IntuneHow-to

Windows Autopilot from scratch: register devices, build a user-driven profile and assign it

Set up Windows Autopilot end to end: tenant prerequisites, collecting and importing hardware hashes, group tags and dynamic groups, a user-driven Entra join profile, an Enrollment Status Page and the first test device.

Windows Autopilot turns a factory-fresh laptop into a managed, Microsoft Entra joined device after the user signs in once during the out-of-box experience. Getting there means a few tenant settings, a registered hardware identity for each device, a group to target, a deployment profile and an Enrollment Status Page. In this post I'll build the classic user-driven Entra join scenario from nothing, point out where first attempts usually stall, and explain where the newer Windows Autopilot device preparation fits.

How this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (5 steps: Register the devices; Import the CSV; Group tags and a dynamic group; Create the deployment profile; Pair it with an Enrollment Status Page). 3. Verify. 4. Tips & gotchas. Toolbox: Get-WindowsAutopilotInfo, Install-Script, dsregcmd /status, …\CurrentVersion\UserOOBE, Windows Autopilot › Devices.1Prerequisites2Step-by-step3Verify4Tips & gotchas1Register thedevices2Import the CSV3Group tags and adynamic group4Create thedeployment profile5Pair it with anEnrollment Status…TOOLBOXGet-WindowsAutopilotInfoInstall-Scriptdsregcmd /status…\CurrentVersion\UserOOBEWindows Autopilot › DevicesHow this guide is organised: Prerequisites → Step-by-step → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. Step-by-step (5 steps: Register the devices; Import the CSV; Group tags and a dynamic group; Create the deployment profile; Pair it with an Enrollment Status Page). 3. Verify. 4. Tips & gotchas. Toolbox: Get-WindowsAutopilotInfo, Install-Script, dsregcmd /status, …\CurrentVersion\UserOOBE, Windows Autopilot › Devices.1Prerequisites2Step-by-step1Register the devices2Import the CSV3Group tags and a dynamic group4Create the deployment profile5Pair it with an Enrollment Status Page3Verify4Tips & gotchasTOOLBOXGet-WindowsAutopilotInfoInstall-Scriptdsregcmd /status…\CurrentVersion\UserOOBEWindows Autopilot › Devices
At a glance: how this guide is organised · 5 steps · 5 key settings and tools

Prerequisites#

  • Licensing: the enrolling user needs an Intune licence and Microsoft Entra ID P1 or P2. Microsoft 365 Business Premium, E3/E5, F1/F3 and A3/A5, and EMS E3/E5 include both.
  • Windows edition: a supported Windows 11 or Windows 10 release in the Pro, Enterprise or Education family; Home can't enrol in Intune.
  • Automatic MDM enrolment: under Devices › Enroll devices › Automatic Enrollment (also in Microsoft Entra ID under Mobility (MDM and WIP) › Microsoft Intune), set MDM user scope to All, or Some with a pilot user group.
  • Microsoft Entra device settings: the deploying users must be allowed to join devices to Microsoft Entra ID. Company branding is required if you want the profile's Hide change account options setting.
  • Permissions: Intune Administrator or Policy and Profile Manager. The registration script asks for consent to the Microsoft Graph PowerShell enterprise application on first run.
  • Network: internet access over HTTP, HTTPS and NTP during OOBE. Use a wired connection for the first test; a profile's language and keyboard settings only skip pages on Ethernet.

Step-by-step#

1. Register the devices#

For new purchases, have the OEM or your CSP partner register the devices to your tenant at the factory or through Partner Center; Microsoft recommends this for production because the 4K hardware hash is sensitive and manual capture means booting into Windows. For existing devices, labs and pilots, collect the hash yourself with the Get-WindowsAutopilotInfo script (it uses the Microsoft Graph PowerShell modules, not the retired AzureAD module). To save a CSV locally from an elevated PowerShell prompt:

PowerShell
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
New-Item -Type Directory -Path "C:\HWID" -Force
Set-Location -Path "C:\HWID"
$env:Path += ";C:\Program Files\WindowsPowerShell\Scripts"
Set-ExecutionPolicy -Scope Process -ExecutionPolicy RemoteSigned
Install-Script -Name Get-WindowsAutopilotInfo -Force
Get-WindowsAutopilotInfo -OutputFile AutopilotHWID.csv -GroupTag "Pilot"

On a device still sitting at OOBE, press Shift+F10, start powershell.exe, run the same Install-Script line and then Get-WindowsAutopilotInfo -Online; after you sign in with an Intune Administrator account the hash uploads directly and a restart picks up the profile. Without a script, Ctrl+Shift+D during Windows 11 OOBE opens the diagnostics page and exports logs including a hash CSV.

2. Import the CSV#

Merge single-device files into one CSV with exactly this header, no quotation marks, ANSI encoding and at most 500 rows:

Text
Device Serial Number,Windows Product ID,Hardware Hash,Group Tag,Assigned User

Edit it in Notepad, not Excel, which rewrites the file in a form Intune rejects. Then go to Devices › Windows › Enrollment › Windows Autopilot › Devices, select Import, upload the file and, when it finishes, select Sync. Import errors are self-explanatory once you know the names: ZtdDeviceAlreadyAssigned (already in your tenant), ZtdDeviceAssignedToAnotherTenant (the previous owner must release it), ZtdDeviceDuplicated (duplicate row) and InvalidZtdHardwareHash (manufacturer or serial missing).

3. Group tags and a dynamic group#

The group tag you set in the CSV, during -Online registration or by editing the device in the portal is stored as the OrderID physical ID on the Microsoft Entra device object, which makes it the cleanest way to split devices between profiles. Create a security group with Dynamic Device membership and one of these rules:

Text
All Autopilot devices:
(device.devicePhysicalIDs -any (_ -startsWith "[ZTDid]"))

Devices with the group tag "Pilot":
(device.devicePhysicalIds -any (_ -eq "[OrderID]:Pilot"))

Use only Autopilot attributes in these rules; properties that exist only after enrolment aren't populated when the profile needs to be assigned.

4. Create the deployment profile#

Under Devices › Windows › Enrollment › Windows Autopilot › Deployment Profiles, select Create Profile › Windows PC. On Basics, leave Convert all targeted devices to Autopilot at No for now; Yes registers every corporate, non-Autopilot device in the assigned groups within about 48 hours, and turning it off later doesn't undo that. On the Out-of-box experience page:

SettingRecommended valueWhy
Deployment modeUser-drivenThe signing-in user becomes the primary user
Join to Microsoft Entra ID asMicrosoft Entra joinedCloud-native; no domain controller needed
Microsoft Software License TermsHideFewer OOBE pages
Privacy settingsHideLocation services are then off by default; enable by policy if needed
Hide change account optionsHideRequires company branding
User account typeStandardUse Windows LAPS or EPM instead of local admin
Allow pre-provisioned deploymentNo for a user-driven pilotYes later if technicians pre-stage devices
Language (Region) / Automatically configure keyboardYour locale / YesSkips those pages on wired connections
Apply device name templateYes, for example CAI-%SERIAL%15 characters max, letters, numbers and hyphens, not all digits; %RAND:x% adds x random digits

Assign the profile to the dynamic group from step 3. If a device matches several profiles, the oldest wins, and a device with no match gets any profile assigned to All devices. Back on the Devices blade, watch Profile status move from Unassigned through Assigning to Assigned and wait until Date assigned is populated before you boot the device.

5. Pair it with an Enrollment Status Page#

The default ESP doesn't show progress. Create your own under Devices › Windows › Enrollment › Enrollment Status Page (the default plus up to 50 custom profiles) and assign it to the same group. Set Show app and profile configuration progress to Yes, keep the 60-minute default timeout unless your apps are large, turn on log collection and the diagnostics page, set Only show page to devices provisioned by out-of-box experience to Yes, and if you block device use until apps install, list only the two or three apps that truly must be there before first sign-in. The newer Install Windows quality updates option patches Windows 11 devices at the end of OOBE, so day one doesn't start with a restart prompt.

Verify#

  1. Reset the test device (or start the VM from install media) on a wired connection. After the network step, OOBE should show your tenant name and branding instead of the consumer account page; that proves the profile was downloaded.
  2. Sign in as the pilot user. The ESP runs the device phase (device-targeted policies and apps) and then the account phase after sign-in.
  3. In the admin center, the device appears under Devices › Windows with the name template applied, and Devices › Monitor › Windows Autopilot deployment status (preview) shows the deployment, its duration and any failed step for 30 days.
  4. On the device, dsregcmd /status shows AzureAdJoined : YES and an MDM URL pointing at Intune.

Tips & gotchas#

  • Profile changes don't reach an already enrolled device; reset and redeploy to test an edit.
  • Don't exclude groups from a profile assigned to All devices; exclusions aren't supported there.
  • Deleting a device cleanly means removing its Intune, Microsoft Entra ID and Autopilot records; a stale Autopilot record on a device sold to another organisation blocks their import.
  • If OOBE has been restarted many times, Windows can enter a recovery mode that skips Autopilot; Microsoft documents resetting HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\UserOOBE to 1 in that case.

Note: Windows Autopilot device preparation is Microsoft's newer provisioning flow, positioned as simpler, faster and more observable. It runs on Windows 11 only (24H2, or 22H2/23H2 with KB5035942), supports Microsoft Entra join only, uses one policy assigned to a user group plus a device security group filled through enrolment time grouping, installs up to 25 selected apps and 10 scripts during OOBE, and reports in near real time. It doesn't need a hardware hash, so it's often the quicker route for new tenants, while classic Autopilot remains the choice for pre-provisioning, self-deploying mode and hybrid join. If a device is registered for classic Autopilot and not associated with the tenant, the classic profile takes precedence.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)