Windows Autopilot: Provision a PC Without Touching It
Windows Autopilot guide for SMBs and MSSPs: hardware hash, deployment profiles, Enrollment Status Page, user-driven mode, break-glass and device reassignment.
Preparing a new Windows PC used to mean building an image master, plugging the machine into a staging bench, installing apps by hand and running a domain join. That model breaks down the moment your staff are spread across sites, working from home or hired remotely. Windows Autopilot answers exactly that problem: it lets you ship a machine straight from the supplier to the employee, who powers it on, signs in with their work account, and lets the device configure itself.
This guide is for SMBs and MSSPs managing Windows fleets with Microsoft Intune and Microsoft Entra ID. It covers how Autopilot actually works, the three ways to register a device, how to design a deployment profile, the role of the Enrollment Status Page, common pitfalls, and how AuPoint prepares the security baseline your machines receive at first sign-in.
How Autopilot actually works
Contrary to a common belief, Autopilot does not reinstall Windows and does not deploy an image. It customizes the factory install (the Out-of-Box Experience, or OOBE). Each device is identified by a unique hardware hash registered with the Autopilot service and tied to your Entra tenant. On power-up, once the machine reaches the network, it queries the service, recognizes it belongs to your organization, and applies the deployment profile you defined.
- The device must be registered in Autopilot via its hardware hash, associated with your tenant.
- A deployment profile describes the experience: user-driven mode, skipped screens, and the type of Entra join.
- The Enrollment Status Page (ESP) can block desktop access until critical apps and policies are applied.
- Internet connectivity and automatic MDM enrollment into Intune are required for the sequence to complete.
Register the devices in Autopilot
Registration is the most sensitive step, because it is what physically ties a PC to your tenant. The hardware hash can be supplied in three ways, in increasing order of convenience. The earlier the registration happens, the fewer CSV files you handle and the less likely the user is to see a generic setup screen.
- 1Ideally, the reseller or OEM registers the PCs directly to your tenant at purchase, using your organization identifier. No file ever moves on your side.
- 2Otherwise, a PowerShell script (Get-WindowsAutopilotInfo) run on each machine extracts the hash and uploads it to Intune; useful for devices already in stock.
- 3As a last resort, a manual CSV import for a few test machines or a small batch.
The pitfall of extracting the hash too late
Extracting the hash with a script means booting the machine and reaching a prompt. If you do it after passing through the OOBE, you have already consumed the setup experience and will need to reset the device so it goes through Autopilot cleanly. Plan the extraction before any user sign-in, or favour reseller registration to avoid the problem entirely.
Designing the profile and user experience
Once devices are registered, the deployment profile decides what the user sees and does. A well-designed profile hides unnecessary screens, enforces must-have apps before desktop access, and ensures a delivered PC is immediately compliant and ready to work. For most SMB scenarios, user-driven mode with an Entra join is the right choice.
Tuning the Enrollment Status Page
- Choose user-driven deployment for most SMB scenarios.
- List in the ESP only the apps that are genuinely blocking (antivirus, VPN, management agent), not the whole catalogue.
- Set a reasonable timeout so a user is never stuck indefinitely on a blocked screen.
- Decide whether to allow use of the device if an app install fails, based on your risk tolerance.
Test and plan a break-glass access
Always test on a pilot device before shipping machines to end users: a mistargeted policy or a required app that fails can block the entire remote deployment, with no technician on site to step in. Also keep a break-glass account excluded from your strictest Conditional Access policies, so you can regain control if a machine ends up in a dead end.
Reassignment and device lifecycle
Autopilot does not stop at the first delivery. When an employee leaves or changes role, the returned machine should be resettable and able to go through Autopilot again for a new user, with no physical intervention. Because the hash stays registered in your tenant, a wipe followed by a restart automatically relaunches the provisioning sequence with the up-to-date profile.
Autopilot does not replace good configuration hygiene: it accelerates it. The same compliance, BitLocker encryption, Windows LAPS and Microsoft Defender Antivirus policies you would apply by hand are applied here automatically, from the very first sign-in. If the policy baseline is shaky, Autopilot will simply reproduce a poor configuration quickly across the whole fleet.
How AuPoint prepares the baseline
Autopilot shines when the policies applied behind it are clean and predictable. That is exactly what AuPoint is for: preparing, in plain language and without PowerShell, the security and compliance baseline (ISO 27001, NIS2, GDPR) your machines receive at first sign-in. You connect your Microsoft tenant in a few clicks, preview the impact of a policy before applying it, keep break-glass safety, and keep policies reversible.
- Impact preview before applying: you see who and what will be affected.
- Built-in break-glass safety so you are never locked out of your tenant.
- Reversible policies: rolling back stays simple if a setting causes trouble.
FAQ
Does Autopilot reinstall Windows on the PC?
No. In classic user-driven mode, Autopilot customizes the factory install without re-imaging the machine. There is an Autopilot Reset mode and a pre-provisioning (white glove) scenario to stage a device in advance, but the common case keeps the OEM image and only applies your configuration.
Do I need a specific licence?
Autopilot relies on Microsoft Intune and Microsoft Entra ID. You therefore need licences covering Intune management and Entra ID (for example through the relevant Microsoft 365 plans), plus automatic MDM enrollment enabled for your users. Check your subscriptions before rolling the deployment out broadly.
What happens without an Internet connection?
Autopilot needs the Internet to reach the service, perform the Entra join and enroll the device into Intune. With no network during OOBE, the sequence cannot complete. Make sure Wi-Fi is available from the first screen, or use a wired machine for deliveries to poorly equipped sites.
Ready to deliver compliant machines from the moment they power on? Connect your Microsoft tenant and prepare your security baseline in a few clicks, with impact preview and reversibility. Start free at aupoint.io.