Unable to enroll in ESU because of MDM whose origin I do not understand

TomD22 20 Reputation points
2025-10-06T20:24:14.78+00:00

I have a home-built PC which is quite old; I started with Win 7 OEM version and later updated to Win 10 Pro. I have been attempting to enroll in ESU, but the link is not appearing in Updates. I have all the updates, and a MS account.

I asked about this problem on an expert site ("AskWoody"), and got several diagnosis scripts to run which showed that, even though nothing appears on "Accounts->Work and School," my PC thinks it has MDM. That is, IsDeviceRegisteredWithManagement() run in Powershell returns True.

Also, the relevant registry keys are

reg.exe query "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU"

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU

ESUEligibility    REG_DWORD    0x1

ESUEligibilityResult    REG_DWORD    0x4

indicating Ineligible and Commercial.

The ONLY thing I can imagine is that I purchased a copy of Office 2013 Professional Plus at a discount, using my employee status at a major company. Could this be related to my problem?

Any ideas on how to fix this would be appreciated.

Thanks,

Tom

Windows for home | Windows 10 | Extended Security Update (ESU)
0 comments No comments

Answer accepted by question author
Francisco Montilla 31,090 Reputation points Independent Advisor
2025-10-06T22:18:28.4533333+00:00

Hi Tom,

You are right about what those values mean. ESUEligibility is the cached state and ESUEligibilityResult 0x4 is Commercial. Windows thinks the PC is work managed, so the consumer ESU offer is hidden. Office 2013 Pro Plus by itself does not enroll a PC into MDM. What usually causes this is that at some point a work or school account was added or the device was Workplace Joined and the tenant had auto-enrollment enabled. Even if Settings shows nothing under Access work or school, stale Workplace Join and MDM traces can remain and keep reporting IsDeviceRegisteredWithManagement as True.

The single fix that works most often is to remove the hidden Workplace Join and MDM remnants, then force ESU to re-evaluate. Do this end to end exactly once.

Sign in with an admin account. Create a restore point if you like. Open Windows Terminal as Administrator. Run this to leave any hidden Workplace Join and clear the token cache.

dsregcmd /debug /leave

Open the legacy certificate console to remove the Workplace Join certificates. Press Win+R, type certlm.msc, press Enter. In Local Computer > Personal > Certificates, delete any certificate named MS-Organization-Access and MS-Organization-P2P-Access if you see them. Close the console.

Open Task Scheduler and expand Task Scheduler Library > Microsoft > Windows > EnterpriseMgmt. If you see one or more folders with long GUID names, delete the folder(s). If EnterpriseMgmt is empty, just close Task Scheduler.

Now back up and remove the local MDM enrollment keys. Still in the elevated Terminal run these in order.

reg export "HKLM\SOFTWARE\Microsoft\Enrollments" "%USERPROFILE%\Desktop\Enrollments_backup.reg" /y
reg export "HKLM\SOFTWARE\Microsoft\EnterpriseEnrollment" "%USERPROFILE%\Desktop\EnterpriseEnrollment_backup.reg" /y

reg delete "HKLM\SOFTWARE\Microsoft\Enrollments" /f
reg delete "HKLM\SOFTWARE\Microsoft\EnterpriseEnrollment" /f

Clear the ESU detection cache in your profile so Windows will recalc eligibility.

reg delete "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\ConsumerESU" /f

Restart the PC. After the reboot, confirm the device is no longer seen as managed. Open Windows Terminal and run:

powershell -NoLogo -NoProfile -Command "([System.Management.Automation.PSCustomObject]@{ AzureAdJoined = (dsregcmd /status | findstr /C:'AzureAdJoined').Trim(); WorkplaceJoined = (dsregcmd /status | findstr /C:'WorkplaceJoined').Trim(); MDM = (powershell -c '$env:COMPUTERNAME' >$null); })"

If you prefer the plain tool, just run dsregcmd /status and check the top section. You want AzureAdJoined: NO and WorkplaceJoined: NO.

Sign in with your Microsoft account under Settings > Accounts > Your info if you are not already. Go to Settings > Update and Security > Windows Update and select Check for updates. The ESU enrollment banner should appear within a minute if the device is now seen as a personal unmanaged PC. If it does not, give it one more Check for updates, then sign out and back in and check again.

If you still get ESUEligibilityResult showing 0x4 after this cleanup, it means something on the machine is still asserting management. In that case, share just the top Device State section from dsregcmd /status and I will tell you exactly what line is tripping the Commercial flag. But in most cases, the sequence above removes the stale join, resets the enrollment traces, and the ESU offer shows up.

Was this answer helpful?

4 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. David Allen 5 Reputation points
    2025-11-23T15:51:05.5966667+00:00

    Microsoft could not resolve this issue :-(

    After several hours of searching, I finally found what the results meant (why pc was not eligible for Windows 10 ESU) - which led me to your thread.

    Following your instructions resolved this issue for me - Thanks so much for sharing!

    Was this answer helpful?

    1 person found this answer helpful.

  2. Richard G 0 Reputation points
    2026-01-21T19:33:43.6133333+00:00

    I wish I could understand exactly what this all means but it is, sadly beyond me. MS Have just told me that as my PC was once connected with a business, they cannot change it to have ESU, but my level of technical experience is not enough to even understand how to open Windows Terminal!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.