Windows AutoPilot Device Preparation Explained: What Device Association Really Adds to the OOBE Experience

22/09/2026

Over the past few years, Microsoft has invested heavily in Windows Autopilot Device Preparation, sometimes also referred to as AutoPilot V2. However, several features available in traditional Windows AutoPilot were initially missing from Device Preparation, which raised questions about how this enrollment method should be positioned.

Microsoft has recently introduced a new capability for Device Preparation: Device Association. Device Association adds more flexibility and options to Device Preparation. One capability that significantly improves the onboarding process is the Out-of-Box Experience (OOBE). This article examines Device Association from both a user and administrator perspective and explains how it transforms the Out-of-Box Experience


What does Device Association actually add?

If Device Preparation already works, where does Device Association deliver real value? The difference lies in how the device fleet is structured, governed, and controlled.

With Device Preparation, there was a simplified provisioning method in which devices that were not yet bound to the organization could be enrolled through an OOBE flow. However, the concept of a device being "bound to the organization" often caused confusion. If enrollment restrictions were not configured carefully, virtually any device used by a corporate user could potentially be enrolled

However, the concept of a device being "bound to the organization" often caused confusion. If enrollment restrictions were not configured carefully, virtually any device used by a corporate user could potentially be enrolled

Device Preparation and Device Association are not the same. Device Association is an additional capability within Device Preparation that establishes a trusted relationship between a device and the organization before enrollment starts. Once this trust is established, additional OOBE options and capabilities become available.

With Device Association, a pre-enrollment trust is established and the OOBE process can be customized.

  • Device is identified as corporate-owned
  • Device naming is available before enrollment
  • Device-targeted policies can be applied
  • Additional OOBE customization options are enabled
  • Onboarding experience is streamlined
NOTE: These options are available in the Device Preparation Policy, but will only take effect when using Device Association

User Experience with Device Association

From a user perspective, the flow changes during the Out Of the Box Experience (OOBE). Certain screens are no longer displayed in the OOBE phase because these settings can now be predefined. In addition, a device name template can be applied. Once a device is associated, it can no longer be enrolled as a personal device by the user. 

Although the provisioning process itself stays mostly the same, Device Association changes once trust is established. Instead of identifying the device during enrollment, the organization already knows the device before the user signs in. This allows for OOBE customization, device naming, device-based targeting, and stronger governance from the very beginning of the provisioning process.

OOBE options with Device Association
OOBE options with Device Association

While users enjoy fewer screens during installation with this OOBE, the real value happens behind the scenes. To fully benefit from this new OOBE flow, the device must be set up as an associated device.

Once a device is associated, it becomes visible to the organization and can take advantage of all the benefits described above. In practice, this results in a smoother experience for end users and stronger control over the entire device fleet.


The Process to Associate a Device

How can a device be made an associated device? Microsoft has documented several approaches. 

  1. Export device information from OOBE
  2. Export management logs (from Settings > Accounts or by using MdmDiagnosticsTool.exe)
  3. Collect diagnostics from Intune

I won't go into detail in these approaches, these are already provided by the community and the Microsoft Learn documentation.

To associate a device, a CSV file must be uploaded. The MDMDiagnosticTool can be used to export this information as a Device-Link CSV file. This information is displayed in the tool once the device meets the necessary requirements and the export command has been executed.

MdmDiagnoticsTool
MdmDiagnoticsTool

The Device-Link CSV must be uploaded into the Device Association node in the Intune Portal:

Device Association establishes a verifiable link between a physical device and your tenant by writing a tenant affinity marker into the device's UEFI firmware. It makes use of a physical TPM chip, therefore Virtual machines aren't supported.

From the Intune Portal, head over to:

Devices > Enrollment

Device Association overview
Device Association overview

Here we can upload the CSV file, when a wrong CSV file is used you will see an error, make sure that we you met the necessary requirements like physical TMP 2.0 chip, supported OS build and the necessary KB5120998 update. Choose the device preparation policy which this device will be using and complete the upload. The Device is now ready for enrollment.

CSV upload wizard
CSV upload wizard


Once network connectivity is available, associated devices are recognized automatically and skip some parts of the OOBE screen, also the user is informed to sign in with a Work of School account of the organization. The status of associated devices can be viewed in the Associated Devices node in the Intune portal. This section provides detailed information related to the enrollment status.

Associated Devices status page
Associated Devices status page

Final Thoughts

Windows AutoPilot Device Preparation already delivers a modern deployment experience. Device Association does not replace Device Preparation; it enhances it by establishing trust before enrollment even starts. Device Association may seem like a small feature update, but it represents a significant architectural shift. 

Traditional AutoPilot relied on hardware registration and profile assignment, while Device Association introduces a model based on TPM-backed identity and tenant affinity, moving the trust boundary closer to the device itself.

For administrators, this means greater control and more accurate targeting. For users, it enables a smoother, more personalized OOBE experience. Most importantly, it offers an early glimpse into Microsoft’s evolving vision for Windows provisioning. 

It is still challenging to position Traditional AutoPilot against Device Preparation with Device Association because the registration process is fundamentally different. Device Association is not just another new feature; it is Microsoft’s first concrete step away from the hardware hash model toward a TPM-based device identity.