Windows Autopilot is a set of Microsoft Windows technologies that simplify and streamline the bulk deployment, setup, and configuration of new Windows 10 or above devices, so they reach employees corporate-ready. It supports the device through its entire lifecycle in an organization, from initial deployment to retirement.
With a combination of a mobile device management (MDM) solution and Microsoft Entra ID (formerly Azure Active Directory), organizations can get Windows devices ready for corporate use with zero admin intervention. When the MDM supports Windows Autopilot, employees can start using a device the moment they activate it, with the required apps, configurations, and documents already in place. Integrating Windows Autopilot with Entra ID also lets organizations add devices to directory groups automatically.
Windows Autopilot skips the traditional build-and-image process and configures a device straight from the factory image. The flow works like this:
Microsoft Azure, formerly known as Windows Azure, is the public cloud platform behind this, and it integrates with tools that support Windows Autopilot to simplify device deployment across the organization.
One of the biggest challenges IT admins face is deploying and provisioning the Windows 10 or above devices their workforce needs. Windows Autopilot simplifies this in a few important ways:
A one-time setup: Admins no longer need to manually deploy each device, which normally means activating it, configuring activation settings, creating user accounts, and deploying apps, profiles, and configurations. Autopilot automates the entire activation and user-assignment process with a single, upfront setup.
Automated deployment of corporate resources: By integrating the Windows Autopilot portal with an MDM solution, admins can push the required apps and documents to enrolled devices in bulk, so devices can be shipped straight to employees without admin intervention.
Restrict administrator account creation: Autopilot can prevent local administrator accounts from being created on devices, so only the IT team controls admin permissions.
Beyond the device running a supported version of Windows, make sure the following are in place before you enroll devices with Windows Autopilot:
Microsoft Entra ID is the identity foundation for Autopilot. Autopilot devices are registered to your Entra ID tenant, deployment profiles are assigned through Entra ID device groups, and when a device joins Entra ID during the out-of-box experience it is recognized as a corporate device. That Entra ID join is also what triggers automatic enrollment into your MDM.
Automatic enrollment is configured once in Entra ID under Mobility (MDM and WIP) by adding your MDM application, which for Mobile Device Manager Plus is the ManageEngine MDM app, along with its terms-of-use URL, discovery URL, and a user scope. After that, any device that joins Entra ID, or any user who adds an Entra ID work account, is automatically enrolled into Mobile Device Manager Plus and receives its assigned apps, policies, and configurations with no manual setup.
ManageEngine's Mobile Device Manager Plus provides extensive support for Windows Autopilot by integrating Autopilot and MDM. To automate bulk enrollment and deployment of Windows 10 or above devices once the requirements above are met, follow these steps:
Capture each device's hardware ID (hardware hash) and register it to your organization. You can obtain a CSV of hardware IDs directly from your OEM or reseller, or run a PowerShell script on the device to generate an AutopilotHWID.csv file containing the device serial number, Windows product ID, and hardware hash. Upload the CSV to the Microsoft Entra ID portal to register the devices as Autopilot devices for your tenant.
In the Mobile Device Manager Plus console, navigate to Devices -> Windows -> Enrollment -> Deployment Profiles -> Create profile -> Windows PC. Name the profile, choose whether existing targeted devices should convert to Autopilot on reset, and assign the profile to the relevant device groups.
Within the deployment profile, define what the user sees on first boot. You can skip privacy settings, the End User License Agreement, and the Cortana, OneDrive, and OEM registration steps, disable local administrator account creation, optionally restrict Windows Hello for Business, and apply custom branding such as your logo, a banner, and custom text for a tailored setup experience.

In the Entra ID portal, go to Microsoft Entra ID -> Manage -> Mobility (MDM and WIP) -> Add application, select the ManageEngine MDM app, and enter the terms-of-use URL and MDM discovery URL from the Mobile Device Manager Plus console, then set the MDM user scope. For an on-premises MDM, add a trusted third-party certificate first; MDM Cloud does not require this. Once saved, any device that joins Entra ID is enrolled into Mobile Device Manager Plus automatically.
Map users to devices, either by letting users self-authenticate with their Entra ID credentials or by assigning devices from the MDM console. On enrollment, Mobile Device Manager Plus automatically distributes team-specific management profiles, security configurations, Wi-Fi and VPN settings, apps, and content, so the device is corporate-ready at first boot. You can also grant access to Exchange and Microsoft 365 apps only to enrolled devices and lock devices into Kiosk mode when needed.
Refer to this document for detailed steps on performing device enrollment with Windows Autopilot.
Autopilot supports different deployment models so you can match the setup experience to how each device will be used:
Windows Autopilot, or Microsoft Azure deployment, gives organizations the following benefits:
No. Windows Autopilot is a deployment and provisioning technology, not a management platform. It gets a device from the factory to a corporate-ready state and then hands ongoing management to an MDM such as Mobile Device Manager Plus, which handles apps, policies, security, and monitoring for the life of the device.
No. Autopilot is not tied exclusively to Intune. By configuring automatic enrollment in Microsoft Entra ID to point to a third-party MDM, you can use Autopilot with a solution like Mobile Device Manager Plus instead.
Yes. Once automatic enrollment is set up in Entra ID with the MDM's application details, devices that join Entra ID enroll into that MDM. Mobile Device Manager Plus supports this flow and manages the devices from first boot.
Traditional imaging means building and applying a custom OS image to each device, which is slow and has to be repeated for new hardware. Autopilot keeps the OEM image and customizes the device through a cloud deployment profile and MDM policies, so there is no imaging and devices can ship straight to users.
Yes. Entra ID (formerly Azure AD) is the identity foundation for Autopilot. Devices are registered to your Entra ID tenant, join Entra ID during setup, and are automatically enrolled into your MDM.