What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Intune enrollment error 0x801c0003 usually means the user is not authorized to enroll that Windows device. Check the exact code, Windows edition, the user’s Intune device limit, the assigned Windows enrollment restrictions, and Microsoft Entra device-join permissions before trying local workarounds. Microsoft also shows 80180003 with a similar “Something went wrong” message; record the exact code on your screen because that wording can cover different failures.

Start with the exact error and enrollment method

“Something went wrong” is a generic screen, not a diagnosis. Microsoft documents 0x801c0003 in the “This user is not authorized to enroll” scenario and shows 80180003 in the same troubleshooting context. Preserve the exact characters and any 0x prefix from your device, event logs, or enrollment report; do not assume every 801c... or 801800... code has the same cause.

First note how enrollment was started: Windows Settings > Accounts > Access work or school, Windows out-of-box experience (OOBE), Autopilot, Company Portal, Group Policy automatic enrollment, or co-management. The same screen text can accompany different problems. For example, Microsoft lists separate errors for an already-enrolled device, incorrect MDM configuration, Autopilot, and hybrid join. Use the Windows enrollment error guide if your exact code differs or your setup uses a different route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick checks, in order

  1. Confirm the exact error code and whether the device is personal or organization-owned.
  2. Check the PC’s Windows edition. Windows Home is not supported for this enrollment path; Windows Pro or higher is required.
  3. Check whether the user has reached the applicable Intune device limit.
  4. Verify that the user’s assigned enrollment restrictions allow Windows MDM enrollment and the device’s ownership type.
  5. Confirm the user is allowed to join devices to Microsoft Entra ID.
  6. Check licensing and, for automatic enrollment, the user’s MDM scope.
  7. If this PC was previously managed or assigned to someone else, investigate its existing Intune, Entra, and—where applicable—Autopilot records before cleanup.

1. Check the Intune device limit

Microsoft’s troubleshooting guidance gives 15 as the standard maximum in the applicable user device-limit setting. That is not a universal limit for every enrollment model: Device Enrollment Manager (DEM) is a separate approach that can enroll up to 1,000 devices, subject to its own requirements and limitations.

In the Microsoft Intune admin center, go to Users > All users, select the affected user, and open Devices. Identify obsolete records carefully; compare the device name, serial number, user, ownership, and last check-in rather than deleting records indiscriminately. Remove only records confirmed to be unused or obsolete, then allow time for changes to propagate and retry.

If the user legitimately needs more enrollments, review the setting instead: go to Devices > Enrollment restrictions, open the applicable default restriction under Device limit restrictions, choose Properties, then Edit beside Device limit. Adjust it only as needed, within the maximum supported by the setting, and select Review + Save. Raising a restriction can affect more than one user; removing stale records or choosing an enrollment method suited to the fleet may be more precise.

A DEM account is intended for scenarios such as preparing multiple shared devices, not as a blanket bypass for an individual’s authorization problem. Windows devices enrolled this way use shared-device behavior, and DEM may not fit personal devices or personalized deployments. See Microsoft’s DEM requirements and limitations.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Verify Windows platform and ownership restrictions

In Intune, open Devices > Enrollment and find Enrollment device platform restrictions (labels can vary slightly as the admin center changes). Open the restriction that applies to the user, then check its properties and assignments. Confirm Windows MDM enrollment is allowed and review ownership, minimum and maximum OS versions, manufacturer settings, filters, and policy priority. Intune separates platform restrictions from device-limit restrictions; an allowed platform does not necessarily mean that every ownership type or device passes the assigned policy. See Microsoft’s overview of enrollment restrictions and platform restriction guidance.

For a personal or BYOD PC, check explicitly whether personally owned Windows devices are allowed. A tenant can allow corporate Windows enrollment while blocking personal Windows enrollment. Review the Windows restriction assigned to the affected user, including any higher-priority policy or enrollment filter that may exclude the device. Microsoft covers this scenario in its guide to troubleshooting “Set up for work or school” enrollment.

If the applicable Windows restriction already says Allow, first verify its assignment and scope. Microsoft documents changing Windows to Block, saving, and then setting it back to Allow as a targeted reset for a particular troubleshooting scenario—not as a substitute for checking the actual policy. After changing restrictions, group membership, or filters, wait before retrying: Microsoft says enrollment assignment updates between Entra and Intune typically take about 15 minutes.

3. Check the Windows edition

On the PC, open Settings > System > About and look under Windows specifications for Edition. If it says Windows Home, an Intune policy change will not make this edition eligible for the documented enrollment path. Upgrade to an eligible Pro-or-higher edition, activate it, restart if required, and try again. Microsoft’s error-specific guidance and Windows enrollment guide describe the edition requirement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Edition eligibility and support lifecycle are separate questions. Windows 10 reached the end of general support on October 14, 2025, but Microsoft says Windows 10 devices may still enroll in Intune; functionality is not guaranteed. Do not infer that Windows 10 cannot enroll solely because it is out of support.

4. Confirm Microsoft Entra device-join permission

The user can be blocked before Intune enrollment if the tenant does not permit that account to join devices to Microsoft Entra ID. In the Microsoft Entra admin center, open Microsoft Entra ID > Devices > Device settings and check Users may join devices to Microsoft Entra ID. If it is None, or set to Selected without the affected user or group, update it to the organization’s intended scope: All, or Selected with the correct user/group included. Save, allow the change to propagate, and retry.

Permission to join Entra devices is necessary in relevant scenarios, but it does not guarantee enrollment by itself. The user still needs an eligible Intune entitlement, the right automatic-enrollment configuration if applicable, and enrollment restrictions that allow the platform and ownership type.

5. Verify license and automatic-enrollment scope

Check that the user has an eligible Intune entitlement for the enrollment method in use. There is no single license name that applies to every tenant and enrollment scenario. For automatic Windows enrollment, verify that the user is included in the Microsoft Entra MDM automatic-enrollment scope and that the MAM/WIP scope is not mistakenly being used in place of MDM for this scenario. Also confirm that the device is using the expected tenant and that its enrollment route is supported for its edition and ownership.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Autopilot, BYOD user enrollment, automatic enrollment, and co-management have different prerequisites. Use Microsoft’s Windows device enrollment guide to check the method actually being used rather than applying another method’s setup steps.

6. Investigate previous enrollment or stale device identity

If the PC was reset, cloned, reassigned, or enrolled by another user, its existing state may complicate a new attempt. Check Settings > Accounts > Access work or school for existing connections. In Intune and Entra, compare device records using the device name, serial number, user, and ownership. For an organization-owned Autopilot device, also confirm its Autopilot record and assigned profile.

Microsoft documents 8018000a as an already-enrolled-device error, distinct from 0x801c0003. The distinction matters: a prior enrollment can be relevant, but it does not make the codes interchangeable. If cleanup is appropriate, first verify that the device is no longer needed by its previous user and follow your organization’s process for the work/school connection and the correct cloud records. Restart, then retry the intended enrollment method.

Deleting a cloud record does not necessarily remove local enrollment state, and deleting the wrong object can disrupt a working device. Do not start by removing certificates or editing the registry: Microsoft documents such cleanup for a different “machine already enrolled” condition, and applying it indiscriminately can damage enrollment state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If enrollment is through Autopilot or hybrid join

Do not treat an OOBE or hybrid-join failure as an ordinary user enrollment without checking the route. Autopilot, hybrid join, and Group Policy automatic enrollment can depend on the assigned Autopilot profile, domain connectivity, synchronization, connector health, and enrollment status page. Start with the exact code and the device’s assigned method, then use Microsoft’s Windows enrollment troubleshooting guide or Autopilot troubleshooting FAQ for that specific path.

Collect evidence before escalating

On the affected PC, run this in Command Prompt or PowerShell:

dsregcmd /status

This is diagnostic output, not a repair command. It can help establish whether the device is Microsoft Entra joined, registered, or hybrid joined and show relevant authentication state. Redact sensitive identifiers before sharing it.

Give the administrator or support team:

  • The exact code and complete message, plus a screenshot if permitted.
  • Windows edition and build, and whether the device is personal or organization-owned.
  • Enrollment route and when the failure occurs (during OOBE or after setup).
  • User and group assignments, the applicable platform and device-limit restrictions, and Entra join permission scope.
  • Device name and serial number, plus matching Intune, Entra, and—if applicable—Autopilot records.
  • Whether the user has reached the applicable device limit or another work account is connected.
  • Relevant Windows enrollment/device-management event logs and enrollment-report details.
  • The time of the failure, including time zone, and redacted dsregcmd /status output.

Admin-center paths and labels can change. If a label differs slightly in your tenant, look for the setting’s purpose—Windows platform/ownership restriction, device limit, or Entra device-join scope—rather than changing an unrelated policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.