First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/Everything You Need to Know About Windows Autopi…

Everything You Need to Know About Windows Autopilot Deployment in 2026: Prerequisites and Setup

2026-06-16·IT Partnerhowtowindows autopilotMicrosoft IntuneMicrosoft 365

Windows Autopilot is still one of the cleanest ways to provision business PCs, but the setup guidance has changed significantly since the Azure AD and Windows 10 era. In 2026, successful Autopilot depends on Microsoft Intune, Microsoft Entra ID, current Windows 11 support, modern licensing, and security policies that are ready before the first device is unboxed.

What Windows Autopilot does today

Windows Autopilot helps organizations deploy, reset, repurpose, and retire Windows devices with less manual imaging work. Instead of building and maintaining traditional OS images, IT registers the device, assigns deployment and management settings, and lets the user or IT technician complete setup through the Windows out-of-box experience.

The core flow is still straightforward:

  1. Register the device with the Windows Autopilot service. This can be done by an OEM, reseller, cloud solution provider, IT partner, or your internal IT team by importing the device hardware hash.
  2. Assign the device to the right Autopilot profile and Microsoft Entra group. Microsoft Intune applies the deployment profile, apps, configuration profiles, compliance policies, and security baselines.
  3. Deploy the device. The user signs in with a work account, or IT pre-provisions the device before shipping it to the user, depending on the scenario.

The biggest change from older guidance is that the ecosystem now centers on Microsoft Intune and Microsoft Entra ID, not the legacy Azure AD portal experience.

2026 prerequisites checklist

Before deploying Windows Autopilot, confirm these requirements:

  • Supported Windows edition: Focus on Windows 11 Pro, Windows 11 Enterprise, or Windows 11 Education. Windows 10 reached end of support for most editions in October 2025, so it should only remain in scope for organizations with a valid Extended Security Updates plan or a documented exception.
  • Microsoft Intune: Users or devices need appropriate Intune licensing, commonly through Intune Plan 1, Microsoft 365 Business Premium, Microsoft 365 E3/E5, Enterprise Mobility + Security, or eligible Frontline plans.
  • Microsoft Entra ID: Automatic MDM enrollment generally requires Microsoft Entra ID P1 or licensing that includes it, such as Microsoft 365 Business Premium or Microsoft 365 E3/E5.
  • Device identity: Autopilot commonly uses Microsoft Entra join for cloud-native deployments. Hybrid Microsoft Entra join is still possible, but it adds complexity and should only be used when there is a clear technical dependency.
  • Network access: Devices must reach Microsoft cloud endpoints during the out-of-box experience. Restrictive proxy, SSL inspection, captive portal, or firewall configurations can break provisioning.
  • Hardware readiness: Modern Windows 11 devices should meet Windows 11 hardware requirements, including TPM 2.0, Secure Boot, and UEFI. Self-deploying and pre-provisioned scenarios have additional hardware and TPM attestation considerations.
  • Device registration process: Decide whether devices will be registered by your OEM/reseller/IT partner, through Partner Center, or manually in Intune.
  • User readiness: Users must be allowed to join devices to Microsoft Entra ID and enroll devices in Intune unless you use a scenario that avoids user-driven enrollment.

Choose the right Autopilot scenario

Autopilot is not a single deployment mode. The right option depends on who touches the device and how much setup must happen before the user receives it.

  • User-driven Microsoft Entra join: The most common cloud-first scenario. The user signs in during setup, the device joins Microsoft Entra ID, enrolls in Intune, and receives assigned apps and policies.
  • Pre-provisioned deployment: IT, a reseller, or a partner prepares the device before delivery. The user receives a device that already has many required apps and policies installed, reducing first sign-in time.
  • Self-deploying mode: Used for kiosks, shared devices, and digital signage where no primary user signs in during provisioning. This mode has stricter hardware and TPM requirements.
  • Autopilot Reset: Returns a managed device to a business-ready state while preserving its management relationship, useful for reassignment or troubleshooting.
  • Wipe, retire, or delete: Used when a device is leaving service, being reissued from scratch, or removed from the organization.
  • Windows Autopilot device preparation: A newer cloud-native approach designed to simplify certain deployment experiences. It may be a good fit for organizations standardizing on modern Windows 11 and Intune deployment patterns, but it should be evaluated against existing Autopilot profiles and operational needs.

One-time setup: Microsoft Intune and Microsoft Entra ID

Use the current admin centers rather than the old Azure portal instructions.

  1. Configure automatic MDM enrollment
  • Go to the Microsoft Intune admin center or Microsoft Entra admin center.
  • In Microsoft Entra ID, configure Mobility / MDM and MAM settings for Microsoft Intune.
  • Set the MDM user scope to All or to a controlled group for pilot rollout.
  • Confirm that users in scope have Intune and Microsoft Entra ID licensing.
  1. Configure Microsoft Entra company branding
  • In the Microsoft Entra admin center, configure company branding so users recognize the sign-in experience during Windows setup.
  • Use current logo, background, privacy, and support text.
  • This is more than cosmetic: clear branding helps users trust the sign-in prompt and reduces help desk confusion.
  1. Allow the right users to join devices
  • In Microsoft Entra ID device settings, confirm which users may join devices to Microsoft Entra ID.
  • Avoid allowing more users than necessary if your governance model requires tighter control.
  • Review device limits per user so legitimate deployments do not fail unexpectedly.
  1. Create Autopilot deployment profiles
  • In the Microsoft Intune admin center, create deployment profiles that match your scenarios: user-driven, pre-provisioned, or self-deploying where supported.
  • Assign profiles to dynamic Microsoft Entra device groups when possible.
  • Use clear naming conventions for geography, department, device type, or deployment mode.
  1. Configure the Enrollment Status Page
  • The Enrollment Status Page shows progress while apps, profiles, and policies are applied.
  • Use it carefully: blocking too many apps during setup can increase deployment time or cause failures if an app is unreliable.
  • For best results, block only the apps and policies that are truly required before the user reaches the desktop.

Security and governance settings to review before rollout

Autopilot success is not only about device registration. Security policies can directly affect the out-of-box experience.

Review these items before production deployment:

  • MFA and Conditional Access: Strong authentication is recommended, but policies must be tested during Autopilot. Avoid blocking enrollment because a device is not yet compliant during its first sign-in.
  • Device compliance policies: Define what makes a device compliant, such as encryption, secure boot, firewall, antivirus, OS version, and risk state.
  • Enrollment restrictions: Block unsupported platforms and decide whether personal Windows device enrollment is allowed. Many organizations restrict enrollment to corporate-owned or Autopilot-registered devices.
  • Device platform restrictions: Prevent accidental enrollment of unmanaged or unsupported device types.
  • Windows Hello for Business: Decide whether to require it during provisioning, after enrollment, or through a staged rollout.
  • Local administrator policy: Decide whether users should be standard users or local administrators. For most organizations, standard user is the safer default.
  • Role-based access control: Limit who can create Autopilot profiles, import devices, change enrollment settings, and perform wipe or reset actions.
  • Device Enrollment Managers: Use only when needed and monitor carefully, because these accounts can enroll multiple devices.
  • App deployment reliability: Test required apps, scripts, Win32 packages, and security agents so they do not delay or break provisioning.

Windows subscription activation in 2026

Subscription activation is still useful when you want eligible users to move from Windows Pro to a higher edition without reimaging.

Common examples:

  • Microsoft 365 E3/E5 or Windows Enterprise E3/E5 can activate Windows Enterprise features for licensed users on eligible Windows Pro devices.
  • Microsoft 365 Business Premium includes Windows Business benefits for eligible devices, but it is not the same as Windows Enterprise E3/E5.
  • The user must have the appropriate license assigned and must sign in with their work account.

This is especially relevant when you plan to use Enterprise-only security and management capabilities. Confirm licensing before designing policies that depend on a specific Windows edition.

Licensing notes for CSP and NCE customers

For most small and midsize organizations, Microsoft 365 Business Premium is a practical baseline because it includes Microsoft Intune Plan 1 and Microsoft Entra ID P1. Larger or more regulated organizations often standardize on Microsoft 365 E3 or E5, depending on security, compliance, and Windows Enterprise requirements.

Under the Cloud Solution Provider program and New Commerce Experience subscriptions, licensing should be reviewed before rollout because add-ons, Frontline plans, Windows Enterprise rights, Intune capabilities, and Entra ID features vary by SKU. Do not assume that every Microsoft 365 plan includes the same Autopilot, Intune, Conditional Access, or Windows activation capabilities.

A practical rollout plan

A safe Autopilot rollout usually follows this path:

  1. Pilot with a small group of IT-owned test devices.
  2. Register devices and confirm profile assignment.
  3. Test the complete out-of-box experience on a clean device.
  4. Validate app installation, security baselines, compliance, encryption, and Conditional Access.
  5. Test Autopilot Reset and device reassignment.
  6. Expand to a user pilot group across departments and locations.
  7. Document the support process for failed enrollments, device replacement, and remote users.
  8. Move new device procurement to OEM or partner registration so devices arrive ready for Autopilot.

The goal is not just zero-touch deployment. The goal is a repeatable device lifecycle process from purchase through retirement.

Key takeaways

  • Windows Autopilot remains relevant in 2026, but deployments should be designed around Windows 11, Microsoft Intune, and Microsoft Entra ID.
  • The old Azure AD terminology and portal paths should be replaced with Microsoft Entra admin center and Microsoft Intune admin center workflows.
  • Licensing matters: Intune, Microsoft Entra ID P1/P2, Microsoft 365 Business Premium, Microsoft 365 E3/E5, and Windows Enterprise rights provide different capabilities.
  • Security policies such as MFA, Conditional Access, compliance, enrollment restrictions, and Windows Hello for Business must be tested during the Autopilot experience.
  • A successful deployment includes the full lifecycle: registration, provisioning, management, reset, reassignment, retirement, and support.

If you want a clean Windows 11 deployment process without maintaining images or manually configuring every PC, IT Partner can help design and implement Microsoft Intune and Windows Autopilot for your environment. Start with our Microsoft Intune, Microsoft 365, Managed IT, or Cybersecurity services to align deployment, licensing, and security from day one.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.