Use this troubleshooting path for Windows device setup failures tied to enrollment or configuration:
- Verify Intune enrollment prerequisites.
- Confirm the affected user has a valid Intune license.
- Confirm automatic MDM enrollment is enabled for the users who should enroll devices.
- Confirm the device is running a supported version of Windows.
- If enrollment is done through Group Policy autoenrollment, verify device join state.
- On the device, run
dsregcmd /status. - For Microsoft Entra hybrid join, confirm AzureAdJoined = YES and DomainJoined = YES.
- Also confirm AzureAdPrt = YES in the SSO State section.
- If these values are not correct, fix the hybrid join state first before retrying enrollment.
- On the device, run
- Check whether Intune is blocking Windows enrollment.
- In the Microsoft Intune admin center, go to Devices > Enrollment restrictions.
- Open the relevant device type restriction.
- Select Properties > Edit next to Platform settings.
- Make sure Windows (MDM) is set to Allow.
- Save the change.
- If users are setting up devices with Set up for work or school during OOBE and enrollment fails, check personal device restrictions.
- This enrollment path can classify the device as a personal device.
- If personal device enrollment is blocked, setup can fail with enrollment errors such as
80180014. - In the Microsoft Intune admin center, go to Devices > Enroll devices > Enrollment device platform restrictions.
- Select Windows restrictions > Create restriction.
- On Platform settings, set Personally owned devices to Allow.
- Assign the restriction only to the users or groups that need personal Windows enrollment.
- Refresh enrollment diagnostics during OOBE if the failure occurs in Autopilot or enrollment status processing.
- Press Shift + F10 during OOBE to open Command Prompt.
- Run:
%windir%\system32\mdmdiagnosticstool.exe -area Autopilot;DeviceEnrollment -cab %temp%\autopilot-logs.cab - Review the generated CAB for Autopilot and DeviceEnrollment failures.
- If the setup stalls during device preparation with timeout
0x800705b4, inspect client installation state.- Run:
$key = 'HKLM:\SOFTWARE\Microsoft\Windows\Autopilot\EnrollmentStatusTracking\Device\DevicePreparation\PolicyProviders\ConfigMgr' Get-ItemPropertyValue -Path $key -Name InstallationState - Expected values:
-
1= Not installed -
2= Not required -
3= Complete -
4= Error
-
- If the state is not
3, review%windir%\ccmsetup\Logs\ccmsetup.logand confirm the device receivedCCMSetup.msifrom Intune and full client content from the CMG.
- Run:
- Re-run setup after correcting the enrollment configuration.
- For Windows 365 Cloud PCs, reset the Cloud PC after fixing the Intune or MDM configuration so setup runs again.
- If setup still fails after the reset, open a support request.
This sequence addresses the main causes of setup-incomplete scenarios: missing licensing, disabled autoenrollment, incorrect Microsoft Entra join state, blocked Windows MDM enrollment, blocked personal device enrollment, and Autopilot/ESP timeout during client installation.