zero trust network access enrollment failing on managed device
Fixes ZTNA client enrollment failures on managed devices. Covers device compliance, certificate, and policy assignment. Use when the ZTNA agent will not enroll or activate. Not for app-access policy denials after enrollment.
TL;DR
Confirm the device is compliant in the MDM/Intune and has the required client certificate, then check the user is assigned to a ZTNA policy. Enrollment fails on non-compliant devices, missing certs, or unassigned users, in that order.
The error
Enrollment failed. Your device does not meet the requirements.Steps
- Check device compliance in Intune or the MDM: the device must show Compliant. Expected: compliant. Non-compliant devices are rejected by design; fix compliance first (encryption, OS version, PIN).
- Verify the device identity certificate exists (Keychain on macOS, cert store on Windows). Expected: present and valid. ZTNA enrollment usually requires the device cert.
- Confirm the user is assigned to the ZTNA app policy in the admin console. Expected: assigned. Unassigned users fail enrollment with a generic error.
- Check the client version against the minimum supported. Expected: current. Push the update via MDM if behind.
- Retry enrollment and watch the client logs for the specific rejection. Expected: enrolled. Collect logs before escalating to the ZTNA admin.
When to use
- ZTNA agent will not enroll or activate
- "Device does not meet requirements" errors
When not to use
- Enrolled but app access denied (policy issue)
- Performance problems on working ZTNA
Compatibility
- ZTNA products (Zscaler Private Access, Cloudflare Access, Entra Private Access); Intune/Jamf-managed devices
Variants
Enrollment loops
The client enrolls then immediately unenrolls; usually a policy conflict or cert issue. Check both.
Works for some users on the same device model
User assignment or group difference; compare policies.
Why it happens
ZTNA enrollment validates device posture before granting anything. Compliance, certificate, and assignment are the three gates, and the client error rarely says which one failed.
Edge cases
- Personally-owned devices in BYOD: enrollment requirements differ; check the BYOD policy.
- Fresh MDM enrollments need time for compliance to evaluate; wait and retry.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_Wxxgu02C1RPZxCCiVk2X0Q
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.