Windows Autopilot vs. Windows Autopilot Device Preparation

Windows Autopilot vs. Windows Autopilot Device Preparation: In this post, I’ll explain the key differences between Windows Autopilot and Windows Autopilot Device Preparation. Both are designed to configure new Windows devices by managing the Out-of-Box Experience (OOBE), but they take different approaches.

📌 Windows Autopilot: It works best for organizations that need advanced customizations, hybrid join scenario, multiple device support and have already established or can establish a process to upload device hardware hash in Intune.

📌 Windows Autopilot Device Preparation: As of writing this post, this method supports only Microsoft Entra joined deployments and does not require collecting or uploading the hardware hash of devices. It is based on Enrollment time grouping and focuses on device-based targeting of apps and scripts delivered during OOBE.

The table below provides a quick summary of the differences between Windows Autopilot and Windows Autopilot Device Preparation. In the next sections, I provide a more detailed comparison along with my recommendation for the given scenario.

FeatureAutopilotAutopilot Device Preparation
Setup requirementDevices must be registered with Windows Autopilot before deployment.Device registration is not mandatory. Devices can optionally be associated with the organisation before enrollment.
Join supportMicrosoft Entra join and Microsoft Entra hybrid join.Microsoft Entra join only.
OOBE screenEnrollment Status Page (ESP)Device Preparation page
Apps during setupCan install many apps; may slow setupInstalls only critical apps/scripts [Up to 25]
PowerShell scriptsSupportedSupported (system context only)
LOB and Win32 appsDeploying LOB and Win32 apps together during ESP can cause installation conflicts.Supports deploying LOB and Win32 applications during the same deployment.
MonitoringBasic Intune reportingReal-time app/script status with diagnostics
Pre-provisioning (White Glove)Supported.Not supported.
Windows version supportWindows 11 and supported Windows 10 editions.Windows 11 only.
Device typesPhysical, VM, and VDI supportedPhysical PCs, VMs, Windows 365 Frontline (preview)
Co-managementSupported (Autopilot into Co-management)Not supported
Deployment modesUser-driven, self-deploying, pre-provisioningUser-driven deployment and automatic deployment for supported Windows 365 Cloud PCs.
User account typeConfigurable (standard or admin)Configurable (standard or admin)
Enrollment Status PageUses ESP to track device and user configuration during provisioning.Uses its own provisioning progress experience without requiring ESP configuration.
Time to desktopLonger if many apps, policies, and scripts installFaster OOBE with minimal setup

Windows Autopilot vs. Windows Autopilot Device Preparation

In the following sections, I’ll compare the features of Windows Autopilot and Windows Autopilot Device Preparation and highlight which method has the advantage in each case.

Device Registration

Windows Autopilot requires devices to be registered before deployment, typically by importing their hardware hashes into Intune or having them registered by an OEM or partner.

Windows Autopilot device preparation does not require mandatory device registration. However, administrators can now optionally use device association to bind physical devices to their organisation before enrollment. This enables device-specific policy assignments, additional OOBE customisation, and automatic corporate ownership identification.

Unlike classic Autopilot registration, device association uses a DeviceLink CSV file and TPM-backed identity verification rather than the traditional hardware hash registration process.

🏆 Windows Autopilot Device Preparation ✅ Optional Device Registration

Device Join types

Windows Autopilot supports both Microsoft Entra Join and Microsoft Entra Hybrid Join. However, the Windows Autopilot Device Preparation method currently supports only Microsoft Entra Join.

🏆 Windows Autopilot ✅ Supports both Microsoft Entra Join and Entra Hybrid Join

Supported Scenarios

Windows Autopilot supports several deployment modes, including User-Driven, Self-Deploying, and Pre-Provisioning (White Glove). In contrast, Windows Autopilot Device Preparation currently supports only User-Driven and Automatic (for Windows 365) modes.

🏆 Windows Autopilot ✅ Supports more deployment modes

Windows Version Coverage

Windows Autopilot supports Windows 10, Windows 11, and HoloLens (Autopilot #requirements), while Windows Autopilot Device Preparation is limited to newer Windows 11 builds (device preparation #requirements).

🏆 Windows Autopilot ✅ Supports multiple Windows OS

Cloud Services Support

Windows Autopilot Device Preparation supports Government Community Cloud High (GCCH) and Department of Defense (DoD) environments, whereas Windows Autopilot does not.

🏆 Windows Autopilot Device Preparation ✅ Supports (GCCH) and (DoD) cloud environments

Admin Effort

Configuring and managing Windows Autopilot requires more administrative effort because of device registration and ESP page setup. In contrast, implementing and managing autopilot device preparation involves less effort.

🏆 Windows Autopilot Device Preparation ✅ Less administrative effort for standard user-driven deployments.

LOB and Win32 App Deployment Support

With Windows Autopilot Device Preparation, you can deploy both line-of-business (LOB) and Win32 apps within the same deployment. In classic Windows Autopilot enrollment, mixing Win32 and LOB app installations can cause failures since both depend on the TrustedInstaller service running simultaneously.

🏆 Windows Autopilot Device Preparation ✅ Supports both LOB and Win32 apps in the same deployment

Monitoring and Troubleshooting

Windows Autopilot provides ESP status and standard reporting, while Device Preparation offers near real-time reporting for each app and script, along with simple options to export diagnostics.

🏆 Windows Autopilot Device Preparation ✅ Near Real-Time Reporting

Overall OOBE Experience

Windows Autopilot uses the Enrollment Status Page (ESP), while Device Preparation provides a simplified percentage-based progress indicator without requiring ESP setup. Although there are a few additional OOBE screens with Device Preparation, the profile installs only essential apps and scripts during setup. This allows users to reach the desktop more quickly and delivers a smoother overall OOBE experience.

🏆 Windows Autopilot Device Preparation ✅ Simplified OOBE with fewer configuration steps.

Autopilot Co-management Scenario

Windows Autopilot Device Preparation does not support co-management, and attempting to enable it during the Device Preparation flow may result in failed deployments. In contrast, Windows Autopilot (classic) supports co-management.

Autopilot into co-management is a classic Autopilot workflow that enrolls a new Windows device into both Intune and Configuration Manager during OOBE, making it co-managed from day one with workloads split according to your co-management settings.

Note

Autopilot vs. Device Preparation: Can you use both?

Yes, Windows Autopilot (V1) and Windows Autopilot device preparation (V2) can coexist within the same Microsoft Intune tenant. Organisations can use both deployment methods for different devices, depending on their enrollment and configuration requirements.

However, a device can use only one deployment method during a particular provisioning process. When a device is configured for both, Windows determines which deployment experience to use based on its registration and device association status.

If a device is registered with classic Windows Autopilot but is not associated with the organisation through device association, the classic Windows Autopilot deployment takes precedence. However, if the device is associated with the organisation, Windows Autopilot device preparation takes precedence, and the device is provisioned using the applicable device preparation policy.

Hardware Hash + Device Association = Priority?

If a device’s hardware hash has already been uploaded to Intune for classic Windows Autopilot and the same device is also associated with the organisation using Windows Autopilot device association, device association takes precedence over hardware hash registration.

During OOBE, the device follows the Windows Autopilot device preparation deployment instead of the classic Windows Autopilot deployment profile. Therefore, administrators do not need to remove the existing Windows Autopilot registration to use device preparation, provided the device has been successfully associated with their tenant.

If you want to use Windows Autopilot device preparation on an existing Autopilot-registered device without using device association, you must first remove its classic Windows Autopilot registration. For step-by-step instructions, refer to my post: Delete Windows Autopilot Devices from Intune and Entra ID.

Note

Leave a Comment