What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Intune enrollment error 0x801c0003 usually means the user is not authorized to enroll that Windows device. Check the exact code, Windows edition, the user’s Intune device limit, the assigned Windows enrollment restrictions, and Microsoft Entra device-join permissions before trying local workarounds. Microsoft also shows 80180003 with a similar “Something went wrong” message; record the exact code on your screen because that wording can cover different failures.
Start with the exact error and enrollment method
“Something went wrong” is a generic screen, not a diagnosis. Microsoft documents 0x801c0003 in the “This user is not authorized to enroll” scenario and shows 80180003 in the same troubleshooting context. Preserve the exact characters and any 0x prefix from your device, event logs, or enrollment report; do not assume every 801c... or 801800... code has the same cause.
First note how enrollment was started: Windows Settings > Accounts > Access work or school, Windows out-of-box experience (OOBE), Autopilot, Company Portal, Group Policy automatic enrollment, or co-management. The same screen text can accompany different problems. For example, Microsoft lists separate errors for an already-enrolled device, incorrect MDM configuration, Autopilot, and hybrid join. Use the Windows enrollment error guide if your exact code differs or your setup uses a different route.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Quick checks, in order
- Confirm the exact error code and whether the device is personal or organization-owned.
- Check the PC’s Windows edition. Windows Home is not supported for this enrollment path; Windows Pro or higher is required.
- Check whether the user has reached the applicable Intune device limit.
- Verify that the user’s assigned enrollment restrictions allow Windows MDM enrollment and the device’s ownership type.
- Confirm the user is allowed to join devices to Microsoft Entra ID.
- Check licensing and, for automatic enrollment, the user’s MDM scope.
- If this PC was previously managed or assigned to someone else, investigate its existing Intune, Entra, and—where applicable—Autopilot records before cleanup.
1. Check the Intune device limit
Microsoft’s troubleshooting guidance gives 15 as the standard maximum in the applicable user device-limit setting. That is not a universal limit for every enrollment model: Device Enrollment Manager (DEM) is a separate approach that can enroll up to 1,000 devices, subject to its own requirements and limitations.
#1 Best Overall
In the Microsoft Intune admin center, go to Users > All users, select the affected user, and open Devices. Identify obsolete records carefully; compare the device name, serial number, user, ownership, and last check-in rather than deleting records indiscriminately. Remove only records confirmed to be unused or obsolete, then allow time for changes to propagate and retry.
If the user legitimately needs more enrollments, review the setting instead: go to Devices > Enrollment restrictions, open the applicable default restriction under Device limit restrictions, choose Properties, then Edit beside Device limit. Adjust it only as needed, within the maximum supported by the setting, and select Review + Save. Raising a restriction can affect more than one user; removing stale records or choosing an enrollment method suited to the fleet may be more precise.
A DEM account is intended for scenarios such as preparing multiple shared devices, not as a blanket bypass for an individual’s authorization problem. Windows devices enrolled this way use shared-device behavior, and DEM may not fit personal devices or personalized deployments. See Microsoft’s DEM requirements and limitations.
Free tools Windows power users keep installed
One-click scans. No signup required.
2. Verify Windows platform and ownership restrictions
In Intune, open Devices > Enrollment and find Enrollment device platform restrictions (labels can vary slightly as the admin center changes). Open the restriction that applies to the user, then check its properties and assignments. Confirm Windows MDM enrollment is allowed and review ownership, minimum and maximum OS versions, manufacturer settings, filters, and policy priority. Intune separates platform restrictions from device-limit restrictions; an allowed platform does not necessarily mean that every ownership type or device passes the assigned policy. See Microsoft’s overview of enrollment restrictions and platform restriction guidance.
Rank #2
For a personal or BYOD PC, check explicitly whether personally owned Windows devices are allowed. A tenant can allow corporate Windows enrollment while blocking personal Windows enrollment. Review the Windows restriction assigned to the affected user, including any higher-priority policy or enrollment filter that may exclude the device. Microsoft covers this scenario in its guide to troubleshooting “Set up for work or school” enrollment.
If the applicable Windows restriction already says Allow, first verify its assignment and scope. Microsoft documents changing Windows to Block, saving, and then setting it back to Allow as a targeted reset for a particular troubleshooting scenario—not as a substitute for checking the actual policy. After changing restrictions, group membership, or filters, wait before retrying: Microsoft says enrollment assignment updates between Entra and Intune typically take about 15 minutes.
3. Check the Windows edition
On the PC, open Settings > System > About and look under Windows specifications for Edition. If it says Windows Home, an Intune policy change will not make this edition eligible for the documented enrollment path. Upgrade to an eligible Pro-or-higher edition, activate it, restart if required, and try again. Microsoft’s error-specific guidance and Windows enrollment guide describe the edition requirement.
Recommended Free Tools
Edition eligibility and support lifecycle are separate questions. Windows 10 reached the end of general support on October 14, 2025, but Microsoft says Windows 10 devices may still enroll in Intune; functionality is not guaranteed. Do not infer that Windows 10 cannot enroll solely because it is out of support.
Rank #3
4. Confirm Microsoft Entra device-join permission
The user can be blocked before Intune enrollment if the tenant does not permit that account to join devices to Microsoft Entra ID. In the Microsoft Entra admin center, open Microsoft Entra ID > Devices > Device settings and check Users may join devices to Microsoft Entra ID. If it is None, or set to Selected without the affected user or group, update it to the organization’s intended scope: All, or Selected with the correct user/group included. Save, allow the change to propagate, and retry.
Permission to join Entra devices is necessary in relevant scenarios, but it does not guarantee enrollment by itself. The user still needs an eligible Intune entitlement, the right automatic-enrollment configuration if applicable, and enrollment restrictions that allow the platform and ownership type.
5. Verify license and automatic-enrollment scope
Check that the user has an eligible Intune entitlement for the enrollment method in use. There is no single license name that applies to every tenant and enrollment scenario. For automatic Windows enrollment, verify that the user is included in the Microsoft Entra MDM automatic-enrollment scope and that the MAM/WIP scope is not mistakenly being used in place of MDM for this scenario. Also confirm that the device is using the expected tenant and that its enrollment route is supported for its edition and ownership.
Autopilot, BYOD user enrollment, automatic enrollment, and co-management have different prerequisites. Use Microsoft’s Windows device enrollment guide to check the method actually being used rather than applying another method’s setup steps.
Rank #4
6. Investigate previous enrollment or stale device identity
If the PC was reset, cloned, reassigned, or enrolled by another user, its existing state may complicate a new attempt. Check Settings > Accounts > Access work or school for existing connections. In Intune and Entra, compare device records using the device name, serial number, user, and ownership. For an organization-owned Autopilot device, also confirm its Autopilot record and assigned profile.
Microsoft documents 8018000a as an already-enrolled-device error, distinct from 0x801c0003. The distinction matters: a prior enrollment can be relevant, but it does not make the codes interchangeable. If cleanup is appropriate, first verify that the device is no longer needed by its previous user and follow your organization’s process for the work/school connection and the correct cloud records. Restart, then retry the intended enrollment method.
Deleting a cloud record does not necessarily remove local enrollment state, and deleting the wrong object can disrupt a working device. Do not start by removing certificates or editing the registry: Microsoft documents such cleanup for a different “machine already enrolled” condition, and applying it indiscriminately can damage enrollment state.
If enrollment is through Autopilot or hybrid join
Do not treat an OOBE or hybrid-join failure as an ordinary user enrollment without checking the route. Autopilot, hybrid join, and Group Policy automatic enrollment can depend on the assigned Autopilot profile, domain connectivity, synchronization, connector health, and enrollment status page. Start with the exact code and the device’s assigned method, then use Microsoft’s Windows enrollment troubleshooting guide or Autopilot troubleshooting FAQ for that specific path.
Best Value
Collect evidence before escalating
On the affected PC, run this in Command Prompt or PowerShell:
dsregcmd /status
This is diagnostic output, not a repair command. It can help establish whether the device is Microsoft Entra joined, registered, or hybrid joined and show relevant authentication state. Redact sensitive identifiers before sharing it.
Give the administrator or support team:
- The exact code and complete message, plus a screenshot if permitted.
- Windows edition and build, and whether the device is personal or organization-owned.
- Enrollment route and when the failure occurs (during OOBE or after setup).
- User and group assignments, the applicable platform and device-limit restrictions, and Entra join permission scope.
- Device name and serial number, plus matching Intune, Entra, and—if applicable—Autopilot records.
- Whether the user has reached the applicable device limit or another work account is connected.
- Relevant Windows enrollment/device-management event logs and enrollment-report details.
- The time of the failure, including time zone, and redacted
dsregcmd /statusoutput.
Admin-center paths and labels can change. If a label differs slightly in your tenant, look for the setting’s purpose—Windows platform/ownership restriction, device limit, or Entra device-join scope—rather than changing an unrelated policy.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsQuick Recap
Sources
- Windows user is not authorized to enroll in Intune
- Troubleshooting Windows device enrollment problems in Intune
- Windows device enrollment guide
- Overview of enrollment restrictions
- Create device platform restrictions
- Troubleshoot “Set up for work or school” enrollment
- Enroll devices using a device enrollment manager account
- Windows Autopilot troubleshooting FAQ
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

