All devices were joined to the AAD using the same account

%3CLINGO-SUB%20id%3D%22lingo-sub-1211893%22%20slang%3D%22en-US%22%3EAll%20devices%20were%20joined%20to%20the%20AAD%20using%20the%20same%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1211893%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there!%20All%20devices%20were%20joined%20to%20the%20AAD%20using%20the%20same%20account.%20Basically%20like%20a%20bulk%20enrollment%20but%20manually.%20This%20has%20the%20consequence%20that%20in%20the%20AAD%20device%20list%2C%20this%20account%20is%20owner%20of%20all%20devices%20and%20also%20listed%20in%20%22user%20name%22%20table.%20Will%20this%20have%20any%20consequences%20for%20other%20services%20or%20make%20any%20other%20services%20unusable%3F%3C%2FP%3E%3CP%3EIs%20it%20possible%20to%20reassign%20the%20device%20to%20the%20actual%20user%20so%20that%20the%20user%20appears%20as%20the%20owner%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1211893%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1211941%22%20slang%3D%22en-US%22%3ERe%3A%20All%20devices%20were%20joined%20to%20the%20AAD%20using%20the%20same%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1211941%22%20slang%3D%22en-US%22%3EThis%20has%20a%20big%20impact%20on%20Intune.%3CBR%20%2F%3EIt's%20not%20possible%20to%20change%20it%20yet%2C%20but%20it's%20currently%20in%20development%20(%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Ffundamentals%2Fin-development%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Ffundamentals%2Fin-development%3C%2FA%3E)%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1212102%22%20slang%3D%22en-US%22%3ERe%3A%20All%20devices%20were%20joined%20to%20the%20AAD%20using%20the%20same%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1212102%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3BThanks%20for%20your%20answer.%3C%2FP%3E%3CP%3EThe%20device%20owner%20is%20not%20a%20problem%3F%3CBR%20%2F%3EI%20was%20looking%20for%20more%20information%20about%20the%20role%20of%20the%20%22owner%22%20and%20the%20%22primary%20user%22%20but%20I%20haven't%20found%20anything%20useful.%20Do%20know%20perhaps%20a%20resource%20that%20explains%20the%20roles%20in%20more%20detail%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1213041%22%20slang%3D%22en-US%22%3ERe%3A%20All%20devices%20were%20joined%20to%20the%20AAD%20using%20the%20same%20account%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1213041%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F370645%22%20target%3D%22_blank%22%3E%40simmei%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3Bhas%20said%2C%20the%20biggest%20impact%20here%20is%20with%20reference%20to%20Intune.%20The%20Primary%20User%20is%20used%20to%20associate%20a%20device%20with%20a%20user%20in%20the%20company%20portal%20app%20to%20support%20actions%20such%20as%20PIN%20reset%2C%20device%20reset%20etc.%20It's%20also%20associated%20with%20the%20device%20in%20the%20AAD%20%2F%20Intune%20portals%20to%20support%20device%20identification%20based%20on%20username%20-%20so%20there's%20an%20operational%20constraint%20in%20terms%20of%20how%20easily%20you%20can%20identify%20devices%20when%20troubleshooting%20for%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESee%20here%20for%20more%20information%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fintune-customer-success%2Fsupport-tip-how-user-device-affinity-works-in-intune%2Fba-p%2F708196%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fintune-customer-success%2Fsupport-tip-how-user-device-affinity-works-in-intune%2Fba-p%2F708196%3C%2FA%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20ability%20to%20change%20the%20primary%20user%20is%20rolling%20out%20at%20the%20moment%20-%20a%20number%20of%20tenants%20have%20had%20this%20feature%20added%20in%20recent%20weeks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKelvin%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi there! All devices were joined to the AAD using the same account. Basically like a bulk enrollment but manually. This has the consequence that in the AAD device list, this account is owner of all devices and also listed in "user name" table. Will this have any consequences for other services or make any other services unusable?

Is it possible to reassign the device to the actual user so that the user appears as the owner?

4 Replies
This has a big impact on Intune.
It's not possible to change it yet, but it's currently in development (https://docs.microsoft.com/en-us/intune/fundamentals/in-development)

@Thijs Lecomte Thanks for your answer.

The device owner is not a problem?
I was looking for more information about the role of the "owner" and the "primary user" but I haven't found anything useful. Do know perhaps a resource that explains the roles in more detail?

@simmei,

 

As @Thijs Lecomte has said, the biggest impact here is with reference to Intune. The Primary User is used to associate a device with a user in the company portal app to support actions such as PIN reset, device reset etc. It's also associated with the device in the AAD / Intune portals to support device identification based on username - so there's an operational constraint in terms of how easily you can identify devices when troubleshooting for users.

 

See here for more information: https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-how-user-device-affinity-....

 

The ability to change the primary user is in active development - it was made available in a number of tenants recently, but subsequently revoked. Keep your eyes peeled...!

 

Kelvin

 

[Edited to clarify status of Primary User change deployment]

@Kelvin Papp 

Thank you for your time.


The planned functionality to change the primary user will be available in Intune. This would mean that the devices must first be enrolled in Intune before the primary user can be changed. Enrolling the devices in the current configuration (all with the same primary user) in Intune is not a problem?