Runbook — Provision a New Windows Laptop with Intune
| Version | 1.0 |
| Date | 2026-06-22 |
| Employee | Sally Wong → swong@mptwork.com |
| Device | Windows 11 laptop (corporate, provisioned via Windows Autopilot + Microsoft Entra join) |
| Tenant | mptwork.com (mptwork.onmicrosoft.com) |
| Consoles | Intune intune.microsoft.com · M365 admin admin.microsoft.com · Entra entra.microsoft.com |
| Companion SOPs | Intune device management — sop-manage-devices-intune-mptwork.md · macOS equivalent — runbook-provision-macbook-intune-ben-scully.md |
Assumes tenant prerequisites are in place: Intune is the MDM authority, Windows automatic enrollment (MDM user scope) is on, a Windows Autopilot deployment profile and Enrollment Status Page exist, and compliance/configuration policies and apps are assigned to a staff group. This runbook provisions one laptop for one new hire.
Phase A — Pre-provisioning (IT, before powering on the laptop)
A1. Create Sally's identity and license
- M365 admin center → Users → Add a user:
- Display name: Sally Wong
- Username:
swong@mptwork.com - Usage location, job title, department, manager.
- Assign Microsoft 365 Business Premium (includes Intune, Defender for Business, Entra ID P1, Windows Update for Business). Confirm under Licenses.
- Set a temporary password and require change at first sign-in.
A2. Add Sally to the right groups
- Entra → Groups → add
swong@mptwork.comto:- the licensing group (if using group-based licensing),
- the Windows staff group that compliance policies, configuration profiles, and required apps are assigned to (e.g.,
Staff-Windows).
- This drives policy/app targeting during provisioning — confirm before the device is turned on.
A3. Register the laptop in Windows Autopilot
- Get the device's hardware hash:
- New device: the OEM/reseller can register it to your tenant automatically, or supply a hardware-hash CSV.
- Manual: run
Get-WindowsAutopilotInfoon the device and export the CSV.
- Intune → Devices → Enrollment → Windows → Windows Autopilot → Devices → Import the CSV (or confirm the OEM-registered device appears).
- Confirm the device receives a user-driven, Microsoft Entra join Autopilot deployment profile (assign via its device group / group tag), and that the Enrollment Status Page (ESP) is configured.
Newer alternative: Windows Autopilot device preparation uses a device-preparation policy targeted to a security group and doesn't require pre-importing the hardware hash. Either path achieves a zero-touch, Entra-joined, Intune-enrolled laptop.
A4. Pre-flight checks
- Compliance policy assigned to
Staff-Windows(BitLocker, Secure Boot, minimum OS build, Defender healthy, firewall on). - Configuration profiles assigned: security baseline, BitLocker disk encryption (with recovery-key escrow to Entra), Windows Update rings, Wi-Fi/VPN, restrictions.
- Required apps assigned: Microsoft 365 Apps, Microsoft Edge, Company Portal, Microsoft Defender.
- Windows Hello for Business policy enabled (PIN/biometric).
Phase B — Provisioning at the device (Windows OOBE / Autopilot)
This can be done by IT first or handed to Sally. The laptop must reach the internet.
- Power on the laptop; choose region and keyboard; connect to Wi-Fi (or Ethernet).
- Autopilot recognizes the device and shows the MPT Work-branded company sign-in (OOBE is locked down per the profile).
- Sally signs in with
swong@mptwork.comand the temporary password, then completes MFA if prompted. - The laptop performs a Microsoft Entra join and auto-enrolls into Intune.
- The Enrollment Status Page runs, applying device- and user-phase policies, certificates, and required apps before handing over the desktop.
- Sally lands on the Windows desktop signed in with her account; she's prompted to set up Windows Hello (PIN/biometric).
Alternate (not Autopilot-registered): on the desktop go to Settings → Accounts → Access work or school → Connect → Join this device to Microsoft Entra, sign in as swong@mptwork.com (auto-enrolls). Then in Intune set the device Ownership = Corporate. This skips the branded OOBE experience.
Phase C — Automatic configuration and apps (verify, don't rush)
Allow several minutes and keep the laptop online.
- Configuration profiles apply: security baseline, BitLocker (encryption begins; the recovery key escrows to Entra), Windows Update ring, Wi-Fi/VPN, restrictions.
- Required apps install: Microsoft 365 Apps, Microsoft Edge, Microsoft Defender, Company Portal.
- Defender for Business onboards the device.
- Compliance policy evaluates (BitLocker on, Secure Boot, minimum build, Defender healthy, firewall on).
Phase D — Verify and enforce (IT)
- Intune → Devices → Windows → open Sally's laptop:
- Enrolled = yes, Ownership = Corporate, Primary user = Sally Wong (set under Properties if needed).
- Compliance = Compliant (wait out any grace period; if non-compliant, open the policy to see which setting failed).
- Confirm BitLocker is On and the recovery key is stored (device → Recovery keys, or in Entra under the device).
- Confirm required apps installed (device → Managed Apps) and that Sally can install optional apps from Company Portal.
- Confirm Defender shows the laptop onboarded (Defender portal → Devices).
- Confirm Conditional Access: from this compliant laptop Sally can reach Microsoft 365; a non-compliant/unmanaged device is blocked.
Phase E — Hand off to Sally
Provide Sally with:
- Sign-in:
swong@mptwork.com+ temporary password (change at first sign-in). - MFA enrollment: register at
https://aka.ms/mfasetup(Microsoft Authenticator recommended). - Windows Hello: finish setting up a PIN/biometric for fast, secure sign-in.
- Company Portal: where to install approved apps and check device status.
- What's already set up: email/Teams/OneDrive, BitLocker encryption, security software.
- IT support contact and the acceptable-use / device policy to acknowledge.
Sally's quick start:
- Sign in, set up Windows Hello, complete MFA registration, change the password.
- Open Outlook/Teams to confirm mail and chat.
- Open Company Portal to confirm the device is compliant and browse optional apps.
Phase F — Record and close out
- Set/confirm Primary user = Sally Wong in Intune.
- Update the asset register: serial number, model, assigned to Sally Wong, issue date, enrollment date.
- Note the BitLocker recovery key location (Entra/Intune) for support.
- Close the onboarding ticket.
Quick checklists
IT pre-provisioning
| ✔ | Item |
|---|---|
| ☐ | swong@mptwork.com created, licensed (Business Premium) |
| ☐ | Added to Staff-Windows (+ licensing group) |
| ☐ | Laptop hardware hash imported to Autopilot (or device-preparation group set), deployment profile + ESP assigned |
| ☐ | Compliance, config (BitLocker), Update rings, apps, Windows Hello assigned |
Post-enrollment verification
| ✔ | Item |
|---|---|
| ☐ | Enrolled, Corporate, Primary user = Sally Wong |
| ☐ | Compliant; BitLocker on, key escrowed to Entra |
| ☐ | Required apps installed; Defender onboarded |
| ☐ | Conditional Access enforced; Company Portal works |
Notes
- Signing in as Sally during OOBE (user-driven Autopilot) is what binds the laptop to her and applies her user-targeted policies — don't pre-complete OOBE with a generic account.
- If the device isn't registered in Autopilot, you lose the branded zero-touch OOBE; use Entra join + auto-enrollment and set ownership to Corporate.
- BitLocker recovery keys escrow to Entra automatically with the disk-encryption policy — verify they're present before handing the device over.
- Verify current steps against Microsoft Learn — the Intune portal, Autopilot, and device-preparation flows change periodically.