Profile not applicable

SCEP profile shows 'Not applicable'

Last reviewed 2026-07-18 by the Just Software engineering team · also seen as not applicable, scep not applicable

What it means

"Not applicable" is a targeting verdict, not an error: Intune (or the device) determined the profile should not be applied to this device at all. No SCEP request was ever attempted, so server-side logs will show nothing. Fix the targeting or dependency, then the state moves to pending/succeeded/failed.

Common causes

  1. Platform or edition mismatch — e.g. a profile created for a different Windows platform channel, or settings unsupported on the device's edition.

  2. The profile is user-targeted but the device has no affinity to a targeted user (shared or userless devices), or vice versa for device-targeted certs.

  3. Subject or SAN variables in the profile (such as {{UserPrincipalName}}) cannot be resolved for this device/user combination.

  4. Assignment filters exclude the device even though its group is targeted.

How to fix it

  1. In Devices > Configuration > (profile) > Device status, check the per-device state and the user column — a blank user on a user-targeted certificate profile explains the verdict.

  2. Review assignment filters attached to the assignment (Devices > Configuration > (profile) > Assignments) with the filter evaluation report.

  3. If the subject uses user variables, confirm the enrolment type gives the device a primary user; for shared devices switch to device-based subject variables.

  4. Lint the profile's subject/SAN template for variables that cannot resolve for the targeted population.

An unhandled error has occurred. Reload 🗙