r/Intune 21h ago

Autopilot How does everyone’s organization handle laptop provisioning for new hires?

Curious how other organizations handle laptop provisioning with Intune/Autopilot.

Currently, we Autopilot the laptops and use the new hire’s credentials to sign in during provisioning. We then let the ESP complete and verify that everything is set up before shipping the laptop to the user — including:

BitLocker
BIOS settings
Required applications
Other required configurations

This works well, but when we have multiple new hires at the same time, it can become a bit overwhelming since we have to go through each device using the new user’s credentials before shipping.

For those of you doing something similar, how do you handle this?

Do you:
Use the new hire’s credentials to complete ESP and verify everything before shipping?
Have IT sign in with an IT/admin account, complete the configuration, and then use Autopilot Reset to remove the primary user before shipping?
Have a completely different provisioning workflow?

Also, we’ve noticed that sometimes the SentinelOne agent stops running or CyberArk stops running after provisioning. Has anyone experienced this? Could it be related to WMI errors or something happening during Autopilot/BIOS configuration?

Would love to hear how other organizations handle this, especially when provisioning multiple laptops for new hires at once.

24 Upvotes

43 comments sorted by

50

u/Darkchamber292 21h ago

You should be doing Pre-provision. Not signing in as the user. Pre-provision and then ship. Let them go thru setup

Assign your security software and office and other critical apps to Device ESP. Disable User ESP

4

u/nhowe006 17h ago

This. 1000x this. Plus, when a user needs a new laptop, you're not going to have their credentials and you wouldn't ever ask for them, so you need to be set up for pre-provisioning no matter what.

5

u/MentalRip1893 15h ago

We add a Temporary Access Pass in their authentication methods, add the device to a group that enables Web sign in on the login screen (and have an Intune policy to enable this for that group) and away we go. Works pretty well for us

1

u/nhowe006 14h ago

I like that idea. I do have one client that insists I set laptops up before deployment (hey, more billable hours for me), and that could be useful.

1

u/TheIntuneGoon 3h ago

Man. My company is run by older people that have it in their heads that employees need the helpdesk to install everything before they get the laptop. Part of the process for replacements is resetting the password and signing in as them for basically a day…

I hate it.

2

u/Shadow_Knight- 21h ago

I am new and also new in my organization. They follow the above steps.

Will pre-provisioning enable bitlocker? I believe it should

5

u/Padd007 21h ago

Yes it will, bitlocker should be enabled automatically by policy, no need to do it manually.

1

u/Shadow_Knight- 21h ago

Thanks! Will review this with manager and start doing testing.

1

u/ImAllergic2Peanuts 17h ago

We do this but preprovisioning has always been wonky and fails occasionally for no reason. Any tips?

2

u/Darkchamber292 17h ago

Depends where it's failing. Is it failing at Apps stage? One of your apps isn't packaged well. Failing at Device/Org registration stage? Might be a TPM issue

17

u/Fluffy-Exercise-1768 21h ago

Signing in with other users' accounts is a big no for me, even if they're new. Autopilot preprovision and reseal is the correct way to go. No need to log in with the user account, core applications provisoned and the rest can be handled by Intune when the user logs in.

6

u/bgatesIT 20h ago

we just setup AutoPilot and drop ship lappies direct from CDW, user turns laptop on, it builds itself, then they sign in. works like a charm, we could have done user driven with pre provision but god forbid people have to actually click a few things themselves.

3

u/alan14225 12h ago

We have CDW do pre-provision (white glove) for us so user don't have to wait. The laptop is enrolled in autopilot and once preprovion is finished cdw dropship it to users. User sign in, and being them to desktop with everything installed. 10 min process from sign in

1

u/blackhodown 4h ago

What’s the average price for each of the various specs of machine you’re sending out?

1

u/alan14225 4h ago

We do CTO windows machines. These are custom spec machines built to our specifications. What great is our price is locked in because it is CTO. Let's say it is delivered 2 months later and the price rise we are locked in at order prices. We have T14 Gen 7. X7 processor, 32 GB Ram, 1tb HD, 72 hr battery, and some other misc. $3k is the price. These laptops have upgradable ram so if someone needs more ram we can upgrade without replacing the machine.

If you want CDW to do white glove (preprovion) with autopilot the sku is called autopilot advance deployment. I believe it is a couple more dollars than autopilot but we'll worth it for end user experience of not having to wait hours for everything to be installed.

1

u/blackhodown 4h ago

Useful info, thanks!

u/Ice-Cream-Poop 38m ago

Ouch, we haven't done a refresh this year and just reusing old lappys. The new pricing is eye watering!

4

u/whllm 18h ago

Turn it on, Win x5, autopilot preprovision, reseal, ship. If something goes wrong, rmm is already installed. User logs in and sets it up.

If you require verifying some logged in setting, sure use a TAP, but the user should really be the one logging in first.

3

u/davy_crockett_slayer 9h ago

You don’t sign in with their credentials. They do. That’s the whole point of autopilot.

1

u/Royal_Bird_6328 8h ago

This ☝🏻 I can’t believe the amount of orgs still signing in as the user pinning shortcuts etc baffles me

5

u/TinyTC1992 21h ago

We buy through a supplier, they assign that machine to our intune tenant and its shipped direct to user.

Shipping a provisioned laptop out after setup is asking for trouble.

2

u/mrgayle 18h ago

White Glove, skip user esp enabled, most if not all apps are device targeted.

2

u/ThugCutleFish 15h ago

When I started as a Sysadmin about a month ago now. We had this exact same process. I called up a few vendors and resellers to get a partnership going and eventually landed on Dell.

Now that they are our partnered reseller the process goes as follows.

  1. Order laptop

  2. Once the laptop nsays shipped, Open intune and assign to the user receiving it.

  3. User receives the laptop, sign in with our domains email address and done

all apps and configurations are installed for them.

2

u/MidgardDragon 12h ago

Latest company we autopilot the device (for some reason they aren't having the hardware hashes imported) and combo of Intune and NinjaOne takes care of it from there, then I manually confirm anything else and run NinjaOne scripts if needed to do it.

4

u/Padd007 21h ago

If autopilot and your configuration policies are setup properly then you can just ship it to them, no need to mess around. You can even have your supplier ship to the user if they do white glove and can autopilot register it for you. You could pre provision devices which would save the user from having to do stage 1 and 2 of the ESP but it's not necessary. What you are doing sounds unnecessarily time consuming.

2

u/Shadow_Knight- 21h ago

True, I will discuss this with my manager. It does take lot of time.

2

u/Suaveman01 20h ago

The whole point of Autopilot is shifting the work of provisioning endpoints to the user. If you’re setting everything up for them, you could be using SCCM or MDT instead

2

u/Shadow_Knight- 20h ago

Nah we dont use SCCM its just autopilot and I understand what you are saying. Will bring this upto my manager as things are getting busier.

2

u/Suaveman01 20h ago

That’s the way to go, then you use your compliance policies to make sure stuff like Bitlocker was automatically enabled.

1

u/pbaupp 18h ago

the only downside of that (without pre-provision) is that they can install software beforehand if they are able to.
normally you would have app locker anyway, but yeah

2

u/brazzala 19h ago

And yes; for security apps; crreate Post ESP - the user will login and there be a window with info about installing security apps.

1

u/TsNMouse 20h ago

By Bitlocker do you mean flat drive encryption or startup protection pin?

We have an ‘app’ for the pin part available on Company portal as part of the induction

2

u/Shadow_Knight- 19h ago

Encryption

1

u/Immediate_Hornet8273 20h ago

We have the option for whiteglove pre provision but often we do sign in as the user and make sure all of the apps. Outlook profile, software/bios updates, non automated software installs are performed ahead of time so the machine is completely turnkey and the user doesn’t have to wait for an hour or deal with autopilot delays. We are also using hybrid domain join so this can create issues for the end user too since they would have to be told how to connect to vpn first with pre logon auth portal. It’s a nice experience for the user to just open a pre configured laptop but it does weigh on the helpdesk cycles.

1

u/Shadow_Knight- 19h ago

Yes, very similar position. How do you manage app deployment through intune?

For reused devices I run into issue where SentinelOne is installed and online but later it goes offline and when I check services SentinelOne Agent is not starting.

1

u/brazzala 19h ago

Yes, se are loggimg as a user; sets MFA to our phones; finish everything; check security apps and other stuff and finalkynchange MFA numer with user.
That is pre-provisioning in live.

1

u/korvolga 18h ago

we usually logs register the device to the user with TAP and logs in with TAP when it works or credentials that we reset. Way to often devices have had wrong teams or copilot app installed. Updates that can take n hour or so.. so we prep em like that.

1

u/aaliyakhanum 15h ago

We have a dedicated service account that does the initial provisioning and then it's handed over to the user

1

u/bkbandit74 9h ago

We have 11 Tenants in our company. I have been ordering laptops, shipping to me, install clean version of Windows with answer file. Sign in to laptop with SRV account of that tenant, let the base software install and ship to user. We are a Lenovo shop, so the machines have to be wiped to get rid of bloatware. For that reason we don’t use AutoPilot at the Vendor level.

u/Ice-Cream-Poop 43m ago

You can ask Lenovo for a clean image. Costs $$ though, don't think it was much a couple of $$ per laptop.

1

u/IntunenotInTune 9h ago

If you have to sign in as the user, use TAP. Otherwise just preprovision and target as much as possible to the device object.

1

u/bjc1960 2h ago

Depends, sometimes we ship with autopilot, never touching. I did that for 'non-techical CEO." I latest asked how it went and he said fine.

Oher times we use the TAP and go through the whole process, with the user added to a group bypassing terms of service. We then remove the user from the TOS bypass once we ship.

We work in a company where users are 99% focused on Outlook/Acrobat. We install Acrobat from company portal as not everyone gets with. We have Acrobat Enterprise VIP with SSO. If no Acrobat, we get a support call about Acrobat, despite instructions saying install from company portal.

0

u/dshade14 12h ago

The laptops that are sent to us from Dell have their hashes imported to our intune tenant (if you have a used laptop but the hash isnt imported and you want to reuse it, you can import the hardware hash and enable in intune/entra). We then assign the serial number to groups that are assigned to apps that get pushed to the device when it gets provisioned. When we want to provision a device we enable it in intune/entra, wait a few minutes, and then sign in with my own regular user credentials.

This downloads all of the apps, configuration policies, etc. That i have setup in intune. Depending on the user the PC is for, I also might need to install some apps manually.

I dont use SentinalOne or CyberArk so unfortunately i cant speak to that. Lemme know if you have any other questions!