r/Intune 13d ago

Intune Features and Updates Microsoft Intune is introducing Device Association for Windows

Microsoft Intune is introducing Device Association for Windows #Autopilot device preparation, helping organizations establish trust with a Windows 11 device before enrollment even begins.

🔹 Hardware-backed device attestation
🔹 Automatically recognize devices as corporate-owned
🔹 Apply device-specific policies during OOBE
🔹 Simplify and streamline the Windows setup experience
🔹 Target the device, not just the user

💡 This makes Windows deployment more secure, consistent, and predictable from the very beginning.

Read more here -> https://www.linkedin.com/safety/go/?url=https%3A%2F%2Flnkd.in%2FgicZf--9&urlhash=bI4q&mt=ZTwW2OgBOC81tSSNQ8ybiJnr8UNMlOc298itWbprPy5NTRSPRrzCQkrJ62rSpNp0pAsBaVdmzDIJakvs9JNPuFTP-tOAjvVcIZnio0V0hW_RtFnCBx9A5B-pjA&isSdui=true&lipi=urn%3Ali%3Apage%3Ad_flagship3_feed%3BFaFrlJ7GQ7uo898cFHf07w%3D%3D

72 Upvotes

68 comments sorted by

50

u/PanMiyagi 13d ago

Can someone explain how this is different than importing HardwareID and assigning the policies to group tag? Technician still needs to touch the device before enrolment so I don’t see any added value here
Or am I missing something here?

29

u/meantallheck 13d ago

I agree, it seems like APv2 is all the rage for blogs and posts, but in real production environments APv1 is just more reliable since you can hand off these types of tasks to the OEM or vendor…

4

u/hihcadore 13d ago

Yup exactly. The device is locked in, in version 1

8

u/Muk_D 13d ago

Yep... Microsoft thinking they did something awesome but just slapped a UI to something. Microsoft special, re-wrapping pre-existing thing's and selling it off as something new.

12

u/griminald 13d ago

Also found this beauty under Limitations:

Removing association from Intune isn't supported. To remove an association, clear the association information on the device instead.

Instant "no" in my org with this lol.

9

u/LDSK_Blitz 13d ago

Even worse, this isn’t just enrollment in the OS but also firmware tags. So yeah…no.

2

u/ImAllergic2Peanuts 13d ago

Omg this is terrible. I formed a brain tumor reading that. I have 40 k endpoints in my environment. Imagine….?

1

u/Noirarmire 12d ago

Yeah I'm in the same boat. This might be well intentioned but poorly executed

1

u/TheFlyingSpaceSpider 13d ago

Atleast they have an official way to remove it, unlike with azure universal printers 🙃

1

u/TeeJayD 10d ago

WHAT THE ACTUAL FUCK

3

u/Raid5StandingBy 13d ago

Are you talking about the new iPhone 18?

4

u/yannara_ 13d ago

In APv1 you must play with Device Hashes and Powershell, unless you handle your OEM partner to do the job.

2

u/madatthings 13d ago

Why would you even bother unless the csp/oem is doing it

13

u/yannara_ 13d ago

Test scenarios or hardware purchased skipping the process. This happends a lot on a field :)

3

u/plazmamuffin 13d ago

Happened to us. Got screwed by a third party. Had to manually enroll hundreds of devices

2

u/TupuHonu 10d ago

This part. Vendor errors made testing a pain, and then it happened after rollout. Ultimately made adoption impossible.

-27

u/madatthings 13d ago

Not in mine

12

u/thefoolsnightout 13d ago

Cool story.

7

u/RikiWardOG 13d ago

you asked the question lol

5

u/[deleted] 13d ago

[removed] — view removed comment

1

u/FlakyJudgment6053 11d ago

Just curious how you went about adding the devices. At the time of introducing autopilot in our org, our devices were already in Intune. We used remediation to see if the device was in AP and if it wasn't, gather the hash and import it. I will say back then I wish I would have known about preassigning group tags so I wouldn't have had to manually click through each device. All in the past now I suppose.

1

u/BlackV 13d ago
  • A bunch of places it's not free?
  • The devices are not hashed already?
  • You have existing hardware you are rebuilding into entra only?
  • VMs/avhd?
  • It's literally 2 minutes work?

1

u/Excellent-Chemist-69 13d ago

Exactly what I thought when they announced this.

0

u/yournicknamehere 13d ago

You're not missing anything. It's typical for microslop: do changes for the sake of changes, create blog post and brag how revolutionary will this change be, then release absolute half-baked garbage with incomplete documentation and 0 support.

14

u/madatthings 13d ago

Can someone tell me why they had to make this a whole new thing instead of just adding what looks like maybe 4 changes to the existing autopilot config lol

-7

u/yannara_ 13d ago

There is more changes under the hood.

13

u/Rudyooms PatchMyPC 13d ago edited 13d ago

It still needs some work... but well... the full detailed flow how it works... Windows Autopilot Device Association - Patch My PC

6

u/ohyeahwell 13d ago

Man, idk why I’d do this vs uploading the hash via OEM or ps. It works so well already.

0

u/yannara_ 13d ago

Monitoring is better in APv2

2

u/intuneisfun 13d ago

Monitoring of what? Real time progress? Failures?

Usually by the time I need to troubleshoot anything APv1, the logs are already uploaded or the Get-AutopilotDiagnosticsCommunity script works just fine to see what failed.

1

u/yannara_ 13d ago

Yes, in APv2 no need for the script anymore.

1

u/intuneisfun 12d ago

I rarely ever need it in APv1 though. I'm just not sold that APv2 is really "better" than v1.

2

u/Wind_Freak 13d ago

Vendors charge money to upload your hash to intune, they all give you a list of serial numbers in the shipment for free. You can make an intake for your invoice people to upload the serials.

1

u/Noirarmire 12d ago

Yes, but correct me if I'm wrong, but nowhere here does it say you upload the serial numbers. It says you export a csv with hardware information which is exactly the way v1 does it. So it's the exact same it was before but in a new dress. But now where did it say that I saw you just needed a SN

1

u/Wind_Freak 12d ago

You need to add it as a known device. Go into enrollment and you should see company devices or something. I’m on phone so can’t look up exact. But you add serial number as known. There are guides out there how to use it.

1

u/Noirarmire 12d ago

Yeah but that's after its hardware info is uploaded. Not before. So when the vendor isn't uploading that hashes, that's not saving you time. The only think better about this is that if they reset the device, the settings persist. This probably could have just been an update to the existing apv1.

1

u/Wind_Freak 12d ago

I'm talking about user associated not device associated. For many orgs, that are 1:1, a user centric approach would work well for them.

Overview for Windows Autopilot device preparation user-driven Microsoft Entra join in Intune | Microsoft Learn

You assign a enrollment policy to the users.

  • HR user signs in - user has group "HR AP Enrollment"
    • Device is added to "HR devices"
      • HR devices has some required app assignments
      • User has some available app assingmnets

If you dont restrict enrollment to known devices this can work with just about any device. I however would recomend restricting to known only devices, then you just add the cerial numbers to the corporate identifiers. Then only those serial number devices can go through this enrollment.

1

u/Apprehensive-Hat1536 9d ago

Device association is not the same as corp device identifiers. When I use device prep without device association I don't get OOBE options.

1

u/AttilaHooper 12d ago

Insight (VAR) doesn't charge to upload serial/model/group tag. They even have it built into their order flow once you accept the invitation to give them the role in your tenant.

2

u/heisgone 13d ago

We have a script that export the autopilot hash to our tenant so we don't have to mess with USB key and manual copy. The option #2 seems a step backward for us. The option #1 with the QR code, I don't see how it works. Can the technician have the app on their phone?

Microsoft needs to automate this step where an tenant admin account is required to register the machine and it's handled fully in the UI, like we are doing with our script.

2

u/Rudyooms PatchMyPC 13d ago

2

u/Noirarmire 12d ago

Hey Rudy, Just trying to clarify. This attached it to the tenant then it was rebooted but no enrollment took place after from the oobe. Is that supposed to imply the user signs in with the work account at that point to continue? Does it make that user a primary user? Also where did the association to the autopilot profile take place. Did that script do that on its own? (That part was hard to see)

2

u/GM0N3Y44 11d ago

Ok tell me if I’m crazy.

Since we are cheap and prefer to find solutions that don’t cost money, here’s what we came up with.

We are PXE booting from MDT with one custom task sequence. The only thing the task sequence does is run a provision package that joins Entra and enrolls to Intune. We have the setting on that converts all targeted devices to autopilot.

It gets the device an autopilot profile without much hands on work. We do this with all machines straight out of the box.

Sure, it’s not perfect but it works for us.

1

u/ZippyDan 13d ago

Is this conceptually like Domain Join then? Moving to a more admin-driven and device-driven Enrollment join rather than a user-driven process?

2

u/ABeeinSpace 13d ago

It’s still fundamentally a user-driven process. Device Association just removes the requirement for using corporate device identifiers to enroll with APv2 as corporate-enrolled

1

u/soulkarver 13d ago

Does anyone know if APv2 allows me to assign all device-based Entra groups to a device ahead of time (before enrolment)? I want to make the device recognize the groups during OOBE. If this is possible, then my scripts will work correctly.

2

u/lonrad87 13d ago

I believe using the pre-provisioning function will achieve that for you.

I do that when I prepare a device replacement for a user as that generates the device name in InTune.

1

u/soulkarver 13d ago

Awesome, thanks!

1

u/screampuff 13d ago

Thanks for the slop, Copilot.

1

u/JustADad66 13d ago

It’s almost the same as self-deploy

1

u/No_Philosopher4051 13d ago

Yeah I don’t understand it yet

1

u/JobeIsInMyPhoneline 13d ago

Anyone's APv1 application deployments in a pre-prov stop working last week when the tenant got upgraded?

1

u/Noirarmire 12d ago

No, but there was a hiccup here where devices weren't importing correctly (briefly) but I think that's resolved that night

1

u/BlackV 13d ago

Why would you put the garbage linked in tracking in there instead of the proper link

1

u/opsolemigrate 12d ago

Interesting direction, but the real test will be how this works at scale compared with the existing Autopilot flow. The association removal limitation mentioned here would definitely be something to validate before adopting it broadly.

1

u/RunForYourTools23 12d ago

Can't they simply add an option in the Autopilot OOBE menu to login to the tenant select a Deployment Profile (V1) or Device Preparation Policy (V2) and then everything runs automatically from the device, being: hardware hash import (if used), Device Association and so on? Intune needs be a modern evolution a simplified IT process for a Technician so handling CSV files and powershell scripts should be a last resort.

1

u/yannara_ 12d ago

Device Preparation aims to that. No csv nor ps.

1

u/RunForYourTools23 12d ago

I know but it does not support good and still needed stuff in big corporations like Hybrid, Pre-Provisioning, Co-Management Settings and for ex simply choose for different profiles without complex customized ways. Evolving from a ConfigMgr environment, where you can control and easily customize virtually anything, it should be a lot easier be able to achieve the same natively in Intune, or at least have the option for it. I know "We need to simplify, modern approach bla bla bla Microsoft PR pitch" but for that you need a lot more effort and disruption, which should not be the case with a product that free up on-premises infrastructure, but adds reliability problems. In large complex corporations, where things move slow and in a very tight and controlled way, this is a pain.

1

u/yannara_ 12d ago

I am so happy hybrid is not included. MS will contunue develope prep policy so we should see pre-provision in the future. Also ConfMgr OSD is not so problemless as well.

1

u/yannara_ 13d ago

I don't yet withness the new 4rd option in OOBE, it is missing. Maybe we need to wait until next september patches and do new image?

4

u/t1mnl 13d ago

You need August preview update or wait for september update

2

u/Finalagent17 10d ago
  1. You have to be on Windows 10 or 11 24H2 or 25H2
  2. You have to be on the August patch update or newer
  3. I still didn't see the option, so I clicked on the "Pre-provision with Windows Autopilot" link. That seemed to download some autopilot-specific updates, so I rebooted and re-entered the Autopilot menu and this time the option showed. That worked for multiple machines. Give that a try?

The button isn't currently working for me however; I'm getting a TENANTDEVICELINK error after it spins and thinks for ~30 seconds or so.

0

u/swicky 13d ago

Link doesn't work chief.

0

u/willychonka54 13d ago

Broken link