# Separate Windows enrollment classification from lasting Intune ownership

> Does a Windows corporate identifier permanently set the ownership shown in Intune?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:49+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Does a Windows corporate identifier permanently set the ownership shown in Intune?

## Potentially affected

Review this distinction when troubleshooting a Windows enrollment restriction or reconciling an ownership report. Confirm the documented OS-build requirements and exact enrollment route before attributing an outcome to the identifier list.

## DSE recommendation

Maintain separate acceptance fields for admission during enrollment and ownership after enrollment.

## Article

## Source facts

Windows corporate identifiers affect enrollment-time classification, not the device’s lasting ownership record. The Windows identifier combines manufacturer, model, and serial number; all three must match. For Add Work Account enrollment, a matching device can pass the corporate enrollment check but subsequently appear as personal. Deleting an enrolled device’s identifier does not change its ownership. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers).

## Applicability

Review this distinction when troubleshooting a Windows enrollment restriction or reconciling an ownership report. Confirm the documented OS-build requirements and exact enrollment route before attributing an outcome to the identifier list.

## DSE recommendation

Maintain separate acceptance fields for admission during enrollment and ownership after enrollment. Compare the submitted manufacturer, model, and serial values with the device evidence, then record which enrollment path was used. Route any requested ownership correction through an approved device-record change rather than repeatedly replacing the imported identifier.

## Verification

Test the intended enrollment route on a controlled device and capture both the restriction decision and the settled ownership property. Ask the reviewer to explain any difference using the source’s enrollment-method table. Do not treat successful CSV import as proof of either result. Retain the sanitized identifier match and final device record without placing unrelated personal inventory in the test evidence.

## Official references

[Microsoft Learn: Add corporate identifiers to Intune](https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers).

## Primary reference

- Name: Add corporate identifiers to Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-enrollment/add-corporate-identifiers
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate Windows enrollment classification from lasting Intune ownership,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-367-separate-windows-enrollment-classification-from-lasting-intune-ownership/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
