Windows Autopilot: Checklist before rollout
With Windows Autopilot, new devices go straight from the reseller to your employees. At first startup, the employee signs in with their work account, and the device sets itself up through Intune, without any imaging by IT. For this to run smoothly, the following points should be settled in advance.
Classic Autopilot or device preparation?
Alongside classic Autopilot, there is the newer Windows Autopilot device preparation. It does not need pre-registered hardware hashes; setup is tied to the user group. Intune installs apps and scripts during the initial setup (up to 25 apps and 10 PowerShell scripts).
In return, device preparation supports only Windows 11 and Microsoft Entra join: no hybrid join, no self-deploying mode and no pre-provisioning. Both variants can run side by side in the same tenant. For new, simple environments, device preparation is often the faster route. If you need kiosk devices, pre-provisioning or hybrid join, stay with classic Autopilot.
Licenses and prerequisites
- Intune and Entra ID P1 for all users, e.g. through Microsoft 365 Business Premium, E3 or E5.
- Automatic MDM enrollment enabled in Entra ID for the right user group.
- Windows Pro, Enterprise or Education: Windows Home is not supported.
Registering devices (classic Autopilot)
- Have the reseller register new devices directly (hardware hash in your tenant).
- Capture existing devices with a PowerShell script and upload them.
- Clear group and tag logic for different device types or locations.
Key decisions
- Microsoft Entra join instead of hybrid join: For new devices, Microsoft Entra join is the recommended approach. Hybrid join is more complex and depends on your on-premises Active Directory.
- User-driven or self-deploying, e.g. for kiosk or shared devices.
- Local administrator rights for users: the default should be “no.”
Configuration in Intune
- Deployment profile and Enrollment Status Page: mark only the apps that are truly necessary as blocking; otherwise setup takes a very long time.
- Core apps packaged as Win32 apps, including detection rules and uninstall.
- Security baseline: BitLocker, Windows Hello for Business, Defender, firewall.
- Update rings or Windows Autopatch for Windows and Office updates.
Network and testing
- Microsoft endpoints reachable, with no SSL inspection on the Autopilot and Intune addresses.
- Run a pilot device through the whole process: unboxing, sign-in, apps, policies, updates.
- A short guide for employees for the first startup.