## TL;DR
Confirm the device is compliant in the MDM/Intune and has the required client certificate, then check the user is assigned to a ZTNA policy. Enrollment fails on non-compliant devices, missing certs, or unassigned users, in that order.

## The error
```text
Enrollment failed. Your device does not meet the requirements.
```

## Steps
1. Check device compliance in Intune or the MDM: the device must show Compliant. Expected: compliant. Non-compliant devices are rejected by design; fix compliance first (encryption, OS version, PIN).
2. Verify the device identity certificate exists (Keychain on macOS, cert store on Windows). Expected: present and valid. ZTNA enrollment usually requires the device cert.
3. Confirm the user is assigned to the ZTNA app policy in the admin console. Expected: assigned. Unassigned users fail enrollment with a generic error.
4. Check the client version against the minimum supported. Expected: current. Push the update via MDM if behind.
5. Retry enrollment and watch the client logs for the specific rejection. Expected: enrolled. Collect logs before escalating to the ZTNA admin.

## When to use
- ZTNA agent will not enroll or activate
- "Device does not meet requirements" errors

## When not to use
- Enrolled but app access denied (policy issue)
- Performance problems on working ZTNA

## Compatibility
- ZTNA products (Zscaler Private Access, Cloudflare Access, Entra Private Access); Intune/Jamf-managed devices

## Variants
### Enrollment loops
The client enrolls then immediately unenrolls; usually a policy conflict or cert issue. Check both.
### Works for some users on the same device model
User assignment or group difference; compare policies.

## Why it happens
ZTNA enrollment validates device posture before granting anything. Compliance, certificate, and assignment are the three gates, and the client error rarely says which one failed.

## Edge cases
- Personally-owned devices in BYOD: enrollment requirements differ; check the BYOD policy.
- Fresh MDM enrollments need time for compliance to evaluate; wait and retry.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_Wxxgu02C1RPZxCCiVk2X0Q
