Autopilot shows Registering your device for mobile management (Failed: 3, 0x801C03EA). The documented cause is a TPM that supports version 2.0 but is still running 1.2 firmware and has not been upgraded. A second, entirely separate cause produces the same error: the device sits in two assigned groups, each of which has a different Autopilot profile, so provisioning cannot decide which profile applies. In pre-provisioning (the technician flow) and self-deploying mode the same step also fails when TPM attestation cannot complete, which is why it clusters on particular OEM models and firmware revisions rather than on particular tenants.
0x801C03EA
Registering your device for mobile management failed
What it means
Common causes
The device has a TPM chip capable of version 2.0 that has not yet been upgraded to 2.0 firmware.
The same device is a member of two groups, each assigned a different Autopilot deployment profile.
Pre-provisioning or self-deploying mode: TPM attestation failed โ outdated TPM firmware on the device, or the attestation endpoints (the Intel, AMD and Qualcomm endorsement-key services and
*.microsoftaik.azure.net) are blocked by the firewall or proxy.
How to fix it
Upgrade the TPM firmware to version 2.0 using the OEM's tool, then re-run Autopilot. Vendors ship this as a firmware or BIOS update.
If the TPM is already 2.0, check group membership: find every group containing the device and confirm only one Autopilot profile reaches it. Remove the assignment that shouldn't apply.
For pre-provisioning and self-deploying failures, apply the latest BIOS/TPM firmware from the OEM and confirm the network allows the TPM attestation hosts listed in the Intune network endpoints cheat sheet. Test with user-driven mode on the same device: if that succeeds, attestation is the problem.