## TL;DR
WARP team enrollment on managed devices fails when the MDM-pushed configuration is missing, the device certificate is not trusted, or the Zero Trust enrollment policy blocks the device. Verify the MDM profile, the certificate trust, and the enrollment rules.

## The query
```text
cloudflare warp team enrollment failing on managed devices
```

## Use this when
- WARP team enrollment fails on MDM-managed devices
- enrollment works manually but not via MDM push
- certificate errors during enrollment

## Not for
- personal devices enrolling in consumer WARP
- WARP connected but traffic issues (different problem)
- Zero Trust access policy denials after enrollment

## Steps
1. Confirm the MDM configuration profile for WARP is installed on the device. Expected output: profile present
2. Check the device certificate used for enrollment is valid and trusted. Expected output: certificate valid
3. In the Cloudflare Zero Trust dashboard, check the enrollment policy targets the device and its serial or user. Expected output: policy covers the device
4. Try manual enrollment with the team name to isolate MDM versus account issues. Expected output: you know which side fails
5. Check the device meets any posture requirements in the enrollment policy, such as OS version. Expected output: posture requirements met
6. Re-push the MDM profile and retry enrollment. Expected output: enrollment completes

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_Al4IzeAx59gjrGwPjPsxmg
