# Clear device association on the device before it permanently leaves the tenant

> Can Windows Autopilot device association be removed entirely from the Intune portal?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:19+00:00
- Modified: 2026-09-10T00:55:35+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Can Windows Autopilot device association be removed entirely from the Intune portal?

## Potentially affected

Apply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization's data-removal process as separate items in the handoff.

## DSE recommendation

Include an on-device association-removal task in the permanent-transfer plan.

## Article

## Source facts

Windows Autopilot device association writes tenant-affinity information into a device’s UEFI after verifying its TPM-backed identity. Microsoft says removing that association from Intune is not supported. The removal operation runs on the device and deletes the UEFI marker. Its lifecycle guidance calls for removal when the device permanently leaves the tenant. Device association does not apply to Windows 365 devices. [Microsoft Learn](https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview).

## Applicability

Apply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization’s data-removal process as separate items in the handoff.

## DSE recommendation

Include an on-device association-removal task in the permanent-transfer plan. Confirm who will have authorized access to the device before it leaves organizational custody. Use Microsoft’s dedicated removal procedure for the actual device, and preserve the association identity beforehand. Do not close the handoff from an Intune inventory change alone. Coordinate the association step with, but do not substitute it for, the separately approved preservation and device-retirement requirements.

## Verification

In an approved transfer rehearsal, record the original association state and the documented removal result on the device. Reconcile that evidence with the intended tenant and asset identity. Verify the separate data and access-removal tasks through their own checks. If the device cannot be reached, record the association task as unresolved rather than assuming a portal action cleared the firmware marker.

## Official references

[Microsoft Learn: Overview of Windows Autopilot device association](https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview).

## Primary reference

- Name: Overview of Windows Autopilot device association | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/autopilot/device-preparation/device-association/overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Clear device association on the device before it permanently leaves the tenant,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-157-clear-device-association-on-the-device-before-it-permanently-leaves-the-tenant/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
