To roll out new Windows laptops with zero touch, register each device's hardware hash with Windows Autopilot (ideally through the OEM or reseller), put the registered devices in a dynamic Microsoft Entra group, assign that group a user-driven Microsoft Entra join deployment profile and an Enrollment Status Page, and target your required apps and policies at the same group. When the user unboxes the laptop and signs in with their work account, Windows joins Microsoft Entra ID, enrolls in Intune and installs everything before the desktop appears. The tenant-side prerequisites are automatic MDM enrollment, permission for users to join devices, and an Intune license on each user.
Who this is for and what you will have
This guide is for Intune administrators moving new Windows 11 laptops to cloud-native management. It covers the classic Windows Autopilot user-driven flow with Microsoft Entra join, which Microsoft recommends over hybrid join for new devices. At the end you will have:
- Automatic enrollment and device join settings ready for Autopilot.
- A registration process for new hardware and a CSV method for test devices.
- A dynamic device group, an Enrollment Status Page (ESP) profile and a deployment profile assigned to it.
- A tested deployment, a way to monitor it, and fixes for the errors you are most likely to meet.
Windows Autopilot or Autopilot device preparation
Microsoft now offers two provisioning experiences. Pick one per device population before you build anything.
| Windows Autopilot | Windows Autopilot device preparation | |
|---|---|---|
| Device registration | Required (hardware hash) | Not required |
| Supported Windows | Supported Windows 10 and Windows 11 editions | Windows 11 22H2 or 23H2 with KB5035942 or later, or 24H2 and later |
| Join types | Microsoft Entra join, hybrid join | Microsoft Entra join only |
| Group membership | Dynamic group on Autopilot attributes | Enrollment time grouping into a static device group |
| Setup progress | Enrollment Status Page | Its own OOBE progress page; ESP not used |
| Mixing LOB and Win32 apps | Not supported during ESP | Supported |
This guide uses classic Autopilot because it supports pre-provisioning, self-deploying mode and Windows 10, and because most new hardware can arrive registered by the reseller.
Prerequisites
- Licensing: Microsoft Entra ID P1 or P2 and Intune for every user who enrolls a device. Microsoft 365 Business Premium, Microsoft 365 E3 or E5, EMS E3 or E5, Microsoft 365 F1 or F3, and the A1, A3 and A5 academic plans all qualify. The license must be assigned to the user, not just purchased.
- Windows: a supported version of Windows 11 Pro, Pro Education, Pro for Workstations, Enterprise, Education or Enterprise LTSC (or the equivalent Windows 10 editions). Windows Home isn't supported.
- Roles: Intune Administrator or Policy and Profile Manager for registration and profiles. A custom Intune role works if it has all Enrollment programs permissions except the four token management options.
- Network: DNS resolution of internet names, and HTTP (80), HTTPS (443) and NTP (UDP 123) to the internet. The device must reach
ztd.dds.microsoft.com,login.live.com,time.windows.com, the Microsoft Entra ID and Intune endpoints, and*.msftconnecttest.comover HTTP so Windows detects internet access. Configure proxies on the proxy server, not through Intune policy.
Step 1: Turn on automatic MDM enrollment
Autopilot relies on the Microsoft Entra join triggering Intune enrollment.
- In the Azure portal, open Microsoft Entra ID.
- Under Manage, select Mobility (MDM and WIP), then Microsoft Intune.
- Set MDM user scope to All, or to Some and select the user groups that will enroll devices.
- Select Save.
Also check Devices > Windows > Device onboarding > Enrollment > Device platform restriction in the Intune admin center: if a restriction sets Windows (MDM) to Block for your users, Autopilot enrollment fails.
Step 2: Allow users to join devices
In the Azure portal, open Microsoft Entra ID > Devices > Device settings and set Users may join devices to Microsoft Entra to All or Selected. If you choose Selected, add the user groups that will receive laptops. The per-user device limit defaults to 50; users who exceed it get join errors.
Optionally configure company branding in Microsoft Entra ID. The square logo, sign-in page text and tenant name appear on the Autopilot sign-in page, and branding is required if you want to hide the change account options.
Step 3: Register the devices
Registration associates each device's hardware hash with your tenant. When a device is registered, a Microsoft Entra device object is created automatically; don't delete it, because Autopilot uses it for group membership and profile targeting.
Through your OEM or reseller
For production hardware, ask the OEM, reseller or distributor to register devices to your tenant at purchase through Microsoft Partner Center. Microsoft recommends this over uploading hashes yourself, because 4K hardware hashes contain sensitive information that only device owners should hold. Ask the reseller to set a group tag if you want to separate device types.
Manually, for test or existing devices
On a device that has already been through setup, collect the hash from an elevated PowerShell prompt:
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory -Path "C:\HWID"
Set-Location -Path "C:\HWID"
$env:Path += ";C:\Program Files\WindowsPowerShell\Scripts"
Set-ExecutionPolicy -Scope Process -ExecutionPolicy RemoteSigned
Install-Script -Name Get-WindowsAutopilotInfo
Get-WindowsAutopilotInfo -OutputFile AutopilotHWID.csvOn a device sitting at the out-of-box experience, press Shift+F10, run powershell.exe, then upload directly to Intune. You sign in as at least an Intune Administrator, and the first run asks you to approve the script's app permissions:
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Set-ExecutionPolicy -Scope Process -ExecutionPolicy RemoteSigned
Install-Script -Name Get-WindowsAutopilotInfo -Force
Get-WindowsAutopilotInfo -OnlineOn Windows 11 you can also press Ctrl+Shift+D during OOBE to open the diagnostics page and export logs, including a CSV with the hash, to a USB drive.
To import a combined file, build it in a plain-text editor, not Excel, which produces a file Intune can't import. Up to 500 rows per file, ANSI encoding, no quotation marks, no extra columns, and case-sensitive headers:
Device Serial Number,Windows Product ID,Hardware Hash,Group Tag,Assigned User
<serialNumber>,<ProductID>,<hardwareHash>,<optionalGroupTag>,<optionalAssignedUser>In the Intune admin center, go to Devices > Windows > Device onboarding > Enrollment > Windows Autopilot > Devices, select Import, choose the file and select Import. When it finishes, select Sync and then Refresh until the devices appear. Confirm one batch has registered before importing the next.
Step 4: Create the Autopilot device group
In the Intune admin center, select Groups > New group and set Group type to Security and Membership type to Dynamic Device. Add a dynamic query. To include every Autopilot device:
(device.devicePhysicalIDs -any (_ -startsWith "[ZTDid]"))To include only devices with a specific group tag (Intune's group tag maps to the OrderID attribute):
(device.devicePhysicalIds -any (_ -eq "[OrderID]:Sales-Laptops"))Build these groups only on Autopilot attributes. Rules on other device attributes don't guarantee membership before provisioning starts, so the device might miss its configuration during OOBE.
Step 5: Configure the Enrollment Status Page
The ESP keeps the user on a progress screen until required apps and policies are installed. In the Intune admin center, go to Devices > Device onboarding > Enrollment, and on the Windows tab under Windows Autopilot select Enrollment Status Page. Select Create and use these settings as a starting point:
| Setting | Suggested value | Why |
|---|---|---|
| Show app and profile configuration progress | Yes | Enables the ESP and the settings below |
| Show an error when installation takes longer than specified number of minutes | 60 (default), raise if your app set is large | The timeout covers the whole phase |
| Turn on log collection and diagnostics page for end users | Yes | Gives users a log export button and the Windows 11 diagnostics page |
| Only show page to devices provisioned by OOBE | Yes | Later users on a shared device don't sit through the ESP |
| Install Windows quality updates (might restart the device) | Yes on Windows 11, if you accept 20 to 40 extra minutes | Installs the monthly security update during OOBE |
| Block device use until all apps and profiles are installed | Yes | Users can't reach the desktop half-configured |
| Allow users to reset device if installation error occurs | Yes | Lets users retry without calling IT |
| Allow users to use device if installation error occurs | Your choice | Yes trades completeness for availability |
| Block device use until these required apps are installed | Selected | Pick only the apps a user needs on day one |
Assign the profile to the Autopilot device group. You can select up to 100 blocking apps. Profile priority matters if you have several: the highest-priority profile assigned to the device wins, then the highest assigned to the user, then the default profile.
Step 6: Create the deployment profile
Go to Devices > Windows > Device onboarding > Enrollment > Windows Autopilot > Deployment Profiles and select Create Profile > Windows PC.
- Basics: name the profile. Leave Convert all targeted devices to Autopilot at No unless you want existing corporate devices in the assigned groups registered automatically; registration done this way takes up to 48 hours and isn't undone by turning the setting off.
- Deployment mode: User-driven.
- Join to Microsoft Entra ID as: Microsoft Entra joined.
- Microsoft Software License Terms and Privacy settings: hide them. Hiding privacy settings turns location services off by default, so enable them by policy if you need them.
- Hide change account options: Hide (requires company branding).
- User account type: Standard.
- Allow pre-provisioned deployment: Yes if a technician or reseller will pre-stage devices.
- Language (Region) and Automatically configure keyboard: set these only if devices use Ethernet during OOBE; Wi-Fi requires the user to pick language and keyboard first.
- Apply device name template: for example
CTS-%RAND:6%, or a short prefix with%SERIAL%. Names must be 15 characters or less, can contain letters, numbers and hyphens, and can't be all numbers.%RAND:x%adds x random digits instead.
On Assignments, select the Autopilot device group. Don't combine an All Devices assignment with exclusions; Microsoft notes this can break assignment and force you to upload hashes again. If a device falls into several profiles, it gets the oldest one.
Step 7: Assign apps and policies to the device group
Target required apps, compliance policies, configuration profiles and update rings at the same device group so they're present when the ESP starts. Keep two rules in mind:
- Don't mix line-of-business (MSI) apps and Win32 apps during the ESP. Both use TrustedInstaller, which allows one installation at a time.
- Deploy Microsoft 365 Apps as a Win32 app rather than the built-in Microsoft 365 Apps app type, which can hang the ESP when it overlaps with another Win32 installation.
Policies that force a reboot during device setup, such as AppLocker or some DeviceLock password settings, can break autologon; test them carefully. Device compliance then becomes the basis for Conditional Access, which is the device half of a Zero Trust access architecture.
Step 8: Confirm assignment and deploy a test device
Before you hand out hardware, open Windows Autopilot devices and check that the device's Profile Status has moved from Unassigned through Assigning to Assigned, and that Date assigned is filled in on the device's properties. Assignment time varies with group evaluation and the Autopilot service; don't deploy until it shows.
Then deploy a test device: power it on, connect to the network, and sign in at the branded page with a licensed test user. The device joins Microsoft Entra ID, enrolls in Intune, runs the ESP device setup phase, signs the user in and runs the account setup phase. If the device was already at OOBE when you assigned the profile, it may have cached an empty profile; press Shift+F10 and run shutdown.exe /r /t 0 to restart and download it again.
Verification
- Devices > Monitor > Windows Autopilot deployment status shows each deployment that triggered a new Intune enrollment, kept for 30 days.
- On the device, Event Viewer under Application and Services Logs > Microsoft > Windows > ModernDeployment-Diagnostics-Provider > Autopilot shows event 153 (profile state changed to available) and 161 (profile downloaded).
- The registry key
HKLM\SOFTWARE\Microsoft\Provisioning\Diagnostics\AutopilotshowsCloudAssignedTenantDomainset to your tenant andTenantMatchedset to1. - The device appears under Windows devices in Intune with the expected name, and its join type in Microsoft Entra ID is Microsoft Entra joined.
Troubleshooting
Device goes through consumer OOBE with no company sign-in page. No profile was downloaded. Event 807 ZtdDeviceIsNotRegistered means the hash isn't registered; event 815 ZtdDeviceHasNoAssignedProfile means no profile is assigned and there's no default. Fix registration or assignment, then restart from Shift+F10. A value of 1 for IsAutopilotDisabled in the registry key above can also mean the network blocked the download.
0x80180014 when redeploying a device. Either the device was previously deployed with self-deploying or pre-provisioning mode (select the device in Windows Autopilot devices and choose Unblock device), or a device platform restriction blocks Windows (MDM).
80180018 on a "Something went wrong" page. Usually a missing license or a user over their device enrollment limit.
"Can't connect to the URL of your organization's MDM terms of use." The user signing in has no Intune, EMS or Microsoft 365 license that includes Intune.
ESP fails with "Another installation is in progress, please try again later." An LOB MSI and a Win32 app tried to install at once. Repackage the LOB app as Win32. Teams installed through Microsoft 365 Apps can trigger the same conflict.
ESP sits at "Identifying" indefinitely. The user signing in doesn't have an Intune license, so Intune can't calculate the apps and policies to track.
CSV import errors. ZtdDeviceAssignedToAnotherTenant means another tenant owns the device and it must be deregistered there first. ZtdDeviceAlreadyAssigned and ZtdDeviceDuplicated mean the device is already registered or appears twice in the file. InvalidZtdHardwareHash means fields are missing; check Get-CimInstance Win32_BaseBoard | Select-Object Manufacturer, SerialNumber. If Import does nothing at all, the hash usually needs Base64 padding; Microsoft's troubleshooting FAQ shows how to test it.
Device shows as "Microsoft Entra registered" instead of joined. It was workplace-joined before Autopilot. Delete the device from Intune, Autopilot and Microsoft Entra ID, register it again and redeploy.
Retiring or reassigning devices
When a device leaves the organization, delete it from Intune first, then delete it from Windows Autopilot devices (unassign the user first if that option is available). For Microsoft Entra joined devices, don't delete the Microsoft Entra object by hand; removing records out of order can leave devices orphaned.
Closing checklist
- Users licensed for Entra ID P1 and Intune; MDM user scope and device join settings cover them.
- Windows (MDM) allowed in device platform restrictions; required endpoints reachable.
- Production devices registered by the OEM or reseller, with group tags where needed.
- Dynamic device group on
ZTDidorOrderID; ESP and user-driven Entra join profile assigned to it. - Required apps packaged as Win32 and assigned to the device group; reboot-heavy policies tested.
- Test device shows Assigned with a Date assigned, completes OOBE and appears in the deployment status report.
- Deregistration procedure documented for repairs and disposals.
References
- Windows Autopilot requirements
- Set up Windows automatic Intune enrollment
- Allow users to join devices to Microsoft Entra ID
- Windows Autopilot registration overview
- Manually register devices with Windows Autopilot
- Create device groups for Windows Autopilot
- Set up the Enrollment Status Page
- Configure Windows Autopilot profiles
- Overview of Windows Autopilot device preparation
- Windows Autopilot troubleshooting FAQ