All case studies

Enterprise (sanitized) · Endpoint Operations · Recurring endpoint support

Intune / Company Portal Enrollment Recovery

Support pattern for endpoints stuck partway through Intune enrollment — Company Portal loops, missing MDM policies, or sync issues blocking a clean managed state. Executed the user-side recovery steps and escalated when a deeper tenant action was required.

01

Context

Enrollment issues rarely produce a clean error. Devices sit in a half-managed state — Entra-joined but not Intune-compliant, or Company Portal reporting sync failures — and required apps and policies never land.

02

Challenge

Get the device to a clean managed state through the supported recovery steps, and escalate cleanly when tenant-level action is needed.

03

My role

Endpoint support technician diagnosing enrollment state and executing the user-side recovery path.

04

What I did

  • Checked the device's join state (Entra ID / hybrid / workgroup) and Company Portal sync.
  • Ran the supported Company Portal sync and MDM refresh steps.
  • Validated policy and required-app delivery post-recovery.
  • Escalated to the identity/endpoint team when stale tenant-side records or a re-deploy were required.
  • Confirmed sign-in, MFA, and required apps before returning the device to the user.

05

Workflow / approach

  1. 01

    Inspect join and enrollment state

    Confirm what the device reports: Entra-joined, hybrid, workgroup, MDM-enrolled, or stuck.

  2. 02

    Run the supported recovery steps

    Company Portal sync, sign-out/sign-in, and MDM refresh.

  3. 03

    Escalate when needed

    Route to the identity/endpoint team for stale tenant records or a full re-deploy.

  4. 04

    Validate policy and app delivery

    Confirm compliance policies applied and required apps installed through Company Portal.

  5. 05

    Return the device to the user

    Verify sign-in, MFA, and required apps before handoff.

  6. 06

    Document the recovery path

    Record which branch was used so the pattern is reusable.

06

Outcome and value

Users get back a device that is actually managed — compliant, policy-applied, and Company Portal-clean — instead of one silently stuck between states.

07

What this demonstrates

  • Working knowledge of Intune enrollment and Entra ID device join states.
  • Judgment on when to run the recovery steps vs escalate.
  • Endpoint discipline: don't hand back a device that's half-managed.

08

Related skills

IntuneCompany PortalEntra ID JoinMDMEndpoint Support