MDM troubleshooting

Find the failing stage: access, provider connection, enrollment, profile delivery, or device response.

On this page

Start with the workspace, device identity, and operation ID. Record the time and exact status message without including credentials or enrollment profiles. Each stage has its own prerequisites; a connected service does not prove successful device enrollment or command execution.

Device management is missing

Check the workspace's MDM feature grant. Owners and administrators can request access in Setup, but requesting access does not enable it. MDM additionally requires role permission: owners/admins operate, security managers/auditors read, and members/billing-only roles have no MDM access.

Switching to an authorized workspace matters; do not assume a role in one workspace carries into another.

Service connected, but enrollment unavailable

Inspect Apple and Windows readiness separately on Enrollment & installers. Apple needs APNs and SCEP; Windows needs its WSTEP identity. A missing signed installer is a release-artifact problem, not necessarily a connection failure.

Have your operator check the exact workspace mapping, provider credentials, certificate validity, and service storage. Avoid rotating identity keys as a generic troubleshooting step.

Device or profile is missing

Confirm you are looking at the correct provider and inventory page. Native results are paginated, and Intune results can be partial. Verify the actual management enrollment on the device, not only the presence of a desktop inventory agent.

For profiles, confirm platform compatibility and membership in the engine's Unassigned group. Beam does not apply this workflow's profiles to every existing Fleet group. Wait for a device check-in and compare provider delivery state.

Sync or remote action is unavailable

Check role, deployment enablement, platform capability, and the device's response binding. Intune sync needs explicit permission and configuration. Fleet high-impact controls can require Fleet Premium and platform prerequisites. Beam response requires a verified channel and per-device enablement; wipe has an additional independent switch.

An active or uncertain response command can prevent another action. Resolve the existing operation first.

Action accepted, but no visible effect

Treat acceptance as a delivery-stage result. Offline Apple commands may remain queued and execute later. Windows response has collection and authorization windows, and its lock behavior is a session disconnect rather than persistent lockout.

For unknown results, preserve receipts and ledger records. Ask the operator to inspect NanoMDM, Windows OS state, or Fleet before retrying. Never remove durable storage to clear a stuck status.

Escalate with useful evidence

Send support the workspace ID, stable device ID, platform/OS, approximate UTC time, operation ID, channel, and redacted status text. Include whether provider state and the physical endpoint were checked. Do not attach secrets, PINs, enrollment files, complete profile payloads, or raw callback bodies.

Explore the docs