Customers can purchase devices from resellers, distributors, or other partners. As long as these resellers, distributors, and partners are part of the Cloud Solution Partners (CSP) program, they too can register devices for the customer.
As with OEMs, CSP partners must be granted permission to register devices for an organization. This process is described in the CSP authorization section of the Windows Autopilot customer consent article. In summary:
The CSP partner requests a relationship with the organization. That organization's Global Administrator approves the request.
After the approval, CSP partners add devices using Partner Center, either directly through the web site or via available APIs that can automate the same tasks.
Windows Autopilot doesn't require delegated administrator permissions when establishing the relationship between the CSP partner and the organization. As part of the Global Administrator's approval process, they can choose to uncheck the Include delegated administration permissions checkbox.
Important
Microsoft recommends using roles with the fewest permissions. Using lower permissioned accounts helps improve security for an organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when an existing role can't be used.
Tip
While resellers, distributors, or partners could boot each new Windows device to obtain the hardware hash for purposes of providing them to customers or direct registration by the partner, this method isn't recommended. Instead, these partners should register devices using the PKID information obtained from the device packaging, such as the barcode, or obtained electronically from the OEM or upstream partner/distributor.
Note
Partner Center doesn't have access to profiles created in Intune or Microsoft Store for Business. It only has access to the Autopilot profiles created through Partner Center.
This module teaches education partners how to enroll devices with Intune for Education and Autopilot. This module is part of the Partner Success Series.
Plan and execute an endpoint deployment strategy, using essential elements of modern management, co-management approaches, and Microsoft Intune integration.