Deploy Windows Autopilot device preparation in Nerdio Manager

This article explains how to configure and deploy Windows Autopilot device preparation for Windows 11 devices using Nerdio Manager for MSP (NMM). It uses NMM's solution baselines, group templates, and policy management to push the required Microsoft Entra ID, Intune, and Windows Autopilot settings to one or more customer tenants in bulk, so you don't need to sign in to each customer's Microsoft 365 environment individually to configure device enrollment.

About Windows Autopilot device preparation

Windows Autopilot device preparation is a re-architecture of Windows Autopilot provisioning, designed to set up and configure new Windows 11 devices for productive use without the hardware-hash-based registration step that the original Windows Autopilot requires. It uses a capability Microsoft calls enrollment time grouping: instead of pre-registering individual devices, a user's sign-in during first-run setup adds their device straight into a security group, and the applications, scripts, and policies assigned to that group deploy immediately.

Note

Windows Autopilot device preparation is an improved and expanded version of the original Windows Autopilot - effectively Windows Autopilot v2. Some example variable names in this article use "Autopilot v2" as a shorthand to distinguish Autopilot device preparation from the original Windows Autopilot.

A typical device's journey through Windows Autopilot device preparation follows this flow:

  • During the out-of-box experience (OOBE) - the first-run setup screens a user sees when a new or reset Windows device starts for the first time - the user signs in with their Microsoft Entra ID credentials. Personal devices are allowed to go through this flow unless you explicitly restrict them (see Important notes).

  • The device joins Microsoft Entra ID and automatically enrolls into Intune, Microsoft's mobile device management (MDM) service, because the tenant's MDM scope is set to apply to all devices.

  • The Intune Provisioning Client - a built-in Microsoft Entra service principal - adds the device to the target device security group as soon as the device enrolls. This is the "enrollment time grouping" step and is what lets apps and policies start deploying immediately, rather than waiting for a slower dynamic group to re-evaluate membership.

  • The Intune Management Extension installs the applications and PowerShell scripts assigned to that device group, in the order and priority you configured.

  • The user sees a simplified setup screen showing percentage progress; once the apps and scripts you marked as required finish installing, the user reaches the Windows desktop. 

  • Any remaining apps, scripts, or policies assigned to the device group continue to install in the background after the user reaches the desktop.

How this differs from the original Windows Autopilot

The following table summarizes the practical differences between the original, hardware-hash-based Windows Autopilot and Windows Autopilot device preparation.

Area

Windows Autopilot

Windows Autopilot device preparation

Device registration

Requires a hardware hash, collected via an OEM CSV file or a PowerShell script run on the device.

No hardware hash or pre-registration required.

Policies involved

Typically three to four: an Autopilot deployment profile, an Enrollment Status Page profile, a deployment configuration, and dynamic group rules.

A single device preparation policy.

Targeting

Device-based; devices must be pre-registered before they can be targeted.

User-based; the device joins its security group automatically during OOBE when an authorized user signs in.

Grouping

Manual, after enrollment, or via dynamic group rules that take time to evaluate.

Automatic, at enrollment time (enrollment time grouping).

Administrative overhead

Higher - requires IT involvement to collect hashes and pre-register devices.

Lower - scalable and self-service for end users.

Licensing

Included with supported Intune/Microsoft Entra ID licenses.

Included with the same supported Intune/Microsoft Entra ID licenses - see Licensing.

Note

A device that is already registered as a Windows Autopilot device takes precedence over a Windows Autopilot device preparation policy if the device isn't associated with the tenant. Don't run both against the same device without first unassigning or deregistering the existing Windows Autopilot profile - see Important notes.

Why use Nerdio Manager to deploy Windows Autopilot device preparation

Every setting Windows Autopilot device preparation needs - Entra join scope, automatic Intune enrollment, enrollment restrictions, and the Intune Provisioning Client - normally has to be configured one customer tenant at a time in the Microsoft 365 admin portals. Nerdio Manager's solution baselines let you define these settings once and push them, in Report-only or Enforce mode, to every customer account assigned to the baseline - without having to open each customer's own Microsoft environment.

Prerequisites

Before you begin, confirm the following for each customer tenant you plan to deploy Windows Autopilot device preparation to.

Licensing

The customer tenant needs at least one of the following licenses, which include both Microsoft Entra ID and Intune entitlements:

  • Microsoft 365 Business Premium

  • Microsoft 365 F1, F3, E3, or E5

  • Microsoft 365 Academic A1, A3, or A5

  • Enterprise Mobility + Security E3 or E5

  • Intune for Education

  • Microsoft Entra ID P1 or P2, paired with Intune

See the licensing tab of Windows Autopilot device preparation requirements on Microsoft Learn for Microsoft's own, current list of qualifying licenses.

Microsoft Intune tenant settings

Confirm these two tenant-wide settings in the Microsoft Intune admin center before enrolling any devices. The Nerdio solution baseline in Stage 1 can set both of these for you across customer tenants, but it's worth understanding what they do.

Setting

Location (Microsoft Intune admin center)

Required value

Why it matters

MDM user scope

Devices > Enrollment > Automatic Enrollment

All

Enables automatic Intune enrollment for every Microsoft Entra-joined device. Without this, devices won't enroll during OOBE.

Personally owned Windows (MDM) devices

Devices > Enrollment > Enrollment restrictions > the default All Users platform restriction

Allow

Windows Autopilot device preparation's user-driven enrollment initially registers devices as personally owned. Blocking personally owned Windows devices prevents the device preparation flow from completing, even on a device the organization actually owns.

Windows version requirements

  • Windows 11, version 22H2 or 23H2 with update KB5035942 or later installed. Verify the installed version from the device by running winver, or check it through your RMM. Builds earlier than KB5035942 don't support device preparation policies. (Windows 11, version 24H2 and later already meet this requirement and don't need the update.)

  • Microsoft Entra ID join only - Microsoft Entra hybrid join is not supported. Verify a device's join state by running dsregcmd /status and checking the Device State section; if DomainJoined shows YES alongside AzureAdJoined, the device is hybrid-joined and Windows Autopilot device preparation will not work on it.

Important notes

  • No hardware hash is required for Windows Autopilot device preparation, but that also means the tenant is open to personal device enrollment by default. If you need to restrict enrollment to organization-owned hardware, configure Intune's corporate identifiers feature. see the Microsoft Learn article Identify devices as corporate-owned for details.

  • Don't run Windows Autopilot device preparation against a device that's already registered for the original Windows Autopilot - its profile takes precedence while the device remains unassociated with the tenant. Unassign any existing Windows Autopilot deployment profile first, from Home > Devices > Windows Autopilot deployment profiles in the Microsoft Intune admin center.

Procedure

Configuring Windows Autopilot device preparation for a customer through Nerdio Manager involves the following stages. Stages 2 and 3 are optional, depending on how you want to scope which users can enroll devices.

Stage 1: Configure the Intune solution baseline in Nerdio Manager

The solution baseline pushes the enrollment and provisioning settings Windows Autopilot device preparation needs to every customer account assigned to it, in bulk - removing the need to configure each tenant individually in the Microsoft 365 admin portals.

Tip

Set each setting below to Report-only first and review the results before switching it to Enforce, so you can confirm the baseline will apply the configuration you expect before it takes effect.

  1. In Nerdio Manager, go to Solution Baselines > Intune and open (or create) the baseline you'll assign to the customer account.

  2. Work through the baseline's tabs and configure each of the settings listed in the table below, selecting Enforce (or Report-only while you're still validating) for each one.

Each tab in the solution baseline wizard presents its settings with the same Enforce / Report-only / Exclude choice alongside every option, as shown below for the General Enrollment tab's Microsoft Entra join setting.

windows_autopilot1.png

The remaining settings for Windows Autopilot device preparation follow the same pattern across the wizard's other tabs:

Baseline tab

Setting

Value

Purpose

General Enrollment

Entra (device join scope)

All

Opens device registration so any authorized user can join a device to Microsoft Entra ID during OOBE. Without this, the device can't register and enrollment fails at the first step.

Windows

Automatic Enrollment

All

Ensures every Microsoft Entra-joined device automatically enrolls into Intune. This is the MDM scope setting from Prerequisites; without it, devices join Microsoft Entra ID but never appear in Intune.

Enrollment restrictions

Windows (MDM) - Personally owned

Allow

Windows Autopilot device preparation registers devices as personally owned during user-driven enrollment. Blocking this causes enrollment to be rejected before the device preparation policy ever runs.

Enrollment restrictions

Remove existing enrollment restrictions

Enabled

Clears legacy or custom MDM restrictions that could otherwise conflict with device preparation - for example, leftover Windows Autopilot platform blocks or device-limit overrides.

Prerequisites

Intune Provisioning Client

Enforce

Creates the Intune Provisioning Client service principal that performs enrollment time grouping - the mechanism that automatically adds devices to the target security group during OOBE. Without it, devices enroll but never receive the apps or policies assigned to the device group.

Note

Setting Intune Provisioning Client to Enforce is usually all that's needed to create the service principal - see Stage 2 to confirm it was created.

Stage 2 (optional): Confirm the Intune Provisioning Client service principal exists

The solution baseline in Stage 1 normally creates the Intune Provisioning Client service principal automatically. Use this stage only to double-check, or to troubleshoot if a later stage can't find it.

  1. In the Microsoft Entra admin center, use the global search bar to search for Intune Provisioning Client.

  2. Confirm it appears under Enterprise applications with a Type of Service principal.

  3. If it's missing, return to Nerdio Manager > Solution Baselines > Intune, confirm Intune Provisioning Client is set to Enforce, and reprocess the baseline.

Stage 3 (optional): Create a user assignment group template

Skip this stage if you're targeting All Users for enrollment. Otherwise, this group determines which users can trigger Windows Autopilot device preparation - only users in this group (or in All Users) see the device preparation policy during OOBE.

  1. In Nerdio Manager, go to Group Templates and select Add new group template.

  2. Configure the template:

    1. Group name - for example, Autopilot_V2_UsersGroup.

    2. Group type: Security.

    3. Membership type: Assigned.

    4. Set a naming template and duplicate-handling behavior as needed for your environment.

  3. Save the template and assign it to the customer account.

Stage 4: Create the device group and assign the Intune Provisioning Client as owner

This group is where devices land during enrollment.

Important

The Intune Provisioning Client must be an owner of this group - this is the single most critical configuration for Windows Autopilot device preparation to work. Without it, enrollment time grouping has no permission to add the device to the group.

Create the group using either option below, then add the owner using the steps that follow both options.

Option A: Create the group as a Nerdio group template
  1. In Nerdio Manager, go to Group Templates and select Add new group template.

  2. Configure the template: name it (for example, Autopilot_V2_DeviceGroup), set the group type to Security, and set the membership type to Assigned.

  3. Save the template and assign it to the customer account.

Option B: Create the group directly in Microsoft Entra
  1. In the Microsoft Entra admin center, go to Groups and select New group.

  2. Enter a group name (for example, Autopilot_V2_DeviceGroup).

  3. Set Group type to Security.

  4. Select Create.

Add the Intune Provisioning Client as owner (both options)
  1. In the Microsoft Entra admin center, open the device group you just created.

  2. Go to Owners and select Add owners.

  3. Search for Intune Provisioning Client and add it.

  4. Confirm the Owners list now shows Intune Provisioning Client with a Type of Service principal.

Note

This device group is the one you'll select in the device preparation policy in Stage 6. Without the Intune Provisioning Client as its owner, enrollment will fail.

Stage 5: Assign apps and scripts to the customer account

Important

Complete this stage before creating the device preparation policy in Stage 6 - the policy can only offer apps and scripts that are already assigned to the customer account.

  1. In Nerdio Manager, go to Unified Catalog and deploy the required apps to the customer account at the MSP level.

  2. Go to Windows Scripts, choose the relevant RMM script, and update it with the configuration this customer needs.

  3. Assign the script to the customer account.

Stage 6: Create the device preparation policy in Microsoft Intune

Create this policy directly in Microsoft Intune - not in Nerdio Manager. If your organization maintains a reusable NMM JSON template for this policy, you can import that instead of creating the policy from scratch.

  1. In the Microsoft Intune admin center, go to Devices > Windows > Enrollment, then under Windows Autopilot device preparation select Device preparation policies.

    windows_autopilot2.png
  2. Select Create and configure the policy:

    1. Name - for example, [ALL][APV2] Device Preparation Policy.

    2. Description - add as needed for your organization's conventions.

    3. Device group: the group you created in Stage 4.

    4. Deployment settings: Single user, User-driven, Microsoft Entra joined, Standard user.

    5. Out-of-box experience timeout: 60 minutes or more before showing an installation error.

    6. Custom error message - for example, "Contact your organization's support for help."

    7. Allow users to skip setup after multiple attempts: Yes.

    8. Show link to diagnostics: Yes.

    9. Apps and scripts: select the apps and scripts assigned to the account in Stage 5 (up to 10 total).

    10. Assignments: add the user group from Stage 3, or All users.

    11. Select Save.

Note

The device preparation policy targets users, not devices. When a targeted user signs in during OOBE, their device is added to the device group automatically - you don't assign devices to the policy directly.

Result

The policy's summary page confirms all of the above settings together.

windows_autopilot3.png

Stage 7: Import the device preparation policy into Nerdio Manager

Importing the policy brings it under Nerdio Manager's policy management so you can include it in a policy baseline and reuse it for other customers.

  1. In Nerdio Manager, go to Autopilot Profiles and select Import.

  2. Select Autopilot Device Preparation Policy as the policy type.

  3. Select the name of the policy you created in Stage 6 and select Select.

  4. Add a tag and a version-control name for the import.

  5. Select Evaluate User/Group Assignments so the assigned groups are shown as part of the import.

  6. Select Import.

  7. Confirm the policy now appears in Nerdio Manager with a Source of Custom (imported).

Stage 8: Create a policy baseline for scaling to other customers

A policy baseline packages the imported device preparation policy - along with any other related policies - so you can assign the whole set to additional customer accounts without repeating the previous stages.

  1. In Nerdio Manager, go to Policy Management > Policy Baselines.

  2. Create a policy baseline - for example, [ALL][INTUNE][CFG] APV2 Provisioning.

  3. From the baseline's dropdown menu, select Edit Policies.

  4. Select Add Policies.

  5. Filter by the tag you used in Stage 7, or search directly, to find the device preparation policy and any other related policies to include.

  6. Select Ok, then Apply and Close.

At this point you have a standardized, reusable set of configuration - the solution baseline, the group templates, the device preparation policy, and the policy baseline - ready to assign to other customer accounts.

Stage 9: Pilot the deployment

Before assigning the policy baseline to the customer's full user population, run it against a single test user and device to confirm every earlier stage is wired together correctly.

  1. Confirm the test device is a qualifying Windows 11 device (see Prerequisites) and that it isn't already registered as a Windows Autopilot device - if it is, remove or deregister that registration first, since a Windows Autopilot registration takes precedence over the device preparation policy.

  2. Confirm the test user has a qualifying license assigned (see Licensing) and is covered by the device preparation policy's assignment - either because they're in the user group from Stage 3, or because the policy is assigned to All users.

  3. Start or reset the test device so it boots to OOBE, and sign in with the test user's Microsoft Entra ID credentials when prompted.

  4. Let the device preparation progress screen run to completion. The apps and scripts marked as required in the policy should install, and the user should reach the Windows desktop.

  5. In the Microsoft Intune admin center, go to Devices > Monitor and, under Report name, select Windows Autopilot device preparation deployments.

  6. Select the test device and confirm its details: the signed-in user (UPN), its Microsoft Entra device ID, the deployment policy name and version it received, and the install status of each assigned app and script. A status of Skipped for an app or script usually means it's selected in the policy but isn't actually assigned to the device group from Stage 4.

  7. In the Microsoft Entra admin center, confirm the test device was added as a member of the device group from Stage 4 - this confirms enrollment time grouping worked as expected.

  8. Once the pilot succeeds, assign the policy baseline from Stage 8 to the rest of the customer's users and devices.

See Windows Autopilot device preparation reporting and monitoring on Microsoft Learn for the full list of fields the deployment report shows and what each one means.

Result

The customer account now has Windows Autopilot device preparation fully configured. A user who signs in with their Microsoft Entra ID credentials during OOBE on a qualifying Windows 11 device is joined to Microsoft Entra ID, enrolled in Intune, added to the device security group, and receives the assigned apps and scripts - without any hardware-hash registration or per-tenant manual configuration.

Related information

  • If the Intune Provisioning Client solution baseline setting doesn't create the service principal automatically, you can add it as a group owner manually using the steps in Stage 4.

  • Consider using Nerdio variables for contact information (such as a support phone number or email address) in the device preparation policy's custom error message, so it updates automatically if that information changes.

  • Overview of Windows Autopilot device preparation (Microsoft Learn)

  • Windows Autopilot device preparation FAQ (Microsoft Learn)

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.