← Back to blog
Microsoft 365

Autopilot Device Association: cryptographically binding devices to your tenant before Intune enrollment

By Zarioh Digital Solutions5 min read
Share
Autopilot Device Association: cryptographically binding devices to your tenant before Intune enrollment

Windows Autopilot Device Preparation gained a crucial new capability in August 2026: Device Association. It binds devices to your tenant via TPM attestation before they enroll in Intune, blocking unknown devices during the out-of-box experience itself.

Enrolling a Windows device into Microsoft Intune has traditionally started only after the device was already in the end user's hands. That left a window during the out-of-box experience (OOBE) when no organisational policies were active. With Windows Autopilot Device Preparation, the successor to the classic Autopilot profile, Microsoft is addressing this pattern structurally. The newest step in that approach, Device Association, became generally available in August 2026 and adds a cryptographic verification layer that activates before a user types a single credential.

Device Association makes it possible to bind devices to your tenant via TPM attestation — Trusted Platform Module — before Intune enrollment takes place. Only once that binding is confirmed is the device allowed to complete the OOBE flow in the organisational context. Devices not on the association list are stopped before they can proceed.

What is Windows Autopilot Device Preparation?

Windows Autopilot Device Preparation (DPP) is the architectural successor to the classic Autopilot profile. Where the classic model worked with static profiles tied to hardware hashes, DPP works with preparation policies configured on the device before enrollment. This gives IT teams more control over the OOBE process and makes onboarding less dependent on the exact sequence of steps a user follows.

DPP integrates directly with Microsoft Entra ID and Intune. Devices are assigned to a DPP policy based on dynamic device groups. When a device boots for the first time and connects, Windows Autopilot checks whether it falls under a valid policy and whether the associated binding matches.

What does Device Association do exactly?

Device Association adds a verification step at the very start of the enrollment flow. When a device boots and OOBE begins, the TPM chip generates a cryptographic key unique to that specific piece of hardware. That key is sent to Microsoft's infrastructure, which checks whether this device has already been associated with your tenant in Intune.

If the association exists and matches, the device is allowed to complete OOBE as an organisational device. If not, the process stops. This prevents a device that happens to reach your network, or a device that has been swapped somewhere in the logistics chain, from simply being provisioned as an org device. TPM attestation works at the hardware level and cannot be spoofed via software.

Beyond the security benefit, Device Association offers practical advantages for onboarding. Device names can be set before enrollment based on the association. OOBE screens can be tailored based on the linked device category. And device-based policies, such as BitLocker configuration and compliance requirements, can be active before a user enters credentials.

Which problem does this solve?

In a classic Intune onboarding, a time window exists between first boot and the moment organisational policies become active. During that window, the device runs as an unmanaged consumer system. For most devices this risk is limited, but for environments with strict compliance requirements, processing industries, or organisations handling sensitive customer data, it remains a vulnerable moment.

A more concrete risk is device substitution. If a laptop is ordered, configured, and delivered via a third party and a swap occurs somewhere in that chain, classic Intune enrollment does not automatically detect this. With Device Association the binding is cryptographic: only the exact device with the correct TPM signature can complete the association. A different laptop with the same model number simply will not pass.

How do you configure Device Association?

Configuration runs entirely through the Intune admin centre and requires no additional licences beyond your existing Microsoft Intune subscription. The steps at a high level are as follows.

First, register devices in Intune using the standard approach, importing a hardware hash or via OEM direct enrolment through a manufacturer or reseller connected to the Windows Autopilot programme. From that point the device is known in your tenant.

Next, create a Windows Autopilot Device Preparation policy in the Intune admin centre under Devices > Windows > Enrolment > Autopilot Device Preparation. In this policy, enable Device Association. Assign the policy to a dynamic device group based on hardware ID or purchase group.

The feature requires a specific Windows update that rolls out with the August 2026 update cycle. Devices that have not yet received that update will go through OOBE without the association check. Make sure the update cycle is in order before actively enforcing Device Association.

For the pilot phase you can put Device Association in reporting mode. This means the association check runs and the result is logged in Intune reports, but the OOBE process is not blocked on a failed verification. This lets you see which devices would fail the check before you turn on enforcement mode.

Requirements and device compatibility

Device Association requires TPM 2.0. Virtually all Windows 11-certified devices meet this requirement because TPM 2.0 is a prerequisite for Windows 11 installation. Devices running Windows 10 or devices older than 2019 may have TPM 1.2 or no TPM at all. Those are not compatible.

Beyond the TPM requirement, the device must be able to reach the Microsoft Autopilot service on first boot. This works automatically in most network environments, but if you operate a strictly filtered network or a proxy that blocks certain endpoints, you will need to add the Autopilot service endpoints to your firewall exceptions.

What can you arrange this month?

Four concrete steps to prepare Device Association for your environment. First, check whether you are already using Windows Autopilot Device Preparation or still the classic Autopilot model. DPP and the old profiles coexist, but Device Association is only available within DPP.

Second, verify the TPM version across your current device population. Intune device inventory reports show the TPM version per device, giving you an immediate view of which devices are eligible.

Third, connect Device Association to your procurement process. Discuss with your hardware supplier or reseller whether they support OEM direct enrolment so that new devices arrive already associated with your tenant. This eliminates the manual hash import step for new purchases.

Fourth, set up a pilot group with Device Association in reporting mode. This gives you data on which devices pass the check and which do not, before you switch to enforcement mode. Want guidance on setting up Autopilot Device Preparation, migrating from classic Autopilot profiles, or linking the feature to your procurement process? Reach out to Zarioh for a focused conversation.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share