Endpoint management
Autopilot
Windows Autopilot
Windows Autopilot is Microsoft's zero-touch device provisioning service. It configures new or repurposed Windows devices for corporate use straight out of the box, or after a factory reset, without IT staff ever imaging the device manually or a user having to complete a technical setup process themselves.
Why Autopilot matters in a Microsoft estate
Autopilot matters for endpoint teams because device, app, compliance, update, and troubleshooting signals often sit across several Microsoft admin areas. Linking these terms back to Intune and device-reporting routes helps readers move from definition to action.
How Autopilot shows up in practice
A device's hardware identity, its hardware hash, is registered against the organisation's tenant, either by the OEM or reseller at point of purchase, through a partner integration, or manually by IT for devices already in the estate. From that point forward, whenever that specific device reaches Windows Setup, Autopilot recognises it and applies a tenant-branded, pre-configured out-of-box experience: joining Entra ID, enrolling in Intune, applying assigned configuration profiles, compliance policies, and required applications. In Autopilot's white-glove and pre-provisioning modes, it completes most or all of that provisioning before the device ever reaches the end user, so a new starter can unbox a laptop, sign in with their own credentials, and be working within minutes rather than waiting for IT to image and configure the machine first.
This is the mechanism that makes shipping devices directly from a reseller or OEM to a remote or hybrid employee's home practical without a security compromise. The device only becomes usable and compliant once it authenticates against the tenant and receives its assigned policy, rather than arriving pre-loaded with a static image that immediately falls out of date. Autopilot depends entirely on the hardware hash being registered correctly before the device ships, which is the single most common point of failure in practice.
A device that reaches an employee without its hash registered, or registered against the wrong tenant, falls back to a generic out-of-box experience with no policy applied, requiring either manual re-provisioning or a return to IT. This is a frequent friction point when device procurement and Autopilot registration are handled by different teams or different vendors without a reliable handoff process. Autopilot profiles, which control naming conventions, user account type, whether the privacy and licence agreement screens are skipped, and deployment mode, are assigned per Entra ID dynamic or static group.
A stale or overly broad group assignment is a common cause of a device receiving the wrong profile, most visibly when a device intended for one department's self-deploying kiosk profile ends up applying a standard user-driven profile instead. Autopilot resets, "Wipe and reuse device with Autopilot for existing devices," reprovision a device already in the estate back to a fresh state while keeping its existing Autopilot registration and Intune enrolment intact. This is the standard mechanism for reassigning a device to a new user without a full manual rebuild, though it works reliably only when the device's original Autopilot and Intune records are clean. Stale or duplicate device records are the same recurring housekeeping issue here as elsewhere in the Intune estate.