Windows Autopilot lets you ship a new laptop straight from the reseller to an employee's house. They sign in with their work account, and the device configures itself. When it's set up in the right order, it feels like magic. When it isn't, you get a device stuck at "Identifying" or an Enrollment Status Page that never finishes.
This runbook covers the setup order that works for a small business moving to cloud-only (Entra-joined) devices.
Before you start
- Licensing: each user needs Intune and Entra ID P1, both included in Microsoft 365 Business Premium.
- Windows edition: Pro, Enterprise, or Education. Home isn't supported.
- Network: devices need to reach Microsoft's Autopilot and Intune endpoints during setup. Guest Wi-Fi with a captive portal will fail.
- Work through the Autopilot pre-flight checklist first.
Classic Autopilot or device preparation?
Microsoft now has two flavors:
| Autopilot (classic) | Autopilot device preparation | |
|---|---|---|
| Device registration | Hardware hash uploaded ahead of time | Not required |
| Join types | Entra join and hybrid join | Entra join only |
| Pre-provisioning | Supported | Not supported |
| Best for | Company-owned fleets bought through a reseller | Simple rollouts, or devices you can't easily register |
For most small businesses buying new hardware, classic Autopilot with reseller registration is still the smoothest experience. The rest of this runbook follows classic Autopilot.
The setup order
1. Turn on automatic enrollment
In Intune, set MDM user scope under Windows automatic enrollment to your pilot group (or All). If this is off, devices join Entra ID but never enroll in Intune, which is a very common "why isn't anything applying?" cause.
2. Set up company branding
Autopilot's sign-in screen uses your Entra company branding. Add your logo and sign-in text. It also reassures users that the setup screen is legitimate.
3. Register devices
- New hardware: ask your reseller or OEM to register devices to your tenant at purchase. This is the best option.
- Existing hardware: collect the hardware hash with the
Get-WindowsAutopilotInfoscript and upload it:
# On the device, as administrator
Install-Script -Name Get-WindowsAutopilotInfo -Force
Get-WindowsAutopilotInfo -Online4. Create a dynamic device group
Target Autopilot profiles at a group that automatically includes every registered Autopilot device:
(device.devicePhysicalIDs -any (_ -startsWith "[ZTDid]"))5. Create the deployment profile
Choose User-driven, Microsoft Entra joined, and hide the setup screens users don't need to see. Set a device naming template here if you want consistent names.
6. Configure the Enrollment Status Page
The ESP holds the user on setup until key apps and policies are in place. The biggest mistake is making it block on everything. Block only on what a user truly needs on first sign-in: security tooling, Office, and maybe one line-of-business app.
7. Assign core policies and apps
Compliance, BitLocker, update rings, Microsoft 365 Apps, and your security baseline, all assigned to device groups so they apply during setup.
8. Pilot, then expand
Run a full reset-to-desktop test with a real user account before rolling out to anyone else, and time it. If the ESP takes more than 30–45 minutes, something is overloaded.
Quick checks when it doesn't work
- Device record: Intune -> Devices -> Windows -> Enrollment -> Devices. Does the profile status show Assigned?
- Group membership: is the device in the dynamic group? Dynamic groups can take a while to update.
- Enrollment restrictions: make sure personal-device or platform restrictions aren't blocking the device.
- ESP stuck? See Autopilot pre-provisioning and ESP stuck.