You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: support/mem/intune/device-enrollment/troubleshoot-ios-enrollment-errors.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,11 +19,11 @@ The following table lists errors that end users might see while enrolling iOS/iP
19
19
|-------------|-----|----------|
20
20
|NoEnrollmentPolicy|No enrollment policy found| The Apple Push Notification Service (APNs) certificate is missing, invalid, or expired. Check that enrollment has been set up correctly and that **iOS/iPadOS as a platform** is enabled. For instructions, see [Set up iOS/iPadOS and Mac device management](/mem/intune/enrollment/ios-enroll),[Get an Apple MDM push certificate](/mem/intune/enrollment/apple-mdm-push-certificate-get#steps-to-get-your-certificate), and [Renew Apple MDM push certificate](/mem/intune/enrollment/apple-mdm-push-certificate-get#renew-apple-mdm-push-certificate).|
21
21
|DeviceCapReached|Too many mobile devices are enrolled already.|The user must remove one of their currently enrolled mobile devices from the Company Portal before enrolling another. See detailed instructions [here](troubleshoot-device-enrollment-in-intune.md#device-cap-reached).|
22
-
|Company Portal Temporarily Unavailable| The Company Portal app on the device is out of date or corrupted.| Remove the app, validate user credentials, and then resinstall the app. See detailed instructions [here](troubleshoot-device-enrollment-in-intune.md#company-portal-temporarily-unavailable).|
22
+
|Company Portal Temporarily Unavailable| The Company Portal app on the device is out of date or corrupted.| Remove the app, validate user credentials, and then reinstall the app. See detailed instructions [here](troubleshoot-device-enrollment-in-intune.md#company-portal-temporarily-unavailable).|
23
23
|APNSCertificateNotValid|There's a problem with the certificate that lets the mobile device communicate with your company's network.<br /><br />|The Apple Push Notification Service (APNs) provides a channel to contact enrolled iOS/iPadOS devices. Enrollment will fail and this message will appear if:<ul><li>The steps to get an APNs certificate weren't completed, or</li><li>The APNs certificate has expired.</li></ul>Renew the APNs certificate, and then re-enroll the device.<br/>**Important:** Make sure that you renew the APNs certificate. Don't *replace* the APNs certificate. If you replace the certificate, you have to re-enroll all iOS/iPadOS devices in Intune. For Intune standalone, see [Renew Apple MDM push certificate](/mem/intune/enrollment/apple-mdm-push-certificate-get#renew-apple-mdm-push-certificate). For Microsoft 365, see [Create an APNs Certificate for iOS devices](/microsoft-365/admin/basic-mobility-security/create-an-apns-certificate-for-ios-devices).|
24
24
|AccountNotOnboarded|There's a problem with the certificate that lets the mobile device communicate with your company's network. |The Apple Push Notification Service (APNs) provides a channel to contact enrolled iOS/iPadOS devices. Enrollment will fail and this message will appear if:<ul><li>The steps to get an APNs certificate weren't completed, or</li><li>The APNs certificate has expired.</li></ul>Review [Create an APNs certificate for iOS devices](/microsoft-365/admin/basic-mobility-security/create-an-apns-certificate-for-ios-devices).|
25
25
|DeviceTypeNotSupported|The user might have tried to enroll using a non-iOS device. The mobile device type that you're trying to enroll isn't supported.<br/><br/>Confirm that device is running iOS/iPadOS version 8.0 or later.<br/><br/>|Make sure that your user's device is running iOS/iPadOS version 8.0 or later.|
26
-
|UserLicenseTypeInvalid|The device can't be enrolled because the user's account isn't yet a member of a required user group or the user does not have the correct license.<br/><br/>|Users must have the correct license type for the mobile device management authority. For example, they'll see this error if Intune has been set as the MDM authority, but the user has a System Center 2012 R2 Configuration Manager license.<br/><br/>Review [Set up iOS/iPadOS and Mac management with Microsoft Intune](/mem/intune/enrollment/ios-enroll) and information about how to set up users in [Sync Active Directory and add users to Intune](/mem/intune/fundamentals/users-add) and [organizing users and devices](/mem/intune/fundamentals/groups-add).|
26
+
|UserLicenseTypeInvalid|The device can't be enrolled because the user's account isn't yet a member of a required user group or the user doesn't have the correct license.<br/><br/>|Users must have the correct license type for the mobile device management authority. For example, they'll see this error if Intune has been set as the MDM authority, but the user has a System Center 2012 R2 Configuration Manager license.<br/><br/>Review [Set up iOS/iPadOS and Mac management with Microsoft Intune](/mem/intune/enrollment/ios-enroll) and information about how to set up users in [Sync Active Directory and add users to Intune](/mem/intune/fundamentals/users-add) and [organizing users and devices](/mem/intune/fundamentals/groups-add).|
27
27
|MdmAuthorityNotDefined|The mobile device management authority hasn't been defined.<br /><br />|The mobile device management authority hasn't been set in Intune.<br /><br />Review item #1 in the **Step 6: Enroll mobile devices and install an app** section in [Get started with a 30-day trial of Microsoft Intune](/mem/intune/fundamentals/free-trial-sign-up).|
28
28
29
29
## Sync token errors between Intune and ADE
@@ -43,7 +43,7 @@ This section includes token sync errors related to Apple Automated Device Enroll
43
43
| Invalid configuration profile name | The configuration profile name is either invalid, empty, or too long. | Edit the name of the profile. |
44
44
| Invalid cursor | The cursor was rejected by Apple or not found. | Contact the [Intune support team](/mem/get-support). They can retry syncing from the Intune service. |
45
45
| Cursor expired | The cursor is expired on Intune's side. | Contact the [Intune support team](/mem/get-support). They can retry syncing from the Intune service. |
46
-
| Required cursor | The cursor was not initially set by Intune during the sync. | Contact the [Intune support team](/mem/get-support) to fix the sync and return the cursor. |
46
+
| Required cursor | The cursor wasn't initially set by Intune during the sync. | Contact the [Intune support team](/mem/get-support) to fix the sync and return the cursor. |
47
47
| Apple profile not found | Multiple possible causes | Create a new profile, and assign the profile to devices. |
48
48
| Invalid department entry | The department field entry is invalid | Edit the department field for your profiles. |
49
49
@@ -109,14 +109,14 @@ This section provides troubleshooting steps for these additional scenarios:
109
109
- [Workplace Join failed](#workplace-join-failed)
110
110
- [User Name Not Recognized](#user-name-not-recognized)
- [The configuration could not be downloaded...Invalid Profile](#the-configuration-for-your-iphoneipad-could-not-be-downloaded-from-company-name-invalid-profile)
112
+
- [The configuration couldn't be downloaded...Invalid Profile](#the-configuration-for-your-iphoneipad-couldnt-be-downloaded-from-company-name-invalid-profile)
- [ADE enrollment stuck at user login](#ade-enrollment-stuck-at-user-login)
115
115
- [Authentication doesn't redirect to the government cloud](#authentication-doesnt-redirect-to-the-government-cloud)
116
116
117
117
### Verify WS-Trust 1.3 is enabled
118
118
119
-
Enrolling ADE devices with user affinity requires WS-Trust 1.3 Username/Mixed endpoint to be enabled to request user tokens. Active Directory enables this endpoint by default. If WS-Trust 1.3 is not enabled, Automated Device Enrollment (ADE) iOS/iPadOS devices can't be enrolled.
119
+
Enrolling ADE devices with user affinity requires WS-Trust 1.3 Username/Mixed endpoint to be enabled to request user tokens. Active Directory enables this endpoint by default. If WS-Trust 1.3 isn't enabled, Automated Device Enrollment (ADE) iOS/iPadOS devices can't be enrolled.
120
120
121
121
To get a list of enabled endpoints, use the `Get-AdfsEndpoint` PowerShell cmdlet and looking for the trust/13/UsernameMixed endpoint. For example:
122
122
@@ -138,7 +138,7 @@ This error indicates that the Company Portal app is out of date or corrupted.
138
138
139
139
### User Name Not Recognized
140
140
141
-
The error "User Name Not Recognized. This user account is not authorized to use Microsoft Intune. Contact your system administrator if you think you have received this message in error." indicates that the user who is trying to enroll the device does not have a valid Intune license.
141
+
The error "User Name Not Recognized. This user account isn't authorized to use Microsoft Intune. Contact your system administrator if you think you have received this message in error." indicates that the user who is trying to enroll the device doesn't have a valid Intune license.
142
142
143
143
1. Go to the [Microsoft 365 admin center](https://admin.microsoft.com), and then choose **Users** > **Active Users**.
144
144
2. Select the affected user account, and then choose **Product licenses** > **Edit**.
**Solution:** Fix the connection issue, or use a different network connection to enroll the device. You may also have to contact Apple if the issue persists.
163
163
164
-
### The configuration for your iPhone/iPad could not be downloaded from \<Company Name>: Invalid Profile
164
+
### The configuration for your iPhone/iPad couldn't be downloaded from \<Company Name>: Invalid Profile
165
165
166
166
**Cause:** The enrollment is blocked by a device type restriction.
167
167
@@ -187,15 +187,15 @@ When you turn on an ADE-managed device that is assigned an enrollment profile, t
187
187
188
188
When you turn on an ADE-managed device that is assigned an enrollment profile, the initial setup sticks after you enter credentials.
189
189
190
-
**Cause:**Multi-Factor authentication (MFA) is enabled. Currently, MFA doesn't work during enrollment on ADE devices if the authentication method is set to **Setup Assistant (legacy)**.
190
+
**Cause:**Multifactor authentication (MFA) is enabled. Currently, MFA doesn't work during enrollment on ADE devices if the authentication method is set to **Setup Assistant (legacy)**.
191
191
192
192
**Solution:** Disable MFA, and then re-enroll the device. Alternatively, change the authentication method to **Setup Assistant with modern authentication**.
193
193
194
194
### Authentication doesn't redirect to the government cloud
195
195
196
196
Government users signing in from another device are redirected to the public cloud for authentication rather than the government cloud.
197
197
198
-
**Cause:** Microsoft Entra ID does not yet support redirecting to the government cloud when signing in from another device.
198
+
**Cause:** Microsoft Entra ID doesn't yet support redirecting to the government cloud when signing in from another device.
199
199
200
200
**Solution:**
201
201
Use the iOS Company Portal **Cloud** setting in the **Settings** app to redirect government users' authentication towards the government cloud. By default, the **Cloud** setting is set to **Automatic** and Company Portal directs authentication towards the cloud that is automatically detected by the device (such as Public or Government). Government users who are signing in from another device will need to manually select the government cloud for authentication.
0 commit comments