Everything You Wanted to Know About Windows Autopilot for Windows 11
Windows Autopilot is still the modern way to deliver business-ready Windows devices without traditional imaging. In 2026, the best practice is to combine Windows 11, Microsoft Intune, Microsoft Entra ID, and partner/OEM registration so employees can receive a device, sign in, and let the cloud complete setup.
What Windows Autopilot does in 2026
Windows Autopilot replaces the old image-build-and-reimage process with cloud-based provisioning. Instead of wiping a new PC and applying a custom image, IT defines the desired configuration in Microsoft Intune and Microsoft Entra ID. The device starts from the OEM-installed Windows image, checks in with the Autopilot service during Windows out-of-box experience, and receives your organization’s enrollment, naming, security, app, and policy settings.
For most organizations, Autopilot is now part of a broader endpoint management model: Windows 11, Microsoft Intune, Microsoft Entra ID, Microsoft Defender, Microsoft 365 apps, compliance policies, and optional services such as Windows Autopatch. Windows 10 reached end of support on October 14, 2025, except for special servicing scenarios such as LTSC or Extended Security Updates, so new Autopilot planning should normally start with Windows 11.
Why organizations use Autopilot instead of traditional imaging
Autopilot is valuable because it moves device deployment from a desk-side IT task to a repeatable cloud process.
Key benefits include:
- Devices can be shipped directly from the OEM, distributor, reseller, or IT stockroom to the employee.
- IT can avoid maintaining large custom Windows images and driver libraries.
- Users can complete a guided Windows 11 setup with their work account.
- Apps, certificates, Wi-Fi/VPN settings, security baselines, compliance policies, and Microsoft 365 apps can be delivered from Intune.
- IT can standardize device setup while still using the OEM-optimized Windows installation.
- Existing devices can be reset or repurposed with Autopilot Reset or redeployed through Autopilot for existing devices.
The result is not magic: you still need good identity, licensing, network access, app readiness, and support processes. But when those are in place, Autopilot significantly reduces manual staging work.
Current administration portals
Autopilot administration is now centered on the Microsoft Intune admin center and partner/OEM registration flows.
Use these current entry points:
- Microsoft Intune admin center: used by customer IT teams to view Autopilot devices, create deployment profiles, configure Enrollment Status Page profiles, assign apps and policies, and monitor enrollment.
- Partner Center: used by CSP partners, OEMs, distributors, and resellers that are authorized to register devices to a customer tenant.
- OEM/distributor/reseller ordering systems: many hardware providers can register devices with Autopilot during procurement, often including group tags or purchase order IDs.
Do not plan new processes around Microsoft Store for Business or Store for Education. Those portals were retired and are no longer the place to manage Autopilot.
Licensing and identity requirements
At a minimum, Autopilot deployments require supported Windows devices, Microsoft Entra ID, and mobile device management through Microsoft Intune or another supported MDM.
Common licensing options include:
- Microsoft Intune Plan 1.
- Microsoft 365 Business Premium.
- Microsoft 365 E3 or E5.
- Enterprise Mobility + Security E3 or E5.
Microsoft Entra ID P1 capabilities are commonly required for automatic MDM enrollment, dynamic groups, and Conditional Access-based modern management scenarios. Microsoft 365 Business Premium, Microsoft 365 E3/E5, and EMS E3/E5 include relevant Entra ID capabilities; standalone licensing should be reviewed carefully.
Devices should run a supported Windows 11 edition such as Pro, Enterprise, or Education. Windows Home is not appropriate for business Autopilot enrollment. If you buy through a CSP partner under the New Commerce Experience (NCE), validate that your subscription mix includes the Intune and Entra ID capabilities needed for your deployment design.
Autopilot deployment options
Autopilot is not a single deployment mode. Choose the scenario that matches how the device will be delivered and used.
- User-driven deployment: the most common scenario. The user receives the device, connects to the internet, signs in with a work or school account, and Autopilot enrolls the device into Intune.
- Pre-provisioned deployment: formerly called white glove. IT, a partner, or the OEM preloads device-targeted apps and policies before the device is handed to the user. The employee then completes the user-specific phase.
- Self-deploying mode: used for kiosks, shared devices, and digital signage where no primary user signs in during setup. This requires supported TPM-based attestation and has stricter hardware and network requirements.
- Autopilot Reset: returns an enrolled device to a business-ready state while preserving its Entra ID join and Intune enrollment relationship.
- Autopilot for existing devices: helps migrate or reprovision existing Windows devices into an Autopilot-managed state, often as part of a refresh or modernization project.
For many businesses, the practical starting point is user-driven Microsoft Entra join with Intune enrollment. Hybrid Microsoft Entra join is still available for specific legacy dependencies, but it adds complexity and should be used only when there is a clear requirement.
Step 1: Register devices
Before Autopilot can customize a device, the device identity must be registered with the Windows Autopilot deployment service. Registration links the physical device to your organization.
The best approach is partner or OEM registration during procurement. Your OEM, distributor, reseller, or CSP partner may be able to:
- Register devices directly to your tenant through Partner Center or an approved OEM workflow.
- Add group tags that Intune and Microsoft Entra dynamic groups can use for profile assignment.
- Include purchase order IDs or other procurement metadata for reporting and grouping.
- Ship devices directly to employees after registration.
For existing devices, IT can import the hardware hash into Intune. This is useful for pilots, repurposed devices, or devices purchased outside a formal Autopilot-ready channel. However, large-scale hardware hash collection is more operationally intensive than having the supplier register devices for you.
Step 2: Create and assign an Autopilot deployment profile
After devices are registered, create an Autopilot deployment profile in the Microsoft Intune admin center. Current navigation is typically: Devices > Windows > Windows enrollment > Deployment Profiles. Microsoft occasionally adjusts portal navigation, so the quickest route is often to search for Windows enrollment in the Intune admin center.
A deployment profile defines how Windows setup behaves. Depending on deployment mode, you can configure options such as:
- Microsoft Entra join or hybrid Microsoft Entra join.
- User-driven, self-deploying, or pre-provisioned deployment.
- Whether the user becomes a local administrator.
- Device naming template.
- Whether to hide selected out-of-box experience pages.
- Language and region behavior where supported.
- Assignment to specific device groups.
For most organizations, standard users should not become local administrators unless there is a documented business need. Local admin rights increase risk and can weaken the value of endpoint security policies.
Step 3: Use dynamic groups for automation
Autopilot becomes much more scalable when profile assignment is automated with Microsoft Entra dynamic device groups.
Common grouping approaches include:
- All Autopilot devices: use the Autopilot device attribute, often represented in rules with ZTDId.
- Group tag-based groups: assign different profiles for departments, regions, device types, or deployment scenarios.
- Purchase order-based groups: useful when a batch of devices should receive a specific profile or app set.
Example use cases:
- Devices tagged SALES receive the standard Windows 11 laptop profile and sales apps.
- Devices tagged KIOSK receive a self-deploying kiosk profile.
- Devices from a specific purchase order receive a pilot deployment profile before broader rollout.
Dynamic group evaluation and Autopilot profile assignment are not always instant. Build time into your process before shipping devices, especially for large batches or new profiles.
Step 4: Configure the Enrollment Status Page
The Enrollment Status Page, or ESP, controls what the user sees while Intune completes enrollment tasks. In the Intune admin center, use Devices > Windows > Windows enrollment > Enrollment Status Page.
ESP can help ensure that required apps and policies install before the user reaches the desktop. You can configure behavior such as:
- Show installation progress.
- Block use of the device until required apps and policies are installed.
- Set timeout behavior.
- Display a custom support message if setup fails.
- Track device preparation, device setup, and account setup phases.
Be selective with blocking apps. If too many large or unreliable apps are required during ESP, enrollment can become slow or fail. A good design blocks only what is truly needed before first sign-in, then installs the rest after the desktop is available.
What the employee experiences
A typical user-driven Windows 11 Autopilot experience looks like this:
- The employee receives the device and turns it on.
- The device connects to the internet through wired network or Wi-Fi.
- Windows checks the Autopilot service and identifies the organization profile.
- The employee signs in with a work or school account.
- The device joins Microsoft Entra ID or completes the configured hybrid join process.
- Intune enrollment starts automatically.
- Required apps, certificates, policies, and security settings install.
- The employee reaches a managed Windows 11 desktop.
The exact experience depends on your profile, network, licensing, Conditional Access policies, MFA requirements, and app deployment design.
Operational tips and troubleshooting
Autopilot is reliable when the prerequisites are clean. Most deployment issues come from registration, assignment, networking, licensing, identity, or app installation problems.
Check these areas first:
- Registration: confirm the device appears under Windows Autopilot devices in Intune and is assigned to the correct tenant.
- Profile assignment: confirm the device is in the correct Microsoft Entra group and that the Autopilot profile assignment status has completed.
- Network: ensure the device can reach Microsoft cloud endpoints during OOBE. Captive portals, restrictive proxies, and blocked authentication endpoints can break setup.
- Licensing: confirm the user has Intune and Entra ID capabilities needed for enrollment and automatic MDM enrollment.
- TPM: self-deploying and some pre-provisioning scenarios depend on supported TPM attestation.
- ESP configuration: avoid blocking on nonessential apps; review timeouts and failed app installs.
- App packaging: Win32 app detection rules, dependencies, and restart behavior can affect enrollment success.
- Partner handoff: define who owns device registration, incorrect tenant assignment, warranty replacement, and deregistration when devices are returned or retired.
For support, collect the device serial number, Autopilot device record, Intune enrollment status, failed app details, and the exact setup phase where the user is stuck.
Recommended 2026 design
For a modern small or midsize business, a strong baseline is:
- Windows 11 Pro or Enterprise devices purchased through an Autopilot-capable OEM, distributor, reseller, or CSP partner.
- Microsoft 365 Business Premium or Microsoft 365 E3/E5, depending on organization size and requirements.
- Microsoft Entra join unless hybrid join is genuinely required.
- Microsoft Intune for device management, compliance, app deployment, and security baselines.
- Dynamic groups using group tags for deployment profiles.
- A carefully scoped Enrollment Status Page.
- Standard user accounts with no default local admin rights.
- Documented support and replacement processes.
This gives IT a repeatable deployment model while giving employees a simpler first-run experience.
Key takeaways
- Windows Autopilot remains a current and important deployment capability, but new planning should focus on Windows 11, Microsoft Intune, and Microsoft Entra ID.
- Autopilot administration is now primarily done in the Microsoft Intune admin center, with OEM, reseller, distributor, and CSP registration handled through approved partner flows such as Partner Center.
- Microsoft Store for Business is retired and should not be used in new Autopilot processes.
- The core process is still register devices, assign profiles, automate grouping, and manage the user experience with the Enrollment Status Page.
- Licensing matters: validate Intune, Microsoft Entra ID P1-related capabilities, and CSP/NCE subscription coverage before rollout.
- The best Autopilot deployments keep the Enrollment Status Page lean, automate profile assignment with dynamic groups, and clearly define partner and IT support responsibilities.
Planning a Windows 11 device rollout or replacing manual imaging with Autopilot? IT Partner can help design Microsoft Intune, Microsoft Entra ID, and Autopilot deployment profiles, validate licensing, and coordinate OEM or CSP registration workflows.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.