Autopilot deployment illustrated title card

Autopilot deployment turns a new, unopened Windows device into a fully managed, business-ready machine the moment your user signs in, no imaging, no engineer required. It relies on Microsoft Entra ID for identity and an MDM such as Microsoft Intune for policy and app delivery, and it only works on supported Windows editions with the right licensing in place. If you are planning a rollout, the next step is straightforward: confirm your prerequisites, then follow the workflow below in order.


TL;DR:

  • Devices must have supported Windows 10 or 11 editions with current builds and be connected to necessary network endpoints for successful Autopilot deployment.
  • Licensing requirements include Microsoft 365 Business Premium, E3/E5, or Entra ID P1/P2 with Intune, and some features need specific license combinations within the tenant.
  • Follow the deployment workflow precisely, including device registration, group creation, profile assignment, and testing on a small scale before tenant-wide rollout.
  • Configuring the Enrolment Status Page properly prevents users from accessing incomplete setups and allows cancellation or resetting for troubleshooting.
  • Performing a pre-deployment checklist, such as pilot testing and documenting group strategies, reduces risks and saves time during large-scale rollouts.

Ctasystems
Keep Your Autopilot Rollout Reliable
CTA Systems provides proactive IT support, helping businesses manage Microsoft 365, cybersecurity risks, and technical issues before they disrupt operations.

Explore CTA Systems support

Table of Contents

Prerequisites and requirements before you start

Before touching a single device, take a few minutes to check your environment is actually ready. Most Autopilot failures trace back to something missed at this stage rather than a fault with the technology itself.

  • Windows edition: devices need a supported Windows 10 or Windows 11 edition (Pro, Enterprise, or Education) with a current, supported build.
  • RBAC roles: your Microsoft Entra ID and Intune administrators need the roles that permit device registration, profile assignment, and enrolment management.
  • Network endpoints: allow traffic to ztd.dds.microsoft.com, login.live.com, Windows Update, Delivery Optimization, and lgmsapeweu.blob.core.windows.net, plus NTP access via time.windows.com so devices can register successfully and upload diagnostics without a firewall or proxy silently blocking the connection.

Get these three areas right and most of the deployment friction disappears before it starts.

Which Microsoft licences unlock Autopilot features

Licensing confusion causes more stalled rollouts than any technical fault, so it is worth checking entitlement before you register a single device. According to Microsoft’s own requirements documentation, Autopilot and its related features are enabled through specific subscription combinations rather than a single standalone product.

  • Microsoft 365 Business Premium, suited to smaller organisations that want Intune and Entra ID bundled together.
  • Microsoft 365 F1 or F3, aimed at frontline workforces with lighter device management needs.
  • Microsoft 365 Academic A1, A3, or A5, built for education tenants.
  • Microsoft 365 Enterprise E3 or E5, the common choice for larger organisations.
  • Microsoft Entra ID P1 or P2 combined with Microsoft Intune as a standalone pairing, useful where you already hold Intune separately.

Some device preparation features expect specific licence combinations to be present in the same tenant, so check both your Microsoft 365 SKU and any conditional access policies that might quietly block enrolment before you begin testing.

The step-by-step Autopilot deployment workflow

Once your prerequisites and licensing are confirmed, the deployment sequence itself is a fairly disciplined process. Microsoft’s existing devices workflow sets out the stages in order, and it pays to follow them exactly rather than skip ahead.

  1. Enable automatic Intune enrolment in Microsoft Entra ID and double-check your RBAC roles are correctly assigned.
  2. Register devices, preferably through your OEM or reseller’s automated registration, or by importing a hardware hash CSV for lab and emergency scenarios.
  3. Sync the registered hardware in Intune so the devices appear as recognised Autopilot devices.
  4. Create device groups, deciding whether static membership or dynamic rules based on device attributes suits your rollout pattern better.
  5. Create and assign Autopilot profiles, choosing user-driven, self-deploying, or pre-provisioning mode depending on how much you want the end user involved.
  6. Boot the device. It connects to your network, the user signs in with their Entra ID credentials, and the Enrolment Status Page phases run through device and user setup before handing over a working desktop.

Pro Tip: Test your profile against a single device model and one small pilot group before assigning it tenant-wide, this catches app or policy conflicts while the blast radius is still small.

Configuring the Enrolment Status Page and device preparation

The Enrolment Status Page exists for one reason: to stop a user opening a half-configured desktop and ringing your helpdesk in confusion. Configured properly, it holds the device back until the essentials are actually installed.

  • Show app and profile progress so users see something happening rather than a blank screen.
  • Block device use until required apps and policies finish installing.
  • Allow reset or bypass for administrators, useful when a device genuinely needs to move forward despite a stuck app.
  • Select required apps carefully, since every app added extends the wait the user experiences.

Windows Autopilot device preparation, a newer alternative to the classic Autopilot profile, introduces Enrolment Time Grouping, which places devices into security groups the moment they enrol rather than waiting for a later sync cycle. According to Microsoft Learn, this shortens the time it takes for policies and apps to reach the device and improves reporting accuracy during rollout. On Windows 11, device preparation also supports mixing line-of-business and Win32 apps in the same provisioning run, something the classic ESP could not do. Keep your timeouts realistic and factor in Cloud PC scenarios separately, since virtual desktops behave differently during provisioning than physical hardware.

Troubleshooting common Autopilot deployment failures

When a device stalls during OOBE, work through the likely causes in a fixed order rather than guessing. It saves time and stops you chasing the wrong fault.

  • Network connectivity: confirm the device can reach the required endpoints and that DNS and NTP are both resolving correctly, since a clock drift alone can break Entra ID authentication.
  • Profile presence: check the registry for IsAutopilotDisabled and review the ModernDeployment event logs to see whether the Autopilot profile actually downloaded.
  • ESP app conflicts: a stuck line-of-business app fighting a Win32 install is a common cause of a device that never finishes provisioning.
  • Tenant enrolment blocks: Intune tenant settings occasionally block MDM enrolment outright, so check these before assuming a device fault.
  • Stale device records: if a device previously ran self-deploying or pre-provisioning mode, Microsoft’s troubleshooting guidance recommends deleting the old Intune record and unblocking the device before you redeploy it, otherwise stale state causes repeat failures.

Pro Tip: Enable the Autopilot diagnostics page (Ctrl+Shift+D during OOBE) through your ESP settings before rollout, and confirm lgmsapeweu.blob.core.windows.net is reachable, since diagnostic bundles cannot upload without it.

A pre-deployment checklist that keeps rollouts smooth

A short checklist run before every mass deployment saves considerably more time than it costs. Treat it as a gate rather than a suggestion.

  • Pilot first: test one device model with at least one app and one policy assigned before wider rollout.
  • Register through your OEM or partner wherever possible, keeping manual hash imports for exceptions only.
  • Document your grouping strategy so anyone on the team can see why a device landed in a particular group.
  • Configure ESP to show progress and switch on diagnostics upload from the outset.
  • Set sensible device preparation timeouts rather than accepting defaults that were never tested against your own app set.
  • Lean on a cloud-native approach and keep a standard image only for genuine exceptions, since Autopilot’s value drops sharply the more custom imaging you reintroduce.

Who’s behind this guide and what CTA Systems brings to it

CTA Systems I.T. Solutions Ltd has supported small and medium businesses with Microsoft 365 management and device onboarding for over 30 years. Its remote monitoring, management, and Microsoft 365 services align directly with the groundwork an Autopilot rollout depends on.

Autopilot rollout foundation components

In-house rollout or managed support: making the call

Running Autopilot in-house suits small, well-staffed teams with time to test properly. Where the rollout is time-limited, the environment mixes hybrid Active Directory with cloud identity, or Intune experience is thin, managed support adds real value through diagnostics, device grouping, and ongoing monitoring after go-live.

— Will

How CTA Systems supports your Autopilot rollout

Getting Entra ID, Intune, and licensing aligned before your first device ships takes time most in-house teams do not have spare. IT SYSTEMS: Managed IT Support, Remote Monitoring & Management, and Microsoft 365 services from CTA Systems cover exactly this groundwork, with fixed monthly fees and no hidden costs.

Ctasystems

Care Plans bring device onboarding and ongoing monitoring under one predictable contract, so your rollout does not end at go-live with nobody watching the fleet. Get in touch through CTA Systems to talk through a pilot for your own environment.

FAQ

What is Autopilot and how does it work?

Windows Autopilot is a collection of technologies that work alongside an MDM platform such as Microsoft Intune to turn a new device into a business-ready machine during setup. It relies on Intune for enrolment and policy enforcement rather than handling management itself.

Is Autopilot an MDM platform?

No, Autopilot is not an MDM. It is a deployment technology that depends on an MDM like Intune to actually enforce policies and app delivery once the device enrols.

Is Microsoft Autopilot free to use?

Autopilot itself carries no separate fee, but it requires licensing such as Microsoft 365 Business Premium, E3 or E5, or Microsoft Entra ID P1 or P2 paired with Intune. Check your existing subscription against Microsoft’s requirements before assuming you already qualify.

How do I deploy Intune Autopilot step by step?

Start by enabling automatic Intune enrolment in Microsoft Entra ID, then register your hardware, create device groups, and configure the Enrolment Status Page. From there you create and assign an Autopilot profile before booting the device into its guided setup.

CTA Systems I.T. Solutions Ltd

CTA Systems I.T. Solutions Ltd

Typically replies within an hour

Office Currently Closed

Contact Us

CTA Systems I.T. Solutions Ltd
Thankyou for visiting CTA Systems I.T. Solutions Ltd, How can we help? Send us A message.
Contact Us Chat With Us!
Pauline

Left us a 5 star review

googleCTA Systems Reviews
5.0
Based on 72 Reviews

Prompt attention, very helpful and friendly. Would definitely recommend.

google

Will Howell of CTA Systems has looked after my Company IT needs for the last 11 years. Recently helped me out with major Website and Business 365 transfer issues -he knows his stuff and keeps his prices realistic. I would recommend him without hesitation.

google

Great Customer service. Would definitely recommend to anyone.

google

Called for some advice and to enquire of service recently. Spoke to Will, he was so helpful and educated, answered all my questions and just overall a really lovely experience! Would 100% recommend them and will definitely use them in the future!

Really reliable service!

Holly
trustpilot

Very good customer service. Would definitely use again. Thanks!

google

An excellent, prompt and efficient service from Will. A really knowledgeable chap who is very personable, he makes the subject of computers really easy to understand. Great service offered both remotely and on site. Back up service too and ongoing support is very welcome. Nothing appears to be too much trouble. Thank you for sorting out our computers, email addresses and de-bugging everything.

google