Registering devices with Intune for management and policy enforcement
HoloLens 2 tenant association is controlled by two things:
- Windows Autopilot registration (which tenant the device is registered to)
- TenantLockdown CSP (whether the device is locked to Autopilot-only enrollment for that original tenant)
Once TenantLockdown/RequireNetworkInOOBE has been set on a HoloLens 2, that setting and the original tenant association persist even after re-flashing or OS updates. To move the device from tenant A to tenant B, the device must first be fully released from tenant A and any TenantLockdown configuration must be unset there. There is no supported way to bypass this from tenant B only.
From the provided information, only the following supported actions are documented:
- If TenantLockdown/RequireNetworkInOOBE was set to true in tenant A
- OOBE will wait indefinitely for an Autopilot profile from tenant A and will block:
- Creating a local user via runtime provisioning
- Azure AD join via runtime provisioning
- Selecting who owns the device in OOBE
- To remove these restrictions, the device must:
- Be enrolled again in its original tenant (tenant A) using Autopilot.
- In Intune for tenant A, create a custom OMA-URI device configuration profile that sets
./Vendor/MSFT/TenantLockdown/RequireNetworkInOOBEto false and assign it to the device group. - Ensure the profile is successfully applied to the device (verify in Intune).
- Once applied, the effects of TenantLockdown become inactive.
- OOBE will wait indefinitely for an Autopilot profile from tenant A and will block:
- How TenantLockdown is unset in Intune (must be done in the original tenant)
- In Microsoft Intune for tenant A:
- Remove the HoloLens 2 from the device group that had the original TenantLockdown profile (where
RequireNetworkInOOBEwas set to true). - Create a new custom OMA-URI device configuration profile.
- OMA-URI:
./Vendor/MSFT/TenantLockdown/RequireNetworkInOOBE - Value: false
- OMA-URI:
- Create a device group and assign this new profile to that group.
- Add the HoloLens 2 device to this group and trigger a sync.
- Verify in Intune that the configuration profile has successfully applied to the device.
- Remove the HoloLens 2 from the device group that had the original TenantLockdown profile (where
- After this, TenantLockdown is inactive and the device is no longer forced to stay with the original Autopilot tenant during OOBE.
- In Microsoft Intune for tenant A:
- If the Autopilot profile is unassigned after TenantLockdown was set to true
- During OOBE, the device will wait indefinitely for an Autopilot profile from the original tenant and show a blocking dialog.
- The only documented way to remove TenantLockdown in this state is to:
- Re-enroll the device with its original tenant using Autopilot, and
- Then unset
RequireNetworkInOOBEas described above.
- Moving the device to tenant B after TenantLockdown is disabled
- Once TenantLockdown is unset (RequireNetworkInOOBE = false) and the device is no longer locked to tenant A’s Autopilot:
- The device can be treated as a normal HoloLens 2 for enrollment into tenant B.
- Follow the standard steps in tenant B to:
- Register the device with Windows Autopilot in tenant B.
- Configure Autopilot for HoloLens 2 in tenant B.
- Enroll and manage the device via Intune in tenant B.
- Once TenantLockdown is unset (RequireNetworkInOOBE = false) and the device is no longer locked to tenant A’s Autopilot:
- If the device cannot be managed in tenant A anymore
- The documentation does not provide an alternative technical path if tenant A cannot or will not:
- Remove the device from Autopilot, and
- Push a TenantLockdown profile with
RequireNetworkInOOBE = false.
- In such a case, the supported next step is to open a support ticket as described for Autopilot/HoloLens issues, including offline diagnostic logs captured during OOBE, so that support can assist with the device’s Autopilot and tenant lock state.
- The documentation does not provide an alternative technical path if tenant A cannot or will not:
Summary of required sequence (high level):
- In tenant A (original tenant):
- Ensure the device is still registered and reachable via Intune.
- Apply a custom OMA-URI profile to set
./Vendor/MSFT/TenantLockdown/RequireNetworkInOOBEto false. - Confirm the profile is successfully applied; TenantLockdown becomes inactive.
- After TenantLockdown is inactive:
- Remove or delete the device from Autopilot in tenant A (per standard Autopilot device deletion guidance).
- In tenant B (new tenant):
- Register the HoloLens 2 with Windows Autopilot for tenant B.
- Configure Autopilot and Intune policies for HoloLens 2.
- Enroll the device into tenant B using the new functional account.
If any of these steps cannot be completed in tenant A, contact Microsoft Endpoint Manager support or HoloLens support as documented to work through the Autopilot and TenantLockdown state for the device.
References: