Skip to content

Windows Autopilot Overview

The core use case of Windows Autopilot is to allow automatic configuration and setup of endpoints across an enterprise. Once configured, it can take a fresh out of the box copy of Windows into a user ready state with little to no intervention from IT admins. At no point should device “Imaging” be used. If done, this should be a very strict bare-bones use.

Designed for individual users who will “Own” the device. Requires login during setup. Ideal for knowledge workers, remote staff, and dedicated laptops.


FeatureUser-Driven EnrollmentSelf-Deploying / Shared Device
User PresenceRequired during setupNot required
Device AssignmentLinked to primary userDevice-level, not tied to one user
PersonalizationHigh – user-specific apps, settingsLow – apps and settings are device-wide
App DeploymentPer-userPer-device
Reset BehaviorRetains user data and configReset to default state
Use CasesDedicated devices, remote workersLabs, reception, kiosks, signage

The Enrollment status page is displayed during the Autopilot process, and delegates which apps are deployed and configures what is displayed during this process. Ideally, you would need very few ESP’s as it should be very bare-bones, and not be used to deploy a full suite of applications.

  1. ESP starts after network is established.
  2. Required apps and configurations are applied.
  3. User (or device) reaches desktop or login screen.
  • Keep ESP lightweight to avoid bloated deployment times and time outs.
  • Avoid large apps like Microsoft Office or Adobe creative cloud at this stage.
  • Focus on reporting/IT administration apps, if any during this stage.

Both Autopilot modes support reset workflows. However:

  • User-Driven: Use Autopilot Reset to reassign and reconfigure quickly.
  • Self-Deploying: Autopilot Reset is not supported. Use a full wipe instead and it it should re-enroll

The lifecycle of devices should be relatively straight forward and kept simple. By default, once onboarded into autopilot, a device should not be removed until full retirement.

  1. Device hash is uploaded during purchase/onboarding.
  2. Device is assigned and used.
  3. When reassigned or reset, Autopilot record stays in place.
  4. Only remove from Intune, Entra, and Autopilot at end-of-life.