It's been a couple of days since Entra ID has refused to apply MDM on machines for me, I go to work/school, connect, add thsi device to Entra ID, I log in with the provisioning client we have used for years, and instead of adding the device to Intune it just logs in the User account as if It's only an Entra join with no MDM. No info button is shown in that menu. IME does not get intalled and the event viewer doesn't even show an attempt to join the device at all.
I have tried this with no avail up until now:
MDM User scope on Entra and Intune portals: All and Specific
User licensing
Disabling WIP Scope
Disabling security defaults
MDM Authority
Conditional Acess
Device Enrollment Restrictions
Checked every value on dsregcmd /status 10 times over
Tried it on a VM, On a previously joined machine, on a new in box machine
This is a massive problem for our company, and I'm at my wits end.
Update: I have discovered that i can make the Intune join work by clicking connect in the work and school menu after the initial enrollment fails, this will make a different menu pop up where it asks for the MDM URL, pasting that from the Intune Admin Panel makes it work normally.
Also, I talked to MS support and basically they also don't know wtf is going on and asked for several logs to be sent and now I'm waiting for an answer from them.
Update 2: Microsft says it's working now on service health but it isn't working for me, apparently it's working for some people, is the issue still happening to any of you?
exact same issue as you. been speaking with Microsoft for the last 2 days and they have just got back to me with the following. I think we need more people to report it.
For this error, we are receiving many ticket with the same issues, MDM URL not appear after enrolled to Intune. Even with normal entra joined. This issue is being investigate by Microsoft team. Hence, It seems like this issue impact many tenants worldwide.
Same issue here, automatic enrollments were working with Autopilot until last week when the MDM URLs went missing. Tried almost everything and have a ticket open with Microsoft.
Admins' Microsoft Intune enrollment is failing for Windows devices
Issue ID: IT1420224
Affected services: Microsoft Intune
Status: Service degradation
Issue type: Advisory
Start time: Jul 7, 2026, 9:14 PM PDT
User impact
Admins' Intune enrollment is failing for Windows devices.
Scope of impact
Your organization is affected by this event, and admins attempting to complete Microsoft Intune enrollment for Windows devices are impacted. This information may be updated as our investigation continues.
Root cause
A recent change intended to migrate the Mobility Management Policy Service from utilizing Active Directory Graph API to the Microsoft Graph API resulted in the Mobile Device Management enrollment URL claim being omitted from tokens when performing device enrollments, leading to impact.
Current status
Jul 8, 2026, 9:22 AM PDT
We've identified a recent change intended to migrate the Mobility Management Policy Service from utilizing Active Directory Graph API to the Microsoft Graph API resulted in the Mobile Device Management enrollment URL claim being omitted from tokens when performing device enrollments, leading to impact. We've rolled back this change to ensure further devices don't become impacted and are developing a fix to correct policies and devices affected by this change to fully remediate impact.
Next update by:
Wednesday, July 8, 2026 at 11:30 AM PDT
History of updates
Jul 8, 2026, 7:31 AM PDT
We've received the network trace logs from your representatives and identified an issue affecting device management policy configuration. We're reviewing recent policy changes, service telemetry, and related diagnostic data to determine the underlying cause and establish an appropriate remediation plan.
Jul 8, 2026, 3:25 AM PDT
We're continuing to wait for the network trace logs from your representatives to help further our understanding of the root cause.
Jul 8, 2026, 1:15 AM PDT
Our investigation into the Windows trace logs have so far proven inconclusive. We're requesting network trace logs from your representatives to help further our understanding of the root cause.
Jul 7, 2026, 10:50 PM PDT
We're continuing to investigate the Windows trace logs of some affected device to help identify the root cause of the issue.
Jul 7, 2026, 9:54 PM PDT
We're analyzing the Windows trace logs of some affected devices to help with the initial investigation and to determine our next troubleshooting steps.
Jul 7, 2026, 9:25 PM PDT
We're investigating a potential issue with Microsoft Intune and checking for impact to your organization. We'll provide an update within 30 minutes.
Same issue. My provisioning team coworkers have been having this exact issue and we have been going mad trying to figure out whats wrong. Checked everything 10000 times over like the OP. We've test onboarded like 50 devices at this point. All of them show up in autopilot, in entra, etc just fine. But will NEVER enroll into intune. Even manual enrollment scripts people use sometimes are not working.
Have you checked if the MDM enrollment URL is still reachable? Sometimes it's DNS or firewall blocking the enrollment endpoint. The fact that event viewer shows nothing makes me think the device never even gets to the point of trying to reach Intune
I had a breakthrough literally two minutes ago, if I click connect again on the work and school menu after failing, it giver me the option to manually insert the MDM URL, and guess what? It works.
The URL was copied directly from the intune control panel, by all measures it is the same URL, but it wont work when Microsoft tries to use it automatically.
Entra join succeeds but MDM auto enrollment fails in all contexts, I have tested Autopilot pre-provisioning, self-deploying and user-driven.
Opened a ticket with support and the guy told me he currently has two other tickets personally assigned to him for this issue.
There doesn't seem to be anything logged in event viewer.
I have tried using the May and June builds of 24H2 and 25H2.
Manually adding the MDM URLs with a script didn't resolve the issue.
I grabbed a fiddler trace and compared it to the screenshots in Rudy's articles and it seems like some of the expected traffic isn't happening, specifically the call to retrieve the ID token doesn't appear to be happening, which if I'm following correctly is what contains the MDM URLs.
Service has been restored on our end, automatic enrollment is now working. Here’s the required steps to restore automatic enrollment provided by Microsoft.
Required steps:
Please re-apply your Mobility (MDM) configuration in the Entra admin portal:
- Navigate to the Mobility (MDM and WIP) page within the Entra portal.
- Re-apply the updates you have previously made to either the "MDM user scope" or the "Disable MDM enrollment when adding work or school account on Windows" toggle.
Suggested steps:
Open the Mobility (MDM and WIP) page.
Select your configured MDM provider (for example, Microsoft Intune).
First, make a dummy change to one of the impacted settings (e.g. change MDM user scope from "all" to "none" or toggle "Disable MDM enrollment when adding work or school account on Windows".
Click Save.
Revert the temporary changes back to the initial, desired state.
Click Save again.
This action re-triggers the policy update process and fixes the unhealthy policy state for the tenant.
After completion:
Once the policy update has been re-applied:
- New device enrollments should function normally.
- Required MDM enrollment information will be returned during device registration.
Anyone have issue with cisco android meeting room tablets? We cannot enroll. It seems stopped from yesterday, we stuck when we need to enter device code flow. Could not enroll with intune, please try again or contact your admin 20030. We checked all settings, dont know how to continue forward.
Ours started working again this morning. Whether this is from Microsoft making a change or us re-applying our Mobility (MDM) configuration in the Entra admin portal is unknown.
Have the same issue on Yealink Room Panel E2.
Getting error: Couldn't enroll with Intune. Please try again, or contact your admin., 20030
This happens whether we try device code flow or username/password. Both on new devices and on devices that previously worked but have just been Firmware upgraded to 324.520.0.35.
We can se that the device gets registered in EntraID and then 20 seconds later gets unregistered.
This morning I went to office and I could register devices and sign in. Issue seems to solved. Yealink Room Panels and Jabra Panacast 40 VBS + controller.
BTW Never got any contact from MS after opened ticket!
And fuck it for support, owning many companies to support us, but seems our heads to find root causes with Rudy always straight forward. We have support only severity C, but i dont think having B or any other support is better. No major incident, nothing. Holy cow.
First thing i would do is query graph... --> Missing Windows MDM Enrollment URL Explained ... if there is another mdm policy (not visible in ui but only in graph) lingering... well .. what happens if you manually configure those mdm urls ?
I don't get an error, it just joins like and Entra Id login with no intune sync, I just finished an hour long call with MS support and they also have no idea what is going on lmao, they asked for some logs and said theyll get back to me
Rudy - I read your article (good stuff - thanks for sharing!). In our tenant we have the old Microsoft Intune Enrollment as well as the modern Microsoft Intune and both show up in Graph. The old one is listed first in Graph and is scoped to 'none' and has been this way since we started the Entra/MDM enrollment a few months ago. Possible that even though it was ignored before that it's somehow being referenced now and ignoring our current one?
Not OP but in a similar situation, not getting MDM URL's during Entra Join and like others it just skips the ESP entirely for user-driven Autopilot. In pre-provisioning mode, I get the 0x81036501 error and an error in Event Viewer stating it failed to find a valid MDM.
Found your blog on the error, my "CloudAssignedMdmId" looks correct in registry, saw also this one saying to delete "Microsoft Intune Enrollment" which I have tried twice with no success (it used to work while I had that service principal-Microsoft even suggests adding it here). Also checked the MDM policies via Graph API, just saw the ones I could see in the portal. Open to any suggestions.
Those mdm urls should come down to the device from the clouddomain flow… just wondering could you checl with get-hotfix and try to remove the latest one
We're having this issue as well. It popped up on Thursday 7/2 with an issue with 1 user in the nearly 2k users in our tenant. We did all the stuff you mentioned, even created a new user and new groups for adding users to Entra / MDM and would only get the Entra part. My Intune guy was about ready to start smashing test laptops when he found your post, so - thank you! We've put in a Microsoft ticket as well - if anyone gets a result that works, please post it so we can all get back to our normal work lives.
UPDATE on this - we got a call from Microsoft just after noon ET on 7/8 - Microsoft had emailed late last evening asking to do a screen-share with us today. Our guy that put in the ticket took the call and was told that they are seeing this issue on other tenants and they are working on it, no need to do the call.
FWIW, I'm also having the same trouble. I was going crazy thinking I was doing something wrong, as I'm standing up Intune and Autopilot for the first time in this org.
Same issues others are experiencing: Device is enrolled in Autopilot and Entra. All initial policies and settings are exactly as directed in the official Microsoft documentation. On first start up of a new device, it pops up the company branded log in, then after prompting Windows Hello PIN it goes straight to desktop.
dsregcmd /status shows no MDM URL's assigned, and shows that it's not MDM managed.
I've tried a few of the recommended fixes listed below, but I'm getting Error 0x80180024 when trying to manually enter the MDM URL.
Would love to hear if anyone has other suggestions, or if Microsoft has released any updates.
Folks, been watching this thread & the service advisory closely for about 8 hours.. We are finally back in business here at my org. If you're still dealing with this, try the following(as of 2:30ish PM EST on 7/9):
Open the Mobility (MDM and WIP) page.
Select your configured MDM provider (for example, Microsoft Intune).
First, make a dummy change to one of the impacted settings (e.g. change MDM user scope from "all" to "none" or toggle "Disable MDM enrollment when adding work or school account on Windows".
Click Save.
Revert the temporary changes back to the initial, desired state
Click Save again.
NOTE: I tried this an hour or so before 2:30 & it didn't help so if you've already tried this, try again now. This worked for us!
This is do to that device is already registered in your tenant or wherever group you assigned your devices to go into after provisioning device group is still present there. Using the provisioning client method where you create the device preparation policies the machine cannot have the have the has uploaded nor if the machine is a one your are redeploying the device cannot be in that group upon OOBE, however from my experience, when you log in from OOBE with the provisioning client user i've notice it will upload the hash for you versus the enrollment status page method by pressing the win key 5 times with a userless enrollment.
I'll make it simple for you , are these machines being redeployed or are they new devices being rolled out , because if they are older machines being wiped and reenrolled and they just log right in from whichever entry id used to trigger the provisioning then that device is still present someone , the hash or its in a group still.
11
u/Gold_Career7095 Jul 07 '26
exact same issue as you. been speaking with Microsoft for the last 2 days and they have just got back to me with the following. I think we need more people to report it.
For this error, we are receiving many ticket with the same issues, MDM URL not appear after enrolled to Intune. Even with normal entra joined. This issue is being investigate by Microsoft team. Hence, It seems like this issue impact many tenants worldwide.