0x8007064C

The machine is already enrolled

Last reviewed 2026-08-05 by the Just Software engineering team · also seen as 8007064c, hr 0x8007064c, the machine is already enrolled

What it means

hr 0x8007064c appears in the enrolment log with the message The machine is already enrolled. Windows still holds the artefacts of an earlier MDM enrolment — the Intune-issued account certificate and the OnlineManagement registry keys — so the enrolment client refuses to start a new one. The device may look completely unenrolled in the Intune console; the leftovers are entirely local.

Common causes

  1. The computer was enrolled before, and unenrolment did not remove the local artefacts.

  2. The computer was imaged from a machine that had already been enrolled, so it inherited that machine's certificate and registry state.

  3. The account certificate issued by the previous enrolment is still present in the local computer store.

How to fix it

  1. Open certlm.msc (Certificates - Local Computer) > Personal > Certificates and delete the certificate issued by Sc_Online_Issuing, if present.

  2. Delete the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OnlineManagement and all of its subkeys, then retry enrolment. Back up the registry first.

  3. If enrolment still fails, delete HKEY_CLASSES_ROOT\Installer\Products\6985F0077D3EEB44AB6849B5D7913E95 if it exists, and retry.

  4. Build images from a machine that was never enrolled, or generalise with sysprep, to stop this recurring across a fleet.

Frequently asked

The device isn't in Intune — why does it say it's already enrolled?
The check is local. Windows looks at its own certificate store and the OnlineManagement registry keys, not at the Intune service, so a device that was removed from the console still refuses to enrol until those artefacts are cleared.
An unhandled error has occurred. Reload 🗙