GuideInformationCybersecurityIT

Clear device association on the device before it permanently leaves the tenant

Can Windows Autopilot device association be removed entirely from the Intune portal?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Can Windows Autopilot device association be removed entirely from the Intune portal?

Potentially affected

Apply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization's data-removal process as separate items in the handoff.

DSE recommendation

Include an on-device association-removal task in the permanent-transfer plan.

Source facts

Windows Autopilot device association writes tenant-affinity information into a device’s UEFI after verifying its TPM-backed identity. Microsoft says removing that association from Intune is not supported. The removal operation runs on the device and deletes the UEFI marker. Its lifecycle guidance calls for removal when the device permanently leaves the tenant. Device association does not apply to Windows 365 devices. Microsoft Learn.

Applicability

Apply this check to Windows 11 devices using the device-association feature of Autopilot device preparation. Keep the firmware association, ordinary management records and the organization’s data-removal process as separate items in the handoff.

DSE recommendation

Include an on-device association-removal task in the permanent-transfer plan. Confirm who will have authorized access to the device before it leaves organizational custody. Use Microsoft’s dedicated removal procedure for the actual device, and preserve the association identity beforehand. Do not close the handoff from an Intune inventory change alone. Coordinate the association step with, but do not substitute it for, the separately approved preservation and device-retirement requirements.

Verification

In an approved transfer rehearsal, record the original association state and the documented removal result on the device. Reconcile that evidence with the intended tenant and asset identity. Verify the separate data and access-removal tasks through their own checks. If the device cannot be reached, record the association task as unresolved rather than assuming a portal action cleared the firmware marker.

Official references

Microsoft Learn: Overview of Windows Autopilot device association.

Primary reference

Review the official source

Overview of Windows Autopilot device association | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE