Windows Autopilot device association binds a physical Windows 11 device to your Microsoft Entra tenant before it enrolls in Intune: you export a DeviceLink CSV from the device, upload it under Devices > Enrollment > Device association > Devices, and when the device next connects to a network in OOBE it proves its TPM-backed identity and writes a tenant marker into UEFI firmware. Associated devices are treated as corporate-owned, can receive a device preparation policy assigned directly to the device, and unlock OOBE settings such as hidden license and privacy pages and a device name template. The feature shipped on August 27, 2026 and needs Windows 11 24H2 or 25H2 with KB5120998 or later and a healthy TPM 2.0.
Who this is for and what you will have
This guide is for Intune administrators who use, or plan to use, Windows Autopilot device preparation and want some of the control that classic Autopilot registration provides. If you're still choosing between the two provisioning models, start with Autopilot device preparation vs classic Autopilot. At the end of this guide you will have:
- A device preparation policy with the OOBE settings that only associated devices honor.
- A repeatable way to export device information, pre-associate devices and confirm association.
- A lifecycle process for resets, re-uploads, stale records and decommissioning.
How device association works
Before device association, a device going through device preparation knew nothing about your tenant until a user signed in. Device association establishes that link earlier. It uses the device's TPM-backed identity, verified through hardware attestation, and stores tenant affinity in UEFI so the MDM provider can recognize and authenticate the device before enrollment starts.
Three operations make up the lifecycle:
| Operation | Who performs it | What happens |
|---|---|---|
| Pre-associate | Administrator in Intune | Records the intent to create a TPM-backed association in a central service |
| Associate | Automatic when the device connects to a network in OOBE, or triggered by a technician | Verifies the TPM-backed identity and writes a tenant affinity marker to UEFI |
| Remove association | Admin, OEM or partner on the device | Deletes the UEFI marker that proves the association |
In Intune each device shows one of three association states: Pre-associated (added by CSV, waiting for OOBE), Associated (completed the OOBE step and ready to enroll) or Pending removal (a removal request is being processed).
What association unlocks
- OOBE customization. The user-driven device preparation policy gains Language (Region), Automatically configure keyboard, Hide Microsoft Software License Terms, Hide privacy settings, Hide change account options and Apply device name template. These settings have no effect on devices that aren't associated, including devices onboarded only with corporate identifiers.
- Device naming before enrollment. The name template accepts
%SERIAL%or%RAND:x%; names can be up to 63 characters of letters, numbers and hyphens, and can't be only numbers. - Device-targeted policy. You can assign a device preparation policy to the device at pre-association. A device-based assignment takes precedence over a user-based one, so one user can enroll several devices with different policies.
- Automatic corporate marking. Associated devices aren't blocked by personal-device enrollment restrictions, so you don't upload corporate identifiers for them.
On Windows Pro editions, the Personal account / Work and school account page is hidden by default for all associated devices.
How it compares with registration and corporate identifiers
| Device association | Classic registration | Corporate identifiers | |
|---|---|---|---|
| Used with | Device preparation | Classic Autopilot | Device preparation (and other enrollment) |
| What you upload | DeviceLink CSV exported from the device | Hardware hash CSV, or OEM/reseller registration | Manufacturer, model and serial number |
| Identity check | TPM attestation, marker in UEFI | Hardware hash match | Identifier match |
| Marks device corporate | Yes | Yes | Yes |
| OOBE customization | Yes, for associated devices | Yes, through the deployment profile | No |
Classic registration can be done by the OEM or reseller. For device association, Microsoft's FAQ states that OEM and partner pre-association is planned but not available yet, so today every device is pre-associated through Intune.
Requirements
Software and hardware
- Windows 11, version 25H2 or 24H2, with KB5120998 or later.
- Windows 11 Pro, Pro Education, Pro for Workstations, Enterprise, Education or Enterprise LTSC.
- A physical device. Virtual machines aren't supported.
- TPM 2.0, enabled and in a good state, and not in Reduced Functionality Mode. TPM attestation is enforced during association.
Network
Device association has the same baseline network requirements as device preparation, plus HTTPS on TCP 443 to https://ztd.dds.microsoft.com and to Microsoft's attestation endpoints:
https://peapdamaa1.eus2.attest.azure.net
https://peapdamaa2.wus2.attest.azure.net
https://peapdamaa3.cus.attest.azure.net
https://peapdamaa5.cus.attest.azure.net
https://peapdamaa6.neu.attest.azure.net
https://peapdamaa7.weu.attest.azure.net
https://peapdamaa8.sasia.attest.azure.net
https://peapdamaa9.eau.attest.azure.net
https://peapdamaa19.wus2.attest.azure.net
https://peapdamaa86.cin.attest.azure.net
https://peapdamaa89.jpe.attest.azure.net
https://peapdamaa93.weu.attest.azure.netLicensing
The same subscriptions as Windows Autopilot device preparation, for example Microsoft 365 Business Premium, Microsoft 365 E3 or E5, EMS E3 or E5, or Microsoft Entra ID P1 or P2 with Intune.
RBAC
To configure the device preparation policy, a role needs Device configurations Read, Delete, Create and Update; Enrollment programs > Enrollment time device membership assignment; and Read on Managed apps, Mobile apps and Organization. To manage associated devices, it also needs Enrollment programs Read device, Create device and Delete device, plus Device configurations Assign. Create a custom role under Tenant administration > Roles > Create > Intune role if you don't want to use Intune Administrator.
Step 1: Prepare device preparation
Device association is optional step 7 of the device preparation user-driven Microsoft Entra join tutorial, so steps 1 to 6 must be in place:
- Automatic MDM enrollment is enabled and users can join devices to Microsoft Entra ID.
- An assigned security device group exists with the Intune Provisioning Client service principal (AppId
f1346770-5b25-470b-88bd-d5744ab7952c) as owner. - A user group exists for the people who will set up devices.
- Essential apps and scripts are assigned to the device group, in System context.
Step 2: Create the policy with associated-device settings
- In the Intune admin center, go to Devices > Windows > Enrollment and, under Windows Autopilot device preparation, select Device preparation policies > Create > User Driven.
- On Device group, select the assigned device group (not the user group).
- Under Deployment settings, choose User-driven, Single user, Microsoft Entra joined and a User account type.
- Under Out-of-box experience settings, set the timeout (15 to 720 minutes) and error options, then configure the associated-device settings:
- Language (Region) and Automatically configure keyboard. If the device uses Wi-Fi in OOBE, these pages aren't hidden.
- Hide Microsoft Software License Terms and Hide privacy settings. Hiding privacy settings disables location services by default.
- Hide change account options, only if company branding is configured in Microsoft Entra ID.
- Apply device name template, for example a short prefix with
%SERIAL%.
- Add up to 25 apps and 10 scripts, assign the policy to the user group, and select Save.
Even if you plan to assign this policy directly to devices, keep a user-group assignment as a fallback; a device with no device assignment uses the policy assigned to the user who signs in, and gets none if that user has none.
Step 3: Export the DeviceLink CSV
From a new device in OOBE
Use a USB drive formatted with NTFS.
- Power on the device and stop at the region selection page. Don't complete OOBE.
- Press the Windows key five times quickly to open the Autopilot menu.
- Insert the USB drive and select Export device information. The CSV is saved to the drive.
- Copy the CSV to a computer with access to the Intune admin center.
The menu also has Scan QR code, but Intune's upload accepts only the CSV from Export device information. The QR option is for custom apps that pre-associate through Microsoft Graph.
From a device that is already set up
The Autopilot menu isn't available after OOBE. Collect Autopilot diagnostics instead and take the DeviceLink CSV from them, using any of these methods:
- Settings > Accounts > Access work or school > Export your management logs > Export.
- From an elevated command prompt:
MdmDiagnosticsTool.exe -area Autopilot -cab C:\Diagnostics\Autopilot.cab- In the Intune admin center, Devices > All devices > select the device > Collect diagnostics, then download from Device diagnostics.
If you export the CSV several times, the contents differ because the DeviceLink contains timestamps. That's expected and doesn't change the device's hardware identity.
Step 4: Pre-associate the device in Intune
- In the Intune admin center, go to Devices > Enrollment > Device association > Devices.
- Select Add, then on Import CSV select Browse and upload the file.
- On Assign device preparation policy, optionally choose the policy from step 2.
- Select Next, review the summary and select Add.
The device appears with Association state set to Pre-associated. Only one device per CSV file is supported at the moment, so upload a separate file for each device.
Step 5: Complete association and enroll
Association completes automatically when the pre-associated device connects to a network in OOBE. If a technician exported the CSV and the device is still at the Autopilot menu, they can return to the menu after pre-association and select Next; the device contacts the Autopilot service, finds the record and shows Association complete.
The user then signs in. The device enrolls with the device-targeted (or user-targeted) device preparation policy, is marked corporate-owned and gets the configured OOBE customizations.
Verification
- In Devices > Enrollment > Device association > Devices, the state changes from Pre-associated to Associated. Use Search for serial number or device name, and filter by state, policy, manufacturer or model.
- The device name matches your template and the hidden pages didn't appear during OOBE.
- The device preparation deployment report on the Monitor tab of Devices > Enrollment shows the deployment and its app and script status.
Lifecycle management
Resets. The association persists across a reset, a Windows reinstall and enrollment removal. Resetting alone never removes it.
Uploading a new CSV for the same device. If the hardware identity hasn't changed, the existing pre-association record is updated in place, which is how you change the assigned policy. If the identity has changed, a new record is created and the old one becomes stale.
What changes the hardware identity. Running a script to remove association, resetting BIOS or UEFI settings, or changing the Secure Boot configuration. After any of these, export a fresh CSV and pre-associate again.
Registered classic Autopilot devices. You can pre-associate a device that is already registered. During OOBE, association takes precedence and the device enrolls with device preparation. Without association, the classic profile wins.
Stale records. A record becomes stale when a new record replaces it after an identity change, or when the device was pre-associated and then associated with a different tenant. Stale pre-associated records are deleted automatically after 360 days.
Removing an association
Remove an association only when the device permanently leaves your tenant, for example at disposal or transfer to another organization.
Pre-associated devices: select the device in Device association > Devices and select Delete. It disappears immediately.
Associated devices: deleting the record in Intune doesn't clear the marker in firmware. First make sure the device is no longer enrolled with your MDM provider; if it's still enrolled, Intune tries to re-associate it at the next check-in. Then clear all four variables in the Device Link UEFI namespace on the device:
| UEFI namespace | Variable |
|---|---|
{B3DE75DA-819C-4FD5-9F01-C3D49E8CBBD7} | DeviceLinkId |
{B3DE75DA-819C-4FD5-9F01-C3D49E8CBBD7} | DeviceLinkJwtCompressed |
{B3DE75DA-819C-4FD5-9F01-C3D49E8CBBD7} | DeviceLinkJwtLastWrite |
{B3DE75DA-819C-4FD5-9F01-C3D49E8CBBD7} | DeviceLinkCreationTimeUtc |
Finally, select the device in Intune (its state changes to Pending removal) and select Delete. Clearing these variables doesn't reset the TPM, unenroll the device or delete its Microsoft Entra ID or Intune records, so handle those separately. Physical access is required, and Microsoft treats whoever has physical access as the owner from an association security perspective; keep this step inside your asset disposal process.
Troubleshooting
Several devices in one CSV. Only one device per CSV file is supported at the moment. Upload one file per device and use the CSV from Export device information, not the QR code.
Association never completes. Confirm the build has KB5120998 or later, the TPM 2.0 is enabled and not in Reduced Functionality Mode, the device is physical, and the attestation endpoints and ztd.dds.microsoft.com are reachable on TCP 443.
Pre-association stopped matching after BIOS work. A UEFI reset or Secure Boot change gives the device a new hardware identity. Export and upload a new CSV; the old record becomes stale and is cleaned up after 360 days.
Language and keyboard pages still appear. Expected when the device uses a Wi-Fi connection during OOBE; Microsoft documents that the language and keyboard selection screens aren't hidden in that case.
OOBE settings ignored. They apply only to associated devices. A device onboarded with corporate identifiers alone gets the deployment, but not the customizations.
Wrong policy applied. A device-targeted assignment from pre-association always beats a user-targeted one. Re-upload the CSV with the right policy, which updates the record in place.
Device can't be removed from Intune. Removing an association from Intune isn't supported for associated devices. Clear the UEFI variables on the device first.
Windows 365 Cloud PCs. Device association doesn't apply; Cloud PCs are already trusted corporate devices.
Closing checklist
- Devices on Windows 11 24H2 or 25H2 with KB5120998 or later, physical, healthy TPM 2.0.
- Attestation endpoints and
ztd.dds.microsoft.comallowed on TCP 443. - Custom role includes the Enrollment programs device permissions and Device configurations Assign.
- Device preparation policy configured with the associated-device OOBE settings and a user-group fallback.
- Company branding configured if you hide change account options.
- DeviceLink CSV exported per device and pre-associated with the right policy.
- State confirmed as Associated before handover.
- Disposal process unenrolls the device, clears the four Device Link UEFI variables and deletes the Intune record.
References
- Overview of Windows Autopilot device association
- Requirements for Windows Autopilot device association
- Associate devices (device preparation tutorial, step 7)
- Create a Windows Autopilot device preparation policy
- Device association lifecycle management
- Remove a Windows Autopilot device association
- Windows Autopilot device association FAQ
- What's new in Windows Autopilot device preparation
- Windows Autopilot device preparation requirements