First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Intune Initial Setup for Windows Autopilot & Zero-Touch Deployment
Implementation

Microsoft Intune Initial Setup for Windows Autopilot & Zero-Touch Deployment

Microsoft Intune Initial Setup for Windows Autopilot & Zero-Touch Deployment is a fixed-fee add-on that makes new Windows PCs deploy themselves: the device ships from the vendor straight to the employee, and Autopilot plus your Intune foundation turn it into a fully configured, policy-compliant workstation at first sign-in. IT Partner selects the right Autopilot path for your fleet — classic Autopilot or the newer Autopilot device preparation — configures the deployment experience, sets up device registration, validates on pilot devices, and stays available for one month of post-implementation support. It extends the foundation built by Microsoft Intune Initial Setup for Windows Device Management.

Timeline 3 weeksService owner Roman SotnikOffice 365microsoft 365

What this engagement is

Every hand-configured laptop costs you an IT hour and a shipping detour. Windows Autopilot removes both: the vendor ships the sealed box to the employee, the employee signs in, and the device configures itself against the Intune baseline you already trust — no image, no bench, no detour through the office. This add-on builds the zero-touch deployment layer on your Intune foundation. IT Partner selects the right Autopilot path for your estate — classic Autopilot or Autopilot device preparation — configures the deployment profile or device preparation policy, the provisioning status experience, and device naming and grouping conventions, establishes the device registration process with your hardware vendor, collects hardware identifiers for existing pilot devices where the classic path requires them, and validates the full unbox-to-desktop experience on pilot devices before production rollout guidance and handoff. This service belongs to our Intune family and requires the Windows management foundation from Microsoft Intune Initial Setup for Windows Device Management — Autopilot deploys devices into the policies and applications that foundation defines. The Android and iPhone & iPad add-ons extend the same tenant to mobile, and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices defends the fleet Autopilot deploys. Who this is for: US commercial organizations of roughly 100–500 seats on the Microsoft cloud that buy corporate-owned Windows PCs and want them shipped directly to employees. Who it is not for: estates without an Intune foundation (build that first), or fleets needing kiosk, self-deploying, or hybrid-join scenarios in the first phase — each is separately scoped on top of this design. The engagement includes one month of post-implementation consulting and support after the pilot is validated.

Success criteria

01The Autopilot path decision — classic Autopilot or Autopilot device preparation — is documented with its rationale in the approved implementation plan.
02Your tenant is configured to support the selected Autopilot path end to end: registration, deployment configuration, provisioning status experience, and naming and grouping conventions.
03A device registration process is established with your hardware vendor for production devices, and hardware identifiers are collected for the agreed existing pilot devices where the classic path requires them.
04Every agreed pilot device completes the unbox-to-desktop experience: the user powers on, connects, signs in with a work account, and receives the foundation's policies and applications with no hands-on IT setup.
05A reset-and-redeploy test returns a representative pilot device to the expected Autopilot experience.
06Your administrators can register a future device, monitor deployment status, and troubleshoot a failed provisioning run using the delivered runbook, and the one-month post-implementation support period has started.

What you receive

Autopilot readiness assessment and path decision: device fleet and Windows versions, join requirements, vendor registration options, and the classic-vs-device-preparation recommendation with rationale.
Project plan and schedule agreed at kickoff.
Configured deployment experience for the selected path: a user-driven Microsoft Entra join Autopilot deployment profile with Enrollment Status Page, or an Autopilot device preparation policy with its deployment status experience and enrollment-time grouping.
Device naming and group-tag conventions, with user assignment to specific devices where the design calls for it.
Device registration process established with your hardware OEM, reseller, or CSP for production devices, plus collected hardware identifiers for the agreed existing pilot devices where the classic path requires them.
Pilot validation: test device deployment and lifecycle — deploy, reset, redeploy — with issues found in scope corrected.
Production deployment monitoring guidance and use-case documentation for the scenarios validated in the pilot.
Administrator runbook: registering future devices, monitoring deployment status, and first-line troubleshooting of failed provisioning runs.
Project closeout report with acceptance criteria evidence and any outstanding items, followed by one month of post-implementation consulting and support.

How the work unfolds

Week 1 — Kickoff, readiness, and path decision

Confirm objectives, fleet composition, and vendor relationships. Verify the Intune foundation, select classic Autopilot or Autopilot device preparation based on your devices and join requirements, and approve the plan.

Weeks 1–2 — Deployment configuration and registration

Configure the deployment profile or device preparation policy, the provisioning status experience, and naming and grouping conventions. Establish vendor registration for production devices and collect hardware identifiers for pilot devices where required.

Weeks 2–3 — Pilot validation and remediation

Deploy the agreed pilot devices through the full unbox-to-desktop experience, run the reset-and-redeploy lifecycle test, and correct in-scope configuration issues.

Week 3 — Handoff and support start

Deliver the runbook and use-case documentation, review rollout recommendations and the closeout report, and open the one-month post-implementation support period.

Prerequisites

An Intune-managed Windows foundation — established through Microsoft Intune Initial Setup for Windows Device Management, an existing equivalent Intune deployment, or a concurrent implementation. Autopilot deploys devices into that foundation's policies and applications.
Licensing that provides Microsoft Intune and Microsoft Entra ID P1 or P2 for the affected users — Microsoft 365 Business Premium, Microsoft 365 E3/E5, or Enterprise Mobility + Security E3/E5 all qualify. Licensing costs are not included.
Sufficient administrative rights in the Microsoft Intune admin center and Microsoft Entra portal for the agreed tasks.
Devices supported by Microsoft for the selected Autopilot path. Classic Autopilot supports Windows 10 and Windows 11 Pro, Pro Education, Pro for Workstations, Enterprise, and Education editions; Autopilot device preparation requires Windows 11 22H2 or 23H2 with the March 2024 update (KB5035942) or later, or 24H2 and later.
A hardware OEM, reseller, or CSP able to register production devices to your tenant where the classic path is selected — or physical access to pilot devices for manual hardware-identifier collection.
Network access from deployment locations to the Microsoft endpoints Autopilot requires, per Microsoft's published requirements, without a blocking captive portal.
Between one and five representative pilot devices that can be reset to the Windows out-of-box experience, with your authorization to erase each after data is backed up.
A client project owner who can provide decisions, vendor coordination, and pilot users within the three-week schedule.

Who does what

IT Partner

  • Lead the readiness assessment, path decision, implementation plan, pilot, and acceptance review.
  • Configure the deployment profile or device preparation policy, provisioning status experience, and naming and grouping conventions for the selected path.
  • Establish the device registration process and collect hardware identifiers for the agreed pilot devices where required.
  • Coordinate with your hardware provider to obtain the information production registration requires.
  • Validate the pilot deployment and lifecycle, troubleshoot in-scope issues, and document results.
  • Deliver the runbook, use-case documentation, closeout report, and one month of post-implementation consulting and support.

Your team

  • Provide and maintain the required Microsoft licensing, supported devices, and vendor relationships.
  • Provide administrative access and timely decisions on the path, naming, grouping, and pilot population.
  • Coordinate the hardware OEM, reseller, or CSP for production device registration.
  • Provide pilot devices, back up their data, authorize resets, and make pilot users available for the unbox-to-desktop validation.
  • Own network and firewall changes at deployment locations that remain your responsibility.
  • Review deliverables and approve acceptance within the agreed schedule.

What's not included

The Intune foundation itself — Windows enrollment, the security baseline, and application deployment are the separate service Microsoft Intune Initial Setup for Windows Device Management, which this add-on requires.
Other Autopilot scenarios — self-deploying and kiosk modes, pre-provisioning (white glove), Microsoft Entra hybrid join, and Autopilot for existing devices via Configuration Manager task sequences are each separately scoped.
Device and data migration — moving local documents and settings off old PCs (OneDrive and SharePoint migration is its own engagement), Windows edition or version upgrades, and support for out-of-support Windows versions.
Fleet logistics — organization-wide hands-on enrollment beyond the pilot, physical staging, warehousing, labeling, shipping, firmware work, and on-site presence (available by request, invoiced separately).
Commercial items — hardware, Microsoft licensing and subscription costs, end-user training beyond the administrator handoff, support beyond the included one month, and anything not expressly listed as included. More extensive documentation is available for an additional fee.

Limitations & technical notes

!Zero-touch means no custom image and no IT bench setup — the user still powers on the device, connects to the internet, and signs in with a work account; Autopilot and Intune do the rest.
!Advance device registration applies to the classic Autopilot path, where OEM, reseller, or CSP registration is the scalable production method and manual hardware-identifier collection is reserved for the pilot and small exceptions. The device preparation path registers devices dynamically at sign-in and needs no advance registration.
!If a device is registered with classic Autopilot and also receives a device preparation policy, the classic Autopilot profile takes precedence — mixed estates are designed deliberately, not by accident.
!Provisioning time varies with device performance, network bandwidth, Microsoft service availability, and application payload; no fixed per-device time is guaranteed.
!The three-week schedule assumes the Intune foundation is ready, vendor cooperation on registration, pilot devices available for reset, and timely client decisions.
!The fixed fee covers the selected deployment path, the agreed pilot, and the documented registration process. Additional scenarios, personas, or fleet rollout require a written, approved change in scope.
!Technical content reviewed August 2026.

Frequently asked questions

Which Autopilot path is right for us — classic Autopilot or Autopilot device preparation?

Windows Autopilot now has two paths, and choosing correctly is the first deliverable of this engagement. Autopilot device preparation (often called Autopilot v2) needs no hardware-hash registration: devices register dynamically when the user signs in, which removes the biggest logistics burden of classic Autopilot. It supports Microsoft Entra join only, user-driven and Windows 365 modes only, uses enrollment-time grouping so configuration lands immediately, has its own deployment status experience instead of the Enrollment Status Page, supports up to 25 managed apps and 10 scripts per policy, and requires Windows 11 22H2 or 23H2 with the March 2024 update (KB5035942) or later, or 24H2 and later. Classic Autopilot remains required for Microsoft Entra hybrid join, pre-provisioning (white glove), self-deploying and kiosk modes, Windows 10 devices, reset and existing-device flows, and richer Enrollment Status Page control. Most estates will run both side by side through 2026 — we pick the path (or the split) during the readiness assessment and document why.

How does this service relate to the rest of the Intune family?

Microsoft Intune Initial Setup for Windows Device Management is the required foundation — it defines the policies and applications Autopilot deploys devices into. This add-on builds the zero-touch deployment layer on top. The Android and iPhone & iPad add-ons extend the tenant to mobile, and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices adds detection and response across the managed fleet.

Do we need Intune before this service?

Yes. Autopilot is a deployment mechanism, not a management platform — a zero-touch deployment is only as good as the baseline it deploys into. If your devices are not yet Intune-managed, start with Microsoft Intune Initial Setup for Windows Device Management; we can schedule the two back-to-back so Autopilot lands the week the foundation is verified.

Can new PCs really ship straight from the vendor to the employee?

Yes — that is the production model this service establishes. With classic Autopilot, your OEM, reseller, or CSP registers each device to your tenant before shipment. With Autopilot device preparation, no advance registration is needed at all. Either way, the employee unboxes the PC, connects to the internet, signs in with a work account, and the device configures itself.

Can our existing PCs use Autopilot?

They can, with planning. Existing devices must be registered (we collect hardware identifiers for the agreed pilot devices) and returned to the Windows out-of-box experience, which normally means a reset that erases local data. The pilot includes a reset-and-redeploy lifecycle test; mass conversion of an existing fleet and data migration are separately scoped.

How much does the service cost, and how long does it take?

The fee is fixed per project — see the price on this page — for the selected deployment path, the agreed pilot, the documented registration process, and one month of post-implementation support. The three-week schedule is elapsed calendar time paced by vendor registration and client decisions. Fleet-wide rollout beyond the pilot is quoted separately, sized to your device count.

What licensing do we need?

Users need Microsoft Intune and Microsoft Entra ID P1 or P2 capabilities — Microsoft 365 Business Premium, Microsoft 365 E3/E5, and Enterprise Mobility + Security E3/E5 all qualify. We verify entitlement during readiness; you purchase and assign all subscriptions.

What happens after the three weeks?

You have a validated zero-touch pipeline, the registration process with your vendor, the runbook, and one month of included consulting and support for questions that come up as production devices start flowing. Natural next steps, each separately scoped: additional Autopilot scenarios (pre-provisioning, kiosk, self-deploying), the mobile add-ons, and Defender for Endpoint across the fleet.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,300 per project
3 weeks
Book an Autopilot scoping call