iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To check Windows enrollment attestation in Intune, open Reports > Device management > Device attestation status. Filter by attestation status or ownership type, then select Generate report (or Generate again for refreshed data). The report shows whether enrollment attestation is Completed, Failed, or Not started, plus device and TPM details that help explain the result.
Find and generate the Device attestation status report
- Sign in to the Intune admin center and go to Reports > Device management > Device attestation status.
- Optionally filter by Attestation status or Ownership type.
- Select Generate report. To retrieve updated data later, select Generate again.
- Select a device row to inspect additional details.
Microsoft describes the report’s summary groups as Completed, Failed, and Not started. The report is a view of enrollment attestation, not a general verdict on every aspect of a device’s security. Microsoft Intune Reports; Windows enrollment attestation.
What the report shows
The report provides fields for investigating a device’s enrollment attestation state:
Recommended Free Tools
- Device name and device ID
- User principal name (UPN)
- Device attestation status and status detail
- Operating system and OS version
- Ownership, last check-in, and enrollment date
- TPM version and manufacturer
- Device model
Use the status detail alongside the device and TPM information; the top-level status alone does not identify the cause of a failure.
#1 Best Overall
Confirm the device is eligible before troubleshooting
Microsoft’s Windows enrollment attestation requirements specify TPM 2.0 or later and a physical device. The published OS thresholds are Windows 10 build 19045.3996 or later, and Windows 11 build 22000.2713, 22621.2792, or 22631.2792 or later. These are the version requirements in Microsoft’s documentation, last updated April 9, 2026; check the current page before applying them operationally.
This feature does not support virtual machines, including Hyper-V and Azure virtual machines, Azure Virtual Desktop session hosts, Windows 365 Cloud PCs, and Microsoft Dev Box. A vTPM does not make those environments eligible for this enrollment attestation feature. Attestation takes place during Intune device-management enrollment, after TPM attestation in Windows Autopilot pre-provisioning and Shared device mode. Microsoft also identifies the Windows CSPs InitiateRecovery, RecoveryStatus, and MDMClientCertAttestation in connection with the feature. Windows enrollment attestation requirements.
Rank #2
Interpret the status detail before choosing a fix
Microsoft lists status details such as the following. They indicate different conditions, so use the exact wording displayed for the device rather than treating every non-completed result as the same problem.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems- “Entra key can’t be attested” or “TPM isn’t trusted”: the detail points to a trust or TPM attestation issue.
- “Feature isn’t supported”: check the physical-device, TPM, and Windows-version requirements.
- “Attestation is in process”: the attestation has not finished; allow processing time before deciding it has failed.
- “Entra token doesn’t match device identity” or “Entra token is missing device identity”: the detail identifies a token and device-identity mismatch or missing identity.
These messages are diagnostic clues, not a complete remediation procedure. Follow the device’s specific status detail and applicable Microsoft guidance. Microsoft cautions that TPM troubleshooting may require Wipe and Reset, which can cause data loss; ensure necessary data is backed up before taking that step. Microsoft’s Windows enrollment attestation guidance.
Rank #3
Retry attestation with Attest device
An administrator with the relevant Remote tasks permission for MDM attestation can use Attest device for devices with Not started TPM attestation and for certain listed failure details. Microsoft’s documented operational limits are:
- Select no more than 100 devices for one action.
- Wait at least one minute between actions.
- Allow up to 15 minutes for completion; processing time depends on device activity and the number of selected devices.
After allowing time for processing, refresh the report to check for an updated result. The retry action does not remove the device eligibility requirements or guarantee a successful attestation. Windows enrollment attestation.
Rank #4
Do not confuse enrollment attestation with the hardware attestation report
Intune has a separate Windows hardware attestation report for devices assigned hardware-attested settings through a compliance policy. It is not another name for the Device attestation status enrollment report.
Free tools Windows power users keep installed
One-click scans. No signup required.
| Report | Where to find it | What it covers | What its output means |
|---|---|---|---|
| Device attestation status | Reports > Device management | Enrollment attestation, with enrollment status and device/TPM details | Shows Completed, Failed, or Not started, with status detail |
| Windows hardware attestation | Reports > Device Compliance > Reports tab | Hardware-attested compliance settings assigned by a compliance policy | Reports success when an attestation report is received; if one cannot be generated, reports an error with its detected type and code. The Latest report column reflects the last health certificate issuance/report generation date. |
See Microsoft’s Windows hardware attestation report documentation for the compliance report’s scope and fields.
Best Value
Graph data and automation caveats
For integrations, Microsoft Graph v1.0 documents the deviceHealthAttestationState resource, including last-update and issue timestamps and other attestation-state properties. Graph for Intune requires an active Intune license for the tenant. See the v1.0 resource documentation.
The Graph beta deviceIdentityAttestationStatus enumeration includes unknown, trusted, unTrusted, notSupported, and incompleteData. Microsoft notes that beta APIs can change more frequently and recommends using v1.0 when the required capability is available there. Treat beta values as provisional and verify current API support before building automation. See the beta enumeration documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

