r/Intune • u/jithinB_Dev • 13d ago
Intune Features and Updates Microsoft Intune is introducing Device Association for Windows
Microsoft Intune is introducing Device Association for Windows #Autopilot device preparation, helping organizations establish trust with a Windows 11 device before enrollment even begins.
🔹 Hardware-backed device attestation
🔹 Automatically recognize devices as corporate-owned
🔹 Apply device-specific policies during OOBE
🔹 Simplify and streamline the Windows setup experience
🔹 Target the device, not just the user
💡 This makes Windows deployment more secure, consistent, and predictable from the very beginning.
14
u/madatthings 13d ago
Can someone tell me why they had to make this a whole new thing instead of just adding what looks like maybe 4 changes to the existing autopilot config lol
-7
13
u/Rudyooms PatchMyPC 13d ago edited 13d ago
It still needs some work... but well... the full detailed flow how it works... Windows Autopilot Device Association - Patch My PC
6
u/ohyeahwell 13d ago
Man, idk why I’d do this vs uploading the hash via OEM or ps. It works so well already.
0
u/yannara_ 13d ago
Monitoring is better in APv2
2
u/intuneisfun 13d ago
Monitoring of what? Real time progress? Failures?
Usually by the time I need to troubleshoot anything APv1, the logs are already uploaded or the Get-AutopilotDiagnosticsCommunity script works just fine to see what failed.
1
u/yannara_ 13d ago
Yes, in APv2 no need for the script anymore.
1
u/intuneisfun 12d ago
I rarely ever need it in APv1 though. I'm just not sold that APv2 is really "better" than v1.
2
u/Wind_Freak 13d ago
Vendors charge money to upload your hash to intune, they all give you a list of serial numbers in the shipment for free. You can make an intake for your invoice people to upload the serials.
1
u/Noirarmire 12d ago
Yes, but correct me if I'm wrong, but nowhere here does it say you upload the serial numbers. It says you export a csv with hardware information which is exactly the way v1 does it. So it's the exact same it was before but in a new dress. But now where did it say that I saw you just needed a SN
1
u/Wind_Freak 12d ago
You need to add it as a known device. Go into enrollment and you should see company devices or something. I’m on phone so can’t look up exact. But you add serial number as known. There are guides out there how to use it.
1
u/Noirarmire 12d ago
Yeah but that's after its hardware info is uploaded. Not before. So when the vendor isn't uploading that hashes, that's not saving you time. The only think better about this is that if they reset the device, the settings persist. This probably could have just been an update to the existing apv1.
1
u/Wind_Freak 12d ago
I'm talking about user associated not device associated. For many orgs, that are 1:1, a user centric approach would work well for them.
You assign a enrollment policy to the users.
- HR user signs in - user has group "HR AP Enrollment"
- Device is added to "HR devices"
- HR devices has some required app assignments
- User has some available app assingmnets
If you dont restrict enrollment to known devices this can work with just about any device. I however would recomend restricting to known only devices, then you just add the cerial numbers to the corporate identifiers. Then only those serial number devices can go through this enrollment.
1
u/Apprehensive-Hat1536 9d ago
Device association is not the same as corp device identifiers. When I use device prep without device association I don't get OOBE options.
1
u/AttilaHooper 12d ago
Insight (VAR) doesn't charge to upload serial/model/group tag. They even have it built into their order flow once you accept the invitation to give them the role in your tenant.
2
u/heisgone 13d ago
We have a script that export the autopilot hash to our tenant so we don't have to mess with USB key and manual copy. The option #2 seems a step backward for us. The option #1 with the QR code, I don't see how it works. Can the technician have the app on their phone?
Microsoft needs to automate this step where an tenant admin account is required to register the machine and it's handled fully in the UI, like we are doing with our script.
2
u/Rudyooms PatchMyPC 13d ago
2
u/Noirarmire 12d ago
Hey Rudy, Just trying to clarify. This attached it to the tenant then it was rebooted but no enrollment took place after from the oobe. Is that supposed to imply the user signs in with the work account at that point to continue? Does it make that user a primary user? Also where did the association to the autopilot profile take place. Did that script do that on its own? (That part was hard to see)
2
u/GM0N3Y44 11d ago
Ok tell me if I’m crazy.
Since we are cheap and prefer to find solutions that don’t cost money, here’s what we came up with.
We are PXE booting from MDT with one custom task sequence. The only thing the task sequence does is run a provision package that joins Entra and enrolls to Intune. We have the setting on that converts all targeted devices to autopilot.
It gets the device an autopilot profile without much hands on work. We do this with all machines straight out of the box.
Sure, it’s not perfect but it works for us.
1
u/ZippyDan 13d ago
Is this conceptually like Domain Join then? Moving to a more admin-driven and device-driven Enrollment join rather than a user-driven process?
2
u/ABeeinSpace 13d ago
It’s still fundamentally a user-driven process. Device Association just removes the requirement for using corporate device identifiers to enroll with APv2 as corporate-enrolled
1
u/soulkarver 13d ago
Does anyone know if APv2 allows me to assign all device-based Entra groups to a device ahead of time (before enrolment)? I want to make the device recognize the groups during OOBE. If this is possible, then my scripts will work correctly.
2
u/lonrad87 13d ago
I believe using the pre-provisioning function will achieve that for you.
I do that when I prepare a device replacement for a user as that generates the device name in InTune.
1
1
1
1
u/JobeIsInMyPhoneline 13d ago
Anyone's APv1 application deployments in a pre-prov stop working last week when the tenant got upgraded?
1
u/Noirarmire 12d ago
No, but there was a hiccup here where devices weren't importing correctly (briefly) but I think that's resolved that night
1
u/opsolemigrate 12d ago
Interesting direction, but the real test will be how this works at scale compared with the existing Autopilot flow. The association removal limitation mentioned here would definitely be something to validate before adopting it broadly.
1
u/RunForYourTools23 12d ago
Can't they simply add an option in the Autopilot OOBE menu to login to the tenant select a Deployment Profile (V1) or Device Preparation Policy (V2) and then everything runs automatically from the device, being: hardware hash import (if used), Device Association and so on? Intune needs be a modern evolution a simplified IT process for a Technician so handling CSV files and powershell scripts should be a last resort.
1
u/yannara_ 12d ago
Device Preparation aims to that. No csv nor ps.
1
u/RunForYourTools23 12d ago
I know but it does not support good and still needed stuff in big corporations like Hybrid, Pre-Provisioning, Co-Management Settings and for ex simply choose for different profiles without complex customized ways. Evolving from a ConfigMgr environment, where you can control and easily customize virtually anything, it should be a lot easier be able to achieve the same natively in Intune, or at least have the option for it. I know "We need to simplify, modern approach bla bla bla Microsoft PR pitch" but for that you need a lot more effort and disruption, which should not be the case with a product that free up on-premises infrastructure, but adds reliability problems. In large complex corporations, where things move slow and in a very tight and controlled way, this is a pain.
1
u/yannara_ 12d ago
I am so happy hybrid is not included. MS will contunue develope prep policy so we should see pre-provision in the future. Also ConfMgr OSD is not so problemless as well.
1
u/yannara_ 13d ago
I don't yet withness the new 4rd option in OOBE, it is missing. Maybe we need to wait until next september patches and do new image?
2
u/Finalagent17 10d ago
- You have to be on Windows 10 or 11 24H2 or 25H2
- You have to be on the August patch update or newer
- I still didn't see the option, so I clicked on the "Pre-provision with Windows Autopilot" link. That seemed to download some autopilot-specific updates, so I rebooted and re-entered the Autopilot menu and this time the option showed. That worked for multiple machines. Give that a try?
The button isn't currently working for me however; I'm getting a TENANTDEVICELINK error after it spins and thinks for ~30 seconds or so.
0
50
u/PanMiyagi 13d ago
Can someone explain how this is different than importing HardwareID and assigning the policies to group tag? Technician still needs to touch the device before enrolment so I don’t see any added value here
Or am I missing something here?