Windows Autopilot deployment scenarios in Microsoft Intune: user-driven, reset, and self-deploying modes
Windows Autopilot is still one of the best ways to deliver Windows 11 devices without traditional imaging. In 2026, the conversation has shifted from Windows 10 and Azure AD to Windows 11, Microsoft Intune, Microsoft Entra ID, and newer options such as Windows Autopilot device preparation. This refreshed guide explains when to use user-driven deployment, Autopilot Reset, and self-deploying mode—and how to choose the right approach for your organization.
What Windows Autopilot does in 2026
Windows Autopilot is a cloud-based provisioning model for new or reset Windows devices. Instead of building and maintaining custom images, you register the device with the Windows Autopilot service, assign a profile in Microsoft Intune, and let the device configure itself during the out-of-box experience.
A typical Autopilot deployment can join the device to Microsoft Entra ID, enroll it into Microsoft Intune, apply security baselines and configuration profiles, install required apps such as Microsoft 365 Apps for enterprise, and present an Enrollment Status Page so the user does not reach the desktop before critical setup is complete.
For most new Windows 11 deployments, Microsoft recommends cloud-native Microsoft Entra join where possible. Microsoft Entra hybrid join is still available for organizations that require on-premises Active Directory dependencies, but it adds complexity and should be used only when there is a clear business or technical requirement.
Current prerequisites and licensing
Before choosing a deployment scenario, confirm the basics:
• Supported Windows edition: Windows 11 Pro, Enterprise, Education, or another edition supported by your Microsoft licensing and deployment scenario. • Device management: Microsoft Intune Plan 1 or an eligible Microsoft 365 suite that includes Intune, such as Microsoft 365 Business Premium, Microsoft 365 E3/E5, or comparable education plans. • Identity: Microsoft Entra ID with automatic MDM enrollment configured for Intune. Many organizations get the required Entra capabilities through Microsoft 365 Business Premium, E3/E5, or Enterprise Mobility + Security. • Licensing procurement: For commercial customers, Microsoft 365, Intune, Windows, and Entra subscriptions are typically purchased and renewed through Microsoft New Commerce Experience (NCE). Review term length, cancellation windows, and add-on requirements before standardizing a deployment model. • Device registration: Classic Windows Autopilot scenarios require the device to be registered with the Autopilot service, often by an OEM, reseller, CSP partner, or by importing the hardware hash. • Network access: The device must reach Microsoft cloud services during OOBE. Avoid captive portals and networks requiring web-based authentication before Windows setup. • TPM requirements: Self-deploying and some zero-touch scenarios depend on TPM 2.0 attestation. Physical devices are expected; virtual machines and unsupported TPM configurations are common causes of failure.
Classic Autopilot profiles vs. Windows Autopilot device preparation
There are now two important ways to think about Autopilot provisioning.
Classic Windows Autopilot deployment profiles are the mature model used for user-driven, self-deploying, pre-provisioned, and many existing enterprise processes. They rely on device registration and profile assignment before or during deployment. This is still the right choice when you need established Autopilot capabilities such as OEM registration workflows, self-deploying kiosks, or mature device lifecycle automation.
Windows Autopilot device preparation is a newer Intune experience designed to simplify many cloud-native, user-driven Windows 11 deployments. It is useful when you want a more streamlined setup process, policy-driven app and script tracking, and a deployment model focused on Microsoft Entra join and Intune enrollment without some of the older hardware-hash-centered operational steps.
In practice: use Autopilot device preparation for new, straightforward Windows 11 user-driven deployments where it meets your requirements. Use classic Autopilot profiles for self-deploying devices, kiosk/shared-device deployments, pre-provisioning, hybrid scenarios, or when your procurement and logistics process already depends on Autopilot registration.
Scenario 1: User-driven deployment
User-driven deployment is the most common Autopilot scenario. It is designed for a device that will be assigned to a specific employee. The device can be shipped directly to the user, powered on, connected to the internet, and configured without IT touching it first.
The flow usually looks like this:
- The device is registered with Windows Autopilot or prepared through the newer device preparation experience.
- The user turns on the Windows 11 device and connects to the internet.
- During OOBE, the device contacts the Autopilot service and receives its assigned deployment instructions.
- The sign-in screen is branded for the organization.
- The user signs in with their Microsoft Entra ID credentials.
- The device joins Microsoft Entra ID and enrolls into Microsoft Intune.
- Intune applies policies, security settings, certificates, VPN/Wi-Fi profiles, and required apps.
- The Enrollment Status Page can hold the user until required setup is complete.
This model works well for remote employees, branch offices, new hires, hardware refreshes, and organizations replacing legacy imaging with cloud provisioning. It also pairs well with direct-from-OEM shipping, especially when the hardware supplier or CSP partner registers devices in Autopilot before delivery.
Enrollment Status Page best practices
The Enrollment Status Page, or ESP, is important because it controls what the user sees while Intune is preparing the device. Without it, a user may reach the desktop while apps and security settings are still installing, which can create confusion and support calls.
In the Microsoft Intune admin center, ESP configuration is managed under Devices > Windows > Windows enrollment > Enrollment Status Page. Autopilot deployment profiles are managed under Devices > Windows > Windows enrollment > Windows Autopilot deployment profiles. Exact labels may change as Microsoft updates the admin center, but Windows enrollment is the area to start from.
Recommended ESP practices:
• Block access only for truly required apps and settings. If every app blocks the desktop, deployment can become slow and fragile. • Prefer well-packaged Win32 apps with reliable detection rules. Poor detection logic is one of the most common causes of ESP delays. • Treat Microsoft 365 Apps for enterprise as a core app, but validate installation behavior in your tenant and network conditions. • Separate device-targeted and user-targeted requirements. Device setup happens before the user context is fully available; account setup applies user-targeted work. • Test on the same hardware models and networks your users will actually use. • Avoid mixing too many legacy installers, scripts, and reboots during ESP unless they are carefully controlled.
A good target is not the shortest possible deployment; it is a predictable deployment where the user reaches the desktop with security controls applied and the essential tools installed.
Scenario 2: Windows Autopilot Reset
Windows Autopilot Reset is for reusing an already managed corporate device. It removes user data, personal files, apps, and settings while preserving the device’s Microsoft Entra join and Intune enrollment. After the reset, the device returns to a managed state and is ready for the next user or purpose.
Use Autopilot Reset when a device is staying in your organization and you want to quickly clean it for reassignment. Typical examples include employee offboarding, replacing a shared workstation user, preparing a training device, or cleaning up a device that accumulated unwanted local changes.
In Intune, the remote action is available by selecting a Windows device and choosing Autopilot Reset, where supported. Local reset from the lock screen can also be enabled by policy, but most organizations prefer the remote Intune action for auditability and control.
Autopilot Reset is different from other Intune actions:
• Autopilot Reset: Keeps Microsoft Entra join and Intune enrollment, removes user data and settings, and prepares the device for reuse inside the organization. • Wipe: Resets the device more completely and can return it to OOBE. Use when you need a deeper reset or are changing ownership state. • Fresh Start: Reinstalls Windows while removing many preinstalled applications. Use when the goal is to clean up the Windows installation rather than simply reassign the device. • Retire: Removes company data and management from a device but does not fully reset the operating system. This is more appropriate for personally owned or BYOD-style scenarios. • Delete: Removes the device record from Intune but does not perform a reset on the physical device.
Choosing the wrong action can create orphaned objects, leave data behind, or make the device harder to redeploy, so define a standard lifecycle process for offboarding and redeployment.
Scenario 3: Self-deploying mode
Self-deploying mode is designed for devices that should configure themselves without a primary user. It is ideal for kiosks, digital signage, shared workstations, front-line or task-worker devices, school labs, reception devices, and other scenarios where the device—not the user—is the center of the deployment.
With self-deploying mode, the device connects to the internet, downloads its Autopilot profile, authenticates using TPM 2.0 attestation, joins Microsoft Entra ID, enrolls into Intune, and applies device-targeted policies and apps. There is little or no user interaction after network connectivity is established.
Important requirements and limitations:
• A physical TPM 2.0 chip and successful TPM attestation are required. • Virtual machines are not a reliable target for this mode. • Wired Ethernet provides the cleanest experience. If Wi-Fi must be used, the user or technician may need to select the network during OOBE unless connectivity is otherwise preconfigured. • Policies and apps should be device-targeted because there may be no primary user. • Kiosk, Shared PC, Edge kiosk, assigned access, and device restriction policies should be carefully tested before broad rollout.
Self-deploying mode is powerful, but it is less forgiving than user-driven deployment. Hardware compatibility, network readiness, TPM state, and Intune targeting must be validated before sending devices to production locations.
How to create or review an Autopilot profile in Intune
For classic Autopilot profiles, use the Microsoft Intune admin center and go to Devices > Windows > Windows enrollment > Windows Autopilot deployment profiles. Create or edit a profile, select the deployment mode, configure OOBE options, assign the profile to an Entra device group, and confirm that devices receive the profile before deployment.
For user-driven profiles, configure organization branding, privacy settings, account type, device naming if required, and whether users are allowed to perform certain OOBE steps. For self-deploying profiles, preconfigure as much as possible because there may be no user present to select region, keyboard, or account settings.
For Windows Autopilot device preparation, use the Windows enrollment area in Intune and create a device preparation policy. Assign it to the appropriate user group, define the required apps and scripts to track during setup, and test the deployment flow on supported Windows 11 hardware.
Whichever model you choose, avoid assigning multiple conflicting profiles to the same deployment population. Keep pilot groups small, document the expected OOBE screens, and use Intune reporting to confirm where failures occur.
Troubleshooting tips for modern Autopilot deployments
Most Autopilot issues fall into a few categories:
• Device not registered or not assigned: Confirm the device appears under Windows Autopilot devices and has the expected profile assigned. • Network blocked: Ensure the device can reach Microsoft activation, Autopilot, Intune, Entra ID, and Windows Update endpoints. • Licensing or enrollment misconfiguration: Verify Intune licensing, automatic MDM enrollment, user scope, and enrollment restrictions. • ESP timeout: Review required apps, detection rules, installation context, and reboot behavior. • TPM attestation failure: Validate firmware, TPM 2.0 status, BIOS settings, and whether the device model supports the selected scenario. • Conflicting policies: Check whether multiple configuration profiles, security baselines, scripts, or app assignments are fighting each other.
A successful Autopilot program depends as much on governance as on technology. Standardize hardware models, align procurement with device registration, pilot every major change, and maintain a clean Intune assignment structure.
Which scenario should you choose?
Choose user-driven deployment when a specific employee will sign in and use the device as their primary workstation. This is the default choice for most knowledge workers and remote employees.
Choose Windows Autopilot device preparation when you are building a new cloud-native Windows 11 user-driven process and want the newer, simplified provisioning experience.
Choose Autopilot Reset when the device is already managed and you want to clean and reassign it without losing Microsoft Entra join and Intune enrollment.
Choose self-deploying mode when the device has no primary user and must configure itself as a shared device, kiosk, lab machine, or digital sign.
Choose Microsoft Entra hybrid join only when you still have dependencies that require on-premises Active Directory during device sign-in or management. For new deployments, evaluate whether those dependencies can be removed so you can simplify with cloud-native Microsoft Entra join.
Key takeaways
- Windows Autopilot remains current for Windows 11 deployment, but terminology and best practices now center on Microsoft Intune and Microsoft Entra ID.
- User-driven deployment is still the primary scenario for employee devices, especially for remote and direct-to-user provisioning.
- Windows Autopilot device preparation is a newer option for simpler cloud-native Windows 11 user-driven deployments, while classic Autopilot profiles remain important for advanced and established scenarios.
- Autopilot Reset is best for reusing managed corporate devices; it is not the same as Wipe, Fresh Start, Retire, or Delete.
- Self-deploying mode is ideal for kiosks and shared devices but requires TPM 2.0 attestation, compatible physical hardware, and careful device-targeted Intune configuration.
Planning a Windows 11 refresh, Intune rollout, or zero-touch device deployment? IT Partner can help you design the right Autopilot approach, configure Microsoft Intune and Microsoft Entra ID, align Microsoft 365 licensing under NCE, and pilot the process before broad rollout.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.