Cloud & infrastructure

Windows Autopilot with Intune: zero-touch laptop deployment end to end

Set up Windows Autopilot user-driven Microsoft Entra join with Intune: automatic enrollment, device registration, groups, Enrollment Status Page, deployment profile, testing and common errors.

13 min read
On this page

To roll out new Windows laptops with zero touch, register each device's hardware hash with Windows Autopilot (ideally through the OEM or reseller), put the registered devices in a dynamic Microsoft Entra group, assign that group a user-driven Microsoft Entra join deployment profile and an Enrollment Status Page, and target your required apps and policies at the same group. When the user unboxes the laptop and signs in with their work account, Windows joins Microsoft Entra ID, enrolls in Intune and installs everything before the desktop appears. The tenant-side prerequisites are automatic MDM enrollment, permission for users to join devices, and an Intune license on each user.

Who this is for and what you will have

This guide is for Intune administrators moving new Windows 11 laptops to cloud-native management. It covers the classic Windows Autopilot user-driven flow with Microsoft Entra join, which Microsoft recommends over hybrid join for new devices. At the end you will have:

  • Automatic enrollment and device join settings ready for Autopilot.
  • A registration process for new hardware and a CSV method for test devices.
  • A dynamic device group, an Enrollment Status Page (ESP) profile and a deployment profile assigned to it.
  • A tested deployment, a way to monitor it, and fixes for the errors you are most likely to meet.

Windows Autopilot or Autopilot device preparation

Microsoft now offers two provisioning experiences. Pick one per device population before you build anything.

Windows AutopilotWindows Autopilot device preparation
Device registrationRequired (hardware hash)Not required
Supported WindowsSupported Windows 10 and Windows 11 editionsWindows 11 22H2 or 23H2 with KB5035942 or later, or 24H2 and later
Join typesMicrosoft Entra join, hybrid joinMicrosoft Entra join only
Group membershipDynamic group on Autopilot attributesEnrollment time grouping into a static device group
Setup progressEnrollment Status PageIts own OOBE progress page; ESP not used
Mixing LOB and Win32 appsNot supported during ESPSupported

This guide uses classic Autopilot because it supports pre-provisioning, self-deploying mode and Windows 10, and because most new hardware can arrive registered by the reseller.

Prerequisites

  • Licensing: Microsoft Entra ID P1 or P2 and Intune for every user who enrolls a device. Microsoft 365 Business Premium, Microsoft 365 E3 or E5, EMS E3 or E5, Microsoft 365 F1 or F3, and the A1, A3 and A5 academic plans all qualify. The license must be assigned to the user, not just purchased.
  • Windows: a supported version of Windows 11 Pro, Pro Education, Pro for Workstations, Enterprise, Education or Enterprise LTSC (or the equivalent Windows 10 editions). Windows Home isn't supported.
  • Roles: Intune Administrator or Policy and Profile Manager for registration and profiles. A custom Intune role works if it has all Enrollment programs permissions except the four token management options.
  • Network: DNS resolution of internet names, and HTTP (80), HTTPS (443) and NTP (UDP 123) to the internet. The device must reach ztd.dds.microsoft.com, login.live.com, time.windows.com, the Microsoft Entra ID and Intune endpoints, and *.msftconnecttest.com over HTTP so Windows detects internet access. Configure proxies on the proxy server, not through Intune policy.

Step 1: Turn on automatic MDM enrollment

Autopilot relies on the Microsoft Entra join triggering Intune enrollment.

  1. In the Azure portal, open Microsoft Entra ID.
  2. Under Manage, select Mobility (MDM and WIP), then Microsoft Intune.
  3. Set MDM user scope to All, or to Some and select the user groups that will enroll devices.
  4. Select Save.

Also check Devices > Windows > Device onboarding > Enrollment > Device platform restriction in the Intune admin center: if a restriction sets Windows (MDM) to Block for your users, Autopilot enrollment fails.

Step 2: Allow users to join devices

In the Azure portal, open Microsoft Entra ID > Devices > Device settings and set Users may join devices to Microsoft Entra to All or Selected. If you choose Selected, add the user groups that will receive laptops. The per-user device limit defaults to 50; users who exceed it get join errors.

Optionally configure company branding in Microsoft Entra ID. The square logo, sign-in page text and tenant name appear on the Autopilot sign-in page, and branding is required if you want to hide the change account options.

Step 3: Register the devices

Registration associates each device's hardware hash with your tenant. When a device is registered, a Microsoft Entra device object is created automatically; don't delete it, because Autopilot uses it for group membership and profile targeting.

Through your OEM or reseller

For production hardware, ask the OEM, reseller or distributor to register devices to your tenant at purchase through Microsoft Partner Center. Microsoft recommends this over uploading hashes yourself, because 4K hardware hashes contain sensitive information that only device owners should hold. Ask the reseller to set a group tag if you want to separate device types.

Manually, for test or existing devices

On a device that has already been through setup, collect the hash from an elevated PowerShell prompt:

[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory -Path "C:\HWID"
Set-Location -Path "C:\HWID"
$env:Path += ";C:\Program Files\WindowsPowerShell\Scripts"
Set-ExecutionPolicy -Scope Process -ExecutionPolicy RemoteSigned
Install-Script -Name Get-WindowsAutopilotInfo
Get-WindowsAutopilotInfo -OutputFile AutopilotHWID.csv

On a device sitting at the out-of-box experience, press Shift+F10, run powershell.exe, then upload directly to Intune. You sign in as at least an Intune Administrator, and the first run asks you to approve the script's app permissions:

[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Set-ExecutionPolicy -Scope Process -ExecutionPolicy RemoteSigned
Install-Script -Name Get-WindowsAutopilotInfo -Force
Get-WindowsAutopilotInfo -Online

On Windows 11 you can also press Ctrl+Shift+D during OOBE to open the diagnostics page and export logs, including a CSV with the hash, to a USB drive.

To import a combined file, build it in a plain-text editor, not Excel, which produces a file Intune can't import. Up to 500 rows per file, ANSI encoding, no quotation marks, no extra columns, and case-sensitive headers:

Device Serial Number,Windows Product ID,Hardware Hash,Group Tag,Assigned User
<serialNumber>,<ProductID>,<hardwareHash>,<optionalGroupTag>,<optionalAssignedUser>

In the Intune admin center, go to Devices > Windows > Device onboarding > Enrollment > Windows Autopilot > Devices, select Import, choose the file and select Import. When it finishes, select Sync and then Refresh until the devices appear. Confirm one batch has registered before importing the next.

Step 4: Create the Autopilot device group

In the Intune admin center, select Groups > New group and set Group type to Security and Membership type to Dynamic Device. Add a dynamic query. To include every Autopilot device:

(device.devicePhysicalIDs -any (_ -startsWith "[ZTDid]"))

To include only devices with a specific group tag (Intune's group tag maps to the OrderID attribute):

(device.devicePhysicalIds -any (_ -eq "[OrderID]:Sales-Laptops"))

Build these groups only on Autopilot attributes. Rules on other device attributes don't guarantee membership before provisioning starts, so the device might miss its configuration during OOBE.

Step 5: Configure the Enrollment Status Page

The ESP keeps the user on a progress screen until required apps and policies are installed. In the Intune admin center, go to Devices > Device onboarding > Enrollment, and on the Windows tab under Windows Autopilot select Enrollment Status Page. Select Create and use these settings as a starting point:

SettingSuggested valueWhy
Show app and profile configuration progressYesEnables the ESP and the settings below
Show an error when installation takes longer than specified number of minutes60 (default), raise if your app set is largeThe timeout covers the whole phase
Turn on log collection and diagnostics page for end usersYesGives users a log export button and the Windows 11 diagnostics page
Only show page to devices provisioned by OOBEYesLater users on a shared device don't sit through the ESP
Install Windows quality updates (might restart the device)Yes on Windows 11, if you accept 20 to 40 extra minutesInstalls the monthly security update during OOBE
Block device use until all apps and profiles are installedYesUsers can't reach the desktop half-configured
Allow users to reset device if installation error occursYesLets users retry without calling IT
Allow users to use device if installation error occursYour choiceYes trades completeness for availability
Block device use until these required apps are installedSelectedPick only the apps a user needs on day one

Assign the profile to the Autopilot device group. You can select up to 100 blocking apps. Profile priority matters if you have several: the highest-priority profile assigned to the device wins, then the highest assigned to the user, then the default profile.

Step 6: Create the deployment profile

Go to Devices > Windows > Device onboarding > Enrollment > Windows Autopilot > Deployment Profiles and select Create Profile > Windows PC.

  • Basics: name the profile. Leave Convert all targeted devices to Autopilot at No unless you want existing corporate devices in the assigned groups registered automatically; registration done this way takes up to 48 hours and isn't undone by turning the setting off.
  • Deployment mode: User-driven.
  • Join to Microsoft Entra ID as: Microsoft Entra joined.
  • Microsoft Software License Terms and Privacy settings: hide them. Hiding privacy settings turns location services off by default, so enable them by policy if you need them.
  • Hide change account options: Hide (requires company branding).
  • User account type: Standard.
  • Allow pre-provisioned deployment: Yes if a technician or reseller will pre-stage devices.
  • Language (Region) and Automatically configure keyboard: set these only if devices use Ethernet during OOBE; Wi-Fi requires the user to pick language and keyboard first.
  • Apply device name template: for example CTS-%RAND:6%, or a short prefix with %SERIAL%. Names must be 15 characters or less, can contain letters, numbers and hyphens, and can't be all numbers. %RAND:x% adds x random digits instead.

On Assignments, select the Autopilot device group. Don't combine an All Devices assignment with exclusions; Microsoft notes this can break assignment and force you to upload hashes again. If a device falls into several profiles, it gets the oldest one.

Step 7: Assign apps and policies to the device group

Target required apps, compliance policies, configuration profiles and update rings at the same device group so they're present when the ESP starts. Keep two rules in mind:

  • Don't mix line-of-business (MSI) apps and Win32 apps during the ESP. Both use TrustedInstaller, which allows one installation at a time.
  • Deploy Microsoft 365 Apps as a Win32 app rather than the built-in Microsoft 365 Apps app type, which can hang the ESP when it overlaps with another Win32 installation.

Policies that force a reboot during device setup, such as AppLocker or some DeviceLock password settings, can break autologon; test them carefully. Device compliance then becomes the basis for Conditional Access, which is the device half of a Zero Trust access architecture.

Step 8: Confirm assignment and deploy a test device

Before you hand out hardware, open Windows Autopilot devices and check that the device's Profile Status has moved from Unassigned through Assigning to Assigned, and that Date assigned is filled in on the device's properties. Assignment time varies with group evaluation and the Autopilot service; don't deploy until it shows.

Then deploy a test device: power it on, connect to the network, and sign in at the branded page with a licensed test user. The device joins Microsoft Entra ID, enrolls in Intune, runs the ESP device setup phase, signs the user in and runs the account setup phase. If the device was already at OOBE when you assigned the profile, it may have cached an empty profile; press Shift+F10 and run shutdown.exe /r /t 0 to restart and download it again.

Verification

  • Devices > Monitor > Windows Autopilot deployment status shows each deployment that triggered a new Intune enrollment, kept for 30 days.
  • On the device, Event Viewer under Application and Services Logs > Microsoft > Windows > ModernDeployment-Diagnostics-Provider > Autopilot shows event 153 (profile state changed to available) and 161 (profile downloaded).
  • The registry key HKLM\SOFTWARE\Microsoft\Provisioning\Diagnostics\Autopilot shows CloudAssignedTenantDomain set to your tenant and TenantMatched set to 1.
  • The device appears under Windows devices in Intune with the expected name, and its join type in Microsoft Entra ID is Microsoft Entra joined.

Troubleshooting

Device goes through consumer OOBE with no company sign-in page. No profile was downloaded. Event 807 ZtdDeviceIsNotRegistered means the hash isn't registered; event 815 ZtdDeviceHasNoAssignedProfile means no profile is assigned and there's no default. Fix registration or assignment, then restart from Shift+F10. A value of 1 for IsAutopilotDisabled in the registry key above can also mean the network blocked the download.

0x80180014 when redeploying a device. Either the device was previously deployed with self-deploying or pre-provisioning mode (select the device in Windows Autopilot devices and choose Unblock device), or a device platform restriction blocks Windows (MDM).

80180018 on a "Something went wrong" page. Usually a missing license or a user over their device enrollment limit.

"Can't connect to the URL of your organization's MDM terms of use." The user signing in has no Intune, EMS or Microsoft 365 license that includes Intune.

ESP fails with "Another installation is in progress, please try again later." An LOB MSI and a Win32 app tried to install at once. Repackage the LOB app as Win32. Teams installed through Microsoft 365 Apps can trigger the same conflict.

ESP sits at "Identifying" indefinitely. The user signing in doesn't have an Intune license, so Intune can't calculate the apps and policies to track.

CSV import errors. ZtdDeviceAssignedToAnotherTenant means another tenant owns the device and it must be deregistered there first. ZtdDeviceAlreadyAssigned and ZtdDeviceDuplicated mean the device is already registered or appears twice in the file. InvalidZtdHardwareHash means fields are missing; check Get-CimInstance Win32_BaseBoard | Select-Object Manufacturer, SerialNumber. If Import does nothing at all, the hash usually needs Base64 padding; Microsoft's troubleshooting FAQ shows how to test it.

Device shows as "Microsoft Entra registered" instead of joined. It was workplace-joined before Autopilot. Delete the device from Intune, Autopilot and Microsoft Entra ID, register it again and redeploy.

Retiring or reassigning devices

When a device leaves the organization, delete it from Intune first, then delete it from Windows Autopilot devices (unassign the user first if that option is available). For Microsoft Entra joined devices, don't delete the Microsoft Entra object by hand; removing records out of order can leave devices orphaned.

Closing checklist

  • Users licensed for Entra ID P1 and Intune; MDM user scope and device join settings cover them.
  • Windows (MDM) allowed in device platform restrictions; required endpoints reachable.
  • Production devices registered by the OEM or reseller, with group tags where needed.
  • Dynamic device group on ZTDid or OrderID; ESP and user-driven Entra join profile assigned to it.
  • Required apps packaged as Win32 and assigned to the device group; reboot-heavy policies tested.
  • Test device shows Assigned with a Date assigned, completes OOBE and appears in the deployment status report.
  • Deregistration procedure documented for repairs and disposals.

References

Questions people ask

Do I need to register devices for Windows Autopilot?

Yes, classic Windows Autopilot needs the device's hardware hash registered to your tenant, ideally by the OEM, reseller or distributor. Windows Autopilot device preparation, the newer Windows 11 option, doesn't require registration and uses enrollment time grouping instead.

What licenses does Windows Autopilot need?

Users need Microsoft Entra ID P1 or P2 plus Intune, which come together in Microsoft 365 Business Premium, Microsoft 365 E3 or E5, EMS E3 or E5, Microsoft 365 F1 or F3 and the A1, A3 and A5 academic plans. The license must be assigned to the user who enrolls the device.

Why does my Autopilot device skip the company sign-in page?

The device didn't download an Autopilot profile, usually because it isn't registered, the profile isn't assigned yet, or the network blocked the Autopilot service. Check that Profile Status shows Assigned with a Date assigned value, then reboot with shutdown.exe /r /t 0 from Shift+F10.

Can I mix Win32 and line-of-business apps during Autopilot?

Not during the Enrollment Status Page. LOB MSI and Win32 installers both use TrustedInstaller, so they collide and the ESP fails with Another installation is in progress. Package everything as Win32, or use Windows Autopilot device preparation, which doesn't use the ESP.

Windows AutopilotMicrosoft IntuneEntra IDWindows 11
  1. Autopilot device preparation vs classic Autopilot: choosing the right one

    Compare Windows Autopilot device preparation and classic Windows Autopilot on join types, modes, app limits, registration, ESP and reporting, and pick the right one for each device population.

  2. Silent BitLocker encryption with Intune and recovery key escrow to Entra ID

    Encrypt Windows devices with no user prompts through an Intune disk encryption policy, and make BitLocker wait until the recovery password is stored in Microsoft Entra ID.

  3. Windows Autopilot device association: pre-bind devices with TPM attestation

    Set up Windows Autopilot device association: export the DeviceLink CSV, pre-associate devices in Intune, unlock OOBE customization and device naming, and remove associations at end of life.