Skip to content
Intune & AutopilotProject guide

Setting Up Windows Autopilot From Scratch: The Right Order

Autopilot fails when steps are done out of sequence. Licensing, enrollment, device registration, profiles, the Enrollment Status Page, and when to use Autopilot device preparation instead.

Windows Autopilot lets you ship a new laptop straight from the reseller to an employee's house. They sign in with their work account, and the device configures itself. When it's set up in the right order, it feels like magic. When it isn't, you get a device stuck at "Identifying" or an Enrollment Status Page that never finishes.

This runbook covers the setup order that works for a small business moving to cloud-only (Entra-joined) devices.

Before you start

  • Licensing: each user needs Intune and Entra ID P1, both included in Microsoft 365 Business Premium.
  • Windows edition: Pro, Enterprise, or Education. Home isn't supported.
  • Network: devices need to reach Microsoft's Autopilot and Intune endpoints during setup. Guest Wi-Fi with a captive portal will fail.
  • Work through the Autopilot pre-flight checklist first.

Classic Autopilot or device preparation?

Microsoft now has two flavors:

Autopilot (classic)Autopilot device preparation
Device registrationHardware hash uploaded ahead of timeNot required
Join typesEntra join and hybrid joinEntra join only
Pre-provisioningSupportedNot supported
Best forCompany-owned fleets bought through a resellerSimple rollouts, or devices you can't easily register

For most small businesses buying new hardware, classic Autopilot with reseller registration is still the smoothest experience. The rest of this runbook follows classic Autopilot.

The setup order

1. Turn on automatic enrollment

In Intune, set MDM user scope under Windows automatic enrollment to your pilot group (or All). If this is off, devices join Entra ID but never enroll in Intune, which is a very common "why isn't anything applying?" cause.

2. Set up company branding

Autopilot's sign-in screen uses your Entra company branding. Add your logo and sign-in text. It also reassures users that the setup screen is legitimate.

3. Register devices

  • New hardware: ask your reseller or OEM to register devices to your tenant at purchase. This is the best option.
  • Existing hardware: collect the hardware hash with the Get-WindowsAutopilotInfo script and upload it:
powershell
# On the device, as administrator
Install-Script -Name Get-WindowsAutopilotInfo -Force
Get-WindowsAutopilotInfo -Online

4. Create a dynamic device group

Target Autopilot profiles at a group that automatically includes every registered Autopilot device:

text
(device.devicePhysicalIDs -any (_ -startsWith "[ZTDid]"))

5. Create the deployment profile

Choose User-driven, Microsoft Entra joined, and hide the setup screens users don't need to see. Set a device naming template here if you want consistent names.

6. Configure the Enrollment Status Page

The ESP holds the user on setup until key apps and policies are in place. The biggest mistake is making it block on everything. Block only on what a user truly needs on first sign-in: security tooling, Office, and maybe one line-of-business app.

7. Assign core policies and apps

Compliance, BitLocker, update rings, Microsoft 365 Apps, and your security baseline, all assigned to device groups so they apply during setup.

8. Pilot, then expand

Run a full reset-to-desktop test with a real user account before rolling out to anyone else, and time it. If the ESP takes more than 30–45 minutes, something is overloaded.

Quick checks when it doesn't work

  • Device record: Intune -> Devices -> Windows -> Enrollment -> Devices. Does the profile status show Assigned?
  • Group membership: is the device in the dynamic group? Dynamic groups can take a while to update.
  • Enrollment restrictions: make sure personal-device or platform restrictions aren't blocking the device.
  • ESP stuck? See Autopilot pre-provisioning and ESP stuck.
// Newsletter

New runbooks, straight to your inbox.

One email when something worth reading ships. No spam, unsubscribe anytime.