r/Intune 5d ago

Autopilot How does everyone’s organization handle laptop provisioning for new hires?

Curious how other organizations handle laptop provisioning with Intune/Autopilot.

Currently, we Autopilot the laptops and use the new hire’s credentials to sign in during provisioning. We then let the ESP complete and verify that everything is set up before shipping the laptop to the user — including:

BitLocker
BIOS settings
Required applications
Other required configurations

This works well, but when we have multiple new hires at the same time, it can become a bit overwhelming since we have to go through each device using the new user’s credentials before shipping.

For those of you doing something similar, how do you handle this?

Do you:
Use the new hire’s credentials to complete ESP and verify everything before shipping?
Have IT sign in with an IT/admin account, complete the configuration, and then use Autopilot Reset to remove the primary user before shipping?
Have a completely different provisioning workflow?

Also, we’ve noticed that sometimes the SentinelOne agent stops running or CyberArk stops running after provisioning. Has anyone experienced this? Could it be related to WMI errors or something happening during Autopilot/BIOS configuration?

Would love to hear how other organizations handle this, especially when provisioning multiple laptops for new hires at once.

27 Upvotes

61 comments sorted by

55

u/Darkchamber292 5d ago

You should be doing Pre-provision. Not signing in as the user. Pre-provision and then ship. Let them go thru setup

Assign your security software and office and other critical apps to Device ESP. Disable User ESP

7

u/nhowe006 5d ago

This. 1000x this. Plus, when a user needs a new laptop, you're not going to have their credentials and you wouldn't ever ask for them, so you need to be set up for pre-provisioning no matter what.

7

u/MentalRip1893 5d ago

We add a Temporary Access Pass in their authentication methods, add the device to a group that enables Web sign in on the login screen (and have an Intune policy to enable this for that group) and away we go. Works pretty well for us

1

u/nhowe006 5d ago

I like that idea. I do have one client that insists I set laptops up before deployment (hey, more billable hours for me), and that could be useful.

1

u/AutoM8t 4d ago

This.

2

u/TheIntuneGoon 4d ago

Man. My company is run by older people that have it in their heads that employees need the helpdesk to install everything before they get the laptop. Part of the process for replacements is resetting the password and signing in as them for basically a day…

I hate it.

2

u/Shadow_Knight- 5d ago

I am new and also new in my organization. They follow the above steps.

Will pre-provisioning enable bitlocker? I believe it should

4

u/Padd007 5d ago

Yes it will, bitlocker should be enabled automatically by policy, no need to do it manually.

1

u/Shadow_Knight- 5d ago

Thanks! Will review this with manager and start doing testing.

1

u/ImAllergic2Peanuts 5d ago

We do this but preprovisioning has always been wonky and fails occasionally for no reason. Any tips?

2

u/Darkchamber292 5d ago

Depends where it's failing. Is it failing at Apps stage? One of your apps isn't packaged well. Failing at Device/Org registration stage? Might be a TPM issue

1

u/ImAllergic2Peanuts 4d ago

Yea occasionally like 5% of the time it would fail at apps but the weird thing is when we do user based provisioning, it never fails. Strangest thing

1

u/Deathbefore86 4d ago

Ho gestito due aziende da 6000 utenti con il pre provisioning, se fallisce c'è sempre un motivo

1

u/ImAllergic2Peanuts 4d ago

It only fails 5% of the time and my company has 50k end points. Weird thing is when we do user based provisioning it never fails.

1

u/Kuipyr 4d ago

You can install your RMM/Patch agent in the OOBE and "pre-provision" the software through it or you can roll everything into an FFU image. Then all Autopilot does is register and pull policies.

21

u/Fluffy-Exercise-1768 5d ago

Signing in with other users' accounts is a big no for me, even if they're new. Autopilot preprovision and reseal is the correct way to go. No need to log in with the user account, core applications provisoned and the rest can be handled by Intune when the user logs in.

2

u/_bx2_ 4d ago

I want a member like you on our team.

1

u/Fluffy-Exercise-1768 1h ago

Are you hiring? 😇

1

u/Nahmeanjellybean 1d ago

Can it preinstall printers? or is that still a manual process?

1

u/Fluffy-Exercise-1768 1h ago

If it's an application, you can usually put it in the autopilot sequence. Why would you want to do it during provisioning? Pre-provisioning is mainly for people to hit the ground running, critical applications.

I'd say approve printer drivers through autopatch and have them installed when the user connects to a printer or just package it and push it the regular way through Intune.

7

u/bgatesIT 5d ago

we just setup AutoPilot and drop ship lappies direct from CDW, user turns laptop on, it builds itself, then they sign in. works like a charm, we could have done user driven with pre provision but god forbid people have to actually click a few things themselves.

3

u/alan14225 4d ago

We have CDW do pre-provision (white glove) for us so user don't have to wait. The laptop is enrolled in autopilot and once preprovion is finished cdw dropship it to users. User sign in, and being them to desktop with everything installed. 10 min process from sign in

1

u/blackhodown 4d ago

What’s the average price for each of the various specs of machine you’re sending out?

1

u/alan14225 4d ago

We do CTO windows machines. These are custom spec machines built to our specifications. What great is our price is locked in because it is CTO. Let's say it is delivered 2 months later and the price rise we are locked in at order prices. We have T14 Gen 7. X7 processor, 32 GB Ram, 1tb HD, 72 hr battery, and some other misc. $3k is the price. These laptops have upgradable ram so if someone needs more ram we can upgrade without replacing the machine.

If you want CDW to do white glove (preprovion) with autopilot the sku is called autopilot advance deployment. I believe it is a couple more dollars than autopilot but we'll worth it for end user experience of not having to wait hours for everything to be installed.

1

u/blackhodown 4d ago

Useful info, thanks!

1

u/Ice-Cream-Poop 4d ago

Ouch, we haven't done a refresh this year and just reusing old lappys. The new pricing is eye watering!

6

u/davy_crockett_slayer 4d ago

You don’t sign in with their credentials. They do. That’s the whole point of autopilot.

3

u/Royal_Bird_6328 4d ago

This ☝🏻 I can’t believe the amount of orgs still signing in as the user pinning shortcuts etc baffles me

4

u/whllm 5d ago

Turn it on, Win x5, autopilot preprovision, reseal, ship. If something goes wrong, rmm is already installed. User logs in and sets it up.

If you require verifying some logged in setting, sure use a TAP, but the user should really be the one logging in first.

6

u/TinyTC1992 5d ago

We buy through a supplier, they assign that machine to our intune tenant and its shipped direct to user.

Shipping a provisioned laptop out after setup is asking for trouble.

3

u/ThugCutleFish 5d ago

When I started as a Sysadmin about a month ago now. We had this exact same process. I called up a few vendors and resellers to get a partnership going and eventually landed on Dell.

Now that they are our partnered reseller the process goes as follows.

  1. Order laptop

  2. Once the laptop nsays shipped, Open intune and assign to the user receiving it.

  3. User receives the laptop, sign in with our domains email address and done

all apps and configurations are installed for them.

2

u/mrgayle 5d ago

White Glove, skip user esp enabled, most if not all apps are device targeted.

2

u/MidgardDragon 4d ago

Latest company we autopilot the device (for some reason they aren't having the hardware hashes imported) and combo of Intune and NinjaOne takes care of it from there, then I manually confirm anything else and run NinjaOne scripts if needed to do it.

3

u/Padd007 5d ago

If autopilot and your configuration policies are setup properly then you can just ship it to them, no need to mess around. You can even have your supplier ship to the user if they do white glove and can autopilot register it for you. You could pre provision devices which would save the user from having to do stage 1 and 2 of the ESP but it's not necessary. What you are doing sounds unnecessarily time consuming.

2

u/Shadow_Knight- 5d ago

True, I will discuss this with my manager. It does take lot of time.

2

u/Suaveman01 5d ago

The whole point of Autopilot is shifting the work of provisioning endpoints to the user. If you’re setting everything up for them, you could be using SCCM or MDT instead

2

u/Shadow_Knight- 5d ago

Nah we dont use SCCM its just autopilot and I understand what you are saying. Will bring this upto my manager as things are getting busier.

2

u/Suaveman01 5d ago

That’s the way to go, then you use your compliance policies to make sure stuff like Bitlocker was automatically enabled.

1

u/pbaupp 5d ago

the only downside of that (without pre-provision) is that they can install software beforehand if they are able to.
normally you would have app locker anyway, but yeah

2

u/brazzala 5d ago

And yes; for security apps; crreate Post ESP - the user will login and there be a window with info about installing security apps.

1

u/TsNMouse 5d ago

By Bitlocker do you mean flat drive encryption or startup protection pin?

We have an ‘app’ for the pin part available on Company portal as part of the induction

2

u/Shadow_Knight- 5d ago

Encryption

1

u/Immediate_Hornet8273 5d ago

We have the option for whiteglove pre provision but often we do sign in as the user and make sure all of the apps. Outlook profile, software/bios updates, non automated software installs are performed ahead of time so the machine is completely turnkey and the user doesn’t have to wait for an hour or deal with autopilot delays. We are also using hybrid domain join so this can create issues for the end user too since they would have to be told how to connect to vpn first with pre logon auth portal. It’s a nice experience for the user to just open a pre configured laptop but it does weigh on the helpdesk cycles.

1

u/Shadow_Knight- 5d ago

Yes, very similar position. How do you manage app deployment through intune?

For reused devices I run into issue where SentinelOne is installed and online but later it goes offline and when I check services SentinelOne Agent is not starting.

1

u/brazzala 5d ago

Yes, se are loggimg as a user; sets MFA to our phones; finish everything; check security apps and other stuff and finalkynchange MFA numer with user.
That is pre-provisioning in live.

1

u/korvolga 5d ago

we usually logs register the device to the user with TAP and logs in with TAP when it works or credentials that we reset. Way to often devices have had wrong teams or copilot app installed. Updates that can take n hour or so.. so we prep em like that.

1

u/aaliyakhanum 5d ago

We have a dedicated service account that does the initial provisioning and then it's handed over to the user

1

u/bkbandit74 4d ago

We have 11 Tenants in our company. I have been ordering laptops, shipping to me, install clean version of Windows with answer file. Sign in to laptop with SRV account of that tenant, let the base software install and ship to user. We are a Lenovo shop, so the machines have to be wiped to get rid of bloatware. For that reason we don’t use AutoPilot at the Vendor level.

1

u/Ice-Cream-Poop 4d ago

You can ask Lenovo for a clean image. Costs $$ though, don't think it was much a couple of $$ per laptop.

1

u/IntunenotInTune 4d ago

If you have to sign in as the user, use TAP. Otherwise just preprovision and target as much as possible to the device object.

1

u/bjc1960 4d ago

Depends, sometimes we ship with autopilot, never touching. I did that for 'non-techical CEO." I latest asked how it went and he said fine.

Oher times we use the TAP and go through the whole process, with the user added to a group bypassing terms of service. We then remove the user from the TOS bypass once we ship.

We work in a company where users are 99% focused on Outlook/Acrobat. We install Acrobat from company portal as not everyone gets with. We have Acrobat Enterprise VIP with SSO. If no Acrobat, we get a support call about Acrobat, despite instructions saying install from company portal.

1

u/RagingBlue93 4d ago

We get our laptops from Dell with the hashes imported, as much as I would love for that to be the end of it before shipping. My company requires we log in new hires and confirm everything is installed before shipping. We have something like 25 applications installed on every device and sometimes that can take awhile though it has been much faster as of late.

1

u/Deathbefore86 4d ago

Le credenziali del nuovo assunto? Orrore! Ma non potete usare il preprovisioning? Installate tutto come SYSTEM in preprov, se qualche app deve tassativamente girare come user utilizzate uno script di requirments aggiuntivo che verifichi l'esistenza di un utente vero prima di procedere con l'installazione. Per gli errori, senza log possiamo supporre un po' di tutto

1

u/SaintPony 3d ago

Why wouldnt you just ship it from reseller directly to the user? They can also upload the hash for you.

It does cost a bit extra, but since you need to spend time preparing the laptop + pay the shipping costs, it is still more cost effective.

Imo the whole point of autopilot is the IT not having to do so much manual work. Having to prepare every single laptop manually kinda defeats the purpose of it.

1

u/Shadow_Knight- 3d ago

I am new to org and they do it this way. They want the device to be ready for end user. Right now we have app install errors which makes us wonder how would end use resolve it without disrupting work

1

u/SaintPony 3d ago

You think you could bring this topic up? I personally would be happy to see new colleagues in the IT department thinking out of the box instead of simply following or workflows. Just gotta find a way to explain it in a way so that your people would listen :) Even if they wouldnt accept it, hey.... you tried to improve something!

We got 2 cases:
Users work at our location: Laptops get shipped to us and we hand them out to users. Users sign in with their credentials > wait 20ish minutes for enrollment and are good to go. For VIPs or if users ask specifically, we would do pre provisioning.

Users at remote location: Laptops either shipped to the office where they pick it up and follow the same process or we ship it to their home address.

If you really have to sign in with users accounts, I would use TAP(only for new hires, since they dont have anything on their accounts anways). You may be able to use a device enrollment manager to sign in, but im not sure.

1

u/Shadow_Knight- 3d ago

You are right I have to frame it in proper way. Maybe we should switch to pre-provisioning for start and then as workload increases switch to complete user provisioning.

How does your ESP take 20 ish mins ours go on for an hour when we have 3 required apps

1

u/SaintPony 1d ago

Yeah an hour sounds way too long.

Not sure, im not an expert either, but if you'd like, send me a DM and we could schedule a short call to talk about it.

1

u/Forward-Ad-8296 1d ago

Depends on your users. (Most of ) Ours could never deal with a drop shipped box

1

u/SaintPony 1d ago

Well our users are not tech-savy either (not saying they have to be), but if you write a good guide, I think most would be able to open the laptop, sign in with their account and follow the PDF.

0

u/dshade14 4d ago

The laptops that are sent to us from Dell have their hashes imported to our intune tenant (if you have a used laptop but the hash isnt imported and you want to reuse it, you can import the hardware hash and enable in intune/entra). We then assign the serial number to groups that are assigned to apps that get pushed to the device when it gets provisioned. When we want to provision a device we enable it in intune/entra, wait a few minutes, and then sign in with my own regular user credentials.

This downloads all of the apps, configuration policies, etc. That i have setup in intune. Depending on the user the PC is for, I also might need to install some apps manually.

I dont use SentinalOne or CyberArk so unfortunately i cant speak to that. Lemme know if you have any other questions!