Windows Autopilot
Device enrollment

Overview of Windows Autopilot device association

In brief

The documentation describes TPM-backed association that writes tenant affinity to UEFI before enrollment, enabling device-targeted policies, device naming, OOBE customization, corporate marking, and stronger onboarding security.

What Intune admins need to know

Administrators can pre-associate devices in Intune, assign device preparation policies, and manage association removal when devices leave the tenant. No mandatory action is stated.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

new file mode 100644

title: Overview of Windows Autopilot device association description: Device association binds a Windows device to your organization before enrollment by stamping tenant affinity into the device's UEFI, enabling a streamlined OOBE, device naming, device-based policy targeting, and stronger onboarding security. ms.date: 08/25/2026 ms.topic: overview appliesto: - ✅ Windows 11

Overview of Windows Autopilot device association

Device association is a feature of Windows Autopilot device preparation that binds a Windows device to your organization before the device enrolls with a mobile device management (MDM) provider, such as Microsoft Intune. It establishes a verifiable link between a physical device and your tenant by writing a tenant affinity marker into the device's UEFI firmware, making the device recognizable and authenticatable by the MDM provider before enrollment begins. By establishing this trusted relationship early in the provisioning process, device association unlocks a streamlined out-of-box experience (OOBE) and strengthens the security of onboarding.

Benefits

Device association provides the following benefits:

  • Streamlined out-of-box experience (OOBE) - Because the device is recognized as an organizational device before enrollment, OOBE can present a simpler, more consistent set of pages to the end user. You can preconfigure settings such as language, keyboard layout, and skipping the license and privacy pages.
  • Device naming before enrollment - Apply a device name using a template before the device enrolls, so the device carries the correct name from the start of its lifecycle.
  • Device-based policy targeting - Target device preparation policies directly to devices instead of relying solely on user group assignments, so the correct policy is applied regardless of which user signs in.
  • Automatic corporate marking - Associated devices are automatically marked as corporate-owned, so they aren't blocked by personal device enrollment restrictions—no separate corporate identifier upload needed.
  • Stronger onboarding security - Device identity is verified before enrollment through hardware-based attestation and TPM-backed cryptographic validation, helping ensure that only trusted devices can access organizational resources.

How device association works

Device association uses the device's TPM-backed identity to establish a trusted association between the device and your tenant. It involves three lifecycle operations:

OperationPerformed byDescription
Pre-associateAdministrator in IntuneStores the intent to create a TPM-backed association between the device and your tenant in a central service before the association is written to UEFI.
AssociateAutomatic—triggered by the technician after pre-associating, or when the device connects to a network in OOBEVerifies that the device presents the expected TPM-backed identity, and then writes a marker containing tenant affinity information to the device's UEFI. The marker is used to attest the device's affinity at enrollment.
Remove associationAdmin, OEM vendor, or partner, by running a PowerShell script on the deviceDeletes the UEFI marker used to verify the device's association, clearing the trusted tenant affiliation from UEFI storage.

The high-level workflow is:

  1. Create a device preparation policy with the deployment and OOBE experience settings you want to apply.
  2. Export device information from the device during OOBE.
  3. Pre-associate the device in Intune by uploading the exported CSV, and optionally assign a device preparation policy.
  4. Associate the device. Association happens automatically when the device connects to a network in OOBE. A technician can also trigger it manually in OOBE, immediately after pre-associating. Associating the device stamps the UEFI marker.
  5. Enroll the device. It receives the device-targeted policy, is marked as corporate-owned, and has the configured OOBE customizations applied.
  6. Remove association when the device is permanently leaving your tenant, such as when you decommission it.

Key capabilities

Device-targeted policy assignment

Assign a device preparation policy directly to a pre-associated device, so the correct policy applies regardless of which user signs in. One user can enroll multiple devices, each with a different policy.

OOBE customization

Device association enables the following settings in the device preparation user-driven policy, applied before enrollment:

  • Language (Region) - Select the language to use for the device.
  • Automatically configure keyboard - When a language is selected, skip the keyboard selection page.
  • Hide Microsoft Software License Terms - Skip the End-User License Agreement (EULA) page during OOBE.
  • Hide privacy settings - Skip the privacy settings page during OOBE. When privacy settings are hidden, location services are disabled by default.
  • Hide change account options - Prevent change account options from appearing on the company sign-in and domain error pages. This setting requires company branding to be configured in Microsoft Entra ID.
  • Apply device name template - Name the device during enrollment by using a template. Names can be up to 63 characters long and can contain letters, numbers, and hyphens, but can't contain only numbers. Use %SERIAL% to include the device serial number or %RAND:x% to include a random numeric string, where x is the number of digits.

Device monitoring

Monitor the status of pre-associated and associated devices from the Device association blade in Intune under Devices > Enrollment > Device association > Devices. The blade shows each device's association state and assigned device preparation policy, and lets you filter by state, policy, manufacturer, and model.

Limitations

The following limitations apply in the current release:

  • Removing association from Intune isn't supported. To remove an association, clear the association information on the device instead. For more information, see Remove association from a device.
  • Device association doesn't apply to Windows 365 devices because they're already marked as trusted corporate devices.

Next steps

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…