How to switch different tenant of the HoloLens 2 device

Damon ZHU 0 Reputation points
2026-03-06T01:51:40.4166667+00:00

My company B carved out from orgnization A, has become a new legal entity, we are currently in the new tenant B on our Azure Intune, we have created a new functional account to sign into the hololens 2 device, but it appears that the the device you are trying to sign is tenant A, so you are not allowed to do it, how to change the tenant of Hololens 2 device?

can you please share the one by one steps? thanks

Microsoft Security | Intune | Enrollment
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-06T01:51:59.38+00:00

    HoloLens 2 tenant association is controlled by two things:

    1. Windows Autopilot registration (which tenant the device is registered to)
    2. TenantLockdown CSP (whether the device is locked to Autopilot-only enrollment for that original tenant)

    Once TenantLockdown/RequireNetworkInOOBE has been set on a HoloLens 2, that setting and the original tenant association persist even after re-flashing or OS updates. To move the device from tenant A to tenant B, the device must first be fully released from tenant A and any TenantLockdown configuration must be unset there. There is no supported way to bypass this from tenant B only.

    From the provided information, only the following supported actions are documented:

    1. If TenantLockdown/RequireNetworkInOOBE was set to true in tenant A
      • OOBE will wait indefinitely for an Autopilot profile from tenant A and will block:
        • Creating a local user via runtime provisioning
        • Azure AD join via runtime provisioning
        • Selecting who owns the device in OOBE
      • To remove these restrictions, the device must:
        1. Be enrolled again in its original tenant (tenant A) using Autopilot.
        2. In Intune for tenant A, create a custom OMA-URI device configuration profile that sets ./Vendor/MSFT/TenantLockdown/RequireNetworkInOOBE to false and assign it to the device group.
        3. Ensure the profile is successfully applied to the device (verify in Intune).
        4. Once applied, the effects of TenantLockdown become inactive.
    2. How TenantLockdown is unset in Intune (must be done in the original tenant)
      • In Microsoft Intune for tenant A:
        1. Remove the HoloLens 2 from the device group that had the original TenantLockdown profile (where RequireNetworkInOOBE was set to true).
        2. Create a new custom OMA-URI device configuration profile.
          • OMA-URI: ./Vendor/MSFT/TenantLockdown/RequireNetworkInOOBE
          • Value: false
        3. Create a device group and assign this new profile to that group.
        4. Add the HoloLens 2 device to this group and trigger a sync.
        5. Verify in Intune that the configuration profile has successfully applied to the device.
      • After this, TenantLockdown is inactive and the device is no longer forced to stay with the original Autopilot tenant during OOBE.
    3. If the Autopilot profile is unassigned after TenantLockdown was set to true
      • During OOBE, the device will wait indefinitely for an Autopilot profile from the original tenant and show a blocking dialog.
      • The only documented way to remove TenantLockdown in this state is to:
        • Re-enroll the device with its original tenant using Autopilot, and
        • Then unset RequireNetworkInOOBE as described above.
    4. Moving the device to tenant B after TenantLockdown is disabled
      • Once TenantLockdown is unset (RequireNetworkInOOBE = false) and the device is no longer locked to tenant A’s Autopilot:
        • The device can be treated as a normal HoloLens 2 for enrollment into tenant B.
        • Follow the standard steps in tenant B to:
          • Register the device with Windows Autopilot in tenant B.
          • Configure Autopilot for HoloLens 2 in tenant B.
          • Enroll and manage the device via Intune in tenant B.
    5. If the device cannot be managed in tenant A anymore
      • The documentation does not provide an alternative technical path if tenant A cannot or will not:
        • Remove the device from Autopilot, and
        • Push a TenantLockdown profile with RequireNetworkInOOBE = false.
      • In such a case, the supported next step is to open a support ticket as described for Autopilot/HoloLens issues, including offline diagnostic logs captured during OOBE, so that support can assist with the device’s Autopilot and tenant lock state.

    Summary of required sequence (high level):

    1. In tenant A (original tenant):
      • Ensure the device is still registered and reachable via Intune.
      • Apply a custom OMA-URI profile to set ./Vendor/MSFT/TenantLockdown/RequireNetworkInOOBE to false.
      • Confirm the profile is successfully applied; TenantLockdown becomes inactive.
    2. After TenantLockdown is inactive:
      • Remove or delete the device from Autopilot in tenant A (per standard Autopilot device deletion guidance).
    3. In tenant B (new tenant):
      • Register the HoloLens 2 with Windows Autopilot for tenant B.
      • Configure Autopilot and Intune policies for HoloLens 2.
      • Enroll the device into tenant B using the new functional account.

    If any of these steps cannot be completed in tenant A, contact Microsoft Endpoint Manager support or HoloLens support as documented to work through the Autopilot and TenantLockdown state for the device.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.