Windows Autopilot Device Preparation Setup Guide | Autopilot v2 Device preparation policies

Поделиться
HTML-код
  • Опубликовано: 8 окт 2024
  • 📚 Device preparation policies | Windows Autopilot Device Preparation Setup Guide | Windows Autopilot Device Preparation | AutoPilot V2 Device Preparation | steps windows autopilot device preparation
    👉 In today's video, I will talk about Windows Autopilot Device Preparation, which is recently introduced by Microsoft.
    Windows Autopilot Device Preparation is used to set up and configure new devices, getting them ready for productive use. Its goal is to simplify device deployment by delivering consistent configurations, enhancing the overall setup speed, and improving troubleshooting capabilities.
    ✅Detailed Requirements:
    learn.microsof...
    🔔 Subscribe and hit the bell to get notified about my weekly videos
    / @chandermanipandey
    ✅ Intune Report Automation
    Intune Reporting Automation Using Logic Apps & Send Email Notification | Logic Apps + Intune Report
    • Intune Report Automati...
    Remove Permissions From Assigned Managed Identity Enterprise Application
    • Azure Enterprise Appli...
    Microsoft Intune Reporting Using Azure Automation With System Assigned Managed Identity
    • Microsoft Intune Repor...
    Automated Intune Report using Azure Automation with User Assigned Managed Identity
    • Intune Reporting Using...
    Bulk Removal of Primary User from Intune devices using Powershell | Remove Intune Primary User
    • Bulk Removal of Primar...
    Intune Primary User and Manually Update Primary User In Intune | Change Primary User Windows Device
    • Intune Primary User an...
    Bulk Update Windows Autopilot Group Tag in Intune | Group Tag in Intune Autopilot Group
    • Bulk Update Windows Au...
    Windows 11 Update Compliance Dashboard & Reporting | Intune Windows 11 Upgrade Custom Reports
    • Windows 11 Update Comp...
    Bulk Update Primary User for Intune Devices | Automatically set Intune Primary User in Bulk
    • Bulk Update Primary Us...
    Intune Patching Compliance Reporting | Intune Windows Update Reporting
    • Intune Patching Compli...
    Intune Windows Update Compliance Reporting Automation & Email Subscription | Intune Patching Report
    • Intune Windows Update ...
    Automatically Schedule Bulk Sync of Windows Devices in Intune | Sync Windows Device in Intune
    • Automatically Schedule...
    Remotely Find Windows 10/11 Upgrade Blocking Factors | Windows 11 Feature Update Blocking Reasons
    • Remotely Find Windows ...
    Setup Email Notification To Get Intune Service Health & Message Center | Service Health Email Alerts
    • Setup Email Notificati...
    Automating Intune Reports - Email Subscription for Intune Patching Compliance Dashboard and Reports
    • Automating Intune Repo...
    🏷️ Tags
    #Intune #WindowsAutopilot #microsoftintune #chandermanipandey

Комментарии • 86

  • @ChanderManiPandey
    @ChanderManiPandey  4 месяца назад +1

    👉 In today's video, I will talk about Windows Autopilot Device Preparation, which is recently introduced by Microsoft.
    Windows Autopilot Device Preparation is used to set up and configure new devices, getting them ready for productive use. Its goal is to simplify device deployment by delivering consistent configurations, enhancing the overall setup speed, and improving troubleshooting capabilities.

  • @RockScissorsRock
    @RockScissorsRock Месяц назад +1

    This works really well and works better than regular autopilot. Reduces all the work and stress helpdesk and desktop techs do when setting up and provisioning devices. You still need to install Windows 11 and do a little on the backend but that should not take to long. Just install from ISO and hand it over to the user and that's it. Time to watch RUclips for the rest of the day..

  • @makarand2474
    @makarand2474 3 месяца назад

    I was getting an enrollment error, After watching your tutorial I saw that the device platform restriction of the personal devices was set to 'Block. Thanks for removing the blocker for me. :)

  • @kojofrempong3260
    @kojofrempong3260 2 месяца назад +1

    This actually helped me understand the Autopilot v2. Thanks

  • @TheRvprasad012
    @TheRvprasad012 2 месяца назад +1

    Vividly explained 👍🏼
    But I have question, apps and scripts needs to be selected during the autopilot device preparation profile creation time right? If so why did you deploy apps and scripts to the device group upfront?

    • @ChanderManiPandey
      @ChanderManiPandey  2 месяца назад

      You also have to deploy as required on the group as well as select in preparation policy..It's mandatory..

  • @jbreezecoleman5345
    @jbreezecoleman5345 2 месяца назад +1

    Hey Chander! How are you? I have a question about your video! The latest video for the New Windows Autopilot Device Preparation video, when you created the Windows autopilot preparation security group. You went back to add an "Owner" and the owner you added was named "Intune Provisioning Client" Under the ENTERPRISE APPLICATIONS tab.
    Normally, I would add an Owner before hitting the create button on the security group BUT the owner that I usually would add is a PERSONS name, like Myself for instance but in this security group you went under Enterprise Applications and added Intune Provisioning Client! Your method is NEW to me! Is this the METHOD NEEDED for this new approach specifically for the New Windows Autopilot Device Preparation deployment process?

    • @ChanderManiPandey
      @ChanderManiPandey  2 месяца назад +1

      Yes, this is by design and the owner must be the same.

  • @vibhorvarshney3542
    @vibhorvarshney3542 17 дней назад +1

    well explained, do we any option to setup a hostname for enroll device automatically, any policy that can setup a hostname which can manage by Device preparation, not manually set up by end-user?

    • @ChanderManiPandey
      @ChanderManiPandey  17 дней назад

      We can use this after Ap
      ruclips.net/video/f8usWIBmu20/видео.htmlsi=dlV50KZetzVL4cTJ

    • @vibhorvarshney3542
      @vibhorvarshney3542 17 дней назад +1

      @@ChanderManiPandey thanks Chander, this will work for me in production environment.

    • @vibhorvarshney3542
      @vibhorvarshney3542 2 часа назад

      Hey Chnader, could please share url for corporate device identifier video.

    • @vibhorvarshney3542
      @vibhorvarshney3542 2 часа назад

      Hey Chander, could please share url for corporate device identifier video.

    • @ChanderManiPandey
      @ChanderManiPandey  56 минут назад

      ruclips.net/video/-8pfyDvPEgg/видео.htmlsi=rLE9ITPoVkKxzh_b

  • @littletoes6622
    @littletoes6622 24 дня назад

    Hi @chanderManiPandey another wonderful and Informative video, is there any way you can tell us that shall we make a dynamic group for user or is manual one is good enough ?

    • @ChanderManiPandey
      @ChanderManiPandey  24 дня назад

      Thanks. We can create dynamic user group. May I know what is your exact requirement ?

  • @chriso1523
    @chriso1523 4 дня назад +1

    Actually, I don't even see the logs within "Monitor." Tried on another device. User has an intune license with E3. I meet all the requirements

    • @ChanderManiPandey
      @ChanderManiPandey  3 дня назад

      Recheck again you are missing some prequeites
      Os versions supported
      Personal enrollment block or not
      Configuration etc

  • @danmosby7980
    @danmosby7980 Месяц назад +1

    Is TPM a required setting for Auto pilot or can it be deactivated. I have a new Lenovo machine that failed at TPM is if stop it being requirement will it work?

  • @syedmali7772
    @syedmali7772 3 месяца назад +1

    is this device configured as a corporate device or personal, means the Autopilot v2 supports corporate or personal devices?

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад +1

      Both , we can use corporate device identifier and block personal enrollment

  • @Will-ti6kb
    @Will-ti6kb 3 месяца назад +1

    I'm wondering how long it took for you to complete the process. On my end, everything works except that the preparation process ended up incomplete. The only difference i can tell from your video is that the duration, which I used the default time - 30 minutes.

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      It takes time.
      How many apps you have in your policy?
      Can you try with 60min..
      Any error logged in device prepration report?

    • @Will-ti6kb
      @Will-ti6kb 3 месяца назад

      I tried 60 minutes but no luck. I even tried without any apps nor scripts. To my surprise it worked the very first time but failed ever since. Not sure if it's a system glitch. Anyway thanks for the video and feedback. ​@ChanderManiPandey

  • @jbreezecoleman5345
    @jbreezecoleman5345 2 месяца назад +1

    Also, under that Enterprise Applications list, I have 7 applications there by DEFAULT, but the one you selected, "Intune Provisioning Client" IS NOT listed as one for me to choose from? How did you get to select that specific name?

    • @ChanderManiPandey
      @ChanderManiPandey  2 месяца назад +1

      Run these commands
      install-module azuread
      Connect-AzureAD
      New-AzureADServicePrincipal -AppId f1346770-5b25-470b-88bd-d5744ab7952c

    • @MicahW1
      @MicahW1 Месяц назад

      You can search for the AppID instead of the username: f1346770-5b25-470b-88bd-d5744ab7952c. The Service Principal may be named Intune Autopilot ConfidentialClient as well.

    • @Hichken
      @Hichken Месяц назад

      @@ChanderManiPandey the new name is Intune Autopilot ConfidentialClient

  • @chriso1523
    @chriso1523 4 дня назад +1

    devices werent auto added to device group. intune provisioning client is the owner if the group. What am I doing wrong

  • @PowerTower25
    @PowerTower25 18 дней назад

    Really good explanation! Thank you so much.

    • @ChanderManiPandey
      @ChanderManiPandey  18 дней назад +1

      Glad you enjoyed it!🙂

    • @PowerTower25
      @PowerTower25 18 дней назад +1

      @@ChanderManiPandey So is this only working with Windows 11 Insider editions, like 24H2? If I use the windows media creation tool that creates a bootable USB, it fails. If I use 24H2 it works. Where else can I download it? The requirements state "Windows 11, version 23H2 with KB5035942 or later - Windows installation media dated April 2024 or later has KB5035942 included." I created a bootable USB yesterday and it failed.

    • @ChanderManiPandey
      @ChanderManiPandey  17 дней назад

      This support starts from windows 11 specific version which i mentioned in video.

  • @dineshchaudhary2918
    @dineshchaudhary2918 2 месяца назад +1

    Is it necessary to assign apps and scripts to a device group as we see in the video when we have to assign again manually the apps and scripts in the device preparation tool profile.

    • @ChanderManiPandey
      @ChanderManiPandey  2 месяца назад

      Yes, if you are not assigning the apps and scripts, they will not be installed during Autopilot.

    • @austins1998
      @austins1998 27 дней назад

      I would think that if there is not an assignment under apps, once Company portal syncs with Intune it would automatically uninstall those apps you installed during enrollment. Or not install at all if it needs to be assigned in apps for it to even work through autopilot.

  • @remcovreeswijk7064
    @remcovreeswijk7064 13 дней назад +1

    I followed all the steps in this video, and tried this with a fresh Windows 11 Enterprise installation in a Hyper V VM Gen2 with TPM and secure boot on. But the autopilot didnt start after loging in with my account which is added to the autopilot user group. I have no idea why it doesnt work. Any suggestion on where it could go wrong for me? The VM has an working internet connection.

  • @TateSpirit
    @TateSpirit 3 месяца назад +1

    After the OBE the device is not showing as a member of the "autopilot device group" even though I followed the steps given in your video, am I missing something?. However, the device is showing under Devices section.

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      Are you able to perform Autopilot via this method?

    • @TateSpirit
      @TateSpirit 3 месяца назад +1

      @@ChanderManiPandey Yes, Autopilot is working but for some reason, the device ends up in the devices rather than in the designated group. Tried with a couple of more devices and they seem to work as intended. Thank you.

    • @alberto4249
      @alberto4249 3 месяца назад

      i'm in the same situation, the device is not appearing in the device group or in the Windows autopilot device preparation deployments , but i can see it under devices tab, and i checked the machines and are fully functional, i even tried the Fresh Star or Autopilot reset and they are working fine.

  • @janandan7122
    @janandan7122 2 месяца назад +1

    Hi @ChanderManiPandey I am facing similar issues as @sunny-handa. Are there any resolution for this issue?

    • @ChanderManiPandey
      @ChanderManiPandey  2 месяца назад

      So u r also getting ESP screen?

    • @janandan7122
      @janandan7122 2 месяца назад +1

      @@ChanderManiPandey Yes -The device added as corporate-owned device and not is not showing as a member of the "autopilot device group"

    • @ChanderManiPandey
      @ChanderManiPandey  2 месяца назад

      It will be added when u r performing ApV2 after entering username and password...

    • @janandan7122
      @janandan7122 2 месяца назад

      ​@@ChanderManiPandey ApV2 not working as you demo in your video.The device resisted in AZ and join to Intune as corporate device.

  • @MrGayle_
    @MrGayle_ 3 месяца назад +1

    Is there a way to not give the user the option to choose setup for personal use, and just setup for work or school ?

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      Use autopilot with hardware hash.
      With this option I think not possible.

    • @MrGayle_
      @MrGayle_ 3 месяца назад +1

      @ChanderManiPandey yes there is a lot missing in this new version, such as accept EULA, privacy settings, device naming, locale and keyboard selection. I'll imagine MS will add them later. For now I think the Autopilot 1 is still better. Good video BTW.

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      Thanks

  • @subramanicam
    @subramanicam 3 месяца назад +1

    Its really helpful. thank you.

  • @PankajRanaa2102
    @PankajRanaa2102 4 месяца назад +1

    Amazing video. Thank you

  • @amirshaikh7173
    @amirshaikh7173 Месяц назад +1

    So autopilot only support for windows 11?

    • @ChanderManiPandey
      @ChanderManiPandey  Месяц назад +1

      Autopilot v2 support is started from specific version of win11.

  • @familyprofile6994
    @familyprofile6994 3 месяца назад +1

    dont see service principal called Intune provisioning client. how to enable it?

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      You have to run following command and create it.
      Install-Module azuread
      Connect-AzureAD
      New-AzureADServicePrincipal -AppId f1346770-5b25-470b-88bd-d5744ab7952c

    • @familyprofile6994
      @familyprofile6994 3 месяца назад

      @@ChanderManiPandey thank you sir

    • @ThadThigpen
      @ThadThigpen 2 месяца назад +1

      In some tenants, the service principal might have the name of Intune Autopilot ConfidentialClient instead of Intune Provisioning Client. As long as the AppID of the service principal is f1346770-5b25-470b-88bd-d5744ab7952c, it's the correct service principal.

    • @ChanderManiPandey
      @ChanderManiPandey  2 месяца назад

      Yes, if Id is matching then use the same.

  • @puneethraj0016
    @puneethraj0016 Месяц назад +1

    Where we can get windows autopilot Provisioning client app

    • @ChanderManiPandey
      @ChanderManiPandey  Месяц назад

      It's an enterprise application

    • @puneethraj0016
      @puneethraj0016 Месяц назад

      ​@@ChanderManiPandey correct. But am unable to find this app in azure enterprise app portal

    • @puneethraj0016
      @puneethraj0016 Месяц назад +1

      Kindly let me know how to create this app

    • @ChanderManiPandey
      @ChanderManiPandey  Месяц назад

      Run these commands
      install-module azuread
      Connect-AzureAD
      New-AzureADServicePrincipal -AppId f1346770-5b25-470b-88bd-d5744ab7952c

    • @puneethraj0016
      @puneethraj0016 Месяц назад +1

      Thanks for your quick response, first connect the graph app then run commands, or directly run the comments in power shell in one of device

  • @fbifido2
    @fbifido2 3 месяца назад +1

    we did not see you try to log into that machine using Entra-ID

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      I actually did. That part I skipped in video.
      May I know if you have specific question?

  • @sunny-handa
    @sunny-handa 3 месяца назад +1

    if you already have working windows autopilot (v1), then V2 doesn't work simultaneously. V1 always takes the precedence and give me ESP page. how to fix it.

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      Remove hardware hash for that Machine

    • @sunny-handa
      @sunny-handa 3 месяца назад +1

      @@ChanderManiPandey Thanks for replying, Yes I have removed the Hash from the tenant. If I format the device and install Windows, I can use it like a normal home device. as soon as I format and try my company ID, it goes to ESP.

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      What is the OS version?

    • @sunny-handa
      @sunny-handa 3 месяца назад +1

      @@ChanderManiPandey i made sure its 23h2 latest one since old version wont support it. I watched your video very carefully.

    • @ChanderManiPandey
      @ChanderManiPandey  3 месяца назад

      Technically it should not give you ESP if the device HH is already removed..
      For testing,If possible can you try on any other machine?