Windows Autopilot device preparation user-driven Microsoft Entra join - Step 7 - Add Windows corporate identifier to device
In brief
Step 7 now identifies corporate identifiers as one option and links to optional device association as another. Associated devices are automatically treated as corporate-owned, and enrollment links were updated.
What Intune admins need to know
Administrators can choose either method for preparing trusted devices; no configuration change is required.
This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: Windows Autopilot device preparation user-driven Microsoft Entra join - Step 7 of 7 - Add Windows corporate identifier to device
description: How to -Add a Windows corporate identifier as one option for onboarding trusted devices with Windows Autopilot device preparation user-driven Microsoft Entra join - Step 7 of 7 - Add Windows corporate identifier to device.preparation.
ms.date: 04/04/202508/07/2026
ms.topic: tutorial
appliesto:
[!div class="checklist"]
- Step
7:7, option 1: Add Windows corporate identifier to device
For an overview of the Windows Autopilot device preparation user-driven Microsoft Entra join workflow, see Windows Autopilot device preparation user-driven Microsoft Entra join overview.
Add Windows corporate identifier for devices
Corporate identifiers in Intune allows pre-uploading of Windows device identifiers (serial number, manufacturer, model) and ensures only trusted Windows devices can be enrolled in Intune. If Intune enrollment restrictions are being used to block personal device enrollments, corporate identifiers need to be uploaded for all devices that are enrolled through Windows Autopilot device preparation before deployment. To add corporate identifier for devices in Intune, see Add Windows corporate identifiersAdd Windows corporate identifiers.
For more information, see:
For more information, see:
- Identify devices as corporate-owned.
What are enrollment restrictions?What are enrollment restrictions?.Create device platform restrictionsCreate device platform restrictions.
Once the corporate identifier is added for the device, then proceed with deploying the device.
@@ -1,7 +1,7 @@ ----title: Windows Autopilot device preparation user-driven Microsoft Entra join - Step 7 of 7 - Add Windows corporate identifier to device-description: How to - Windows Autopilot device preparation user-driven Microsoft Entra join - Step 7 of 7 - Add Windows corporate identifier to device.-ms.date: 04/04/2025+title: Windows Autopilot device preparation user-driven Microsoft Entra join - Step 7 - Add Windows corporate identifier to device+description: Add a Windows corporate identifier as one option for onboarding trusted devices with Windows Autopilot device preparation.+ms.date: 08/07/2026 ms.topic: tutorial appliesto: - ✅ <a href="https://learn.microsoft.com/windows/release-health/supported-versions-windows-client" target="_blank">Windows 11</a>@@ -20,13 +20,17 @@ Windows Autopilot device preparation user-driven Microsoft Entra join steps: > [!div class="checklist"] >-> - **Step 7: Add Windows corporate identifier to device**+> - **Step 7, option 1: Add Windows corporate identifier to device** For an overview of the Windows Autopilot device preparation user-driven Microsoft Entra join workflow, see [Windows Autopilot device preparation user-driven Microsoft Entra join overview](entra-join-workflow.md#workflow). ## Add Windows corporate identifier for devices -Corporate identifiers in Intune allows pre-uploading of Windows device identifiers (serial number, manufacturer, model) and ensures only trusted Windows devices can be enrolled in Intune. If Intune enrollment restrictions are being used to block personal device enrollments, corporate identifiers need to be uploaded for all devices that are enrolled through Windows Autopilot device preparation before deployment. To add corporate identifier for devices in Intune, see [Add Windows corporate identifiers](/intune/intune-service/enrollment/corporate-identifiers-add#add-windows-corporate-identifiers).+Corporate identifiers in Intune allows pre-uploading of Windows device identifiers (serial number, manufacturer, model) and ensures only trusted Windows devices can be enrolled in Intune. If Intune enrollment restrictions are being used to block personal device enrollments, corporate identifiers need to be uploaded for all devices that are enrolled through Windows Autopilot device preparation before deployment. To add corporate identifier for devices in Intune, see [Add Windows corporate identifiers](/intune/device-enrollment/add-corporate-identifiers#add-windows-corporate-identifiers).++> [!NOTE]+>+> Adding corporate identifiers is **one** of two ways to make sure only trusted devices are prepared. The other way is [device association](entra-join-device-association.md), which is optional. You don't need to use both. If you associate devices, they're automatically treated as corporate-owned, so you **don't** need to upload corporate identifiers for those devices. To use device association instead, see [Step 7, option 2: Associate devices](entra-join-device-association.md). > [!IMPORTANT] >@@ -34,8 +38,8 @@ Corporate identifiers in Intune allows pre-uploading of Windows device identifie For more information, see: -- [Identify devices as corporate-owned](/intune/intune-service/enrollment/corporate-identifiers-add).-- [What are enrollment restrictions?](/intune/intune-service/enrollment/enrollment-restrictions-set).-- [Create device platform restrictions](/intune/intune-service/enrollment/create-device-platform-restrictions).+- [Identify devices as corporate-owned](/intune/device-enrollment/add-corporate-identifiers).+- [What are enrollment restrictions?](/intune/device-enrollment/restrictions).+- [Create device platform restrictions](/intune/device-enrollment/create-platform-restrictions). Once the corporate identifier is added for the device, then proceed with deploying the device.