Fix Error 135011: Your Organization Has Disabled This Device

Stuck with Error 135011? Learn how to fix 'Your organization has disabled this device' on Windows & Mac. Remove MDM blocks and reconnect today.

The message "Your organization has disabled this device" is more than just a nuisance; it’s a digital brick wall that shuts you out of your own productivity suite. You try to open Word, launch Teams, or check Outlook, and the screen flashes with a cold, unfeeling command: Error 135011. If you’re sitting at your desk right now, staring at this red block, I understand the immediate spike of frustration. It feels like your computer is betraying you, but in reality, it’s enforcing a strict rule set from somewhere else.

This error, formally known as AADSTS135011, occurs when the Microsoft Entra ID service determines that the device object associated with your account is either manually disabled or deleted. It’s a security guard saying, "You don’t have permission to enter." The good news? You are not powerless. In my fifteen years of troubleshooting enterprise and personal tech, I’ve found that this issue usually falls into one of two distinct buckets. Are you the owner of the machine trying to shake off leftover corporate policies, or are you an employee using a work-issued laptop? This guide covers both scenarios for Windows 10/11 and Mac, providing a clear path to remove the block. Let’s get your productivity back.

A modern laptop on a sleek office desk with a stylish backdrop, ideal for tech enthusiasts.

Why Is My Computer Blocked? Understanding MDM & Group Policy

To fix the problem, you have to understand the machinery behind it. Most users assume that if they signed in with a work email on their personal laptop, they’ve "joined" a network in the traditional sense. That’s a common misconception. Modern blocking mechanisms rely on MDM (Mobile Device Management) and cloud-based identity checks, not just local network wires.

The Difference Between 'Disabled' and 'Non-Compliant' Devices

There is a subtle but critical difference between a device being "disabled" and being "non-compliant." Think of it like a building security system. "Non-compliant" is like failing a fire drill; the building might restrict your access to certain floors until you pass, but your keycard still works in the lobby. This is automatic—triggered by missing security updates or lack of disk encryption.

"Disabled," however, is a manual action. An administrator has taken your specific keycard and deactivated it entirely. Error 135011 specifically points to this manual revocation. It means the device object in Microsoft Entra ID has had its status flipped to "Disabled" by a human decision, or the object was deleted after a period of inactivity. As Microsoft documentation indicates, a disabled device cannot authenticate for Microsoft 365 apps, period. Until the object’s status is corrected in the cloud directory, local passwords won’t help.

Role of Active Directory, Intune, and Group Policy

So, how do these rules get to your laptop? It’s a layered approach.

  1. Active Directory (AD): The backbone. If your computer is domain-joined, AD policies enforce local restrictions (like disabling USB storage).
  2. Intune: The cloud enforcer. This is an MDM solution that pushes policies regardless of where you are. Intune can trigger the 135011 error if it determines the device violates a compliance policy.
  3. Group Policy Objects (GPOs): These are the detailed instruction sets pushed to Windows machines. While GPOs often handle local settings, they can also influence how apps behave.

The key distinction for you is this: Azure AD join (now Entra ID) affects cloud app access like Office and Teams. Windows Domain join affects local resource access like file servers. If you’re seeing Error 135011, the problem is almost certainly in the cloud identity layer—specifically how your device registers itself to the organization’s tenant.

Confident woman working with calculator in bright office setting, surrounded by office tools.

Scenario 1: I Own the Device (BYOD) – How to Remove Organization Restrictions

If this is your personal laptop, and you’re getting blocked because you accidentally linked it to a former employer’s network or a school account, you’re in luck. You have the power to unlink yourself. I’ve seen this happen more often than you’d think; people leave jobs, but the "Access work or school" account sticks around like a ghost.

Unlinking Microsoft Accounts from Work or School

The first step is to sever the tie between your personal machine and the corporate account. This is where most self-service fixes begin.

For Windows 10/11:

  1. Go to Settings > Accounts.
  2. Select Access work or school (sometimes labeled "Work or school accounts" in newer builds).
  3. You’ll see a list of accounts. Look for the one causing the error.
  4. Click on the account, then select Disconnect.

A major warning: If you had enabled OneDrive syncing for this specific account, disconnecting it does not automatically delete your local files, but it stops the sync. However, if you used this account for Office licensing, you may need to sign in with your personal Microsoft account to reactivate Word and Excel. Check your file folders immediately after disconnecting to ensure no data is locked.

For Mac: On macOS, the process is less integrated into System Settings. If you’ve signed in to Office 365 or Intune on a Mac, you often need to go into the specific application’s preferences to sign out. For Intune-managed Macs, you may need to use the profiles command line tool or the "Management" profile in System Settings to remove the MDM payload.

Using dsregcmd and System Restore to Clear Cached Policies

Sometimes, disconnecting isn’t enough. Windows keeps a "memory" of the organization in its registry and credential caches. This is where advanced fixes come in. I recommend using the built-in dsregcmd tool. It’s like a reset button for your cloud identity registration.

Open an elevated Command Prompt (run as Administrator) and type: dsregcmd /status

Look at the output. If you see AzureAdJoined : YES but you’ve already disconnected the account, there’s a residual link. To break it, run: dsregcmd /leave

This removes the device from the Azure AD directory. After running this, a reboot is mandatory.

If that fails, or if you suspect the MDM profile was installed weeks ago, use System Restore. Create a restore point before you install any work software in the future, but for now, if you have a restore point from before the issue started, revert to it. This strips away the registry keys associated with the MDM profile. Finally, open Credential Manager and delete any cached passwords for the work domain to prevent auto-block loops.

Scenario 2: I Use a Work Computer – How to Fix or Unlock via IT

If this laptop was handed to you by your employer, stop. Do not attempt to bypass the block using registry hacks or third-party tools. That violates most employment contracts and can trigger a security audit. Your path to resolution is communication.

What Your IT Admin Needs to Do (For Tech-Savvy Users)

Even if you’re not the admin, understanding the back-end process helps you advocate for yourself. The admin needs to log into the Azure Portal. They navigate to Microsoft Entra ID > Devices. They search for your specific machine.

  • If the device is "Disabled": They click "Enable." This is a one-click fix.
  • If the device is "Deleted": They must re-register it. This often requires you to reinstall the device or re-enroll it into Intune.
  • Why would they block it? Usually, it’s security. Maybe the laptop was lost, or it’s running an unsupported OS version, or it failed a compliance check (like missing BitLocker encryption). Admins are often afraid to unlock a device that doesn’t meet security baselines.

How to Communicate with IT Effectively

IT departments are busy. The best way to get a fast response is to be precise. Don’t just say "My computer is broken." Use a template.

Email Subject: Error 135011 - Device Block - [Your Device Name]

"Hi [Name/Ticket System],

I’m unable to access Microsoft 365 apps on my laptop ([Device Name]). I’m receiving Error Code 135011, which indicates the device is disabled in Microsoft Entra ID.

I haven't lost the device; it’s in my possession and running the latest updates. I believe the device object may have been flagged for non-compliance or manually disabled.

Could you please check the status in the Azure Portal? I am available for a remote call if re-enrollment is needed.

Thanks, [Your Name]"

If IT tells you the device is "marked as lost," you must immediately file a theft report with your local police and submit it to your company. This is a non-negotiable security protocol. Without a police report number, they likely cannot unlock the device.

Advanced Fixes: Bypassing Blocks & Error 135011 Troubleshooting

There are edge cases where the standard disconnect doesn’t work, or the error persists even after a clean sign-in. This is where you need to look deeper.

Specific Fixes for Windows 10/11 and Mac Platforms

Windows PowerShell for App Package Re-registration Sometimes the MDM block isn’t on the user account but on the apps themselves. If you can open other things but not Office, try re-registering the app packages. Open PowerShell as Admin and run:

Get-AppXPackage -AllUsers | ForEach-Object {Add-AppxPackage -Disable2ndLevelActivation -Register "$($_.InstallLocation)\AppXManifest.xml"}

This forces Windows to refresh the licensing checks for your installed apps. It’s a heavy-handed tool, but it often clears stale token data that is triggering the 135011 error in specific contexts.

Mac Terminal Commands On macOS, if you’re stuck with a lingering MDM profile that doesn’t appear in System Settings, you can use Terminal. Be very careful here.

  1. List profiles: profiles list
  2. Identify the UUID of the corporate profile.
  3. Remove it: profiles remove -identifier "UUID"

This is only viable for personal devices. If it’s a company Mac, the command will likely fail because the MDM server enforces the profile’s persistence.

App-Specific Triggers Notice that the error appears only in Teams or Word? That’s because these apps use a specific token validation method called MAM (Mobile Application Management). The Windows login might work fine, but the app itself queries the cloud and gets rejected. In this case, clearing the app’s specific cache folders (found in %LocalAppData% for Windows) before rebooting can sometimes reset the token status.

When to Reinstall Windows or Use Commercial Tools

If you own the device and you’ve tried everything—disconnected the account, ran dsregcmd /leave, and cleared credentials—and you’re still blocked, the last resort is a Clean Install of Windows.

A factory reset (Settings > Reset this PC) often doesn’t work. Why? Because "Reset" usually preserves user files and sometimes retains the MDM registration in the underlying BIOS/UEFI firmware. A Clean Install using a USB drive wipes the disk entirely, removing all registry policies, MDM joins, and cached credentials.

If you don’t have the time or desire to do this yourself, professional MDM removal services exist. They use specialized forensic tools to strip firmware-level MDM locks. This is a commercial service, typically costing a few hundred dollars, but it’s the surest way to scrub a machine. Just ensure you back up all your personal data before doing this, as wiping the disk deletes everything.

Preventing Future Blocks: Best Practices for Device Management

Once you’ve cleared the block, how do you keep it that way? The goal is separation.

Separating Personal and Corporate Data

Think of your computer as a house with two distinct wings. One wing is for you; the other is for your boss.

  1. Use Separate User Accounts: If you must connect to work, do it on a secondary local user profile or a dedicated cloud account. Don’t let the MDM policy apply to your primary user.
  2. No OneDrive Sync for Personal Files on MDM Devices: If you use a work laptop for personal tasks, do not sync your personal photos to OneDrive. When the MDM kicks in, those files are subject to corporate data loss prevention (DLP) policies. Keep personal data on local drives or personal cloud storage only.
  3. Audit Regularly: Every six months, open Settings > Accounts > Access work or school. Check for stray accounts. Delete anything you don’t recognize.

This "wall" approach is the single best defense. MDM policies can only control what they know about. If your personal data isn’t registered with the corporate tenant, the block can’t touch it.

FAQ

Can I fix 'Your organization has disabled this device' without calling IT?

It depends entirely on who owns the device. If it’s a corporate asset, the answer is no. The device object lives in the company’s cloud directory, and only they have the admin keys to unlock it. Trying to bypass it locally is often impossible because the block is enforced at the cloud validation layer. However, if it’s a personal device with a leftover work account, yes. You can self-remediate by unlinking the account under Settings > Accounts or using dsregcmd /leave to remove the Azure AD join.

Does a factory reset remove organization policies?

Not always. A standard "Reset this PC" in Windows often retains MDM profiles if they were pushed at the firmware level or if the reset was not a full "Clean" install. In my experience, I’ve seen devices retain their MDM enrollment even after a soft reset. To be certain the organization policies are gone, a clean install of the operating system from external media is the gold standard. A simple reset is a gamble.

Why do I see this error only when opening Teams or Office apps?

This is a nuance many users miss. Windows itself might still let you log in, but Microsoft 365 applications (Teams, Word, Excel) use a specific authentication token called a MAM/MAD token. These apps check their status with the cloud separately from your Windows login. If the device is blocked in Entra ID, the app’s token check fails, triggering Error 135011 specifically inside the app window, even if your desktop works fine.

What is Error Code 135011 in Microsoft 365?

Formally, it’s AADSTS135011. It indicates that the device object associated with your user account is either disabled or deleted in Microsoft Entra ID. It’s a security lockout. It tells the app that this specific hardware identifier is not allowed to authenticate, usually due to a policy violation or an admin manual block.

Conclusion

Getting back to work after a 135011 error is less about magic and more about clarity. You need to know if you’re the owner or the tenant.

  • For owners: Use the "Unlink and Clean" method. Disconnect the account, run dsregcmd /leave, and if all else fails, perform a clean install of Windows to scrub the policies from the registry.
  • For employees: Use the "Communicate and Comply" method. Send the structured email to IT, provide the error code, and be prepared to re-enroll or prove the device is not lost.

Ignoring MDM policies on corporate devices isn’t just a tech support issue; it’s a compliance risk that can violate your employment terms. Always keep a clean distinction between your personal digital life and your corporate one.

Quick Check:

  1. Check Account: Are you signed into a work account you no longer use?
  2. Check MDM Status: Run dsregcmd /status to see if you’re joined.
  3. Contact IT: If it’s a work device, you need their admin access to unlock the cloud object.

If you found this guide helpful, share it with a colleague who might be stuck at the red error screen. For more tips on keeping your home laptop private from corporate tracking, check out our guide on "How to secure your home laptop against corporate tracking."

← Back to Home