Architektur & Endpoint · Glossar

Windows Autopilot

Microsoft’s cloud-based deployment method for Windows devices. From the box to a ready-to-use corporate device — with no IT technician, no image and no manual setup. Zero-touch provisioning as it should be.

At a glance
2017
Erste Autopilot-Version
OEM-gebunden
Hardware-Hash-basiert
Intune
Steuerungs-Plattform
Zero-Touch
No IT intervention needed

What is Windows Autopilot?

Windows Autopilot is a Cloud-basierter Deployment-Service that turns a new Windows PC, straight out of the box, into a configured corporate device automatically. The user switches it on, signs in with their work email address — and gets a fully configured workplace with every application, policy and access right.

Autopilot replaces classic image-based deployment. No reinstalling Windows, no preparing the device, no manual handover to an IT technician.

A game changer for remote work: Autopilot makes it possible to ship devices straight from the manufacturer to someone working from home. The user unpacks, switches on and signs in — IT no longer has to prepare anything. This gained enormous importance between 2020 and 2022.

What Autopilot requires

PrerequisiteDetails
Windows 10/11 Pro, Enterprise, EducationNot the Home edition
Entra ID P1For device management features
Microsoft IntuneTo configure the devices
Hardware Hash registriertThe OEM registers the hardware identifier in the Autopilot service
Internet connectionDuring the out-of-box experience (OOBE)
An Entra-joined or hybrid-joined targetDepending on the setup

The hardware hash — the core concept

Every Autopilot-capable device is identified by a Hardware-Hash — a unique combination of serial number, TPM chip ID, product key and other hardware signatures. OEMs such as Dell, HP, Lenovo and Microsoft register this hash in the customer tenant at the point of purchase.

The different Autopilot scenarios

ScenarioWhat happens?Use
User-Driven ModeThe user signs in and becomes the device ownerThe standard — personal corporate devices
Self-Deploying ModeThe device is provisioned automatically, with no user neededKiosks, POS, Digital Signage
Pre-ProvisioningIT macht Pre-Setup, User macht nur FinalizationFast unboxing for VIPs
Existing Device AutopilotExisting PCs are made Autopilot-readyRedeploying older devices
Reset & ReuseResetting a device when the user changesMitarbeiter-Wechsel

An Autopilot setup from start to finish

Ein typischer Autopilot-User-Driven-Flow:

  1. Hardware-Kauf: IT orders the device from the OEM (Dell, HP, Lenovo). The OEM registers the hardware hash in the tenant.
  2. Versand: The device is shipped directly to the user — no stopover at IT.
  3. Unboxing: The user unpacks it and switches it on.
  4. OOBE: Windows starts the out-of-box experience and connects to the internet.
  5. Autopilot-Identifikation: From the hardware hash, Windows recognises that this device belongs to company X and shows the tailored sign-in screen.
  6. User-Login: The user enters their work email address and password; MFA follows.
  7. Enrollment: The device joins Entra ID automatically and registers in Intune.
  8. Policies & Apps: Intune pushed Compliance-Policies, Configuration Profiles, Apps (Office, Teams, LOB).
  9. Enrollment Status Page: The user sees the progress; after 15 to 30 minutes everything is ready.
  10. Ready to work: The user has a workplace ready to go.

Autopilot in the DaaS context

In short: Autopilot was originally designed for physical devices. Virtual desktops now have a path of their own:

  • Windows 365: Cloud PCs are provisioned automatically when the licence is assigned, still without a hardware hash. Since May 2026 there is also Autopilot device preparation for Cloud PCs: a Cloud PC only counts as provisioned once the apps and scripts required by policy are installed. Supported for Enterprise, Flex Dedicated, Reserve and Cloud PCs with Citrix integration
  • AVD Session Hosts: Built from gold images, not through Autopilot

The interesting combination: Autopilot plus boot-to-cloud

New since 2024 and 2025: configuring Windows 11 devices through Autopilot so that they boot straight into a Windows 365 Cloud PC. The local Windows becomes a mere launcher while the actual work runs in the cloud. It reduces the local attack surface to almost nothing.

Autopilot-Strategien in DaaS Maps

DaaS Maps shows Autopilot integration for hybrid strategies combining physical devices and Cloud PCs. For rollout questions and Autopilot migration, you will find me on LinkedIn.