Skip to content
Intune & AutopilotChecklist

Autopilot Pre-Flight Checklist: Verify Before You Deploy

The tenant, licensing, enrollment, network, and device checks to run before your first Windows Autopilot deployment. Interactive checklist, and your progress is saved in your browser.

Autopilot failures are almost always discovered at the worst time, with a new hire watching a spinning ESP on their first morning. Every item below is something I've seen break a real deployment. Check them before the first device ships. Click an item to check it off, and your progress is saved in this browser.

Licensing and tenant

  • Every Autopilot user has Intune and Entra ID P1 licenses (both included in Microsoft 365 Business Premium)
  • Company branding is configured in Entra ID (logo, sign-in text)
  • Users are allowed to join devices to Entra ID (Entra ID -> Devices -> Device settings)
  • The maximum devices per user limit won't block new or reassigned devices
  • Users will be prompted for MFA during setup, and have already registered a method

Enrollment

  • Windows automatic enrollment MDM user scope includes your pilot users
  • Enrollment restrictions allow Windows (MDM) and don't block corporate devices
  • An Enrollment Status Page profile is assigned, and blocks only on essential apps
  • Windows Hello for Business settings are decided (enabled, PIN rules), so users aren't surprised

Devices and registration

  • Devices run Windows 10/11 Pro, Enterprise, or Education, and not Home
  • Devices are registered to your tenant by the reseller, or by hardware hash upload
  • A dynamic device group catches Autopilot devices ([ZTDid] rule)
  • The deployment profile is assigned, and the device record shows Assigned before first boot
  • For pre-provisioning: TPM 2.0 is present and firmware is up to date

Network

  • Devices can reach Microsoft's Autopilot, Intune, and Entra endpoints during OOBE
  • No captive portal or user-authenticated proxy on the setup network
  • SSL inspection is bypassed for Microsoft endpoints
  • Setup at home works too: test from a normal home internet connection

Apps and policies

  • Microsoft 365 Apps are assigned to devices, and tested
  • Required apps are packaged as Win32, not mixed with MSI line-of-business apps during the ESP
  • Compliance policies are assigned, with a sensible grace period
  • BitLocker policy will encrypt silently (BitLocker silent encryption)
  • Update rings are assigned (Windows Update rings)

The pilot

  • One full reset-to-desktop test with a real user account (not an admin)
  • The ESP finished in under 45 minutes
  • The user could open Outlook, Teams, and OneDrive without extra sign-ins
  • You wrote down the time and any issues, and fixed them before the next wave
// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.