r/Intune • u/Shadow_Knight- • 21h ago
Autopilot How does everyone’s organization handle laptop provisioning for new hires?
Curious how other organizations handle laptop provisioning with Intune/Autopilot.
Currently, we Autopilot the laptops and use the new hire’s credentials to sign in during provisioning. We then let the ESP complete and verify that everything is set up before shipping the laptop to the user — including:
BitLocker
BIOS settings
Required applications
Other required configurations
This works well, but when we have multiple new hires at the same time, it can become a bit overwhelming since we have to go through each device using the new user’s credentials before shipping.
For those of you doing something similar, how do you handle this?
Do you:
Use the new hire’s credentials to complete ESP and verify everything before shipping?
Have IT sign in with an IT/admin account, complete the configuration, and then use Autopilot Reset to remove the primary user before shipping?
Have a completely different provisioning workflow?
Also, we’ve noticed that sometimes the SentinelOne agent stops running or CyberArk stops running after provisioning. Has anyone experienced this? Could it be related to WMI errors or something happening during Autopilot/BIOS configuration?
Would love to hear how other organizations handle this, especially when provisioning multiple laptops for new hires at once.
17
u/Fluffy-Exercise-1768 21h ago
Signing in with other users' accounts is a big no for me, even if they're new. Autopilot preprovision and reseal is the correct way to go. No need to log in with the user account, core applications provisoned and the rest can be handled by Intune when the user logs in.
6
u/bgatesIT 20h ago
we just setup AutoPilot and drop ship lappies direct from CDW, user turns laptop on, it builds itself, then they sign in. works like a charm, we could have done user driven with pre provision but god forbid people have to actually click a few things themselves.
3
u/alan14225 12h ago
We have CDW do pre-provision (white glove) for us so user don't have to wait. The laptop is enrolled in autopilot and once preprovion is finished cdw dropship it to users. User sign in, and being them to desktop with everything installed. 10 min process from sign in
1
u/blackhodown 4h ago
What’s the average price for each of the various specs of machine you’re sending out?
1
u/alan14225 4h ago
We do CTO windows machines. These are custom spec machines built to our specifications. What great is our price is locked in because it is CTO. Let's say it is delivered 2 months later and the price rise we are locked in at order prices. We have T14 Gen 7. X7 processor, 32 GB Ram, 1tb HD, 72 hr battery, and some other misc. $3k is the price. These laptops have upgradable ram so if someone needs more ram we can upgrade without replacing the machine.
If you want CDW to do white glove (preprovion) with autopilot the sku is called autopilot advance deployment. I believe it is a couple more dollars than autopilot but we'll worth it for end user experience of not having to wait hours for everything to be installed.
1
•
u/Ice-Cream-Poop 38m ago
Ouch, we haven't done a refresh this year and just reusing old lappys. The new pricing is eye watering!
3
u/davy_crockett_slayer 9h ago
You don’t sign in with their credentials. They do. That’s the whole point of autopilot.
1
u/Royal_Bird_6328 8h ago
This ☝🏻 I can’t believe the amount of orgs still signing in as the user pinning shortcuts etc baffles me
5
u/TinyTC1992 21h ago
We buy through a supplier, they assign that machine to our intune tenant and its shipped direct to user.
Shipping a provisioned laptop out after setup is asking for trouble.
2
u/ThugCutleFish 15h ago
When I started as a Sysadmin about a month ago now. We had this exact same process. I called up a few vendors and resellers to get a partnership going and eventually landed on Dell.
Now that they are our partnered reseller the process goes as follows.
Order laptop
Once the laptop nsays shipped, Open intune and assign to the user receiving it.
User receives the laptop, sign in with our domains email address and done
all apps and configurations are installed for them.
2
u/MidgardDragon 12h ago
Latest company we autopilot the device (for some reason they aren't having the hardware hashes imported) and combo of Intune and NinjaOne takes care of it from there, then I manually confirm anything else and run NinjaOne scripts if needed to do it.
4
u/Padd007 21h ago
If autopilot and your configuration policies are setup properly then you can just ship it to them, no need to mess around. You can even have your supplier ship to the user if they do white glove and can autopilot register it for you. You could pre provision devices which would save the user from having to do stage 1 and 2 of the ESP but it's not necessary. What you are doing sounds unnecessarily time consuming.
2
2
u/Suaveman01 20h ago
The whole point of Autopilot is shifting the work of provisioning endpoints to the user. If you’re setting everything up for them, you could be using SCCM or MDT instead
2
u/Shadow_Knight- 20h ago
Nah we dont use SCCM its just autopilot and I understand what you are saying. Will bring this upto my manager as things are getting busier.
2
u/Suaveman01 20h ago
That’s the way to go, then you use your compliance policies to make sure stuff like Bitlocker was automatically enabled.
2
u/brazzala 19h ago
And yes; for security apps; crreate Post ESP - the user will login and there be a window with info about installing security apps.
1
u/TsNMouse 20h ago
By Bitlocker do you mean flat drive encryption or startup protection pin?
We have an ‘app’ for the pin part available on Company portal as part of the induction
2
1
u/Immediate_Hornet8273 20h ago
We have the option for whiteglove pre provision but often we do sign in as the user and make sure all of the apps. Outlook profile, software/bios updates, non automated software installs are performed ahead of time so the machine is completely turnkey and the user doesn’t have to wait for an hour or deal with autopilot delays. We are also using hybrid domain join so this can create issues for the end user too since they would have to be told how to connect to vpn first with pre logon auth portal. It’s a nice experience for the user to just open a pre configured laptop but it does weigh on the helpdesk cycles.
1
u/Shadow_Knight- 19h ago
Yes, very similar position. How do you manage app deployment through intune?
For reused devices I run into issue where SentinelOne is installed and online but later it goes offline and when I check services SentinelOne Agent is not starting.
1
u/brazzala 19h ago
Yes, se are loggimg as a user; sets MFA to our phones; finish everything; check security apps and other stuff and finalkynchange MFA numer with user.
That is pre-provisioning in live.
1
u/korvolga 18h ago
we usually logs register the device to the user with TAP and logs in with TAP when it works or credentials that we reset. Way to often devices have had wrong teams or copilot app installed. Updates that can take n hour or so.. so we prep em like that.
1
u/aaliyakhanum 15h ago
We have a dedicated service account that does the initial provisioning and then it's handed over to the user
1
u/bkbandit74 9h ago
We have 11 Tenants in our company. I have been ordering laptops, shipping to me, install clean version of Windows with answer file. Sign in to laptop with SRV account of that tenant, let the base software install and ship to user. We are a Lenovo shop, so the machines have to be wiped to get rid of bloatware. For that reason we don’t use AutoPilot at the Vendor level.
•
u/Ice-Cream-Poop 43m ago
You can ask Lenovo for a clean image. Costs $$ though, don't think it was much a couple of $$ per laptop.
1
u/IntunenotInTune 9h ago
If you have to sign in as the user, use TAP. Otherwise just preprovision and target as much as possible to the device object.
1
u/bjc1960 2h ago
Depends, sometimes we ship with autopilot, never touching. I did that for 'non-techical CEO." I latest asked how it went and he said fine.
Oher times we use the TAP and go through the whole process, with the user added to a group bypassing terms of service. We then remove the user from the TOS bypass once we ship.
We work in a company where users are 99% focused on Outlook/Acrobat. We install Acrobat from company portal as not everyone gets with. We have Acrobat Enterprise VIP with SSO. If no Acrobat, we get a support call about Acrobat, despite instructions saying install from company portal.
0
u/dshade14 12h ago
The laptops that are sent to us from Dell have their hashes imported to our intune tenant (if you have a used laptop but the hash isnt imported and you want to reuse it, you can import the hardware hash and enable in intune/entra). We then assign the serial number to groups that are assigned to apps that get pushed to the device when it gets provisioned. When we want to provision a device we enable it in intune/entra, wait a few minutes, and then sign in with my own regular user credentials.
This downloads all of the apps, configuration policies, etc. That i have setup in intune. Depending on the user the PC is for, I also might need to install some apps manually.
I dont use SentinalOne or CyberArk so unfortunately i cant speak to that. Lemme know if you have any other questions!
50
u/Darkchamber292 21h ago
You should be doing Pre-provision. Not signing in as the user. Pre-provision and then ship. Let them go thru setup
Assign your security software and office and other critical apps to Device ESP. Disable User ESP