{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/",
        "slug": "dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/"
        },
        "title": "Clear device association on the device before it permanently leaves the tenant",
        "summary": "Can Windows Autopilot device association be removed entirely from the Intune portal?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:19+00:00",
        "modified_at": "2026-09-10T00:55:35+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 237,
        "potentially_affected": "Apply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization's data-removal process as separate items in the handoff.",
        "dse_recommendation": "Include an on-device association-removal task in the permanent-transfer plan.",
        "primary_source": {
            "name": "Overview of Windows Autopilot device association | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Windows Autopilot device association writes tenant-affinity information into a device&#8217;s UEFI after verifying its TPM-backed identity. Microsoft says removing that association from Intune is not supported. The removal operation runs on the device and deletes the UEFI marker. Its lifecycle guidance calls for removal when the device permanently leaves the tenant. Device association does not apply to Windows 365 devices. <a href=\"https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization&#8217;s data-removal process as separate items in the handoff.</p>\n<h2>DSE recommendation</h2>\n<p>Include an on-device association-removal task in the permanent-transfer plan. Confirm who will have authorized access to the device before it leaves organizational custody. Use Microsoft&#8217;s dedicated removal procedure for the actual device, and preserve the association identity beforehand. Do not close the handoff from an Intune inventory change alone. Coordinate the association step with, but do not substitute it for, the separately approved preservation and device-retirement requirements.</p>\n<h2>Verification</h2>\n<p>In an approved transfer rehearsal, record the original association state and the documented removal result on the device. Reconcile that evidence with the intended tenant and asset identity. Verify the separate data and access-removal tasks through their own checks. If the device cannot be reached, record the association task as unresolved rather than assuming a portal action cleared the firmware marker.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Overview of Windows Autopilot device association</a>.</p>",
        "content_text": "Source facts\nWindows Autopilot device association writes tenant-affinity information into a device’s UEFI after verifying its TPM-backed identity. Microsoft says removing that association from Intune is not supported. The removal operation runs on the device and deletes the UEFI marker. Its lifecycle guidance calls for removal when the device permanently leaves the tenant. Device association does not apply to Windows 365 devices. Microsoft Learn.\nApplicability\nApply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization’s data-removal process as separate items in the handoff.\nDSE recommendation\nInclude an on-device association-removal task in the permanent-transfer plan. Confirm who will have authorized access to the device before it leaves organizational custody. Use Microsoft’s dedicated removal procedure for the actual device, and preserve the association identity beforehand. Do not close the handoff from an Intune inventory change alone. Coordinate the association step with, but do not substitute it for, the separately approved preservation and device-retirement requirements.\nVerification\nIn an approved transfer rehearsal, record the original association state and the documented removal result on the device. Reconcile that evidence with the intended tenant and asset identity. Verify the separate data and access-removal tasks through their own checks. If the device cannot be reached, record the association task as unresolved rather than assuming a portal action cleared the firmware marker.\nOfficial references\nMicrosoft Learn: Overview of Windows Autopilot device association.",
        "content_markdown": "## Source facts\n\nWindows Autopilot device association writes tenant-affinity information into a device’s UEFI after verifying its TPM-backed identity. Microsoft says removing that association from Intune is not supported. The removal operation runs on the device and deletes the UEFI marker. Its lifecycle guidance calls for removal when the device permanently leaves the tenant. Device association does not apply to Windows 365 devices. [Microsoft Learn](https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview).\n\n## Applicability\n\nApply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization’s data-removal process as separate items in the handoff.\n\n## DSE recommendation\n\nInclude an on-device association-removal task in the permanent-transfer plan. Confirm who will have authorized access to the device before it leaves organizational custody. Use Microsoft’s dedicated removal procedure for the actual device, and preserve the association identity beforehand. Do not close the handoff from an Intune inventory change alone. Coordinate the association step with, but do not substitute it for, the separately approved preservation and device-retirement requirements.\n\n## Verification\n\nIn an approved transfer rehearsal, record the original association state and the documented removal result on the device. Reconcile that evidence with the intended tenant and asset identity. Verify the separate data and access-removal tasks through their own checks. If the device cannot be reached, record the association task as unresolved rather than assuming a portal action cleared the firmware marker.\n\n## Official references\n\n[Microsoft Learn: Overview of Windows Autopilot device association](https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Clear device association on the device before it permanently leaves the tenant",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/",
                "headline": "Clear device association on the device before it permanently leaves the tenant",
                "description": "Can Windows Autopilot device association be removed entirely from the Intune portal?",
                "abstract": "Can Windows Autopilot device association be removed entirely from the Intune portal?",
                "articleBody": "Source facts\nWindows Autopilot device association writes tenant-affinity information into a device’s UEFI after verifying its TPM-backed identity. Microsoft says removing that association from Intune is not supported. The removal operation runs on the device and deletes the UEFI marker. Its lifecycle guidance calls for removal when the device permanently leaves the tenant. Device association does not apply to Windows 365 devices. Microsoft Learn.\nApplicability\nApply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization’s data-removal process as separate items in the handoff.\nDSE recommendation\nInclude an on-device association-removal task in the permanent-transfer plan. Confirm who will have authorized access to the device before it leaves organizational custody. Use Microsoft’s dedicated removal procedure for the actual device, and preserve the association identity beforehand. Do not close the handoff from an Intune inventory change alone. Coordinate the association step with, but do not substitute it for, the separately approved preservation and device-retirement requirements.\nVerification\nIn an approved transfer rehearsal, record the original association state and the documented removal result on the device. Reconcile that evidence with the intended tenant and asset identity. Verify the separate data and access-removal tasks through their own checks. If the device cannot be reached, record the association task as unresolved rather than assuming a portal action cleared the firmware marker.\nOfficial references\nMicrosoft Learn: Overview of Windows Autopilot device association.",
                "datePublished": "2026-09-10T00:29:19+00:00",
                "dateModified": "2026-09-10T00:55:35+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Clear device association on the device before it permanently leaves the tenant"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 237,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Overview of Windows Autopilot device association | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview"
                }
            }
        ]
    }
}