Enrolment fails with DeviceCapReached, or with the more generic Company Portal Temporarily Unavailable, when a user tries to enrol more devices than their device limit restriction permits. The limit is per user, not per device, so it is usually stale records — devices long since replaced but never removed — that consume the allowance rather than devices the user actually holds.
DeviceCapReached
DeviceCapReached — the user is at their device limit
What it means
Common causes
The user has reached the Device limit set in their device limit restriction.
Old, replaced or wiped devices are still counted against the user because their records were never removed from Intune.
How to fix it
In the Microsoft Intune admin center, check Devices > Enrollment restrictions > Device limit restrictions and note the value in the Device limit column.
Compare it against the user's actual count: Users > All users > the user > Devices.
Remove stale device records, or raise the device limit on the restriction that applies to this user.
Make removing stale records routine — the cap is the symptom, unmanaged lifecycle is the cause.
For shared or kiosk devices enrolled by one account, use a Device Enrollment Manager account, which is exempt from the enrolment cap. Note that a DEM account cannot complete enrolment when Conditional Access is enforced for that account's sign-in.