Using Intune Autopilot to deploy and manage newly setup Windows 10 & 11 devices?

EnterpriseArchitect 2,391 Reputation points
2023-03-06T06:15:45.47+00:00

People,

I have a Hybrid Azure AD setup with Azure AD Premium P2.
The OnPremise AD DS is synched with Azure AD Connect.

The Intune license is also available from: https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/TenantAdminMenu/~/tenantStatus page.

How can I set up the Intune - Autopilot for newly purchased or set up Windows 10/11 devices for my remote workers across the globe, so they don't have to send in their laptops back to the head office?

The goal is for the remote workers with the new laptops and internet connections to achieve the below:

  • Join the AD domain MyCompany.local
  • Configure and Deploy Group Policy for company branding, etc...
  • Remotely install software

I await any help and suggestions.

Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
13,568 questions
Windows Autopilot
Windows Autopilot
A collection of Microsoft technologies used to set up and pre-configure new devices and to reset, repurpose, and recover devices.
261 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,136 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
911 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
2,371 questions
No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 22,121 Reputation points Microsoft Vendor
    2023-03-06T09:29:14.42+00:00

    @Enterprise Architect, Thanks for posting in Q&A. For your situation to deploy Autopilot Hybrid Azure AD join not in office, you can use VPN. The VPN connection either needs to be automatically established (e.g. “always on”) or it needs to be one that the user can manually initiate from the Windows logon screen.

    And the needed VPN configuration needs to be applied during device ESP.

    Here is a link with more details for your reference:

    https://oofhours.com/2020/06/23/windows-autopilot-user-driven-hybrid-azure-ad-join-over-the-internet-using-a-vpn/

    Note: Non-Microsoft link, just for the reference.

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Pavel Yannara Mirochnitchenko 7,101 Reputation points
    2023-03-06T08:21:19.8133333+00:00

    Consider carefully, do you still need Active Directory for this. Specially I would avoid using legacy AD for Computer Accounts, cloud-only would make life much easier. You could leave user accounts as hybrid with AD if you need. Also Group Policies would go away when moving to Intune.


  2. Rudy Ooms 456 Reputation points
    2023-03-06T09:29:07.6433333+00:00
    1. Try to move over from haadj to aadj for new devices... if you stick to haadj you need to make sure you configure all the requirements to enroll a device with autopilot to your ad and azure/intune
    2. Move over from haadj to aadj for new devices :P ....you don't want to end up in a world of pain when you want to use haadj and autopilot :)