
Intune Autopilot
Zero-touch Windows 11 provisioning. Ship the device to the user, they sign in, the device configures itself. Your IT never touches the hardware.
Every New Laptop Is a 2-Hour Manual Install
A new hire starts Monday. Somebody unboxes the laptop, boots it, joins it to Entra, installs Office, VPN, the browser bookmarks, applies compliance settings — 2 to 3 hours per device. Times 10 devices a month. Times the inevitable error on device number 7 that nobody notices until the user calls the helpdesk two weeks later.
This is not a failure of your IT team. It is a workflow that Microsoft solved with Windows Autopilot: the device provisions itself via OOBE, pulls apps and policies from Intune, and is ready before the user finishes their coffee. The license is already in your M365 Business Premium or M365 E3. What is missing: the deployment profile design, the Enrollment Status Page tuning, and a tested pilot flow.
Traditional consulting for an Autopilot setup? Five figures. The consultant configures the profile, writes a handover doc, leaves. Your team inherits defaults they did not pick.
ACTIVITIES IN DETAIL
DELIVERABLES
Prerequisites: Intune and Entra ID P1 plans, MDM enrollment scope, and Windows 11 readiness
Route per Device Group: User-driven, pre-provisioned, or device preparation, with the trade-offs
Group Targeting: The GroupTag convention and the dynamic device groups that match on it
Deployment Profiles: Deployment mode, join type, OOBE settings, company branding, and naming
Enrollment Status Page: Blocking apps, timeout, error handling, and the quality update decision
App Baseline: Exactly three apps, M365 Apps as Win32, Edge, and Company Portal, verified
Device Registration: Pilot devices by hardware hash, existing fleet in bulk, plus the supplier path
End-to-End Pilot: Unbox, boot, OOBE, apps, join type, with the provisioning time measured
Next steps after Intune Autopilot
A cleanly configured tenant is the foundation. These blueprints build directly on it




