Fixing Intune Device Unenrollment After January 2026 Windows Cumulative Updates

Explore Our Microsoft Intune Training →

Fixing Intune Device Unenrollment After January 2026 Windows Cumulative Updates

Problem: The KB5074109 and KB5074752 cumulative updates for Windows have been causing MDM enrollment certificate resets, leading to device unenrollments in Intune-managed environments.

Solution: To fix the issue, follow these steps to verify the Azure AD join status of your devices, check their MDM enrollment certificates, and re-enroll affected devices if necessary.

Verifying Azure AD Join Status

dsregcmd /status

If the device is not Azure AD joined, you will need to join it to your Azure AD first.

Checking MDM Enrollment Certificate

  1. Open MMC (Microsoft Management Console)
  2. Add the ‘Certificates’ snap-in, selecting ‘My user account’ or ‘Local computer’ as appropriate
  3. Navigate to the ‘Trusted Root Certification Authorities’ or ‘Intermediate Certification Authorities’ folder
  4. Look for a certificate with the name ‘Microsoft Intune Enrollment’

If the certificate is missing, your device may be affected.

Re-enrolling Affected Devices

Settings > Accounts > Access work or school

Click ‘Enroll device’ and follow the prompts to re-enroll your device.

Updating Intune Management Extension

After updates, ensure that the Intune Management Extension is up to date on your affected devices. Monitor the Intune portal for policy sync after re-enrollment.

Explore Our Microsoft Intune Training →

Written by Mohammed Akhter

Founder of ITP Training. 50,000+ students trained across 30+ countries in Microsoft endpoint and cloud security. Learn more →