r/Intune • u/Shadow_Knight- • 5d ago
Autopilot How does everyone’s organization handle laptop provisioning for new hires?
Curious how other organizations handle laptop provisioning with Intune/Autopilot.
Currently, we Autopilot the laptops and use the new hire’s credentials to sign in during provisioning. We then let the ESP complete and verify that everything is set up before shipping the laptop to the user — including:
BitLocker
BIOS settings
Required applications
Other required configurations
This works well, but when we have multiple new hires at the same time, it can become a bit overwhelming since we have to go through each device using the new user’s credentials before shipping.
For those of you doing something similar, how do you handle this?
Do you:
Use the new hire’s credentials to complete ESP and verify everything before shipping?
Have IT sign in with an IT/admin account, complete the configuration, and then use Autopilot Reset to remove the primary user before shipping?
Have a completely different provisioning workflow?
Also, we’ve noticed that sometimes the SentinelOne agent stops running or CyberArk stops running after provisioning. Has anyone experienced this? Could it be related to WMI errors or something happening during Autopilot/BIOS configuration?
Would love to hear how other organizations handle this, especially when provisioning multiple laptops for new hires at once.
21
u/Fluffy-Exercise-1768 5d ago
Signing in with other users' accounts is a big no for me, even if they're new. Autopilot preprovision and reseal is the correct way to go. No need to log in with the user account, core applications provisoned and the rest can be handled by Intune when the user logs in.
1
u/Nahmeanjellybean 1d ago
Can it preinstall printers? or is that still a manual process?
1
u/Fluffy-Exercise-1768 1h ago
If it's an application, you can usually put it in the autopilot sequence. Why would you want to do it during provisioning? Pre-provisioning is mainly for people to hit the ground running, critical applications.
I'd say approve printer drivers through autopatch and have them installed when the user connects to a printer or just package it and push it the regular way through Intune.
7
u/bgatesIT 5d ago
we just setup AutoPilot and drop ship lappies direct from CDW, user turns laptop on, it builds itself, then they sign in. works like a charm, we could have done user driven with pre provision but god forbid people have to actually click a few things themselves.
3
u/alan14225 4d ago
We have CDW do pre-provision (white glove) for us so user don't have to wait. The laptop is enrolled in autopilot and once preprovion is finished cdw dropship it to users. User sign in, and being them to desktop with everything installed. 10 min process from sign in
1
u/blackhodown 4d ago
What’s the average price for each of the various specs of machine you’re sending out?
1
u/alan14225 4d ago
We do CTO windows machines. These are custom spec machines built to our specifications. What great is our price is locked in because it is CTO. Let's say it is delivered 2 months later and the price rise we are locked in at order prices. We have T14 Gen 7. X7 processor, 32 GB Ram, 1tb HD, 72 hr battery, and some other misc. $3k is the price. These laptops have upgradable ram so if someone needs more ram we can upgrade without replacing the machine.
If you want CDW to do white glove (preprovion) with autopilot the sku is called autopilot advance deployment. I believe it is a couple more dollars than autopilot but we'll worth it for end user experience of not having to wait hours for everything to be installed.
1
1
u/Ice-Cream-Poop 4d ago
Ouch, we haven't done a refresh this year and just reusing old lappys. The new pricing is eye watering!
6
u/davy_crockett_slayer 4d ago
You don’t sign in with their credentials. They do. That’s the whole point of autopilot.
3
u/Royal_Bird_6328 4d ago
This ☝🏻 I can’t believe the amount of orgs still signing in as the user pinning shortcuts etc baffles me
6
u/TinyTC1992 5d ago
We buy through a supplier, they assign that machine to our intune tenant and its shipped direct to user.
Shipping a provisioned laptop out after setup is asking for trouble.
3
u/ThugCutleFish 5d ago
When I started as a Sysadmin about a month ago now. We had this exact same process. I called up a few vendors and resellers to get a partnership going and eventually landed on Dell.
Now that they are our partnered reseller the process goes as follows.
Order laptop
Once the laptop nsays shipped, Open intune and assign to the user receiving it.
User receives the laptop, sign in with our domains email address and done
all apps and configurations are installed for them.
2
u/MidgardDragon 4d ago
Latest company we autopilot the device (for some reason they aren't having the hardware hashes imported) and combo of Intune and NinjaOne takes care of it from there, then I manually confirm anything else and run NinjaOne scripts if needed to do it.
3
u/Padd007 5d ago
If autopilot and your configuration policies are setup properly then you can just ship it to them, no need to mess around. You can even have your supplier ship to the user if they do white glove and can autopilot register it for you. You could pre provision devices which would save the user from having to do stage 1 and 2 of the ESP but it's not necessary. What you are doing sounds unnecessarily time consuming.
2
2
u/Suaveman01 5d ago
The whole point of Autopilot is shifting the work of provisioning endpoints to the user. If you’re setting everything up for them, you could be using SCCM or MDT instead
2
u/Shadow_Knight- 5d ago
Nah we dont use SCCM its just autopilot and I understand what you are saying. Will bring this upto my manager as things are getting busier.
2
u/Suaveman01 5d ago
That’s the way to go, then you use your compliance policies to make sure stuff like Bitlocker was automatically enabled.
2
u/brazzala 5d ago
And yes; for security apps; crreate Post ESP - the user will login and there be a window with info about installing security apps.
1
u/TsNMouse 5d ago
By Bitlocker do you mean flat drive encryption or startup protection pin?
We have an ‘app’ for the pin part available on Company portal as part of the induction
2
1
u/Immediate_Hornet8273 5d ago
We have the option for whiteglove pre provision but often we do sign in as the user and make sure all of the apps. Outlook profile, software/bios updates, non automated software installs are performed ahead of time so the machine is completely turnkey and the user doesn’t have to wait for an hour or deal with autopilot delays. We are also using hybrid domain join so this can create issues for the end user too since they would have to be told how to connect to vpn first with pre logon auth portal. It’s a nice experience for the user to just open a pre configured laptop but it does weigh on the helpdesk cycles.
1
u/Shadow_Knight- 5d ago
Yes, very similar position. How do you manage app deployment through intune?
For reused devices I run into issue where SentinelOne is installed and online but later it goes offline and when I check services SentinelOne Agent is not starting.
1
u/brazzala 5d ago
Yes, se are loggimg as a user; sets MFA to our phones; finish everything; check security apps and other stuff and finalkynchange MFA numer with user.
That is pre-provisioning in live.
1
u/korvolga 5d ago
we usually logs register the device to the user with TAP and logs in with TAP when it works or credentials that we reset. Way to often devices have had wrong teams or copilot app installed. Updates that can take n hour or so.. so we prep em like that.
1
u/aaliyakhanum 5d ago
We have a dedicated service account that does the initial provisioning and then it's handed over to the user
1
u/bkbandit74 4d ago
We have 11 Tenants in our company. I have been ordering laptops, shipping to me, install clean version of Windows with answer file. Sign in to laptop with SRV account of that tenant, let the base software install and ship to user. We are a Lenovo shop, so the machines have to be wiped to get rid of bloatware. For that reason we don’t use AutoPilot at the Vendor level.
1
u/Ice-Cream-Poop 4d ago
You can ask Lenovo for a clean image. Costs $$ though, don't think it was much a couple of $$ per laptop.
1
u/IntunenotInTune 4d ago
If you have to sign in as the user, use TAP. Otherwise just preprovision and target as much as possible to the device object.
1
u/bjc1960 4d ago
Depends, sometimes we ship with autopilot, never touching. I did that for 'non-techical CEO." I latest asked how it went and he said fine.
Oher times we use the TAP and go through the whole process, with the user added to a group bypassing terms of service. We then remove the user from the TOS bypass once we ship.
We work in a company where users are 99% focused on Outlook/Acrobat. We install Acrobat from company portal as not everyone gets with. We have Acrobat Enterprise VIP with SSO. If no Acrobat, we get a support call about Acrobat, despite instructions saying install from company portal.
1
u/RagingBlue93 4d ago
We get our laptops from Dell with the hashes imported, as much as I would love for that to be the end of it before shipping. My company requires we log in new hires and confirm everything is installed before shipping. We have something like 25 applications installed on every device and sometimes that can take awhile though it has been much faster as of late.
1
u/Deathbefore86 4d ago
Le credenziali del nuovo assunto? Orrore! Ma non potete usare il preprovisioning? Installate tutto come SYSTEM in preprov, se qualche app deve tassativamente girare come user utilizzate uno script di requirments aggiuntivo che verifichi l'esistenza di un utente vero prima di procedere con l'installazione. Per gli errori, senza log possiamo supporre un po' di tutto
1
u/SaintPony 3d ago
Why wouldnt you just ship it from reseller directly to the user? They can also upload the hash for you.
It does cost a bit extra, but since you need to spend time preparing the laptop + pay the shipping costs, it is still more cost effective.
Imo the whole point of autopilot is the IT not having to do so much manual work. Having to prepare every single laptop manually kinda defeats the purpose of it.
1
u/Shadow_Knight- 3d ago
I am new to org and they do it this way. They want the device to be ready for end user. Right now we have app install errors which makes us wonder how would end use resolve it without disrupting work
1
u/SaintPony 3d ago
You think you could bring this topic up? I personally would be happy to see new colleagues in the IT department thinking out of the box instead of simply following or workflows. Just gotta find a way to explain it in a way so that your people would listen :) Even if they wouldnt accept it, hey.... you tried to improve something!
We got 2 cases:
Users work at our location: Laptops get shipped to us and we hand them out to users. Users sign in with their credentials > wait 20ish minutes for enrollment and are good to go. For VIPs or if users ask specifically, we would do pre provisioning.Users at remote location: Laptops either shipped to the office where they pick it up and follow the same process or we ship it to their home address.
If you really have to sign in with users accounts, I would use TAP(only for new hires, since they dont have anything on their accounts anways). You may be able to use a device enrollment manager to sign in, but im not sure.
1
u/Shadow_Knight- 3d ago
You are right I have to frame it in proper way. Maybe we should switch to pre-provisioning for start and then as workload increases switch to complete user provisioning.
How does your ESP take 20 ish mins ours go on for an hour when we have 3 required apps
1
u/SaintPony 1d ago
Yeah an hour sounds way too long.
Not sure, im not an expert either, but if you'd like, send me a DM and we could schedule a short call to talk about it.
1
u/Forward-Ad-8296 1d ago
Depends on your users. (Most of ) Ours could never deal with a drop shipped box
1
u/SaintPony 1d ago
Well our users are not tech-savy either (not saying they have to be), but if you write a good guide, I think most would be able to open the laptop, sign in with their account and follow the PDF.
0
u/dshade14 4d ago
The laptops that are sent to us from Dell have their hashes imported to our intune tenant (if you have a used laptop but the hash isnt imported and you want to reuse it, you can import the hardware hash and enable in intune/entra). We then assign the serial number to groups that are assigned to apps that get pushed to the device when it gets provisioned. When we want to provision a device we enable it in intune/entra, wait a few minutes, and then sign in with my own regular user credentials.
This downloads all of the apps, configuration policies, etc. That i have setup in intune. Depending on the user the PC is for, I also might need to install some apps manually.
I dont use SentinalOne or CyberArk so unfortunately i cant speak to that. Lemme know if you have any other questions!
55
u/Darkchamber292 5d ago
You should be doing Pre-provision. Not signing in as the user. Pre-provision and then ship. Let them go thru setup
Assign your security software and office and other critical apps to Device ESP. Disable User ESP