Company Portal app login fails for student accounts after Intune Wipe (Web Company Portal works)

travis snyder 0 Reputation points
2026-07-07T02:01:31.98+00:00

We have a Microsoft Intune/Autopilot environment for our school district and have run into an issue we cannot resolve.

Environment

  • Windows 11
  • Microsoft Entra joined
  • Intune managed
  • Windows Autopilot
  • Student devices (grades 5–12)

Background

We deployed new Lenovo devices through Autopilot. Students signed in successfully, Company Portal authenticated correctly, applications deployed, and everything worked normally.

We later performed an Intune Wipe on our Acer student devices. After the wipe, we experienced enrollment/sync issues that were eventually resolved.

Now we have a different problem.

Current Issue

  • Devices complete Autopilot successfully.
  • Microsoft Entra join succeeds.
  • Intune enrollment succeeds.
  • Company Portal installs automatically.
  • Company Portal desktop app displays only "A login error occurred" when students attempt to sign in.
  • No additional error code is displayed.

Important Findings

  • This affects student accounts only.
  • Faculty accounts are not affected.
  • Students can successfully sign into the Company Portal website using the same credentials.
  • dsregcmd /status indicates the device is Entra joined and MDM enrolled.
  • We are seeing TokenBroker/AAD-related events in Event Viewer.We have a Microsoft Intune/Autopilot environment for our school district and have run into an issue we cannot resolve. Environment
    • Windows 11
    • Microsoft Entra joined
    • Intune managed
    • Windows Autopilot
    • Student devices (grades 5–12)
    so with that we are trying to find out the login issues with comany portal what we diud wrong and how to fix it etc.
Microsoft Security | Intune | Enrollment

1 answer

Sort by: Most helpful
  1. AI answer

    2026-07-07T02:02:02.36+00:00

    The described behavior points to an issue with the Intune Company Portal app on Windows rather than with the students’ accounts or device join/enrollment state, since:

    • Windows Autopilot completes successfully.
    • Microsoft Entra join and Intune MDM enrollment succeed (dsregcmd /status confirms this).
    • Students can sign in to the Company Portal website with the same credentials.

    From the available troubleshooting guidance, the closest matching pattern is when the Company Portal app itself is out of date or corrupted.

    For affected student devices, use this path:

    1. Remove the Intune Company Portal app
      • Uninstall the Company Portal desktop app from the Windows device.
    2. Validate sign-in via browser
      • On the same device, open a browser and go to https://portal.manage.microsoft.com.
      • Have the student sign in with their school account.
      • If sign-in fails here, test on another network (for example, home vs. school Wi‑Fi) to rule out network-related sign-in issues.
      • If sign-in still fails, verify that the student’s credentials and UPN are correctly synced in Microsoft Entra ID and match the on‑prem directory information (if applicable).
    3. Reinstall Company Portal and reattempt app sign-in
      • Once the student can successfully sign in via the browser, reinstall the Intune Company Portal app on the device (for Windows, via your normal deployment method or Microsoft Store if allowed).
      • Have the student open the Company Portal app and sign in again.
    4. Check for device cap issues if the error persists
      • If the same “A login error occurred” continues after reinstalling, check whether students are hitting a device enrollment cap in Intune. The documentation notes that similar “Company Portal temporarily unavailable”/login issues can occur when users attempt to enroll more devices than allowed.
      • If needed, adjust device enrollment limits or retire old student devices from Intune.
    5. Use Company Portal logs for deeper diagnostics
      • From the Company Portal app, have an affected student submit diagnostics/logs when the error occurs.
      • In the Intune admin center, go to Troubleshooting + support > Diagnostics and download the user-submitted Windows Company Portal logs.
      • Review these logs for TokenBroker/AAD-related errors that may indicate app-level token issues.
    6. Confirm self-service actions and enrollment state
      • From the Company Portal website, verify that the device shows as enrolled under the student’s account and that self-service actions (such as Sync/Check Status) work.
      • If the device appears under the wrong primary user or ownership type, correct that in Intune and re-test.

    These steps focus on correcting a potentially corrupted/out-of-date Company Portal app, validating student sign-in outside the app, and using diagnostics to pinpoint token-related problems, which aligns with the documented guidance for Company Portal login/enrollment issues.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.