Autopilot failures are almost always discovered at the worst time, with a new hire watching a spinning ESP on their first morning. Every item below is something I've seen break a real deployment. Check them before the first device ships. Click an item to check it off, and your progress is saved in this browser.
Licensing and tenant
- Every Autopilot user has Intune and Entra ID P1 licenses (both included in Microsoft 365 Business Premium)
- Company branding is configured in Entra ID (logo, sign-in text)
- Users are allowed to join devices to Entra ID (Entra ID -> Devices -> Device settings)
- The maximum devices per user limit won't block new or reassigned devices
- Users will be prompted for MFA during setup, and have already registered a method
Enrollment
- Windows automatic enrollment MDM user scope includes your pilot users
- Enrollment restrictions allow Windows (MDM) and don't block corporate devices
- An Enrollment Status Page profile is assigned, and blocks only on essential apps
- Windows Hello for Business settings are decided (enabled, PIN rules), so users aren't surprised
Devices and registration
- Devices run Windows 10/11 Pro, Enterprise, or Education, and not Home
- Devices are registered to your tenant by the reseller, or by hardware hash upload
- A dynamic device group catches Autopilot devices (
[ZTDid]rule) - The deployment profile is assigned, and the device record shows Assigned before first boot
- For pre-provisioning: TPM 2.0 is present and firmware is up to date
Network
- Devices can reach Microsoft's Autopilot, Intune, and Entra endpoints during OOBE
- No captive portal or user-authenticated proxy on the setup network
- SSL inspection is bypassed for Microsoft endpoints
- Setup at home works too: test from a normal home internet connection
Apps and policies
- Microsoft 365 Apps are assigned to devices, and tested
- Required apps are packaged as Win32, not mixed with MSI line-of-business apps during the ESP
- Compliance policies are assigned, with a sensible grace period
- BitLocker policy will encrypt silently (BitLocker silent encryption)
- Update rings are assigned (Windows Update rings)
The pilot
- One full reset-to-desktop test with a real user account (not an admin)
- The ESP finished in under 45 minutes
- The user could open Outlook, Teams, and OneDrive without extra sign-ins
- You wrote down the time and any issues, and fixed them before the next wave