Device Immediately Removed from Intune

Resolve MFA-related device enrollment failures.

Last updated: 2025-01-15 Troubleshooting

Overview

Symptom

During device migration, devices successfully join Intune but are immediately removed from the tenant. The device appears briefly in Intune admin center then disappears.

What Happens

Device Joins
Enrollment succeeds
🔐
MFA Check
Policy evaluates
Device Removed
Non-compliant

Root Cause

MFA Required on Provisioning Account

The issue occurs when:

Automatic MDM Enrollment is Enabled

Windows devices automatically enroll in Intune when joining Azure AD

MFA is Required for All Users

Conditional Access policy requires MFA, including the provisioning account

Bulk Token Cannot Satisfy MFA

The provisioning package uses a bulk token that cannot complete MFA challenges

Solution

Exclude Provisioning Account from MFA

1

Access Conditional Access

Navigate to Microsoft Entra admin center → Protection → Conditional Access

2

Edit MFA Policy

Select the Conditional Access policy that requires MFA for device enrollment

3

Add Exclusion

Under Users → Exclude, add the account used to create the provisioning package

4

Save and Test

Save the policy and retry device enrollment with the provisioning package

Prevention

Best Practices

  • Create a dedicated service account for provisioning packages
  • Exclude this account from all MFA policies before creating the package
  • Test the provisioning package manually before bulk deployment
  • Monitor Entra sign-in logs for failed enrollment attempts

Security Consideration

Limit the scope of the MFA exclusion to only the necessary provisioning account. Consider removing the exclusion after migration is complete.

We value your feedback

Help us improve your experience

What would you like to share with us?

Need direct support? Open a ticket