Device association lifecycle management
The page’s update date changed from August 7, 2026, to September 1, 2026, and the note about new Microsoft Entra ID and Intune records after reset and re-enrollment—and cleaning up stale records—was removed.
A cross-product view of Microsoft Intune changes related to Device enrollment.
The page’s update date changed from August 7, 2026, to September 1, 2026, and the note about new Microsoft Entra ID and Intune records after reset and re-enrollment—and cleaning up stale records—was removed.
The page date was updated, and the note about new device records being created after reset and re-enrollment, including the recommendation to clean up stale records, was removed.
The article’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager` for co-management content.
Supported Zebra and Samsung devices in Android Dedicated Device (COSU) mode don't require a Sharer license; only the Helper needs a Remote Help license.
The known-issues documentation now explains that Windows Autopilot pre-provisioning for Microsoft Entra hybrid join can fail when policy conflict resolution requires domain controller connectivity, particularly when a BYO VPN is unavailable during technician flow.
The device association entry was removed from the Windows Autopilot What's New page and moved to Device preparation What's New. The page date was also changed to June 18, 2026.
Windows Autopilot device preparation now supports associating physical Windows 11 devices with an organization before enrollment. Associated devices are marked corporate-owned and can receive device-targeted policies and naming.
The page metadata now uses `mdm` with `configuration-manager` instead of `mobile-device-management` with `microsoft-endpoint-configuration-manager`.
The `ms.service` value changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.
The page metadata now uses `mdm` with `configuration-manager` instead of `mobile-device-management` with `microsoft-endpoint-configuration-manager`.
The page metadata now uses `ms.subservice: mdm` and `ms.service: configuration-manager` instead of the previous values.
The `ms.service` value changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.
The documentation now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`.
The page metadata changes `ms.service` from `microsoft-endpoint-configuration-manager` to `configuration-manager`.
The page metadata now uses `mdm` and `configuration-manager` instead of `mobile-device-management` and `microsoft-endpoint-configuration-manager`.
The documentation metadata changes `ms.service` from `microsoft-endpoint-configuration-manager` to `configuration-manager`, while retaining `ms.subservice: sdk`.
The page metadata now uses `ms.service: configuration-manager` instead of `ms.service: microsoft-endpoint-configuration-manager`.
The article’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.
The documentation now uses `ms.service: configuration-manager` instead of `ms.service: microsoft-endpoint-configuration-manager`.
The page now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`.
The `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`, while the `sdk` subservice remains unchanged.
The comparison now documents that device preparation devices can be associated with a tenant before enrollment, while Windows Autopilot devices can be registered. It also updates the explanation of deployment selection for Autopilot-registered devices.
The new article documents device resets, local association removal, CSV updates, Autopilot registration, stale records, and decommissioning. It notes that associations persist through resets and that stale records are automatically deleted after 360 days.
The tutorial now documents support for up to 25 essential applications, up from 10, and adds device association as an alternative to corporate identifiers. Associated devices can use settings such as OOBE customization and device naming.
The documentation describes TPM-backed association that writes tenant affinity to UEFI before enrollment, enabling device-targeted policies, device naming, OOBE customization, corporate marking, and stronger onboarding security.
The documentation explains that association state determines whether the Windows Autopilot profile or device association takes precedence. Associated physical Windows 11 devices are marked corporate-owned and can receive device-targeted policies and additional OOBE customizations.
The new article explains how to remove pre-associated devices from Intune and how to clear Device Link UEFI variables before deleting associated devices from Intune.
The page specifies Windows 11, physical-device, TPM 2.0, networking, licensing, and Intune RBAC requirements, including custom-role setup steps.
The documentation now lists Chrome, Edge, and Samsung browser as supported for web-based enrollment. The note about phone-call MFA potentially breaking enrollment and its workaround was removed.
The documentation date and “Date added” value changed from August 20, 2026, to August 27, 2026.
Windows Autopilot device preparation now supports associating physical Windows 11 devices with an organization before enrollment. Associated devices are automatically marked corporate-owned and can receive device-targeted policies and naming.
A new FAQ explains DeviceLink CSV timestamp changes, exporting device information after OOBE, corporate identifier requirements, OEM and partner support, and virtual machine limitations.
Step 7 now offers two options: add a Windows corporate identifier or associate devices. The document date was also updated.
Step 7 now offers two paths: add a Windows corporate identifier or associate devices. The page’s update date was also refreshed.
Step 7 now presents two options: adding a Windows corporate identifier or associating devices. The documentation date was also updated.
Step 7 now documents two options: adding a Windows corporate identifier or using Associate devices. The page date was also updated.
The tutorial now lists device association as an alternative to adding a Windows corporate identifier and clarifies the steps for deploying apps and PowerShell scripts.
Step 7 now includes device association as an alternative to corporate identifiers. The documentation explains associated-device OOBE settings, deployment precedence, and device- versus user-based policy assignment.
Step 7 now identifies corporate identifiers as one option and links to optional device association as another. Associated devices are automatically treated as corporate-owned, and enrollment links were updated.
A new Step 7 guide explains associating devices for user-driven Microsoft Entra join, including exporting device information, importing it into Intune, and reviewing associations. Association is an optional alternative to corporate identifiers.
The article now documents additional Android settings, including work profile inactivity, eSIM removal during wipes, screen power behavior, and separate device and work profile locks, with supported enrollment types, platform versions, defaults, and value requirements.
The documentation now lists Accessibility appearance for iOS/iPadOS 17 and later and Liquid Glass for iOS/iPadOS 27 and later.
The macOS setup documentation now lists the Liquid Glass pane as skippable for macOS 27.0 and later.
The documentation now directs administrators to the “Personal Devices on Android Management API” report under Devices > Monitor and clarifies that reporting is not shown in the policy’s device assignment status or the device configuration tab.
Intune will support macOS 15 and later after macOS Golden Gate 27 release this year. Existing devices on macOS 14.x or below remain enrolled but new enrollments on these versions won't be allowed. Organizations should identify and upgrade affected macOS devices in Intune before the change.
The guidance now links to the general Android and iOS store-app instructions without including direct CylancePROTECT Play Store or App Store URLs.
The three metadata tag lines on the Add devices page were reverted to their previous formatting.
The documentation now states that enrollment time grouping is available for iOS/iPadOS and macOS, along with the new Apple enrollment policies experience.
The licensing documentation now explains that eligible shared-device and no-user-affinity enrollment scenarios support device-targeted management through a device-only subscription. It also states that an unlicensed signed-in user doesn't prevent device-targeted policies, apps, or management actions from processing.
The page title capitalization was updated, and its description now states that administrators can gather hardware hashes and import, edit, and delete device records in the Intune admin center.
The macOS ADE guidance warns not to target profiles that enable PSSO registration during Setup Assistant to userless ADE devices, because this can cause unexpected enrollment behavior and loss of expected device affinity.
Updated Microsoft Intune documentation in intune/solutions/azure-virtual-desktop.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/security-settings-management.md.
Added Microsoft Intune documentation in intune/fundamentals/choose-targeting-method.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/manage-devices-tokens-apple.md.
Updated Microsoft Intune documentation in intune/configmgr/mdm/deploy-use/enroll-devices-on-premises-mdm.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/generateprovisioningxml-method-in-class-sms_bulkenrollmentprofiles.md.
Updated Microsoft Intune documentation in intune/configmgr/mdm/deploy-use/bulk-enroll-devices-on-premises-mdm.md.
Updated Microsoft Intune documentation in intune/configmgr/comanage/autopilot-enrollment.md.
Updated Microsoft Intune documentation in intune/configmgr/mdm/deploy-use/user-enroll-devices-on-premises-mdm.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/importforprofile-method-in-class-sms_mdmbulkenrollmentpackages.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/insertmultipleresourceids-method-in-class-sms_mdmdeviceenrollmentmanagers.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-device-restrictions-android-enterprise.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/removemultipleresourceids-method-in-class-sms_mdmdeviceenrollmentmanagers.md.
Updated Microsoft Intune documentation in intune/configmgr/mdm/get-started/set-up-device-enrollment-on-premises-mdm.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-tv-os.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-vision-os.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/sms_bulkenrollmentprofiles-server-wmi-class.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/sms_deviceenrollmentprofile-server-wmi-class.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/sms_mdmbulkenrollmentpackages-server-wmi-class.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/sms_mdmbulkenrollmentprofiles-server-wmi-class.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/sms_mdmcorpenrollmentprofiles-server-wmi-class.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/reference/mdm/sms_mdmdeviceenrollmentmanagers-server-wmi-class.md.
Updated Microsoft Intune documentation in intune/developer/app-sdk/android-phase-4.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/user-help/enrollment/enroll-company-portal-macos.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-macos-token.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/android-management-api-overview.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/android-management-api-overview.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-macos-token.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/device-enrollment/setup-enrollment-manager.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/manage-device-administrator.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/enterprise-work-profile.md.
Updated Microsoft Intune documentation in intune/fundamentals/assign-licenses.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/ref-automated-authentication-methods.md.
Updated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/enroll-entra-join.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/backup-restore-ios.md.
Updated Microsoft Intune documentation in intune/device-enrollment/windows/create-bulk-package.md.
Updated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/enroll-ios-apple-configurator.md.
Updated Microsoft Intune documentation in intune/device-enrollment/configure-chrome-enterprise-connector.md.
Updated Microsoft Intune documentation in intune/fundamentals/certificates/scep-infrastructure.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/connect-managed-google-play.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/school-manager-step-2.md.
Updated Microsoft Intune documentation in intune/device-configuration/certificates/scep-profiles.md.
Updated Microsoft Intune documentation in intune/device-enrollment/create-device-limit-restrictions.md.
Updated Microsoft Intune documentation in intune/device-enrollment/create-platform-restrictions.md.
Updated Microsoft Intune documentation in intune/device-security/laps/deploy-policy.md.
Updated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/enroll-overview.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/device-staging.md.
Updated Microsoft Intune documentation in intune/device-enrollment/windows/create-cname-autodiscovery.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-samsung-knox-mobile.md.
Updated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/enroll-ios-ade.md.
Updated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/enroll-ios-company-portal.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/ref-corporate-methods.md.
Updated Microsoft Intune documentation in intune/device-enrollment/setup-time-grouping.md.
Updated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/enroll-package.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/create-mdm-push-certificate.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/school-manager-step-1.md.
Updated Microsoft Intune documentation in intune/device-enrollment/add-corporate-identifiers.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/mam.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/manage-devices-tokens-apple.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/manage-devices-tokens-macos.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/migrate-device-admin-to-work-profile.md.
Updated Microsoft Intune documentation in intune/device-security/integrate-network-access-control.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/overview-automated-enrollment-apple.md.