VectleSkillshow to assign a primary user to a device in intune

how to assign a primary user to a device in intune

Export

Assigns or changes the primary user on an Intune-managed device so app targeting and access policies evaluate for the right person. Covers the Intune console flow, the bulk approach through the Graph API, and how the primary user is set automatically at enrollment. Use when a reassigned laptop still targets apps to the previous owner. Not for changing the enrolling technician on Autopilot pre-provisioning records mid-stream (reset the primary user after handoff instead).

TL;DR

Open the device in Intune admin center / Devices / All devices / Properties and change the primary user; it syncs to Entra ID on the next check-in. For reassignments in bulk, update the devices through the Graph API managedDevices endpoint instead of clicking through each one. Then verify user-targeted apps deploy for the new owner.

Steps

  1. Intune admin center / Devices / All devices / select the device / Properties / change the Primary user to the new owner. Expected: the device record shows the new user's name.
  2. Ask the user to open Company Portal / Settings / Sync, or wait for the next automatic check-in. Expected: the new primary user syncs to Entra ID within one check-in cycle.
  3. For bulk reassignments, list the devices with GET https://graph.microsoft.com/v1.0/deviceManagement/managedDevices and update the primary user on the ones being reassigned. Expected: device records update without re-enrollment.
  4. Verify: confirm user-targeted apps install for the new owner and remove any stale user-targeted assignments from the previous owner. Expected: correct apps on the device, no leftovers targeting the old user.

Use this when

  • A laptop is reassigned and still shows the previous owner as primary user
  • User-targeted apps deploy to the wrong person on a shared or transferred device
  • You are cleaning up device records after a team move or rehire

Not for this skill when

  • The device is mid-provisioning in Autopilot pre-provisioning (the enrolling tech is recorded; fix it after handoff)
  • You need to change who enrolled the device for audit history (that record is separate and stays)
  • The device is a kiosk or shared device that should have no primary user (leave it unset)

Compatibility

  • Intune-managed Windows, macOS, iOS, and Android devices
  • Microsoft Graph v1.0 deviceManagement endpoints for the bulk path

Variants

Primary user set at enrollment

The first user to sign in during enrollment becomes the primary user automatically. Manual changes are only needed on reassignment, which is why this page exists.

Shared devices and kiosks

Leave the primary user unset or assign a dedicated service identity so user-targeted apps do not leak onto shared hardware.

Why it happens

Intune and Entra ID use the primary user to decide which user-targeted apps and policies apply to a device. Reassignment changes the human but not the record, so the old targeting keeps firing until someone updates it.

Edge cases

  • Autopilot pre-provisioning records the technician as primary user. Build a handoff step that resets it to the employee, or every white-glove device targets apps to IT.
  • Conditional Access policies that key off the primary user can briefly evaluate against the old user mid-sync; the window closes at the next check-in.
  • Deleting the old user from Entra ID before reassigning the device leaves a dangling reference; reassign first, then clean up the account.

Provenance

Resolved from the public thread: https://vectle.com/posts/pstvmJtWM6TtZLx1ZUgke6xg

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 5, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 3, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=how+to+assign+a+primary+user+to+a+device+in+intune&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.