# Autopilot Error 80180003 and 80180014: Fixes

Source: https://srvscripts.com/guides/autopilot-error-80180003-80180014/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

Autopilot failures show up at the worst moment: a new laptop, a user waiting, and a red “Something went wrong” screen with an eight-digit hex code. The two codes covered here, 80180003 and 80180014, both come from the MDM enrollment stage rather than from the Entra ID join, which narrows the cause considerably. This guide applies to Windows 11 24H2, 25H2 and 26H1 devices enrolling into Intune through user-driven or pre-provisioned Autopilot.

In short: Error 80180003 means the enrolling user is not permitted to enroll, usually because they have hit the per-user device enrollment limit or the MDM user scope excludes them; error 80180014 means the device or tenant is not allowed to enroll…

**Short answer:** Error 80180003 means the enrolling user is not permitted to enroll, usually because they have hit the per-user device enrollment limit or the MDM user scope excludes them; error 80180014 means the device or tenant is not allowed to enroll at all, typically because the Intune licence is missing, device type restrictions block it, or the device already has an active Intune record. Check Intune » Devices » Enrollment » Enrollment device limit restrictions and Entra ID » Mobility (MDM and WNS) » MDM user scope first, then review the DeviceManagement-Enterprise-Diagnostics-Provider event log on the device.

## Read the error on the device

Press Shift+F10 at the failure screen to open a command prompt, then pull the enrollment log:

```
wevtutil qe Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin /c:50 /rd:true /f:text
```

Event IDs 76 and 77 carry the enrollment result. You can also export the full Autopilot diagnostics bundle for later analysis:

```
mdmdiagnosticstool.exe -area Autopilot;DeviceEnrollment;TPM -cab C:\autopilot.cab
```

Copy the cab to a USB stick, or open it on another machine with Get-AutopilotDiagnostics from the PowerShell Gallery.

## Causes of 80180003

This code maps to “MENROLL_E_USERLICENSE” and its neighbours: the user is known but cannot enroll this device.

- Device enrollment limit reached. Intune » Devices » Enrollment » Device limit restrictions defaults to 5 devices per user (up to 15). A technician account that provisions machines all day exhausts this quickly. Either raise the limit for a group that contains the provisioning accounts or delete stale device objects from Intune.

- Entra ID device limit. Separately, Entra ID » Devices » Device settings » “Maximum number of devices per user” defaults to 50 and also applies.

- MDM user scope. Entra ID » Mobility (MDM and WNS) » Microsoft Intune » MDM user scope must be “All” or a group containing the user. If the group is dynamic, confirm the membership has evaluated.

- No Intune licence assigned to the user. Assign an Intune Plan 1 or bundle licence and wait for propagation before retrying.

## Causes of 80180014

This code reports that enrollment is blocked for the device or platform.

- Platform restrictions. Intune » Devices » Enrollment » Device platform restrictions may block Windows (MDM) or block personally owned devices. Autopilot devices count as corporate because their hardware hash is registered, but a restriction with a higher priority assigned to the user’s group can still bite.

- Existing enrollment. If the serial number already has an Intune device object from a previous life, reuse can fail. Retire or delete the old object, wait fifteen minutes, then reset the device again.

- Tenant not licensed for Intune at all, or the MDM authority never set.

- The device is joined to a different tenant’s Autopilot profile because the hardware hash was uploaded to the wrong tenant. Check Intune » Devices » Windows » Windows enrollment » Devices for the serial.

## Fix the common ones with PowerShell

Raising the enrollment limit and clearing stale devices can be scripted with the Microsoft Graph PowerShell SDK:

```
Connect-MgGraph -Scopes "DeviceManagementServiceConfig.ReadWrite.All","DeviceManagementManagedDevices.ReadWrite.All"
Get-MgDeviceManagementDeviceEnrollmentConfiguration | Where-Object { $_.Id -like "*Limit*" } | Format-List DisplayName, Priority, Id
Get-MgDeviceManagementManagedDevice -Filter "serialNumber eq 'ABC12345'" | Select-Object DeviceName, Id, EnrolledDateTime
Remove-MgDeviceManagementManagedDevice -ManagedDeviceId
```

After deleting an old record, also remove the Entra ID device object if it exists, then restart the OOBE by running `sysprep /oobe /reboot` or a full reset from the failure screen.

## Verify it worked

Re-run the enrollment; a successful device appears within minutes in Intune » Devices » All devices with an enrollment date. On the device, `dsregcmd /status` should show AzureAdJoined : YES and the MDM URL populated under Device State. Event ID 72 in the DeviceManagement log confirms the enrollment succeeded.

## Common pitfall

A frequent trap is deleting the Autopilot device record itself (under Windows enrollment » Devices) to “start clean”. That removes the hardware hash and turns the next boot into a plain OOBE without the Autopilot profile. Delete the Intune managed device and the Entra ID device, but leave the Autopilot registration alone unless you intend to re-upload the hash. For related provisioning methods see [Bulk-enroll Windows 11 devices into Intune with a provisioning package](/guides/intune-bulk-enrollment-provisioning-package/).

## Autopilot error 80180003 at a glance

**Official documentation:** [Microsoft Intune documentation](https://learn.microsoft.com/en-us/mem/intune/), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Deploy Win32 apps with Intune: IntuneWinAppUtil packaging and detection rules](https://srvscripts.com/guides/intune-win32-app-deployment/) · [Bulk-enroll Windows 11 devices into Intune with a provisioning package](https://srvscripts.com/guides/intune-bulk-enrollment-provisioning-package/) · [How to find the source of Active Directory account lockouts (Event ID 4740)](https://srvscripts.com/guides/ad-account-lockout-source-event-4740/).

## Frequently asked questions

### Does error 80180003 also apply to Entra ID join without Autopilot?

Yes, the same code appears when a user manually joins a device through Settings » Accounts » Access work or school, because the MDM enrollment step and its limits are identical. The fixes are the same: enrollment limit, MDM user scope and licence.

### How long does it take for a raised enrollment limit to take effect?

Enrollment restriction changes normally apply within a few minutes, but licence assignments and dynamic group membership can take up to an hour to propagate. Retry after 15 minutes, and again after an hour before assuming the change did not work.

### Can I retry Autopilot without wiping the device again?

Usually yes: from the error screen choose “Try again” after fixing the tenant-side cause. If the device has partially enrolled, a reset from Settings or `systemreset -factoryreset` is cleaner and only takes a few minutes on modern hardware.
