Autopilot deployment turns a new, unopened Windows device into a fully managed, business-ready machine the moment your user signs in, no imaging, no engineer required. It relies on Microsoft Entra ID for identity and an MDM such as Microsoft Intune for policy and app delivery, and it only works on supported Windows editions with the right licensing in place. If you are planning a rollout, the next step is straightforward: confirm your prerequisites, then follow the workflow below in order.
TL;DR:
- Devices must have supported Windows 10 or 11 editions with current builds and be connected to necessary network endpoints for successful Autopilot deployment.
- Licensing requirements include Microsoft 365 Business Premium, E3/E5, or Entra ID P1/P2 with Intune, and some features need specific license combinations within the tenant.
- Follow the deployment workflow precisely, including device registration, group creation, profile assignment, and testing on a small scale before tenant-wide rollout.
- Configuring the Enrolment Status Page properly prevents users from accessing incomplete setups and allows cancellation or resetting for troubleshooting.
- Performing a pre-deployment checklist, such as pilot testing and documenting group strategies, reduces risks and saves time during large-scale rollouts.
Table of Contents
- Prerequisites and requirements before you start
- Which Microsoft licences unlock Autopilot features
- The step-by-step Autopilot deployment workflow
- Configuring the Enrolment Status Page and device preparation
- Troubleshooting common Autopilot deployment failures
- A pre-deployment checklist that keeps rollouts smooth
- Who’s behind this guide and what CTA Systems brings to it
- In-house rollout or managed support: making the call
- How CTA Systems supports your Autopilot rollout
- Sources
- FAQ
Prerequisites and requirements before you start
Before touching a single device, take a few minutes to check your environment is actually ready. Most Autopilot failures trace back to something missed at this stage rather than a fault with the technology itself.
- Windows edition: devices need a supported Windows 10 or Windows 11 edition (Pro, Enterprise, or Education) with a current, supported build.
- RBAC roles: your Microsoft Entra ID and Intune administrators need the roles that permit device registration, profile assignment, and enrolment management.
- Network endpoints: allow traffic to
ztd.dds.microsoft.com,login.live.com, Windows Update, Delivery Optimization, andlgmsapeweu.blob.core.windows.net, plus NTP access viatime.windows.comso devices can register successfully and upload diagnostics without a firewall or proxy silently blocking the connection.
Get these three areas right and most of the deployment friction disappears before it starts.
Which Microsoft licences unlock Autopilot features
Licensing confusion causes more stalled rollouts than any technical fault, so it is worth checking entitlement before you register a single device. According to Microsoft’s own requirements documentation, Autopilot and its related features are enabled through specific subscription combinations rather than a single standalone product.
- Microsoft 365 Business Premium, suited to smaller organisations that want Intune and Entra ID bundled together.
- Microsoft 365 F1 or F3, aimed at frontline workforces with lighter device management needs.
- Microsoft 365 Academic A1, A3, or A5, built for education tenants.
- Microsoft 365 Enterprise E3 or E5, the common choice for larger organisations.
- Microsoft Entra ID P1 or P2 combined with Microsoft Intune as a standalone pairing, useful where you already hold Intune separately.
Some device preparation features expect specific licence combinations to be present in the same tenant, so check both your Microsoft 365 SKU and any conditional access policies that might quietly block enrolment before you begin testing.
The step-by-step Autopilot deployment workflow
Once your prerequisites and licensing are confirmed, the deployment sequence itself is a fairly disciplined process. Microsoft’s existing devices workflow sets out the stages in order, and it pays to follow them exactly rather than skip ahead.
- Enable automatic Intune enrolment in Microsoft Entra ID and double-check your RBAC roles are correctly assigned.
- Register devices, preferably through your OEM or reseller’s automated registration, or by importing a hardware hash CSV for lab and emergency scenarios.
- Sync the registered hardware in Intune so the devices appear as recognised Autopilot devices.
- Create device groups, deciding whether static membership or dynamic rules based on device attributes suits your rollout pattern better.
- Create and assign Autopilot profiles, choosing user-driven, self-deploying, or pre-provisioning mode depending on how much you want the end user involved.
- Boot the device. It connects to your network, the user signs in with their Entra ID credentials, and the Enrolment Status Page phases run through device and user setup before handing over a working desktop.
Pro Tip: Test your profile against a single device model and one small pilot group before assigning it tenant-wide, this catches app or policy conflicts while the blast radius is still small.
Configuring the Enrolment Status Page and device preparation
The Enrolment Status Page exists for one reason: to stop a user opening a half-configured desktop and ringing your helpdesk in confusion. Configured properly, it holds the device back until the essentials are actually installed.
- Show app and profile progress so users see something happening rather than a blank screen.
- Block device use until required apps and policies finish installing.
- Allow reset or bypass for administrators, useful when a device genuinely needs to move forward despite a stuck app.
- Select required apps carefully, since every app added extends the wait the user experiences.
Windows Autopilot device preparation, a newer alternative to the classic Autopilot profile, introduces Enrolment Time Grouping, which places devices into security groups the moment they enrol rather than waiting for a later sync cycle. According to Microsoft Learn, this shortens the time it takes for policies and apps to reach the device and improves reporting accuracy during rollout. On Windows 11, device preparation also supports mixing line-of-business and Win32 apps in the same provisioning run, something the classic ESP could not do. Keep your timeouts realistic and factor in Cloud PC scenarios separately, since virtual desktops behave differently during provisioning than physical hardware.
Troubleshooting common Autopilot deployment failures
When a device stalls during OOBE, work through the likely causes in a fixed order rather than guessing. It saves time and stops you chasing the wrong fault.
- Network connectivity: confirm the device can reach the required endpoints and that DNS and NTP are both resolving correctly, since a clock drift alone can break Entra ID authentication.
- Profile presence: check the registry for
IsAutopilotDisabledand review the ModernDeployment event logs to see whether the Autopilot profile actually downloaded. - ESP app conflicts: a stuck line-of-business app fighting a Win32 install is a common cause of a device that never finishes provisioning.
- Tenant enrolment blocks: Intune tenant settings occasionally block MDM enrolment outright, so check these before assuming a device fault.
- Stale device records: if a device previously ran self-deploying or pre-provisioning mode, Microsoft’s troubleshooting guidance recommends deleting the old Intune record and unblocking the device before you redeploy it, otherwise stale state causes repeat failures.
Pro Tip: Enable the Autopilot diagnostics page (Ctrl+Shift+D during OOBE) through your ESP settings before rollout, and confirm lgmsapeweu.blob.core.windows.net is reachable, since diagnostic bundles cannot upload without it.
A pre-deployment checklist that keeps rollouts smooth
A short checklist run before every mass deployment saves considerably more time than it costs. Treat it as a gate rather than a suggestion.
- Pilot first: test one device model with at least one app and one policy assigned before wider rollout.
- Register through your OEM or partner wherever possible, keeping manual hash imports for exceptions only.
- Document your grouping strategy so anyone on the team can see why a device landed in a particular group.
- Configure ESP to show progress and switch on diagnostics upload from the outset.
- Set sensible device preparation timeouts rather than accepting defaults that were never tested against your own app set.
- Lean on a cloud-native approach and keep a standard image only for genuine exceptions, since Autopilot’s value drops sharply the more custom imaging you reintroduce.
Who’s behind this guide and what CTA Systems brings to it
CTA Systems I.T. Solutions Ltd has supported small and medium businesses with Microsoft 365 management and device onboarding for over 30 years. Its remote monitoring, management, and Microsoft 365 services align directly with the groundwork an Autopilot rollout depends on.

In-house rollout or managed support: making the call
Running Autopilot in-house suits small, well-staffed teams with time to test properly. Where the rollout is time-limited, the environment mixes hybrid Active Directory with cloud identity, or Intune experience is thin, managed support adds real value through diagnostics, device grouping, and ongoing monitoring after go-live.
— Will
How CTA Systems supports your Autopilot rollout
Getting Entra ID, Intune, and licensing aligned before your first device ships takes time most in-house teams do not have spare. IT SYSTEMS: Managed IT Support, Remote Monitoring & Management, and Microsoft 365 services from CTA Systems cover exactly this groundwork, with fixed monthly fees and no hidden costs.

Care Plans bring device onboarding and ongoing monitoring under one predictable contract, so your rollout does not end at go-live with nobody watching the fleet. Get in touch through CTA Systems to talk through a pilot for your own environment.
FAQ
What is Autopilot and how does it work?
Windows Autopilot is a collection of technologies that work alongside an MDM platform such as Microsoft Intune to turn a new device into a business-ready machine during setup. It relies on Intune for enrolment and policy enforcement rather than handling management itself.
Is Autopilot an MDM platform?
No, Autopilot is not an MDM. It is a deployment technology that depends on an MDM like Intune to actually enforce policies and app delivery once the device enrols.
Is Microsoft Autopilot free to use?
Autopilot itself carries no separate fee, but it requires licensing such as Microsoft 365 Business Premium, E3 or E5, or Microsoft Entra ID P1 or P2 paired with Intune. Check your existing subscription against Microsoft’s requirements before assuming you already qualify.
How do I deploy Intune Autopilot step by step?
Start by enabling automatic Intune enrolment in Microsoft Entra ID, then register your hardware, create device groups, and configure the Enrolment Status Page. From there you create and assign an Autopilot profile before booting the device into its guided setup.
