2. Traditional Windows deployment // The old way
Build a custom image,
gathering everything else
that’s necessary to deploy
Time means money, making
this an expensive proposition
Deploy image to a new
computer, overwriting what
was originally on it
DRIVERS POLICIES
OFFICE & APPS
SETTINGS
3. Modern Windows deployment // The new way
Un-box and turn on
off-the-shelf Windows PC
Device is ready
for productive use
Transform with minimal
user interaction
4. Key Benefits:
No more maintenance of images and drivers
No need for IT to touch the devices
Simple process for users and IT
Integration in the device supply chain
Reset device back to a business ready state
Device lifecycle management
with Windows Autopilot and
Intune
Business ready
Break fix
Retirement
Management
Procurement Deployment
5. OEM-optimized Windows 10
+ Software
+ Settings
+ Updates
+ Features
+ User data
Ready for productive use
The transformation
11. OEMs, distributors, and resellers make the process easy:
• Automatically add new devices to Azure tenant at time of
shipment
• Associate devices to customer’s purchase order for easy device
grouping
• Tag devices with a customer specified label
• Provide an preinstalled image that is ready for configuration*
For a list of those supporting Windows Autopilot supply
chain integration please visit:
https://aka.ms/WindowsAutopilot
Registering new devices
Supply chain integration
12. If you have existing Windows 10 devices:
• Enable new Autopilot profile setting for all targeted devices
• Ensure the Autopilot profile is assigned to a group containing the
existing Windows 10 devices
If your existing Windows 10 devices are not yet Intune-
managed:
• Enable co-management with ConfigMgr via the “Automatic
enrollment into Intune” setting. (See https://docs.microsoft.com/en-
us/sccm/core/clients/manage/co-management-overview#enable-co-management)
• Ensure all new Intune-enrolled Windows 10 devices are part of a
group with an assigned Autopilot profile
Registering existing devices
Automatically for all Intune-managed Windows 10 devices
13. To register existing devices:
• Use the PowerShell script available at
https://www.powershellgallery.com/packages/Get-
WindowsAutoPilotInfo
• Run for each device (requires Windows 10 1703 or higher)
• Upload resulting CSV file via Intune portal
• See https://docs.microsoft.com/en-
us/windows/deployment/windows-autopilot/add-
devices#collecting-the-hardware-id-from-existing-devices-
using-powershell for more information
Great for testing and validation with existing devices and
virtual machines
Registering existing devices
Manually for existing devices
15. Configure important details:
• Deployment mode
• Specific settings required for the deployment
mode
• New! BitLocker encryption even for non-admin users
(requires Windows 10 1809)
• Out-of-box experience (OOBE) settings
• New! Hide change account options (requires Windows 10
1809)
• New! Device naming pattern, supporting variable
substitution (requires Windows 10 1809):
• %SERIAL%
• %RAND:x% (where X is the number of digits)
Creating an Autopilot profile
16. If you have existing Windows 10 devices:
• An Azure AD device object is automatically created for each imported
Autopilot device
• Create one or more Azure AD groups
• Assign an Autopilot profile to the Azure AD group
• Intune will automatically assign the profile to all members of the assigned
group
Options for grouping:
• Dynamic group with all Autopilot devices
• Dynamic group based on purchase order ID
• Dynamic group based on device tag (orderID)
• Manual
Assigning an Autopilot profile
Automated using groups
21. Windows Autopilot overview
Configure
Windows
Autopilot profile
Self-service
deploy
DeviceIDs
Hardware Vendor
IT Admin
Ship
Deliver direct to Employee
Employee unboxes
device, self-deploys
Intune
Windows Autopilot
Device sync
Autopilot profile sync
22. Windows 10 version 1703 or higher
One of the following, to provide needed Azure Active Directory (automatic MDM
enrollment and company branding features) and MDM functionality:
https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/windows-autopilot-
requirements-licensing
24. Ensure policies, apps and settings are
complete prior to the end user gaining
access to the desktop
Confirm minimum baseline requirements
Protect data during device set up
Deliver a compliant secure device
Personalize the out of box experience
New! Unlock Windows 10 in S mode (requires Windows 10 1809)
Requirements
Windows 10, version 1803 (with May cumulative update or later)
Azure Active Directory Premium
Microsoft Intune
Windows Autopilot
Enrollmentstatuspage
28. AVAILABLE in 1809
AVAILABLE in 1809
AVAILABLE in 1809
AVAILABLE in 1809
AVAILABLE
AVAILABLE
Windows Autopilot Scenarios
User-driven mode
Windows 10 1703
and above
Join device to Azure
AD, enroll in
Intune/MDM
Windows Autopilot
for existing devices
Windows 10 1809
and above
Windows 7 to
Windows 10
ConfigMgr task
sequence, followed
by Windows
Autopilot user-driven
mode
Self-deploying
mode
Windows 10 1809
and above
No need to provide
credentials,
automatically joins
Azure AD
Hybrid Azure AD
join
Windows 10 1809
and above
Join device to AD,
enroll in Intune/MDM
Windows Autopilot
reset - local
Windows 10 1709
and above
Execute a device reset
via a local keystroke,
maintaining Azure AD
join and MDM
enrollment
Windows Autopilot
reset - remote
Windows 10 1809
and above
Execute a device reset
via Intune and
maintain Azure AD
join and MDM
enrollment
30. Windows Autopilot User-Driven Mode
Pre-requisites
Windows 10 version 1703 or higher
For the maximum functionality, use the latest Windows 10 release
One of the following, to provide needed Azure Active Directory (automatic MDM
enrollment and company branding features) and MDM functionality:
Microsoft 365 Business subscriptions
Microsoft 365 F1 subscriptions
Microsoft 365 Enterprise E3 or E5 subscriptions, which include all Windows 10, Office 365, and EM+S
features (Azure AD and Intune)
Enterprise Mobility + Security E3 or E5 subscriptions, which include all needed Azure AD and Intune
features
Azure Active Directory Premium P1 or P2 and Intune subscriptions (or an alternative MDM service)
See https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/windows-
autopilot-requirements-licensing for more information
31. Design notes
Should be done by the end user
User authenticates with Azure AD from the start
Choose between admin and non-admin
Typically for single-user (not shared) devices
32. It should be as easy as
Registering your device with Autopilot
Assigning a User-Driven Autopilot Profile using Intune
Connecting to a network and booting your device
Authenticating with user credentials
33.
34. Simple process to prepare a device for a different purpose:
Remove all apps, settings, and personal files
Preserve Azure Active Directory join and MDM enrollment so the device
is still managed
Preserves provisioning packages
Keeps keyboard, language, wi-fi settings*
Takes 20-30 minutes to complete on typical hardware
Windows Autopilot Reset
(previously Windows Automatic Redeployment)
Local
• Windows 10 1709 and above
• Initiated by an admin via
Windows-Control-R
keystroke from lock screen
Remote
• Windows 10 1809 and above
• Initiated remotely via Intune
38. Design notes
Technicians usually set up these types of devices
No defined user to auth or set up the device
May not have peripherals (keyboards, mice, etc.)
Typically involve “walk up and use” scenarios
39. It should be as easy as
Registering your device with Autopilot
Assigning a Self-Deploying Autopilot Profile using Intune
Connecting to a network and booting your device
40.
41.
42. Windows Autopilot overview
Configure
Windows
Autopilot profile
Self-service
deploy
DeviceIDs
Hardware Vendor
IT Admin
Ship
Deliver direct to Employee
Employee unboxes
device, self-deploys
Intune
Windows Autopilot
Device sync
Autopilot profile sync
43. Windows Autopilot Self-Deploying Mode
Pre-requisites
Windows 10 version 1809 or higher running on a device with TPM 2.0
One of the following, to provide needed Azure Active Directory (automatic MDM
enrollment and company branding features) and MDM functionality:
Microsoft 365 Business subscriptions
Microsoft 365 F1 subscriptions
Microsoft 365 Enterprise E3 or E5 subscriptions, which include all Windows 10, Office 365, and EM+S
features (Azure AD and Intune)
Enterprise Mobility + Security E3 or E5 subscriptions, which include all needed Azure AD and Intune
features
Azure Active Directory Premium P1 or P2 and Intune subscriptions (or an alternative MDM service)
See https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/windows-
autopilot-requirements-licensing for more information
47. Design notes
Upgrading the OS is just part of the problem
Need to migrate user data from Win7 to Win10
Unable to harvest hardware hashes in Win7
48. Here’s how it works
Deploy group policy to redirect Known Folders to OneDrive
Generate Autopilot Reuse configuration file
Deploy Task Sequence to upgrade to Windows 10
Windows 10 machine goes through Autopilot on first boot
49.
50. Windows Autopilot for existing devices
Prerequisites:
Windows 10 1809 and above
Azure Active Directory Premium
Microsoft Intune
System Center Configuration Manager current branch (TBD)
Steps:
1. Create task sequence to deploy generic Windows 10 image
with needed drivers (wipe-and-load)
2. Migrate data to OneDrive for Business (in advance)
3. Deploy task sequence to existing Windows 7 devices, installing
Windows 10 and proceeding through Windows Autopilot user-
driven process to join device to Azure AD