0x80090011

NTE_NOT_FOUND: object was not found

Last reviewed 2026-07-18 by the Just Software engineering team · also seen as 80090011, NTE_NOT_FOUND

What it means

0x80090011 is NTE_NOT_FOUND"Object was not found" from the Windows cryptographic subsystem. Something the enrolment needed to reference — a certificate, a key, a provider object — was missing at the moment the SCEP client looked for it.

Common causes

  1. The trusted root certificate the SCEP profile depends on is not (yet) installed on the device — the linked trusted certificate profile failed or has not applied.

  2. A previously created key or pending request was deleted or lost between enrolment steps.

  3. The profile references a certificate by a property that does not match what is actually in the store.

How to fix it

  1. Open certlm.msc on the device and confirm the root/issuing CA certificate from your trusted certificate profile is present in the expected store; fix that profile's deployment first.

  2. In Intune, check the Device status of the trusted certificate profile that the SCEP profile links to — the SCEP profile can only succeed after it applies.

  3. Sync the device again once the root certificate is confirmed present; the SCEP retry should proceed.

An unhandled error has occurred. Reload 🗙