how to assign a primary user to a device in intune
Assigns or changes the primary user on an Intune-managed device so app targeting and access policies evaluate for the right person. Covers the Intune console flow, the bulk approach through the Graph API, and how the primary user is set automatically at enrollment. Use when a reassigned laptop still targets apps to the previous owner. Not for changing the enrolling technician on Autopilot pre-provisioning records mid-stream (reset the primary user after handoff instead).
TL;DR
Open the device in Intune admin center / Devices / All devices / Properties and change the primary user; it syncs to Entra ID on the next check-in. For reassignments in bulk, update the devices through the Graph API managedDevices endpoint instead of clicking through each one. Then verify user-targeted apps deploy for the new owner.
Steps
- Intune admin center / Devices / All devices / select the device / Properties / change the Primary user to the new owner. Expected: the device record shows the new user's name.
- Ask the user to open Company Portal / Settings / Sync, or wait for the next automatic check-in. Expected: the new primary user syncs to Entra ID within one check-in cycle.
- For bulk reassignments, list the devices with
GET https://graph.microsoft.com/v1.0/deviceManagement/managedDevicesand update the primary user on the ones being reassigned. Expected: device records update without re-enrollment. - Verify: confirm user-targeted apps install for the new owner and remove any stale user-targeted assignments from the previous owner. Expected: correct apps on the device, no leftovers targeting the old user.
Use this when
- A laptop is reassigned and still shows the previous owner as primary user
- User-targeted apps deploy to the wrong person on a shared or transferred device
- You are cleaning up device records after a team move or rehire
Not for this skill when
- The device is mid-provisioning in Autopilot pre-provisioning (the enrolling tech is recorded; fix it after handoff)
- You need to change who enrolled the device for audit history (that record is separate and stays)
- The device is a kiosk or shared device that should have no primary user (leave it unset)
Compatibility
- Intune-managed Windows, macOS, iOS, and Android devices
- Microsoft Graph v1.0 deviceManagement endpoints for the bulk path
Variants
Primary user set at enrollment
The first user to sign in during enrollment becomes the primary user automatically. Manual changes are only needed on reassignment, which is why this page exists.
Shared devices and kiosks
Leave the primary user unset or assign a dedicated service identity so user-targeted apps do not leak onto shared hardware.
Why it happens
Intune and Entra ID use the primary user to decide which user-targeted apps and policies apply to a device. Reassignment changes the human but not the record, so the old targeting keeps firing until someone updates it.
Edge cases
- Autopilot pre-provisioning records the technician as primary user. Build a handoff step that resets it to the employee, or every white-glove device targets apps to IT.
- Conditional Access policies that key off the primary user can briefly evaluate against the old user mid-sync; the window closes at the next check-in.
- Deleting the old user from Entra ID before reassigning the device leaves a dangling reference; reassign first, then clean up the account.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstvmJtWM6TtZLx1ZUgke6xg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.