Registering devices with Intune for management and policy enforcement
A likely cause is the AzureAdPrt status not being consistently available. Automatic MDM enrolment using user credentials depends on the user obtaining a valid PRT. If AzureAdPrt is showing No most of the time, focus on fixing the Entra sign-in state first.
Also check:
- Event Viewer -> Applications and Services Logs -> Microsoft -> Windows -> DeviceManagement-Enterprise-Diagnostics-Provider > Admin
- Scheduled Task: Microsoft -> Windows -> EnterpriseMgmt for enrolment failures
-
dsregcmd /statusand confirm AzureAdJoined = YES, DomainJoined = YES, and AzureAdPrt = YES - Entra sign-in logs for MDM enrolment failures or Conditional Access blocks
- Intune enrolment restrictions and device limits
If the device never gets a stable PRT, Intune enrolment via GPO will generally not complete successfully.