Microsoft Intune Initial Setup for Windows Autopilot & Zero-Touch Deployment
Microsoft Intune Initial Setup for Windows Autopilot & Zero-Touch Deployment is a fixed-fee add-on that makes new Windows PCs deploy themselves: the device ships from the vendor straight to the employee, and Autopilot plus your Intune foundation turn it into a fully configured, policy-compliant workstation at first sign-in. IT Partner selects the right Autopilot path for your fleet — classic Autopilot or the newer Autopilot device preparation — configures the deployment experience, sets up device registration, validates on pilot devices, and stays available for one month of post-implementation support. It extends the foundation built by Microsoft Intune Initial Setup for Windows Device Management.
What this engagement is
Every hand-configured laptop costs you an IT hour and a shipping detour. Windows Autopilot removes both: the vendor ships the sealed box to the employee, the employee signs in, and the device configures itself against the Intune baseline you already trust — no image, no bench, no detour through the office. This add-on builds the zero-touch deployment layer on your Intune foundation. IT Partner selects the right Autopilot path for your estate — classic Autopilot or Autopilot device preparation — configures the deployment profile or device preparation policy, the provisioning status experience, and device naming and grouping conventions, establishes the device registration process with your hardware vendor, collects hardware identifiers for existing pilot devices where the classic path requires them, and validates the full unbox-to-desktop experience on pilot devices before production rollout guidance and handoff. This service belongs to our Intune family and requires the Windows management foundation from Microsoft Intune Initial Setup for Windows Device Management — Autopilot deploys devices into the policies and applications that foundation defines. The Android and iPhone & iPad add-ons extend the same tenant to mobile, and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices defends the fleet Autopilot deploys. Who this is for: US commercial organizations of roughly 100–500 seats on the Microsoft cloud that buy corporate-owned Windows PCs and want them shipped directly to employees. Who it is not for: estates without an Intune foundation (build that first), or fleets needing kiosk, self-deploying, or hybrid-join scenarios in the first phase — each is separately scoped on top of this design. The engagement includes one month of post-implementation consulting and support after the pilot is validated.
Success criteria
What you receive
How the work unfolds
Confirm objectives, fleet composition, and vendor relationships. Verify the Intune foundation, select classic Autopilot or Autopilot device preparation based on your devices and join requirements, and approve the plan.
Configure the deployment profile or device preparation policy, the provisioning status experience, and naming and grouping conventions. Establish vendor registration for production devices and collect hardware identifiers for pilot devices where required.
Deploy the agreed pilot devices through the full unbox-to-desktop experience, run the reset-and-redeploy lifecycle test, and correct in-scope configuration issues.
Deliver the runbook and use-case documentation, review rollout recommendations and the closeout report, and open the one-month post-implementation support period.
Prerequisites
Who does what
IT Partner
- Lead the readiness assessment, path decision, implementation plan, pilot, and acceptance review.
- Configure the deployment profile or device preparation policy, provisioning status experience, and naming and grouping conventions for the selected path.
- Establish the device registration process and collect hardware identifiers for the agreed pilot devices where required.
- Coordinate with your hardware provider to obtain the information production registration requires.
- Validate the pilot deployment and lifecycle, troubleshoot in-scope issues, and document results.
- Deliver the runbook, use-case documentation, closeout report, and one month of post-implementation consulting and support.
Your team
- Provide and maintain the required Microsoft licensing, supported devices, and vendor relationships.
- Provide administrative access and timely decisions on the path, naming, grouping, and pilot population.
- Coordinate the hardware OEM, reseller, or CSP for production device registration.
- Provide pilot devices, back up their data, authorize resets, and make pilot users available for the unbox-to-desktop validation.
- Own network and firewall changes at deployment locations that remain your responsibility.
- Review deliverables and approve acceptance within the agreed schedule.
What's not included
Limitations & technical notes
Frequently asked questions
Which Autopilot path is right for us — classic Autopilot or Autopilot device preparation?
Windows Autopilot now has two paths, and choosing correctly is the first deliverable of this engagement. Autopilot device preparation (often called Autopilot v2) needs no hardware-hash registration: devices register dynamically when the user signs in, which removes the biggest logistics burden of classic Autopilot. It supports Microsoft Entra join only, user-driven and Windows 365 modes only, uses enrollment-time grouping so configuration lands immediately, has its own deployment status experience instead of the Enrollment Status Page, supports up to 25 managed apps and 10 scripts per policy, and requires Windows 11 22H2 or 23H2 with the March 2024 update (KB5035942) or later, or 24H2 and later. Classic Autopilot remains required for Microsoft Entra hybrid join, pre-provisioning (white glove), self-deploying and kiosk modes, Windows 10 devices, reset and existing-device flows, and richer Enrollment Status Page control. Most estates will run both side by side through 2026 — we pick the path (or the split) during the readiness assessment and document why.
How does this service relate to the rest of the Intune family?
Microsoft Intune Initial Setup for Windows Device Management is the required foundation — it defines the policies and applications Autopilot deploys devices into. This add-on builds the zero-touch deployment layer on top. The Android and iPhone & iPad add-ons extend the tenant to mobile, and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices adds detection and response across the managed fleet.
Do we need Intune before this service?
Yes. Autopilot is a deployment mechanism, not a management platform — a zero-touch deployment is only as good as the baseline it deploys into. If your devices are not yet Intune-managed, start with Microsoft Intune Initial Setup for Windows Device Management; we can schedule the two back-to-back so Autopilot lands the week the foundation is verified.
Can new PCs really ship straight from the vendor to the employee?
Yes — that is the production model this service establishes. With classic Autopilot, your OEM, reseller, or CSP registers each device to your tenant before shipment. With Autopilot device preparation, no advance registration is needed at all. Either way, the employee unboxes the PC, connects to the internet, signs in with a work account, and the device configures itself.
Can our existing PCs use Autopilot?
They can, with planning. Existing devices must be registered (we collect hardware identifiers for the agreed pilot devices) and returned to the Windows out-of-box experience, which normally means a reset that erases local data. The pilot includes a reset-and-redeploy lifecycle test; mass conversion of an existing fleet and data migration are separately scoped.
How much does the service cost, and how long does it take?
The fee is fixed per project — see the price on this page — for the selected deployment path, the agreed pilot, the documented registration process, and one month of post-implementation support. The three-week schedule is elapsed calendar time paced by vendor registration and client decisions. Fleet-wide rollout beyond the pilot is quoted separately, sized to your device count.
What licensing do we need?
Users need Microsoft Intune and Microsoft Entra ID P1 or P2 capabilities — Microsoft 365 Business Premium, Microsoft 365 E3/E5, and Enterprise Mobility + Security E3/E5 all qualify. We verify entitlement during readiness; you purchase and assign all subscriptions.
What happens after the three weeks?
You have a validated zero-touch pipeline, the registration process with your vendor, the runbook, and one month of included consulting and support for questions that come up as production devices start flowing. Natural next steps, each separately scoped: additional Autopilot scenarios (pre-provisioning, kiosk, self-deploying), the mobile add-ons, and Defender for Endpoint across the fleet.