How to Setup Windows Autopilot in Microsoft Intune
Dec 18, 2024
Imagine a PC that configures itselfâno manual setups or IT intervention required. With Microsoft 365's Autopilot, itâs a reality!
Autopilot can automatically configure your laptops and PCs with all the software that you need, and even better, it can configure them with all the relevant settings.
In this guide, Iâm going to walk you through setting up Autopilot and explore its features. As always, for a more detailed walkthrough, make sure to head over to my YouTube channel for this video and for more Microsoft 365 tutorials and tips.
Without further ado, letâs get started.
Licensing Requirements
Now, youâre likely already thinking: âThis sounds great, but very expensiveâ. Iâm pleased to tell you that Autopilot is very affordable.
All you need is an Entra ID plan, one license or, I recommend purchasing a Microsoft 365 business premium license which includes Autopilot.
And, once youâve sorted that out, itâs onto the good stuff, utilising Autopilot across the board so that you and your colleagues can work smarter, not harder
Create Entra ID Groups
Before I delve into Autopilot, itâs handy to get prepared. So, in the next steps Iâm going to explain how to create Entra ID groups and take a look at branding for a more personalised experience.
- Login into the Microsoft 365 admin centre as global admin. For this step, you'll need the relevant permissions to log into your own Microsoft 365.
- The first thing to do is create a group. This group is going to be the group that all the devices I want to Autopilot fit into. So, in the Microsoft Azure portal, click on âMicrosoft Entra IDâ, displayed across the top bar. If you canât see it, use the âSearchâ bar at the top of the page.
- Once opened, under âManageâ, click âGroupsâ. And, here youâll see all of your groups. Click on âCreate New Groupâ and change âGroup Typeâ to âSecurityâ. Name the group anything youâd like.
- Under âMembership Typeâ, select âDynamic Deviceâ. This will allow you to then automate as much as possible. Select the âOwnersâ and the next step is to add dynamic queries. Click onâ Add Dynamic Queryâ.
- In my demo video, I show how to add all Windows 11 devices to the group, but Autopilot works across various operating systems. So, click on the dropdown menu âPropertyâ and select âDevice OS Typeâ, then the dropdown menu âOperatorâ and select âEqualsâ and then in the Value box, type âWindowsâ.
- Once youâve done this, click âAdd expressionâ and then repeat the above steps but add in the operating code for Windows 11. You can be as specific as you need to be, but for showcasing how this works, I stick with a Windows operating system.
- Before saving the group, click on âValidate Rules (Preview)â which will show which devices will go into the group, based on the expressions selected.
- . Click on â +Add devicesâ. Select the devices you want to add to the Entra ID group, and then click âvalidateâ. Youâll see green ticks next to each to confirm theyâre included. You can then save the group. Now, any other Windows 11 devices added will automatically go into the dynamic group.
Company Branding
The next thing I want to show you is company branding. Itâs a great way to brand experiences for your users with a lot of different options.
- Go back to âHomeâ and click on âEntra IDâ and then âCompany Brandingâ.
- Click on âEditâ and youâll be brought to a selection of default sign-in options to choose from, as well as other types of personalisation. Choose the branding settings youâd like to implement for your users.
- Be sure to edit the âsign-in textâ with a personalized message, this is a nice touch your colleagues will appreciate.
Add Hardware Hash to Intune
You might be asking âwhat even is a hardware hash?â, well every laptop or PC in the world has a unique hardware identifier, known as a hardware hash. In the next steps, Iâm going to show you a couple of ways to add hardware hashes manually to Intune.
- Via the Microsoft manual for manually registering a deviceâs hardware hash, if you scroll down you will find âPowershellâ and an accompanying script that you can run. If you click on âcopyâ, then launch Microsoft Powershell as an Administrator, you can add in the coded script, which copies over a csv file into your drive.
- Head over to your Local Disk (C) and you will be able to open your own PCâs hardware hash data.
Alternative Steps
- Go to âHomeâ on your PC, and âAccountsâ. Click on âAccess work or schoolâ, then âExport your management log filesâ and click âExportâ.
- Head over to your Local Disk (C), click âUsersâ, âPublicâ, âPublic Documentsâ, âMDMDiagnosticsâ, and youâll find the âMDMDiagReportâ click into that and you should see a device hash.
Importing to Intune
- Go to the 365 Admin centre and click into âEndpoint Managerâ. Once launched, click on âDevicesâ, then click on âEnrollmentâ under âDevice Onboardingâ.
-
At the bottom of the page, youâll see a section titled âWindows Autopilotâ. Click on âDevicesâ to start managing Windows Autopilot Devices.
- Click on âImportâ. Go to the folder in your Onedrive and open the device hash data. It might take a few minutes. Refresh the page, and you should see your device added.
Create Deployment Profiles
This next step dictates how the devices using Autopilot are configured. You should by this point, have your device set up as per the previous steps.
-
You will see that âProfile Statusâ is âNot Assignedâ. Youâll need to go back to the âEnrollmentâ step and under âWindows Autopilotâ located towards the bottom of the page, you will see an option named âDeployment Profilesâ, click into this.
- Next, you want to click on â+ Create profileâ. You can name this whatever you want, for example âSales Department Profileâ. Leave the âConvert all targeted devices to Autopilotâ as âNoâ. Then click on âNextâ, which will bring you a page of further settings known as âOut-of-box experience (OOBE)â.
- I prefer to leave the âDeployment modeâ setting as âUser-Drivenâ. For âJoin to Microsoft Entra ID asâ box, select âMicrosoft Entra joinedâ. Leave the âMicrosoft Software License Termsâ and âPrivacy Settingsâ hidden. I also hide âChange account optionsâ and change âUser account typeâ to âStandardâ. Select âNoâ for âAllow pre-provisioned deploymentâ.
-
You can also change the region too, so that itâs relevant for the user. Click âYesâ for âAutomatically configure keyboardâ and âYesâ for âApply device name templateâ. An example will pop up to help you to create a unique name for your device. Once named, click on âNextâ and you can âAdd groupsâ created earlier, then âNextâ and âCreateâ.
- Refresh the page and youâll see the profile youâve created is visible. Go to âWindows Autopilot Devicesâ and click the refresh button. You will see that the PC added is now assigned to the deployment profile.
How to Install Applications using Autopilot
In this next section, Iâm going to talk you through the steps to ensure that Microsoft Office, Google Chrome, and ensure OneDrive is configured for your users.
Microsoft Office
- Click âAppsâ, âAll appsâ. Next, click â+Addâ and youâll see a dropdown menu displaying all of the available apps you can add. Scroll down to âWindows 10 and laterâ then click âSelectâ.
- A new page will open with options, click âNextâ. You will then be presented with some further options, select the options that are relevant/youâd like to change and again, click âNextâ.
- Click on âRequireâ and âincludedâ, you can then select the users that youâd like to have the app. Once youâve done this, click on âNextâ.
- This will bring you to the âreview and createâ page, select âcreateâ.
Google Chrome
- Google âGoogle standalone enterprise versionâ. This will bring you to a page where you can download the Chrome browser for Windows. Make sure to click the âmsiâ version and download Chrome.
- Once downloaded, follow the same steps as before, except for when selecting app type choose âline-of-business appâ. This will bring you to the âAdd appâ page where you can add in the package file.
-
Follow the same steps as before through to âreview and create, then select âcreateâ.
Configure OneDrive & SharePoint Settings
Another great thing to do with Autopilot, is to ensure that everyone has access to easily download OneDrive and Sharepoint too. Let me show you howâŚ
- Once youâre back in the Microsoft 365 admin centre, under âAdmin centersâ, click âSharepointâ. Click into the Sharepoint site, in âDocumentsâ, click âsyncâ, âcancelâ, and âCopy Library IDâ.
- Paste the ID into a word document, using the Powershell command. Copy the command and open Powershell, click âRun as Administratorâ and paste the command. Powershell will then give you another little output which you need to copy.
- Go back into Endpoint Manager, go to âDevicesâ, under âManage Devicesâ click âConfigurationâ, click âPoliciesâ, then âCreate a new policyâ.
- Select the relevant platform, make sure that the profile type is âSettings catalogâ, then click âCreateâ
- Name the profile, click âNextâ, and âAdd settingsâ, scroll down to find OneDrive. Under OneDrive scroll down, configure âteam site librariesâ to âsync automaticallyâ, which will appear on the left-hand side. I also suggest selecting âSilently move Windows known folder to OneDriveâ, âSilently sign in users to OneDriveâ, âUse OneDrive Files On-Demandâ, enable them all.
- Under âConfigure team site libraries to sync automaticallyâ, add in the user, add in the data copied earlier from Powershell so it will sync. Click âNextâ, then under âScope tagsâ choose âAll usersâ and âAll devicesâ. Then, click âCreateâ and refresh the pageâ.
Testing Autopilot
The final step is to test everything out, to make sure itâs all working as it should be. I used a Windows 11 virtual PC to do this. Hereâs the steps you need to follow:
- Go into âSettingsâ and âSystemâ, then âRecoveryâ. Reset the PC.
- Once the PC has restarted, you should see a bit of the company branding settings you added earlier and a âSign inâ option. Login as the user.
-
After youâve signed-in, you should see the apps installed automatically. If you click into OneDrive, you should also see that it is signed-in automatically. You can also check this in File Explorer, where OneDrive should automatically be signed-in.
- If you go into the back-end, you should also see that Shared Drive has automated too.
Final Thoughts
Windows Autopilot in Microsoft Intune revolutionises how devices are deployed, reducing IT workloads and creating a seamless user experience. By following these steps, you can configure devices effortlessly, ensuring theyâre ready for work with minimal intervention.
I hope that youâve enjoyed this tutorial and for more 365 advice, you can reach out to Integral IT at hello@integral-it.co.uk or visit www.integral-it.co.uk.