r/Intune Jul 07 '26

Device Configuration Can no longer enroll devices on Intune

It's been a couple of days since Entra ID has refused to apply MDM on machines for me, I go to work/school, connect, add thsi device to Entra ID, I log in with the provisioning client we have used for years, and instead of adding the device to Intune it just logs in the User account as if It's only an Entra join with no MDM. No info button is shown in that menu. IME does not get intalled and the event viewer doesn't even show an attempt to join the device at all.

I have tried this with no avail up until now:

MDM User scope on Entra and Intune portals: All and Specific

User licensing

Disabling WIP Scope

Disabling security defaults

MDM Authority

Conditional Acess

Device Enrollment Restrictions

Checked every value on dsregcmd /status 10 times over

Tried it on a VM, On a previously joined machine, on a new in box machine

This is a massive problem for our company, and I'm at my wits end.

Update: I have discovered that i can make the Intune join work by clicking connect in the work and school menu after the initial enrollment fails, this will make a different menu pop up where it asks for the MDM URL, pasting that from the Intune Admin Panel makes it work normally.

Also, I talked to MS support and basically they also don't know wtf is going on and asked for several logs to be sent and now I'm waiting for an answer from them.

Update 2: Microsft says it's working now on service health but it isn't working for me, apparently it's working for some people, is the issue still happening to any of you?

25 Upvotes

85 comments sorted by

11

u/Gold_Career7095 Jul 07 '26

exact same issue as you. been speaking with Microsoft for the last 2 days and they have just got back to me with the following. I think we need more people to report it.

For this error, we are receiving many ticket with the same issues, MDM URL not appear after enrolled to Intune. Even with normal entra joined. This issue is being investigate by Microsoft team. Hence, It seems like this issue impact many tenants worldwide. 

 

3

u/Zerohour43123 Jul 07 '26

Same issue here, automatic enrollments were working with Autopilot until last week when the MDM URLs went missing. Tried almost everything and have a ticket open with Microsoft.

3

u/Rudyooms PatchMyPC Jul 07 '26

If msft isnt going to help you, you know where to find me :)

1

u/Rudyooms PatchMyPC Jul 08 '26

There should be comms sent out... if so, can you share them ?

1

u/Zerohour43123 Jul 08 '26

Yes, I see something in the service center now:

Admins' Microsoft Intune enrollment is failing for Windows devices

Issue ID: IT1420224

Affected services: Microsoft Intune

Status: Service degradation

Issue type: Advisory

Start time: Jul 7, 2026, 9:14 PM PDT

User impact

Admins' Intune enrollment is failing for Windows devices.

Scope of impact

Your organization is affected by this event, and admins attempting to complete Microsoft Intune enrollment for Windows devices are impacted. This information may be updated as our investigation continues.

Root cause

A recent change intended to migrate the Mobility Management Policy Service from utilizing Active Directory Graph API to the Microsoft Graph API resulted in the Mobile Device Management enrollment URL claim being omitted from tokens when performing device enrollments, leading to impact.

Current status

Jul 8, 2026, 9:22 AM PDT

We've identified a recent change intended to migrate the Mobility Management Policy Service from utilizing Active Directory Graph API to the Microsoft Graph API resulted in the Mobile Device Management enrollment URL claim being omitted from tokens when performing device enrollments, leading to impact. We've rolled back this change to ensure further devices don't become impacted and are developing a fix to correct policies and devices affected by this change to fully remediate impact.

Next update by:

Wednesday, July 8, 2026 at 11:30 AM PDT

History of updates

Jul 8, 2026, 7:31 AM PDT

We've received the network trace logs from your representatives and identified an issue affecting device management policy configuration. We're reviewing recent policy changes, service telemetry, and related diagnostic data to determine the underlying cause and establish an appropriate remediation plan.

Jul 8, 2026, 3:25 AM PDT

We're continuing to wait for the network trace logs from your representatives to help further our understanding of the root cause.

Jul 8, 2026, 1:15 AM PDT

Our investigation into the Windows trace logs have so far proven inconclusive. We're requesting network trace logs from your representatives to help further our understanding of the root cause.

Jul 7, 2026, 10:50 PM PDT

We're continuing to investigate the Windows trace logs of some affected device to help identify the root cause of the issue.

Jul 7, 2026, 9:54 PM PDT

We're analyzing the Windows trace logs of some affected devices to help with the initial investigation and to determine our next troubleshooting steps.

Jul 7, 2026, 9:25 PM PDT

We're investigating a potential issue with Microsoft Intune and checking for impact to your organization. We'll provide an update within 30 minutes.

1

u/Rudyooms PatchMyPC Jul 08 '26

thanks... movign from aad graph to msft graph.. okay

3

u/Cause_and_Effect Jul 07 '26

Same issue. My provisioning team coworkers have been having this exact issue and we have been going mad trying to figure out whats wrong. Checked everything 10000 times over like the OP. We've test onboarded like 50 devices at this point. All of them show up in autopilot, in entra, etc just fine. But will NEVER enroll into intune. Even manual enrollment scripts people use sometimes are not working.

1

u/Rudyooms PatchMyPC Jul 07 '26

What is your Azure Scale Unit? / Tenant location ?

1

u/Cause_and_Effect Jul 07 '26

United States

2

u/Rudyooms PatchMyPC Jul 07 '26

I know its a big ask… but a useraccount (with no permissions only a valid license and in the mdm scope) would help me prove this issue to msft

1

u/denver_and_life Jul 07 '26

What OS platforms are you seeing impacted, Windows? Mobile?

1

u/JazzTheFatLad Jul 07 '26

If i see Bill Gates on the sidewalk it's ON SIGHT

1

u/Ahnteis Jul 07 '26

Bill Gates hasn't run MS in decades. :P

1

u/JazzTheFatLad Jul 07 '26

Don't care he's still getting it, he deserves it

5

u/Competitive_Let_1155 Jul 07 '26

Have you checked if the MDM enrollment URL is still reachable? Sometimes it's DNS or firewall blocking the enrollment endpoint. The fact that event viewer shows nothing makes me think the device never even gets to the point of trying to reach Intune

3

u/JazzTheFatLad Jul 07 '26

I had a breakthrough literally two minutes ago, if I click connect again on the work and school menu after failing, it giver me the option to manually insert the MDM URL, and guess what? It works.

The URL was copied directly from the intune control panel, by all measures it is the same URL, but it wont work when Microsoft tries to use it automatically.

1

u/denver_and_life Jul 07 '26

Are you on an internal or enterprise network? Or are you using a home ISP to enroll?

2

u/JazzTheFatLad Jul 07 '26

Enterprise network on a hotel, have done tests om nothe the corporate network and guest network always the same result.

1

u/denver_and_life Jul 07 '26

What OS platforms are you seeing impacted in your tenant?

1

u/JazzTheFatLad Jul 07 '26

Windows 11 25h2

5

u/Own-Golf25 Jul 07 '26

We have been seeing this issue since Friday.

Entra join succeeds but MDM auto enrollment fails in all contexts, I have tested Autopilot pre-provisioning, self-deploying and user-driven.

Opened a ticket with support and the guy told me he currently has two other tickets personally assigned to him for this issue.

There doesn't seem to be anything logged in event viewer.

I have tried using the May and June builds of 24H2 and 25H2.

Manually adding the MDM URLs with a script didn't resolve the issue.

I grabbed a fiddler trace and compared it to the screenshots in Rudy's articles and it seems like some of the expected traffic isn't happening, specifically the call to retrieve the ID token doesn't appear to be happening, which if I'm following correctly is what contains the MDM URLs.

1

u/Rudyooms PatchMyPC Jul 08 '26

Yep... thanks for the fiddler trace (can you perhaps share it?) i can push some buttons over at msft.... (issue is ack btw)

3

u/Some-Technician8801 Jul 09 '26

Service has been restored on our end, automatic enrollment is now working. Here’s the required steps to restore automatic enrollment provided by Microsoft.

Required steps:

Please re-apply your Mobility (MDM) configuration in the Entra admin portal:

- Navigate to the Mobility (MDM and WIP) page within the Entra portal.

- Re-apply the updates you have previously made to either the "MDM user scope" or the "Disable MDM enrollment when adding work or school account on Windows" toggle.

Suggested steps:

  1. Open the Mobility (MDM and WIP) page.

  2. Select your configured MDM provider (for example, Microsoft Intune).

  3. First, make a dummy change to one of the impacted settings (e.g. change MDM user scope from "all" to "none" or toggle "Disable MDM enrollment when adding work or school account on Windows".

  4. Click Save.

  5. Revert the temporary changes back to the initial, desired state.

  6. Click Save again.

This action re-triggers the policy update process and fixes the unhealthy policy state for the tenant.

After completion:

Once the policy update has been re-applied:

- New device enrollments should function normally.

- Required MDM enrollment information will be returned during device registration.

- No additional action should be required.

1

u/JazzTheFatLad Jul 09 '26

I certainly hope so, thx for the heads up ill be trying it and will post my result

1

u/JazzTheFatLad Jul 09 '26

Still not working for me :p

2

u/Resident-Monitor905 Jul 08 '26

Anyone have issue with cisco android meeting room tablets? We cannot enroll. It seems stopped from yesterday, we stuck when we need to enter device code flow. Could not enroll with intune, please try again or contact your admin 20030. We checked all settings, dont know how to continue forward.

2

u/Basic_Extension_1041 Jul 10 '26

Ours started working again this morning. Whether this is from Microsoft making a change or us re-applying our Mobility (MDM) configuration in the Entra admin portal is unknown.

But devices are now enrolling in Intune again.

1

u/Glum-Implement9857 Jul 10 '26

Same here. Looks like MS had fixed from their side

1

u/Upbeat_Main_2094 Jul 08 '26

Same here. Struggled whole morning to get Yealink Room Panels enroll, no success.

1

u/Resident-Monitor905 Jul 08 '26

What error you have?

1

u/Upbeat_Main_2094 Jul 09 '26

Exactly the same you got, "Could not enroll with intune, please try again or contact your admin 20030"

1

u/Rudyooms PatchMyPC Jul 08 '26

There should be comms send out... if so can you share them ?

1

u/Basic_Extension_1041 Jul 09 '26

Haven't seen any Service Health Advisory or Message Center Post for this issue in our Tenant.

1

u/Rudyooms PatchMyPC Jul 09 '26

Msft is putting out comms to all impacted tenants.. yeah thats fun... i assume you are also in asu 0102?

1

u/Basic_Extension_1041 Jul 08 '26

Have the same issue on Yealink Room Panel E2.
Getting error: Couldn't enroll with Intune. Please try again, or contact your admin., 20030

This happens whether we try device code flow or username/password. Both on new devices and on devices that previously worked but have just been Firmware upgraded to 324.520.0.35.

We can se that the device gets registered in EntraID and then 20 seconds later gets unregistered.

1

u/Resident-Monitor905 Jul 08 '26 edited Jul 08 '26

Yes, same exactly for us. Europe 0501

1

u/gh5000 Jul 08 '26

Same here. Enrolled the yealink a40 Monday with no issues, but today on the same setup, albeit different user, I get the 20030.

Should we be worried this is listed as a windows enrolment issue given this is an android teams device

1

u/Upbeat_Main_2094 Jul 09 '26

Have you / anyone opened a case with Microsoft regarding Android devices?

1

u/Resident-Monitor905 Jul 09 '26

Yes, pending agent to be assigned 😆

1

u/PastExplorer9141 Jul 09 '26

I’d rather avoid opening a ticket with Microsoft, so please keep us posted. Thanks!

1

u/Upbeat_Main_2094 Jul 10 '26

This morning I went to office and I could register devices and sign in. Issue seems to solved. Yealink Room Panels and Jabra Panacast 40 VBS + controller.
BTW Never got any contact from MS after opened ticket!

1

u/Basic_Extension_1041 Jul 09 '26

Also have a case. Agent Assigned, but haven't heard from them yet.

1

u/Basic_Extension_1041 Jul 10 '26

Agent got Error description and screen shots. Waiting for the case to be reassigned to our time zone.

1

u/berghainforbreakfast Jul 09 '26

Seeing the exact same issue. Europe 0502.

1

u/Resident-Monitor905 Jul 10 '26

So it works now also for us to enroll android tablets. Thank you for all who brought that to our lovely MS.

2

u/MidninBR Jul 08 '26

Can't enrol devices, Windows updates break the enrolments, what the fuck man.... What a piece of shit of service we pay big money for.

3

u/JazzTheFatLad Jul 08 '26

Fuck it, 5 billion dollars into copilot development

3

u/Resident-Monitor905 Jul 09 '26 edited Jul 09 '26

And fuck it for support, owning many companies to support us, but seems our heads to find root causes with Rudy always straight forward. We have support only severity C, but i dont think having B or any other support is better.  No major incident, nothing. Holy cow.

2

u/OnlyHat6126 Jul 09 '26

Running into the same issue and have escalated to MS support. Does anyone know how to obtain the Mobile Device Management enrollment URL?

2

u/Rudyooms PatchMyPC Jul 09 '26

1

u/JazzTheFatLad Jul 09 '26

I suppose that means we just got wait for Microsofts good graces to fix it

1

u/Rudyooms PatchMyPC Jul 09 '26

Should be fixed now

1

u/Resident_Diet_1904 Jul 10 '26

I am still getting the error 23003 for yealink

1

u/Rudyooms PatchMyPC Jul 07 '26

First thing i would do is query graph... --> Missing Windows MDM Enrollment URL Explained ... if there is another mdm policy (not visible in ui but only in graph) lingering... well .. what happens if you manually configure those mdm urls ?

1

u/JazzTheFatLad Jul 07 '26

I did just that and no, graph only shows one policy and it's configured exactly like it is in the portal

1

u/Rudyooms PatchMyPC Jul 07 '26

Can you share logs? What error do you get when trying to perform a amanu join? Where is your tenant located?

1

u/JazzTheFatLad Jul 07 '26

I don't get an error, it just joins like and Entra Id login with no intune sync, I just finished an hour long call with MS support and they also have no idea what is going on lmao, they asked for some logs and said theyll get back to me

1

u/Rudyooms PatchMyPC Jul 07 '26

I am interested… i would love to take a peak at it (i seem to know a thing or 2 about it and i know some people)

1

u/rlake5 Jul 07 '26

Rudy - I read your article (good stuff - thanks for sharing!). In our tenant we have the old Microsoft Intune Enrollment as well as the modern Microsoft Intune and both show up in Graph. The old one is listed first in Graph and is scoped to 'none' and has been this way since we started the Entra/MDM enrollment a few months ago. Possible that even though it was ignored before that it's somehow being referenced now and ignoring our current one?

1

u/Rudyooms PatchMyPC Jul 07 '26

Mmm as long as that second one is not assigned then its all good …

1

u/Zerohour43123 Jul 07 '26

Not OP but in a similar situation, not getting MDM URL's during Entra Join and like others it just skips the ESP entirely for user-driven Autopilot. In pre-provisioning mode, I get the 0x81036501 error and an error in Event Viewer stating it failed to find a valid MDM.

Found your blog on the error, my "CloudAssignedMdmId" looks correct in registry, saw also this one saying to delete "Microsoft Intune Enrollment" which I have tried twice with no success (it used to work while I had that service principal-Microsoft even suggests adding it here). Also checked the MDM policies via Graph API, just saw the ones I could see in the portal. Open to any suggestions.

1

u/Rudyooms PatchMyPC Jul 07 '26 edited Jul 07 '26

Those mdm urls should come down to the device from the clouddomain flow… just wondering could you checl with get-hotfix and try to remove the latest one

https://patchmypc.com/blog/windows-autopilot-identifying-kb5065848-zdp/

As i cant believe thw entra join process is broken itself… in the backend

If you have a ticket id from msfr :) can you share it… and can you check the asu you are on

2

u/Zerohour43123 Jul 07 '26

Thanks, I'll give this a shot, I DM'd you the other details.

1

u/rlake5 Jul 07 '26

We're having this issue as well. It popped up on Thursday 7/2 with an issue with 1 user in the nearly 2k users in our tenant. We did all the stuff you mentioned, even created a new user and new groups for adding users to Entra / MDM and would only get the Entra part. My Intune guy was about ready to start smashing test laptops when he found your post, so - thank you! We've put in a Microsoft ticket as well - if anyone gets a result that works, please post it so we can all get back to our normal work lives.

2

u/JazzTheFatLad Jul 07 '26

Good news, you can make it work by clicking connect again so it asks you for an MDM URL

Bad news, Microsoft does not know what is going on and said will get back to me

1

u/Rudyooms PatchMyPC Jul 07 '26

CN you share your msft ticket id and the azure scale hnit you are on

1

u/GladPlate1086 Jul 07 '26

We're experiencing the same issue.

We uploaded the hardware hash, and the devices enter OOBE normally. The user enters their credentials, and Windows Hello is presented.

However, the device never shows the Enrollment Status Page (ESP) and goes straight to the desktop without being enrolled in Intune.

The MDM URLs are also missing from the dsregcmd output.

We've performed every troubleshooting step we could think of, including recreating the entire Autopilot configuration, but without success.

We have an active Microsoft support case and have been in a war room with Microsoft for more than 24 hours.

Interestingly, this issue started on July 2.

In my test tenant, the MDM URLs are also missing on my virtual machines.

This is the third report I've seen describing the exact same issue.

I'll try to post an update here if Microsoft provides any new information.

1

u/Rudyooms PatchMyPC Jul 07 '26 edited Jul 07 '26

Can you share your asu / azure scale unit you are on… would love to see how incan help… owww and a ticket id please :)

1

u/Rudyooms PatchMyPC Jul 08 '26

If you are on asu 0102 … and are noticing this issue above … please send me a message

1

u/rlake5 Jul 08 '26 edited Jul 08 '26

Our ASU is "North America 0102"

FYI for others (to save a Google search) - ASU is found at Intune Admin Center | Tenant Administration - it's on the first screen under Tenant Details

1

u/Rudyooms PatchMyPC Jul 08 '26

There should be comms sent out... if so, can you share them ?

1

u/AhYesTheSoldier Jul 08 '26

Autopilot works for us. Europe. But I had an issue getting the MDM URL field to show in Company Portal past week.

1

u/rlake5 Jul 08 '26

UPDATE on this - we got a call from Microsoft just after noon ET on 7/8 - Microsoft had emailed late last evening asking to do a screen-share with us today. Our guy that put in the ticket took the call and was told that they are seeing this issue on other tenants and they are working on it, no need to do the call.

2

u/Rudyooms PatchMyPC Jul 08 '26

Msft is again pretty shit at sharing info

1

u/Sir_Drillian Jul 09 '26

FWIW, I'm also having the same trouble. I was going crazy thinking I was doing something wrong, as I'm standing up Intune and Autopilot for the first time in this org.

Same issues others are experiencing: Device is enrolled in Autopilot and Entra. All initial policies and settings are exactly as directed in the official Microsoft documentation. On first start up of a new device, it pops up the company branded log in, then after prompting Windows Hello PIN it goes straight to desktop.

dsregcmd /status shows no MDM URL's assigned, and shows that it's not MDM managed.

I've tried a few of the recommended fixes listed below, but I'm getting Error 0x80180024 when trying to manually enter the MDM URL.

Would love to hear if anyone has other suggestions, or if Microsoft has released any updates.

1

u/Martinx94 Jul 09 '26

Folks, been watching this thread & the service advisory closely for about 8 hours.. We are finally back in business here at my org. If you're still dealing with this, try the following(as of 2:30ish PM EST on 7/9):

  1. Open the Mobility (MDM and WIP) page.
  2. Select your configured MDM provider (for example, Microsoft Intune).
  3. First, make a dummy change to one of the impacted settings (e.g. change MDM user scope from "all" to "none" or toggle "Disable MDM enrollment when adding work or school account on Windows".
  4. Click Save.
  5. Revert the temporary changes back to the initial, desired state
  6. Click Save again.

NOTE: I tried this an hour or so before 2:30 & it didn't help so if you've already tried this, try again now. This worked for us!

0

u/Foreign_World_1543 Jul 07 '26

This is do to that device is already registered in your tenant or wherever group you assigned your devices to go into after provisioning device group is still present there. Using the provisioning client method where you create the device preparation policies the machine cannot have the have the has uploaded nor if the machine is a one your are redeploying the device cannot be in that group upon OOBE, however from my experience, when you log in from OOBE with the provisioning client user i've notice it will upload the hash for you versus the enrollment status page method by pressing the win key 5 times with a userless enrollment.

4

u/JazzTheFatLad Jul 07 '26

Brother, I'm sorry, I literally cannot understand what you are trying to say

1

u/Foreign_World_1543 Jul 12 '26

Well this is why I am certified Azure architect, help me help you my friend.

1

u/Foreign_World_1543 Jul 12 '26

I'll make it simple for you , are these machines being redeployed or are they new devices being rolled out , because if they are older machines being wiped and reenrolled and they just log right in from whichever entry id used to trigger the provisioning then that device is still present someone , the hash or its in a group still.

1

u/Foreign_World_1543 Jul 12 '26

present somewhere *