Hi sir. Likambi, Bismarck
Thank you for contacting Microsoft Q&A community!
Here’s a comprehensive guide to configuring Windows Autopilot for deploying Windows 11 and related applications to remote users across the country:
1. Overview of Windows Autopilot
Windows Autopilot is a cloud-based deployment technology for Windows 10 and Windows 11. It enables zero-touch deployment and configuration of devices, allowing IT departments to remotely set up and configure devices with minimal end-user interaction. The only required user actions are connecting to a network and verifying credentials; everything else is automated.
2. Deployment Paths
For organizations with remote users, Windows Autopilot (modern provisioning) is recommended. It allows you to set up and configure devices remotely. You can also use the Surface Autopilot Cookbook for Cloud Solution Providers if you’re working with CSPs, or the Microsoft Surface Deployment Accelerator for image-based deployments when needed.
3. Prerequisites
- Devices must be registered as Windows Autopilot devices.
- Devices can be registered at purchase through a Surface partner or manually via the Surface Support Portal.
- Devices must have network connectivity (wired or wireless) to download the Autopilot profile and begin provisioning.
- 4. Configuration Steps
Step 1: Set Up Windows Automatic Intune Enrollment
- Configure automatic enrollment in Intune to manage devices and push applications and policies.
Step 2: Allow Users to Join Devices to Microsoft Entra ID
- Enable users to join devices to Microsoft Entra ID (formerly Azure AD).
Step 3: Register Devices as Windows Autopilot Devices
- Register devices either at purchase or manually.
- Devices are identified by a hardware hash.
Step 4: Create Device Groups
- Create device groups in Intune or Microsoft Entra ID for targeted deployment.
Step 5: Configure and Assign Windows Autopilot Enrollment Status Page (ESP)
- Set up ESP to monitor provisioning progress and ensure all required applications and policies are installed before the device is available to the user.
Step 6: Create and Assign Windows Autopilot Profile
- Configure Autopilot profiles to customize OOBE (Out of Box Experience), restrict admin account creation, and auto assign devices to configuration groups.
Step 7: Assign Devices to Users (Optional)
- Assign devices to specific users for personalized provisioning.
5. Deployment Process
Technician Flow (Pre-Provisioned Deployment)
- IT, OEM, or reseller powers on the device, connects to the network, and initiates the Autopilot process.
- Device may reboot to apply critical updates.
- OOBE begins, prompting for country/region and keyboard layout if no network connectivity.
- Once network is established, the device downloads the Autopilot profile and completes technician provisioning.
User Flow
- Device is delivered to the end user.
- User powers on the device, connects to the network, and completes OOBE.
- Device downloads the Autopilot profile, applies updates, and begins the Autopilot process.
- User signs in with Microsoft Entra credentials.
- Enrollment Status Page (ESP) tracks device preparation, setup, and account setup.
- Once ESP completes, the desktop appears and the device is ready for use.
6. Application and Policy Deployment
- Assign applications and policies to device groups and user groups in Intune.
- Ensure at least one policy and one application are assigned to both devices and users for proper testing and deployment.
7. Additional Resources
- Surface Autopilot Cookbook for Cloud Solution Providers: Step-by-step guidance for CSPs.
- Windows deployment process posters: Visual guides for deployment workflows.
For more details, refer to the documentation links and resources provided in the relevant documents. Here’s a comprehensive guide to configuring Windows Autopilot for deploying Windows 11 and related applications to remote users across the country:
- https://learn.microsoft.com/en-us/surface/windows-autopilot-and-surface-devices
- https://learn.microsoft.com/en-us/autopilot/tutorial/pre-provisioning/azure-ad-join-user-flow
- https://learn.microsoft.com/en-us/autopilot/tutorial/user-driven/azure-ad-join-deploy-device
- https://learn.microsoft.com/en-us/autopilot/tutorial/pre-provisioning/azure-ad-join-technician-flow
- https://learn.microsoft.com/en-us/autopilot/deployment-process
If you believe this information adds some value, please accept the answer so that your experience with the issue would help contribute to the whole community.
T&R!
Kate.