## TL;DR
0x801C0003 almost always means the user is not licensed for Intune, the tenant MDM authority is wrong, or an enrollment restriction blocks the device. Verify the license and MDM scope first; the fix is usually admin-side, not on the device.

## The query
```text
intune enrollment failed with 0x801c0003: fix
```

## Use this when
- Intune enrollment fails with 0x801C0003
- one user cannot enroll while others can
- enrollment worked before a tenant or license change

## Not for
- 0x80180014 device-already-enrolled errors
- Autopilot profile assignment problems
- Android or iOS enrollment failures

## Steps
1. Confirm the user has an Intune license assigned in the Microsoft 365 admin center. Expected output: a valid Intune or EMS license is assigned.
2. Check the tenant MDM authority is set to Intune and the MDM user scope includes the user. Expected output: MDM authority is Intune and the user is in scope.
3. Review enrollment restrictions for device platform blocks or personal-device blocks that match this device. Expected output: no restriction targets this user and platform.
4. Check the device join state; a stale hybrid-join or existing work account can conflict. Expected output: the join state is clean or the conflicting registration is identified.
5. Retry enrollment after fixing the admin-side cause. Expected output: enrollment completes and the device appears in Intune.

## Applies to
Microsoft Intune, Entra ID, Windows 10/11 enrollment, current admin center versions.

## Variant phrasings
### 0x801C0003 for every user in the tenant
Tenant-level cause: MDM authority or scope. One fix clears all users.

### License assigned but error persists
Wait for license propagation or check for a conflicting MDM scope from another product.

## Why it happens
The Intune enrollment service checks license, authority, and restrictions before it ever touches the device. A miss at any gate returns this generic code.

## Edge cases
- Users near the device enrollment limit hit different errors; check the per-user device count anyway.
- Third-party MDM remnants can hold the enrollment; remove old MDM profiles first.
- Conditional access requiring a compliant device before enrollment creates a chicken-and-egg loop; exempt the enrollment flow.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_B7MkcTk7kXlx2ao3mjiEbA
