A service that simplifies device provisioning and setup for end users, enabling zero-touch deployment
It is not possible to remove a device from Windows Autopilot or disconnect it from an organization from the device itself. The Autopilot registration and assignment are controlled entirely in the organization’s tenant (Microsoft Intune / Microsoft Entra ID). As long as the device’s hardware hash remains registered there and assigned an Autopilot profile, any reset or clean installation will continue to enforce that organization’s enrollment and sign-in requirements.
Key points from the documented behavior:
- Windows Autopilot Reset and reimaging keep the device’s Microsoft Entra device membership and MDM enrollment information intact and reuse it during deployment.
- The Autopilot device record must be removed or changed in the managing tenant for the device to stop enforcing that organization’s Autopilot profile.
- For Surface devices specifically, Microsoft notes that Autopilot enrollment and deregistration are normally handled by the customer’s tenant or by the partner/CSP that manages the devices.
Because the former employer’s tenant is the only place where the Autopilot registration can be removed, and that tenant is no longer accessible, there is no supported self-service method to:
- Break the Autopilot association on the device, or
- Bypass the requirement to sign in with the work/school account configured by that tenant.
The only potential path in this situation is to open a support case with Microsoft (for example, via Surface business support if the device is a Surface purchased and managed through a CSP or business channel) and provide proof of ownership. Microsoft’s Surface/Autopilot support processes can sometimes assist with registration issues for Surface devices, but this must be handled directly with Microsoft Support and is not something that can be done locally on the device.
If Microsoft Support cannot remove the Autopilot registration from the defunct tenant, the device will continue to enforce the original organization’s Autopilot configuration and cannot be repurposed as a standalone personal device using supported tools.
References: