Autopilot profile is not assigned if a device already registered Azure AD

Occasional Contributor

When import device information for Autopilot, if the devices already registered to Azure AD, the profile status in Windows Autopilot devices have not changed from ”Not Assigned”.


After deleting the device from both Autopilot devices and Azure AD, and import again, it has changed to ”Assigned”.


It is the same behavior at import csv file, which created by PowerShell script manually or use Autopilot profile to convert targeted devices.


Note that we had not applied Autopilot enrollment to all devices, and we use a security group referring ”ZTDId”. And a security group specified Azure AD devices for convert.


And, it seems when import csv file to Autopilot, devices register to Azure AD automatically. If we remove it from Azure AD, the device information will not re-register automatically. Or will it work with the security group of all Azure AD device?


I want to know:
1. Import Autopilot information of devices that already registered to Azure AD does it work?
2. With the security group reference ZTDId, does it work?
3. The best practice to register Autopilot information, that device already registered to Azure AD and Intune


Thank you for reading. If you know anything about it, please teach me.

11 Replies

Having the same issues here (UK) 

When importing Devices into the Autopilot, any devices using the [ZTDId] are not having profiles assigned. 


I have also noted the 'sync', is roughly instant, this is abnormal as usually, it takes a few minutes before successful sync is reported


Hi Nayuta,

This is normal behavior, if you importing the devices using csv file, you need to make sure that the devices do not exist in Azure AD at all. If you have existing devices and you want to apply Auto Enrollment Deployment Profile, you just need hit yes on ‘Convert all Targeted device to Auto Pilot’.

Hope I’m understanding your scenario correctly!




In my instance, the property 'Convert all targeted devices to Autopilot' is already configured to yes. 


However, Devices registered for autopilot are not pulling a profile. 





Could you add the PCs to regular Security group and assign them to the deployment profile? It might be the dynamic group somehow dropping the PCs.





So I have raised this as an MS Support Ticket, they have informed me that currently there is various region issues with profile deployment using Windows Auto-Enrollment. These are backend issues and are currently being resolved. 


Although I have not seen any public comms from MS for this. 

Fyi, Just tried it on my test tenant and worked fine.

Did you manage to resolve this?
I notice this is over a year old - but I am still encountering the same issue. Did anyone get a definitive fix - or is it still a known issue?
Hi scubaAI,

In my environment, it works fine.

Currently, I convert devices by autopilot profile and use groups to assign autopilot profiles. Profiles assignment needs some wait time.


@scubaAl I also still encounter the same issue. A workaround that mostly works is deleting the device from the tenant first, registering it for Autopilot (using csv or graph api), then doing a local windows reset on the device.

I think I just realized how to solve this issue.
I went to the deployment profile (with the dynamic group), click to edit the basics information, add some text there in description box and save. The deployment will reload and update devices in autopilot table. Now all are assigned. For me it worked.