MDM Enroll: Device Credential, Failed (Unknown Win32 Error code : 0xcaa9001f

On a hybrid setup , you may experience workstation failed to Enroll after being Hybrid Join.

Navigating to Event Viewer-Applications and Services-Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Operational, you will get Unknown Win32 Error code : 0xcaa9001f.

Microsoft Docs has a solution which might work if the setup and the problem is identical to what Microsoft explains in the docs or this could be a unique problem in your Infra Setup.

MDM Enroll : Error 0xcaa9001f

MDM Enroll: Error 0xcaa9001f


Enrollment fails in a hybrid environment.

  • You are using AAD Connect to sync with Azure
  • GPO is deployed for MDM Enrollment with user credential
  • You are targeting an OU in AAD Connect.

Cause :

The issue occurs in the following situation.

  • Device was initially part of the OU which was setup with AAD Connect. Device was moved out of the OU several times causing the Registration as pending in Azure. Device when stuck as pending status will most likely end up with Unknow Error at Enrollment.


Move the machine back to the OU which is syncing in AAD Connect. Connect to the device and remove the machine from AAD. Run dsregcmd /leave on the machine with Admin Rights. Restart the machine and let AAD Connect rejoin the machine with Azure

Related Posts

Subscribe to Techuisitive Newsletter

Be the first to know about our new blog posts. Get our newsletters directly in your inbox and stay up to date about Modern Desktop Management technologies & news.

Scroll to Top