Event banner
Windows Autopilot: notes from the field
Event details
Join Microsoft’s Customer Acceleration Team to discuss key learnings from our most complex customers. Take your Windows Autopilot use to the next level by walking through detailed use cases, avoiding common mistakes, and walking through troubleshooting steps that will save you time and improve efficiency.
This session is part of the Microsoft Technical Takeoff: Windows + Intune. Add it to your calendar, RSVP for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
131 Comments
- wollewoldemarBrass ContributorIs it possible to give end user an option to skip the software installation, if the user is connected over low bandwith network/mobile ?
- Herman_Arnedo_Byrne
Microsoft
Hi Viktor, I would like to know more about this scenario. Please, feel free to reach out to me via private message - ZebulonSmithIron ContributorI really like this idea. Timeouts on the ESP are the biggest cause of Autopilot failures that I've seen and the end user's bandwidth is the most difficult variable to overcome. We can specify what apps the ESP should wait for, but it would be nice to allow the user to bypass that step if other items like configuration profiles are applied.
- wollewoldemarBrass ContributorI hope MS will pick this request in their internal dev que.
- Heather_Poulsen
Community Manager
We’ll continue to answer questions here in the chat for the rest of the half hour and we’ll check back throughout the week. For bonus content, make sure to check out our Technical Takeoff Demo Channel!
- NetNightmareBrass ContributorIT would really be helpfull to give any clue on what is going on into the ESP (like what has failed Apps\ Scripts etc.) without having to debug the ESP logs and or Device Events,
- JuanitaBaptiste
Microsoft
Absolutely, we are working on improving the reporting experience across the board so that you do not have to go through the logs to determine what happened, stay tuned!
- GianlucaSBBrass ContributorWhen assigning a device to a user, in the OOBE I still have to insert the user email address. Why isn't it pre-filled already?
- JuanitaBaptiste
Microsoft
Hi Gialuca, this is likely due to the changes we made last year to remove the pre-fill of that information. Please work with your OEM to see if they have enabled this feature: https://techcommunity.microsoft.com/t5/intune-customer-success/return-of-key-functionality-for-windows-autopilot-sign-in-and/ba-p/3583130
- adlewisCopper Contributor
Are there any plans yet to support deploying Configuration Manager client/Co-Management settings in a Hybrid Azure AD Join scenario? This is a significant gap for us to bridge our Endpoint Manager tenant with our existing on-prem environment and investment.
- Chad SimmonsIron Contributor
For reference, https://learn.microsoft.com/en-us/mem/configmgr/comanage/how-to-prepare-win10#windows-autopilot. (see the Note) and it explains that the limitation is due to the identity change of the device during hybrid AAD-join.
I'd love to see a solution (we already have a workaround) to this. Hybrid AAD join isn't going away anytime soon.
- Herman_Arnedo_Byrne
Microsoft
Hi Adam / Chad, We strongly discourage any customer from building their modern provisioning plan on Hybrid Azure AD Join. At best you’re deferring a problem you’ll still have to solve and won’t necessarily get any easier with time. At worst you’ll end up investing lots of time and effort to try and solve a complex problem and gain very little benefit over the current solution you have today that work well and reliably. 1. The HAADJ flow during Autopilot is one we’re seeing customers see issues and lots of unnecessary complexity. 2. HAADJ is really intended to uplift a customer’s existing domain join devices. 3. AAD is the Microsoft recommended path for most new or repurposed devices, especially when using modern deployment tools like Windows Autopilot I would like to know more about your blockers. Please, feel free to reach out to me via private message
- ErinDayBrass ContributorRefreshing! an MS employee saying Autopilot is not as good as task sequences! We all know it. Nice to hear this from MS. Im really hoping it gets there soon, but it would be really good to acknowledge where it falls down. what we've heard most of yesterday is we as admins need to 'relearn' and 'redesign' and 'rethink' the way we do things. Thats fine, but often - the functionality we need, especially as we transition between on-prem and cloud, which can be a long journey, is just not there.
- Herman_Arnedo_Byrne
Microsoft
It is a different scenario, not better, not worse. Task sequence is an orchestrated sequence of actions, Autopilot a collection of technologies used to join your device to Azure AD, enrols it in Intune and then can control certain settings through ESP. The message we wanted to share in this session is that if you're currently using tools like task sequences and Configuration Manager for image-based deployment or app sequences, Windows Autopilot should not be considered as a direct replacement to that. If your organization has complex applications or need to install dozens of apps for a new device provisioning have a look to Co-management settings: Windows Autopilot with co-management - Microsoft Community Hub Another option to look into is just installing a small core set of apps and a few other must-have apps. Then, let the users self-select additional apps they might need using the company portal. If users are okay installing apps with Google Play on Android or the App Store on iOS, there are probably happy to self-select a few apps they need from the company portal and Windows too
Again not better, not worse. There is no specific guidance outside of using what makes more sense for your organization! We are constantly working to improve experiences, stay tuned!
- HeyHey16KIron ContributorAppreciate what you're saying Herman - both Configuration Manager Task Sequences and Autopilot have their strengths. Before implementing Intune, we were solely CM for everything including builds and app/script deployments. We are currently co-managed but only until all apps are migrated to Intune. CM gives us build stability because everything adheres to an ordered TS, with installation files coming from a few dedicated source locations under our control. Autopilot gives us the flexibility to build from anywhere (even the users can do it themselves from home) - however there are many source locations out of our control, many moving parts behind the scenes, the few critical apps etc. we need install in an uncontrolled order, plus issues at central MS cause AP downtime/problems. It, at times, makes AP unreliable whereas once we had a build configured in CM it was 100% success on every build. We embraced Intune/AP as the modern way of working but, reading your comment that AP is not a replacement for CM, are wondering now if we should reconsider moving away from CM.
- ESJeffLBrass ContributorAny information on how to manage AD printers, we do a self service model by using the printer search tool native in Windows but clearly not working on Autopilot devices, this or some other way to add printers would be great.
- Paul_WoodwardIron ContributorToday, it's painful. You can user Add-Printer and target AD print queues, but only in the user context. (If you "Add-Printer" as an admin, the user can't see it). This works if your users are local admin, or if non-admins are allowed to install printers/drivers, which is not a good security stance. In my org we have 2 proactive remediations. One runs as system, and toggles the "non-admins can install printers" settings. The other runs as user, and uses Get-Printer/Add-Printer. Once the User PR has been able to add the printers, it sets a flag so that the System PR knows to restrict printer installation to admins again. Yes, Universal Print makes this all go away, but it is not feature complete yet, and is a massive change, and does not fit all use cases.
- Joe_Lurie
Microsoft
Have you looked at Universal Print? https://aka.ms/UniversalPrint- ESJeffLBrass ContributorThat is the challenge right, long term vs short term. The presentations are great and we want to use new processes with new technologies but to improve adoption we need to solve problems fast and universal print is not something we can do now.
- Nicol HanekomBrass ContributorIs it possible to pre-select the Region and not display it during Autopilot before the network connection screen? Our devices are all in one region so do not need this screen.
- JuanitaBaptiste
Microsoft
Hi Nicol, you cannot pre-select region but you can skip the page for your users in Autopilot.- Nicol HanekomBrass ContributorHow do I skip it?
- Eric_Davignon1Brass ContributorHDJ Autopilot we cant have the same nomanclature flexibility has cloud only. We cant do %SERIAL% we receive a random tenant code, why?
- Tim_PawasaratIron ContributorI agree. Having to run a renaming script after the device is loaded I consider to be a unnecessary step.
- Eric_Davignon1Brass ContributorFor large company who still have some stuff on premiss it's not that simple to put everything on the cloud. I don't get why it's not availabled for us
- Heather_Poulsen
Community Manager
We’re happy you’re here with us at the Microsoft Technical Takeoff! Whether you are attending one session or many, please take this 2-minute survey and let us know your thoughts on this event.