Windows DeepLink enrollment fails with "couldn't auto-discover a management endpoint" — issue self-resolved, root cause unconfirmed
Windows
When enrolling a Windows device via DeepLink provisioning, the device displays the error We couldn't auto-discover a management endpoint matching the username entered and enrollment does not complete.
Why this happens
Windows DeepLink enrollment relies on an MDM discovery endpoint that Windows queries using the identity embedded in the DeepLink URL. If the Base64-encoded payload in the URL is malformed, truncated, or references an invalid blueprint or group, Windows cannot resolve the endpoint and fails immediately. The same error can also appear during brief, transient disruptions to Esper's Windows MDM discovery service, which typically self-resolve within 30 minutes.
Steps to resolve
-
Verify the DeepLink URL structure. A valid Esper Windows DeepLink takes this exact form:
If the URL was copied from a document, email, or chat message, it may have been wrapped, truncated, or had characters altered in transit. Compare it character-by-character against the original URL in the Esper Console before proceeding.https://your-tenant.esper.cloud/api/v2/windows/discovery/<base64-encoded-payload> -
Confirm the target group exists and is correct. In the Esper Console, go to Devices & Groups → [Your Target Group] and note the group UUID. Decode the Base64 payload in your DeepLink and confirm the
group_idvalue matches exactly. A mismatch causes Windows to query for a group that does not exist. - Confirm the referenced Blueprint is active. Go to Blueprints in the Esper Console and locate the blueprint referenced in your DeepLink payload. Confirm it is published and not in a draft state. Windows enrollment cannot target an unpublished blueprint.
- Generate a fresh DeepLink. In the Esper Console, go to Devices & Groups → [Your Target Group] → Provisioning → DeepLink and generate a new URL. Use this URL directly — do not copy it into another application first. Paste it into the Windows enrollment flow immediately to prevent any transformation of the encoded string.
- Test from a different network. Attempt enrollment from a mobile hotspot or a network without a proxy, firewall, or DNS filtering layer. Some corporate network configurations block the MDM discovery endpoint, producing an error that is indistinguishable from a misconfigured URL.
- Wait 15–30 minutes and retry. If the DeepLink is confirmed valid and the network is clean, a transient disruption to Esper's Windows MDM discovery service may be the cause. Wait 15–30 minutes before attempting enrollment again on the same device.
If this doesn't resolve it
If enrollment continues to fail after 30–60 minutes with a confirmed-valid DeepLink on a clean network, check the Esper status page for any active incidents affecting Windows MDM services.
When contacting Esper Support, collect the following before reaching out:
- The full DeepLink URL (you may redact the tenant subdomain, but preserve the complete Base64 payload)
- Your Esper account or environment name
- The exact error message text displayed on the Windows enrollment screen
- The date and time of the failure, including timezone
- Whether the failure affects all groups and Blueprints or only a specific combination
- Whether the issue affects all devices or only specific hardware models
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments