Zero-Touch Provisioning

New device. Zero IT touch. Production-ready.

Windows Autopilot eliminates imaging, manual configuration, and desk-side setup. A user opens the box, signs in, and the device configures itself — apps, policies, security baselines, and compliance checks applied automatically. Our certified engineers design and deploy every Autopilot mode.

User-Driven Mode

Standard Deployment

Self-Deploying Mode

Shared & Kiosk Devices

Pre-Provisioning

White Glove Setup

Device Preparation

Next-Gen Provisioning

Enrollment Status Page

User Experience Control

Hardware Hash Import

Device Registration

Four Modes. One Goal: Zero Touch.

Each Autopilot mode serves a different deployment scenario. We engineer the right mode for your environment.

Most Common

User-Driven

The standard Autopilot experience. The user powers on the device, authenticates with their Entra ID credentials, and the Enrollment Status Page handles the rest — apps install, policies apply, and the desktop is ready. No IT intervention required.

Entra ID JoinESP TrackingApp Pre-InstallPolicy ApplicationCompliance GatingUser Affinity
Kiosk & Shared

Self-Deploying

No user authentication during setup. The device registers itself using its TPM 2.0 chip and configures entirely without user interaction. Designed for shared workstations, kiosks, digital signage, and conference room devices.

TPM AttestationNo User RequiredShared Device ModeKiosk ConfigAutomatic EnrollmentNetwork Required
White Glove

Pre-Provisioning

IT or a partner pre-provisions the device before shipping to the user. The technician completes the heavy setup — app installs, policy application, baseline validation — so the end user gets a device that's ready in minutes, not hours.

Technician PhaseUser PhasePre-Staged AppsValidated BaselinesReduced User WaitPartner Friendly
Next Generation

Device Preparation

Microsoft's newest provisioning method. Simpler admin configuration, better reporting, and a more resilient enrollment flow. Our engineers deploy Device Preparation for organizations ready to adopt the latest Autopilot capabilities.

Simplified ConfigEnhanced ReportingResilient EnrollmentEntra ID NativeGranular MonitoringFuture-Ready

How Autopilot Deployment Works

From hardware hash to production-ready device — engineered end to end.

01

Hardware Hash Import

Device hardware hashes are collected from your OEM or extracted on-site and imported into Intune. Each device is registered and assigned to your tenant before it's ever powered on.

02

Profile Assignment

Our engineers configure deployment profiles — OOBE customization, Entra ID join settings, ESP behavior, and group-based targeting. Every profile is tested before rollout.

03

Enrollment & ESP

The user (or device) enrolls. The Enrollment Status Page tracks progress in real-time — apps install, policies apply, compliance checks run. The desktop unlocks only when everything passes.

04

Production Ready

The device is fully configured, compliant, and secured. Apps are installed, baselines are applied, and the user is productive from the first login. No desk-side visit. No imaging.

Autopilot requires a solid Intune foundation

Autopilot is only as good as the Intune configuration underneath it. If compliance policies aren't enforcing, apps aren't deploying reliably, and security baselines have conflicts — Autopilot will deliver a broken experience. We either build your Intune foundation first or run both engagements concurrently.

See our Intune Foundation Setup →

Intune configured (or concurrent IFS)

Autopilot depends on compliance policies, configuration profiles, and app deployments being properly configured. Our Intune Foundation Setup handles this.

Entra ID P1 or P2 licensing

Conditional Access, device-based compliance, and dynamic groups require Entra ID Premium. Most M365 E3/E5 licenses include this.

Network and TPM readiness

Devices need internet access during OOBE and TPM 2.0 for Self-Deploying mode. We validate hardware readiness before deployment begins.

Who this is for

Autopilot is for organizations that want to stop imaging machines and start shipping them directly to users. If any of these describe your situation, we should talk.

You're still imaging devices with SCCM or USB drives
New hires wait days for a configured laptop
You have multiple office locations and remote workers
IT spends hours per device on manual setup
You're scaling headcount and need provisioning that scales with it
You want OEM-direct shipping with zero IT touch at delivery

Ready to eliminate imaging and manual device setup?

Book an Autopilot consultation. Our engineers will assess your readiness and design a zero-touch provisioning strategy for your environment.

Chat with an engineer