{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/",
        "slug": "dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/"
        },
        "title": "Separate Windows enrollment classification from lasting Intune ownership",
        "summary": "Does a Windows corporate identifier permanently set the ownership shown in Intune?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:49+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 211,
        "potentially_affected": "Review this distinction when troubleshooting a Windows enrollment restriction or reconciling an ownership report. Confirm the documented OS-build requirements and exact enrollment route before attributing an outcome to the identifier list.",
        "dse_recommendation": "Maintain separate acceptance fields for admission during enrollment and ownership after enrollment.",
        "primary_source": {
            "name": "Add corporate identifiers to Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Windows corporate identifiers affect enrollment-time classification, not the device&#8217;s lasting ownership record. The Windows identifier combines manufacturer, model, and serial number; all three must match. For Add Work Account enrollment, a matching device can pass the corporate enrollment check but subsequently appear as personal. Deleting an enrolled device&#8217;s identifier does not change its ownership. <a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review this distinction when troubleshooting a Windows enrollment restriction or reconciling an ownership report. Confirm the documented OS-build requirements and exact enrollment route before attributing an outcome to the identifier list.</p>\n<h2>DSE recommendation</h2>\n<p>Maintain separate acceptance fields for admission during enrollment and ownership after enrollment. Compare the submitted manufacturer, model, and serial values with the device evidence, then record which enrollment path was used. Route any requested ownership correction through an approved device-record change rather than repeatedly replacing the imported identifier.</p>\n<h2>Verification</h2>\n<p>Test the intended enrollment route on a controlled device and capture both the restriction decision and the settled ownership property. Ask the reviewer to explain any difference using the source&#8217;s enrollment-method table. Do not treat successful CSV import as proof of either result. Retain the sanitized identifier match and final device record without placing unrelated personal inventory in the test evidence.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Add corporate identifiers to Intune</a>.</p>",
        "content_text": "Source facts\nWindows corporate identifiers affect enrollment-time classification, not the device’s lasting ownership record. The Windows identifier combines manufacturer, model, and serial number; all three must match. For Add Work Account enrollment, a matching device can pass the corporate enrollment check but subsequently appear as personal. Deleting an enrolled device’s identifier does not change its ownership. Microsoft Learn.\nApplicability\nReview this distinction when troubleshooting a Windows enrollment restriction or reconciling an ownership report. Confirm the documented OS-build requirements and exact enrollment route before attributing an outcome to the identifier list.\nDSE recommendation\nMaintain separate acceptance fields for admission during enrollment and ownership after enrollment. Compare the submitted manufacturer, model, and serial values with the device evidence, then record which enrollment path was used. Route any requested ownership correction through an approved device-record change rather than repeatedly replacing the imported identifier.\nVerification\nTest the intended enrollment route on a controlled device and capture both the restriction decision and the settled ownership property. Ask the reviewer to explain any difference using the source’s enrollment-method table. Do not treat successful CSV import as proof of either result. Retain the sanitized identifier match and final device record without placing unrelated personal inventory in the test evidence.\nOfficial references\nMicrosoft Learn: Add corporate identifiers to Intune.",
        "content_markdown": "## Source facts\n\nWindows corporate identifiers affect enrollment-time classification, not the device’s lasting ownership record. The Windows identifier combines manufacturer, model, and serial number; all three must match. For Add Work Account enrollment, a matching device can pass the corporate enrollment check but subsequently appear as personal. Deleting an enrolled device’s identifier does not change its ownership. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers).\n\n## Applicability\n\nReview this distinction when troubleshooting a Windows enrollment restriction or reconciling an ownership report. Confirm the documented OS-build requirements and exact enrollment route before attributing an outcome to the identifier list.\n\n## DSE recommendation\n\nMaintain separate acceptance fields for admission during enrollment and ownership after enrollment. Compare the submitted manufacturer, model, and serial values with the device evidence, then record which enrollment path was used. Route any requested ownership correction through an approved device-record change rather than repeatedly replacing the imported identifier.\n\n## Verification\n\nTest the intended enrollment route on a controlled device and capture both the restriction decision and the settled ownership property. Ask the reviewer to explain any difference using the source’s enrollment-method table. Do not treat successful CSV import as proof of either result. Retain the sanitized identifier match and final device record without placing unrelated personal inventory in the test evidence.\n\n## Official references\n\n[Microsoft Learn: Add corporate identifiers to Intune](https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Windows enrollment classification from lasting Intune ownership",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/",
                "headline": "Separate Windows enrollment classification from lasting Intune ownership",
                "description": "Does a Windows corporate identifier permanently set the ownership shown in Intune?",
                "abstract": "Does a Windows corporate identifier permanently set the ownership shown in Intune?",
                "articleBody": "Source facts\nWindows corporate identifiers affect enrollment-time classification, not the device’s lasting ownership record. The Windows identifier combines manufacturer, model, and serial number; all three must match. For Add Work Account enrollment, a matching device can pass the corporate enrollment check but subsequently appear as personal. Deleting an enrolled device’s identifier does not change its ownership. Microsoft Learn.\nApplicability\nReview this distinction when troubleshooting a Windows enrollment restriction or reconciling an ownership report. Confirm the documented OS-build requirements and exact enrollment route before attributing an outcome to the identifier list.\nDSE recommendation\nMaintain separate acceptance fields for admission during enrollment and ownership after enrollment. Compare the submitted manufacturer, model, and serial values with the device evidence, then record which enrollment path was used. Route any requested ownership correction through an approved device-record change rather than repeatedly replacing the imported identifier.\nVerification\nTest the intended enrollment route on a controlled device and capture both the restriction decision and the settled ownership property. Ask the reviewer to explain any difference using the source’s enrollment-method table. Do not treat successful CSV import as proof of either result. Retain the sanitized identifier match and final device record without placing unrelated personal inventory in the test evidence.\nOfficial references\nMicrosoft Learn: Add corporate identifiers to Intune.",
                "datePublished": "2026-09-10T00:25:49+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Windows enrollment classification from lasting Intune ownership"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 211,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Add corporate identifiers to Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers"
                }
            }
        ]
    }
}