, then redeploy. A success message might not appear, but the device is ready. Deleting the device record in Intune before redeploying also works. The ETW trace shows Enrollment blocked for AP device by SDM One Time Limit Check.

Windows MDM enrollment is blocked. On the same Enrollment page, select Device platform restriction, open each Windows restriction (starting with All Users), select Properties > Edit next to Platform settings, and make sure Windows (MDM) is set to Allow. A restriction assigned to a group the device or user belongs to can still block it. The user-facing message for this cause is Your organization does not support this version of Windows. (0x80180014).

80180018 and the MDM terms of use error

80180018 on a Something went wrong page usually means the user has no license that includes Intune or has enrolled too many devices. The message Can't connect to the URL of your organization's MDM terms of use has the same licensing root cause. If both MDM for Microsoft 365 and Intune are used in the tenant, also check Microsoft Entra ID > Mobility (MDM and MAM) > Microsoft Intune, select Restore default MDM URLs, and confirm the MDM terms of use URL is https://portal.manage.microsoft.com/TermsofUse.aspx.

The Microsoft Entra per-user device limit defaults to 50 and is configurable. Users who exceed it get join errors.

0x80180022 and 8018000a

0x80180022 means the device runs Windows Home; Autopilot requires Pro or higher. 8018000a ("The device is already enrolled") means another user already enrolled or joined the device. Sign in as that user, remove the work or school account under Settings > Accounts, sign out, and enroll again.

TPM attestation errors

Self-deploying mode and pre-provisioning start with the Securing your hardware step, where the device completes TPM key attestation and receives a token from Microsoft Entra ID. User-driven mode skips this step. The attestation process needs HTTPS access to TPM provider URLs matching *.microsoftaik.azure.net. Firmware TPMs from Intel, AMD and Qualcomm also fetch certificates from the manufacturer on first use, so allow https://ekop.intel.com/ekcertservice, https://ftpm.amd.com/pki/aia or https://ekcert.spserv.microsoft.com/EKCertificate/GetEKCertificate/v1 as appropriate.

0x800705b4

The screen shows:

Securing your hardware (Failed: 0x800705b4)
Joining your organization's network (Previous step failed)
Registering your device for mobile management (Previous step failed)

This general timeout usually means the device isn't TPM 2.0 capable: a virtual machine with a virtual TPM, or hardware with TPM 1.2. Those devices can't use self-deploying mode or pre-provisioning. Use a physical device with TPM 2.0, or switch the profile to user-driven mode for that hardware.

0x801c03ea

Registering your device for mobile management (Failed: 3, 0x801C03EA) means TPM attestation failed, so the device couldn't join Microsoft Entra ID with a device token. Microsoft's guidance is to upgrade a TPM that supports 2.0 but still runs an older version. If the error continues, check whether the device is in two groups that each have a different Autopilot profile assigned, and remove one assignment.

Other attestation codes

  • 0x81039001 (E_AUTOPILOT_CLIENT_TPM_MAX_ATTESTATION_RETRY_EXCEEDED) is intermittent; another provisioning attempt might succeed.
  • 0x81039023 on Windows 11 21H2 is fixed by KB5013943 or later.
  • 0x81039024 means known TPM vulnerabilities were detected. Update the TPM firmware from the PC manufacturer.
  • 0x80070490 on AMD platforms with ASP firmware TPM is fixed in later AMD firmware.
  • "Something happened, and TPM attestation timed out" on Infineon SLB9672 TPMs with firmware 15.22 requires an OEM update.
  • Event ID 171 (AutopilotManager failed to set TPM identity confirmed) and 172 in the Autopilot event log accompany attestation failures.

Attestation can also fail, or the ESP can time out, when the device clock is off by several minutes or more. Boot to the start of OOBE, connect to the network, open a command prompt and resynchronize:

w32tm /resync /force

Selecting Reset after an ESP failure in pre-provisioning can also make TPM attestation fail on the retry.

0xc1036501 and 0x801C03F3

0xc1036501 in self-deploying mode means automatic MDM enrollment can't run because Microsoft Entra ID has more than one MDM configuration. 0x801C03F3 in the Microsoft-Windows-User Device Registration/Admin log during pre-provisioning means Microsoft Entra ID can't find the device object, usually because someone deleted it. Remove the device from Microsoft Entra ID, Intune and Windows Autopilot, then register it again, which recreates the object.

Microsoft Entra hybrid join errors

0x80070774

The message reads Something went wrong. Confirm you are using the correct sign-in information and that your organization uses this feature, typically before the first restart, when the device can't reach a domain controller or can no longer join the domain. Documented causes:

  • Assign user is configured for a hybrid join deployment. Assign user performs a Microsoft Entra join at the initial sign-in screen, which leaves the device unable to join the on-premises domain. In Devices > Windows > Windows devices, select the device, choose Unassign user, and confirm the hybrid profile is assigned before retrying.
  • The Intune Connector for Active Directory can't create the computer object. Event ID 30132 in the connector log with Failed to get the ODJ Blob. The ODJ connector does not have sufficient privileges points to missing OU delegation. Delegate Create and Delete of computer objects, with Full Control, on the target OU to the connector's computer account.
  • Domain mismatch between where the connector is installed and where devices are configured. Configure the connector in the matching domain.
  • The Autopilot object's Entra device was deleted. Delete the Autopilot object and reimport the hash.

0x80004005 timeouts

Hybrid join deployments timing out with 0x80004005 are resolved in KB5065789 or later for Windows 11 25H2, KB5065426 or later for 24H2 and KB5070312 or later for 23H2.

Profile and registration events

When the device shows the consumer OOBE instead of your company sign-in page, the Autopilot event log usually holds the answer:

Event IDMessageFix
807ZtdDeviceIsNotRegisteredUpload or fix the hardware hash and assign a profile
809ZtdDeviceHasNoAssignedProfile - Assigned profile does not existAssign a different profile, then re-enroll
815ZtdDeviceHasNoAssignedProfile - No profile assigned...Assign a profile to the device's group
908SerialNumberMismatch or ProductKeyIdMismatchReregister the device
163Device already provisioned, download not requiredClean or reset the device

Events 153 and 161 confirm a profile was found and downloaded. If you assigned a profile while the device sat at OOBE, it may have cached an empty profile; press Shift+F10 and run shutdown.exe /r /t 0 to restart and download again.

After a hardware change, the Autopilot devices list can show Fix pending or Attention required. Deregister and re-register the device. If a device shows as Microsoft Entra registered instead of joined, it was workplace-joined earlier; delete it from Intune, Microsoft Entra ID and Windows Autopilot, then register and deploy again.

CSV import does nothing

If selecting Import does nothing, the hash is probably unpadded Base64 and the service returns a 400 error. Test the hash with PowerShell. If it fails with Invalid length for a Base-64 char array or string, adjust the padding as Microsoft's troubleshooting FAQ describes (add up to two = characters at the end; if two are already there, replace them with one A and try again) until it decodes:

[System.Text.Encoding]::ascii.getstring([System.Convert]::FromBase64String("DEVICE HASH"))

Edit CSV files in Notepad, not Excel, which can add characters that make the file invalid.

ESP application errors

Another installation is in progress, please try again later during the ESP means an LOB MSI and a Win32 app tried to install at the same time through TrustedInstaller. Repackage the LOB app as Win32, or move the population to Windows Autopilot device preparation, which can mix both types; see Autopilot device preparation vs classic Autopilot. An ESP that never leaves Identifying usually means the signed-in user has no Intune license.

Conditional Access blocking enrollment

If a Conditional Access policy blocks all apps except an exclusion list, and a second policy requires a compliant device for those apps, add Microsoft Intune Enrollment and Microsoft Intune to the exclusion list so the device can enroll. When a policy requires a compliant device for all cloud apps with no exclusion list, Microsoft Intune Enrollment is excluded by default. Policies that require Terms of Use must exclude the Intune Enrollment app. These exclusions keep device compliance usable as a signal in a Zero Trust access architecture without creating a circular dependency.

Closing checklist

  • Collect mdmdiagnosticstool.exe -area Autopilot (add ;TPM for self-deploying and pre-provisioning) before any reset.
  • Check the Autopilot event log for 807, 809, 815 and 908, and the registry for IsAutopilotDisabled and TenantMatched.
  • For 0x80180014, unblock the device and confirm Windows (MDM) is allowed in every platform restriction.
  • For 80180018 or the terms of use error, confirm the user's Intune license and device count.
  • For 0x800705b4 and 0x801c03ea, confirm physical TPM 2.0, current TPM firmware, correct clock and *.microsoftaik.azure.net access.
  • For 0x80070774, remove Assign user from hybrid deployments and verify connector OU delegation.
  • Never delete the Microsoft Entra device object that registration creates.

References

Questions people ask

What does Autopilot error 0x80180014 mean?

It has two documented causes. Either the device was previously deployed with self-deploying or pre-provisioning mode and must be unblocked (select it in Windows Autopilot devices and choose Unblock device, or delete the Intune device record), or a device platform restriction blocks Windows (MDM) enrollment. Allow Windows (MDM) in every restriction that applies to the device.

How do I fix Securing your hardware (Failed 0x800705b4)?

The error is a timeout in the TPM attestation step used by self-deploying mode and pre-provisioning. The usual cause is a device without a physical TPM 2.0, such as a virtual machine or a device with TPM 1.2. Use supported physical hardware, update TPM firmware, and check that the device clock is correct.

Where are Windows Autopilot logs stored?

Autopilot writes events to Event Viewer under Application and Services Logs, Microsoft, Windows, ModernDeployment-Diagnostics-Provider, Autopilot. Profile settings are in the registry under HKLM\SOFTWARE\Microsoft\Provisioning\Diagnostics\Autopilot. Run mdmdiagnosticstool.exe -area Autopilot -cab with an output path to collect everything in one cab file.

What causes error 80180018 during Autopilot?

Microsoft points to the Intune enrollment troubleshooting guide for this code. The common causes are a user without a valid license that includes Intune, or a user who has already enrolled the maximum number of devices.

Windows AutopilotMicrosoft IntuneEntra IDMDM Diagnostics
  1. Silent BitLocker encryption with Intune and recovery key escrow to Entra ID

    Encrypt Windows devices with no user prompts through an Intune disk encryption policy, and make BitLocker wait until the recovery password is stored in Microsoft Entra ID.

  2. Windows Autopilot with Intune: zero-touch laptop deployment end to end

    Set up Windows Autopilot user-driven Microsoft Entra join with Intune: automatic enrollment, device registration, groups, Enrollment Status Page, deployment profile, testing and common errors.

  3. Autopilot device preparation vs classic Autopilot: choosing the right one

    Compare Windows Autopilot device preparation and classic Windows Autopilot on join types, modes, app limits, registration, ESP and reporting, and pick the right one for each device population.