Windows Autopilot
Device enrollment

Windows Autopilot device preparation user-driven Microsoft Entra join - Step 6 - Create a Windows Autopilot device preparation policy

In brief

Step 7 now includes device association as an alternative to corporate identifiers. The documentation explains associated-device OOBE settings, deployment precedence, and device- versus user-based policy assignment.

What Intune admins need to know

Review association and assignment precedence when configuring device preparation policies to ensure the intended deployment and OOBE experience.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Windows Autopilot device preparation user-driven Microsoft Entra join - Step 6 of 7 - Create a Windows Autopilot device preparation policy description: How to - Windows Autopilot device preparation user-driven Microsoft Entra join - Step 6 of 7 - Create a Windows Autopilot device preparation policy.policy for a user-driven Microsoft Entra join deployment. ms.date: 06/11/202508/25/2026 ms.topic: tutorial appliesto:

For an overview of the Windows Autopilot device preparation user-driven Microsoft Entra join workflow, see Windows Autopilot device preparation user-driven Microsoft Entra join overview.

  If there's a deployment failure, setting this option to **Yes** displays a link at the deployment failure page allowing the end-user to retrieve diagnostic logs.
  1. Expand

    1. The AppsLanguage (Region) section allows selection of up- Sets the language and region applied to 25 managed applications reference with the deployment. The applications specified here should be the essential applications that should be installed on the device beforeduring OOBE.

    2. Automatically configure keyboard - Skips the end-user can start using the device.keyboard selection page in OOBE.

    1. Hide Microsoft Software License Terms - Hides the Microsoft Software License Terms (EULA) page in OOBE.

    2. Hide privacy settings - Hides the privacy settings page in OOBE.

    3. Hide change account options - Prevents change account options from appearing on the company sign-in and domain error pages. This setting requires company branding to be configured in Microsoft Entra ID.

    4. Apply device name template - Renames the device before enrollment using a custom prefix combined with %RAND:4% (four random characters) or %SERIAL% (the device serial number). The resulting device name can be up to 63 characters long.

    5. Expand the Apps section by selecting it:

      The Apps section lets you select up to 25 managed applications to install during deployment. Select the essential applications that must be installed before the end user can use the device.

    Policy priority

    If multiple Windows Autopilot device preparation policespolicies are deployedassigned to a user, the policy with the highest priority as displayed intakes precedence. On the Home > Enroll devices | Windows enrollment > Device preparation policies screen gets priority. Thescreen, the highest-priority policy withappears at the highest priority is higher intop of the list and has the smallest number underin the Priority column. To change a policy's priority, movedrag it to a different position in the list by dragginglist.

    A device preparation policy can be assigned to a device or to a user. When a device has both a device-based assignment and a user-based assignment, the device-based assignment takes precedence. For example, if you assign a device preparation policy withindirectly to a device when you pre-associate the device, that policy is used instead of any policy assigned to the list.user who signs in during enrollment.

    Next step: Add WindowsOnboard trusted devices

    After you create the device preparation policy, choose one of the following methods to make sure only trusted devices are prepared. You don't need to use both:

    • Corporate identifiers (optional) - Upload device identifiers so only trusted devices can enroll when personal-device enrollment is blocked.
    • Device association (optional) - Bind devices to your tenant before enrollment. Associated devices are automatically treated as corporate-owned, so you don't need to upload corporate identifieridentifiers for them. Device association also enables the out-of-box experience settings that are only available to deviceassociated devices.

    To use corporate identifiers:

    [!div class="nextstepaction"] Step 7, option 1: Add Windows corporate identifier to device

    To use device association instead:

    [!div class="nextstepaction"] Step 7, option 2: Associate devices

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…