We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Intune and endpoint management
  2. Autopilot device preparation
Windows Autopilot device preparation, UAE

Register a device for classic Autopilot and the Autopilot profile wins. Device preparation never runs.

Microsoft states the precedence rule directly, and it is the single most common reason a device preparation pilot appears to do nothing. The two mechanisms are separate, they are not layered, and a device can only be in one of them.

Book a device preparation reviewSee how it differs
Windows Autopilot device preparation for UAE organisations
  • Entra join onlyHybrid join is not supported
  • Windows 1124H2, or 23H2 and 22H2 with the March 2024 update
  • Enrolment timeWhen the device joins its security group
  • Near real timeDeployment status per device
The precedence rule

A device already registered for Windows Autopilot will ignore the device preparation policy.

This is documented, and it is the reason a proportion of device preparation pilots appear to do nothing at all.

  • The published rule is explicit: the device should not be registered or added as a Windows Autopilot device, and if it is, the Windows Autopilot profile takes precedence over the Windows Autopilot device preparation policy.
  • That produces a confusing pilot. The policy is configured correctly, the device is enrolled correctly, and the classic Autopilot experience appears instead, which looks like the new policy failing rather than the old registration winning.
  • Checking registration state before testing takes a minute and removes the ambiguity entirely. It also forces a useful conversation about which devices should follow which path, rather than leaving the two approaches to collide device by device.
  • The other prerequisite to confirm early is identity: only Microsoft Entra join is supported. Estates that are hybrid joined by default need that difference understood before they plan a rollout around device preparation.
What device preparation does

Eight things that determine whether it works as expected.

Device preparation is a genuinely better provisioning experience with a narrower set of prerequisites than classic Autopilot. Three of its behaviours differ from what people assume, and all three are documented rather than surprising once you know to look.

It cannot coexist with classic Autopilot on the same device

If a device is registered or added as a Windows Autopilot device, the Windows Autopilot profile takes precedence over the device preparation policy. A device intended for device preparation must not be registered for Autopilot, and if it already is, it needs deregistering first.

Microsoft Entra join only

Only Microsoft Entra join is supported. Hybrid Entra join is not, which rules device preparation out for estates still dependent on on-premises domain join for line of business applications, and makes it a natural fit for organisations that have already moved past that.

Enrolment time grouping is the mechanism

When a user authenticates, the device is added to a pre-defined device security group during enrolment, and what is assigned to that group deploys. Microsoft notes direct assignment deploys quicker and more efficiently than a dynamic device group, which is the underlying performance improvement.

Only what you selected runs during setup

Only applications and PowerShell scripts selected in the device preparation profile are deployed during the out of box experience. Anything else assigned to the same device group deploys after the deployment completes, which is a meaningful distinction when a critical application is missing at first sign in.

Policies sync but are not tracked

Device preparation syncs any policies assigned to the device group, and does not track whether those policies are applied during the deployment. They might apply during it or after it completes. Treating policy application as guaranteed at desktop arrival is the mistake to avoid.

No custom images to maintain

It uses the OEM-optimised version of Windows preinstalled on the device, so custom images and drivers do not need maintaining per device model. Rather than re-imaging, the existing Windows installation is transformed into a business-ready state, which is what removes the imaging infrastructure.

A better experience at the machine

A simplified out of box experience with a percentage progress indicator for user-driven flows, users informed when setup is complete, logs exportable easily when something goes wrong, and standard non-administrator users by default rather than as a setting somebody has to remember.

Reporting that actually helps

Near real-time status per device covering device details, profile name and version, deployment status details, applications applied with status, and scripts applied with status. That level of detail is the practical difference when troubleshooting a deployment that stalled.

The three behaviours that catch people

Registered for Autopilot, and device preparation simply does not apply.

Each of these is documented, and each produces a symptom that looks like a fault rather than a design.

  • If the device is registered or added as a Windows Autopilot device, the Windows Autopilot profile takes precedence over the device preparation policy. A pilot device that was previously registered for Autopilot will therefore go through the old flow, with nothing obvious explaining why.
  • Only applications and PowerShell scripts selected in the device preparation profile deploy during the out of box experience. Additional items assigned to the same device security group deploy afterwards, so an application the user needs at first sign in must be selected in the profile rather than merely assigned to the group.
  • Policies assigned to the device group are synced, and device preparation does not track whether they applied during the deployment. They might apply during it or after it. Any acceptance test that assumes a specific policy is in force the moment the desktop appears will be intermittently wrong.
  • The version requirement is also narrower than people expect: Windows 11 version 24H2 or later, or 23H2 and 22H2 with the March 2024 update or later. Devices below that are not candidates, and in a mixed estate that needs establishing before a pilot rather than during it.
Ask us to check your device eligibility
How we approach it

Four things that make a device preparation pilot succeed first time.

The technology is straightforward. Almost every unsuccessful pilot we see traces back to one of three documented behaviours that nobody read before testing.

We check for existing Autopilot registrations first

If a device is registered or added as a Windows Autopilot device, the Autopilot profile takes precedence over the device preparation policy. A pilot run on a previously registered device tests classic Autopilot while everybody believes they are testing device preparation.

We separate profile content from group assignment

Only applications and scripts selected in the profile deploy during the out of box experience. Everything else assigned to the group arrives afterwards. Deciding which applications a user genuinely needs at first sign in is the design decision that determines whether the device feels ready.

We set expectations about policy timing

Device preparation syncs policies assigned to the device group and does not track whether they applied during the deployment. Acceptance criteria written as a specific policy being in force at desktop arrival will pass sometimes and fail sometimes, which is the worst kind of test.

We confirm the join type before anything else

Only Microsoft Entra join is supported. For an organisation still dependent on hybrid join for line of business applications, device preparation is not the right tool yet, and establishing that in the first conversation saves a pilot that was never going to work.

How a rollout runs

Four phases across roughly four weeks.

Faster than a classic Autopilot rollout because there is no per-device registration to manage. The time goes into deciding what belongs in the profile rather than merely in the group.
  1. 01
    Week 1

    Confirm eligibility and clear prior registrations

    Windows version checked against the requirement, join type confirmed as Entra join rather than hybrid, and any devices already registered for classic Autopilot identified, since the Autopilot profile would otherwise take precedence and the device preparation policy would never apply.

    • Windows version coverage established across the estate
    • Entra join confirmed as the target join type
    • Devices registered for classic Autopilot identified
    • Deregistration decisions recorded per device group
  2. 02
    Week 2

    Design the device group and decide what goes in the profile

    The device security group defined, then the important distinction: which applications and scripts must be present at first sign in and therefore belong in the profile, and which can arrive afterwards and can simply be assigned to the group.

    • Device security group created for enrolment time grouping
    • Applications selected in the profile versus assigned to the group
    • PowerShell scripts selected and ordered
    • Policies assigned to the group with expectations set
  3. 03
    Week 3

    Build the profile and pilot on real hardware

    A single profile provisioning deployment and out of box experience settings in one location, then piloted on actual devices of the models you deploy. The percentage progress indicator and completion message are worth observing rather than assuming.

    • Device preparation profile built and assigned
    • Pilot completed on representative hardware
    • Deployment time measured end to end
    • Log export path tested from a pilot device
  4. 04
    Week 4

    Add enrolment controls and hand over

    Corporate identifiers uploaded where enrolment restrictions block personal device enrolment, monitoring reviewed so the near real-time reporting is being used, and the service desk shown the per device view with application and script status.

    • Corporate identifiers uploaded where required
    • Enrolment restrictions aligned with the approach
    • Monitoring demonstrated to the service desk
    • Runbook covering the documented behaviours
Where this fits

Six situations where device preparation is the right choice.

The common requirement is cloud-native Windows provisioning with better visibility than classic Autopilot offers, on hardware that is current enough to qualify.

An organisation already on Entra join

The prerequisite that decides it. For estates that completed the move away from domain join, device preparation offers a simpler profile model, faster deployment through direct group assignment, and considerably better reporting than the classic flow provides.

A business tired of maintaining images

It uses the OEM-optimised Windows preinstalled on the device, so custom images and drivers do not need maintaining for every model. The existing installation is transformed into a business-ready state rather than replaced, which removes the imaging infrastructure entirely.

A team that cannot see why deployments fail

Classic Autopilot troubleshooting is frequently guesswork. Near real-time status with device details, profile name and version, and per application and per script status turns a stalled deployment into a specific failing item, which is a different conversation with the vendor.

An operator shipping devices directly to sites

No technician touch and no per-device registration means a device can go from supplier to site and be provisioned by the person who opens the box. The percentage progress indicator and completion message matter here, because nobody technical is standing next to the machine.

A regulated firm that wants standard users by default

Device preparation makes users standard non-administrator users by default rather than leaving it as a setting somebody configures. For organisations where local administrator sprawl has been an audit finding, defaulting the right way is worth more than documenting the right way.

A company restricting enrolment to known hardware

Corporate identifiers allow pre-uploading serial number, manufacturer and model so only trusted devices go through device preparation. Microsoft notes this is only required where enrolment restrictions block personal device enrolment, which is a common configuration.

Three positions

How UAE organisations provision new Windows devices.

The right column still exists in more estates than anybody admits, and it is the one that ties provisioning speed to how many technicians are available that week.
Custom images maintained
Autopilot device preparationNone
Classic Windows AutopilotNone
Manual build or imagingPer model
Per device registration needed
Autopilot device preparationNo
Classic Windows AutopilotYes
Manual build or imagingNot applicable
Hybrid Entra join supported
Autopilot device preparationNo
Classic Windows AutopilotYes
Manual build or imagingYes
Grouping
Autopilot device preparationAt enrolment time, direct
Classic Windows AutopilotUsually dynamic groups
Manual build or imagingManual
Apps during setup
Autopilot device preparationProfile selected
Classic Windows AutopilotEnrolment status page
Manual build or imagingInstalled by hand
Progress visible to the user
Autopilot device preparationPercentage indicator
Classic Windows AutopilotStatus page
Manual build or imagingNone
Per script deployment status
Autopilot device preparationYes
Classic Windows AutopilotLimited
Manual build or imagingNo
Technician time per device
Autopilot device preparationNone
Classic Windows AutopilotNone
Manual build or imagingSubstantial
Standard user by default
Autopilot device preparationYes
Classic Windows AutopilotConfigurable
Manual build or imagingFrequently not
Suits a hybrid joined estate
Autopilot device preparationNo
Classic Windows AutopilotYes
Manual build or imagingYes
Feature
Autopilot device preparation
Classic Windows Autopilot
Manual build or imaging
Custom images maintained
NoneNonePer model
Per device registration needed
NoYesNot applicable
Hybrid Entra join supported
NoYesYes
Grouping
At enrolment time, directUsually dynamic groupsManual
Apps during setup
Profile selectedEnrolment status pageInstalled by hand
Progress visible to the user
Percentage indicatorStatus pageNone
Per script deployment status
YesLimitedNo
Technician time per device
NoneNoneSubstantial
Standard user by default
YesConfigurableFrequently not
Suits a hybrid joined estate
NoYesYes
Choosing between them

Autopilot device preparation against classic Windows Autopilot.

They are alternatives rather than layers. The join type requirement decides most cases on its own, and the rest turns on how much you value the reporting.
ConsiderationDevice preparation
Join type supportedMicrosoft Entra join only
Windows version requiredWindows 11 24H2, or 23H2 and 22H2 with the March 2024 update
Device registration needed in advanceNo, and prior Autopilot registration takes precedence
Grouping mechanismEnrolment time grouping into a pre-defined device security group
Group assignment typeDirect, which deploys faster than a dynamic device group
Applications during setupOnly those selected in the profile
Application typesLine of business and Win32 in the same deployment
Policy application trackedNo, policies sync but application is not tracked
User rights by defaultStandard non-administrator
ReportingNear real time, with per application and per script status
How an engagement runs

Five steps, and the first two are eligibility rather than build.

Confirming that device preparation can apply at all takes an hour and prevents a fortnight of confusing pilot results.
  1. 1

    Confirm version and join type eligibility

    Windows 11 version 24H2 or later, or 23H2 and 22H2 with the March 2024 update or later, and Microsoft Entra join rather than hybrid join. Both are hard requirements, and an estate failing either needs a different provisioning approach rather than an adjusted one.

  2. 2

    Clear any classic Autopilot registrations

    Where a device is registered or added as a Windows Autopilot device, the Autopilot profile takes precedence. Devices intended for device preparation need deregistering first, otherwise the pilot silently tests the mechanism you were moving away from.

  3. 3

    Design the device group and profile content

    A device security group for enrolment time grouping with direct assignment, since that deploys faster than a dynamic group. Then the split between applications and scripts selected in the profile, which run during setup, and everything else assigned to the group, which runs afterwards.

  4. 4

    Build the profile and pilot on real hardware

    A single profile covering deployment and out of box experience settings, tested on the actual models you deploy. Deployment time measured end to end, and the log export path exercised from a pilot device so the service desk knows it works before they need it.

  5. 5

    Add enrolment controls and hand over the reporting

    Corporate identifiers uploaded where enrolment restrictions block personal devices, and the near real-time monitoring demonstrated to the people who will use it, including the per application and per script status that makes troubleshooting specific rather than general.

Straight answers

What organisations ask about Autopilot device preparation.

Almost certainly because it was already registered as a Windows Autopilot device. Microsoft states that if the device is registered or added as an Autopilot device, the Autopilot profile takes precedence over the device preparation policy. Deregistering the device resolves it.

No. Only Microsoft Entra join is supported. For organisations still dependent on hybrid join because of on-premises line of business applications, device preparation is not available yet, and classic Autopilot remains the route for those devices.

Windows 11 version 24H2 or later, and Windows 11 versions 23H2 and 22H2 with the March 2024 update KB5035942 or later. That is narrower than many estates expect, so establishing version coverage before a pilot is worth the ten minutes it takes.

Structurally, in the grouping. Classic Autopilot generally relies on dynamic device groups. Device preparation adds the device to a pre-defined device security group at enrolment time, and Microsoft notes direct assignment deploys quicker and more efficiently than a dynamic group does.

Not for device preparation itself. Where enrolment restrictions block personal device enrolment, corporate identifiers are required, which means pre-uploading serial number, manufacturer and model so only trusted devices go through the process. That is a different and lighter mechanism.

Most likely because it was assigned to the device group rather than selected in the profile. Only applications and PowerShell scripts selected in the device preparation profile deploy during the out of box experience. Anything else assigned to the group deploys after the deployment completes.

Not guaranteed. Device preparation syncs any policies assigned to the device group but does not track whether they applied during the deployment. Microsoft states they might be applied during the deployment or after it completes, so acceptance tests should not assume one or the other.

Yes, and line of business applications too, in the same deployment. That is one of the specific administrator experience improvements, alongside having a single profile provisioning all the deployment and out of box experience settings in one location rather than across several places.

No. Device preparation uses the OEM-optimised version of Windows preinstalled on the device, so custom images and drivers do not need maintaining for every device model. The existing installation is transformed into a business-ready state rather than replaced.

A simplified out of box experience with a percentage progress indicator for user-driven flows, a clearer and more consistent experience overall, and an explicit message when setup is complete. Where something goes wrong, logs can be exported easily rather than gathered by a technician.

No, by default. Making sure users are standard non-administrator users is one of the stated capabilities rather than something an administrator configures separately. For organisations where local administrator sprawl has been a finding, that default is worth something on its own.

Near real-time deployment status per device, covering device details, profile name and version, deployment status details, applications applied with status, and scripts applied with status. That granularity is the main troubleshooting improvement over the classic experience.

Yes. Windows Autopilot device preparation supports Government Community Cloud High and Department of Defense environments. Microsoft does note separately that Windows 365 Flex in shared mode is not supported for those environments at this time.

Only where the prerequisites are met and the estate is Entra joined. Where hybrid join is still required, or where devices are below the supported Windows versions, classic Autopilot remains the appropriate mechanism and there is no urgency to change that.

We scope by device population and how many application and script dependencies belong in the profile. The free first step: check what proportion of your Windows 11 devices are on 24H2 or later and Entra joined rather than hybrid. That number tells you whether this is available to you.

Only the applications and PowerShell scripts selected in the Windows Autopilot device preparation profile are deployed during OOBE. Anything else assigned to the device group deploys after the device preparation deployment is complete.

No. Device preparation syncs any policies assigned to the device group, but it does not track whether they are applied during the deployment. They might apply during the deployment or after it completes, which matters for anything security relevant.
Before you pilot

Fifteen checks that prevent a confusing first attempt.

The first group determines whether device preparation can apply at all. The second determines whether the deployed device is actually ready when the user reaches the desktop.

Eligibility

  • Are devices on Windows 11 24H2 or later?
    Or 23H2 and 22H2 with the update.
  • Is Entra join the target?
    Hybrid join is not supported.
  • Are any devices registered for Autopilot?
    That profile takes precedence.
  • Do we need to deregister any devices?
    Before piloting them.
  • Are we in a GCCH or DoD environment?
    Both are supported.

Profile content

  • Which apps must exist at first sign in?
    Those go in the profile.
  • Which apps can arrive later?
    Group assignment is enough.
  • Which scripts are needed during setup?
    Selected, not just assigned.
  • Are LOB and Win32 apps both covered?
    They can be in one deployment.
  • Do we depend on a policy being applied at desktop?
    Application is not tracked.

Controls

  • Do we block personal device enrolment?
    Then corporate identifiers are needed.
  • Have serial, manufacturer and model been uploaded?
    The identifier fields.
  • Is the device security group direct assignment?
    Faster than dynamic.
  • Are users standard users by default?
    They are, by design.
  • Has the service desk seen the reporting?
    Per app and per script status.
Related reading

The pages around this one.

Windows Autopilot

The classic mechanism, and the one hybrid joined estates still need.

Learn more

Zero touch deployment

The same idea across Windows, Apple and Android.

Learn more

Device enrolment

The enrolment paths available and what each one requires.

Learn more
Next step

Check two things: Windows version, and whether your devices are Entra joined or hybrid.

Windows 11 24H2 or later, or 23H2 and 22H2 with the March 2024 update, and Entra join only. Those two answers decide whether device preparation is available to you before anybody builds a profile.

Book a device preparation reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Windows Autopilot Dubai

Zero-touch laptop deployment, supplier registration onward

Learn more

Zero-Touch Deployment UAE

Sealed box to working device without IT touching it

Learn more

Device Enrolment

Which path, which reset, and what you can enforce after

Learn more

Intune Configuration Profiles

Settings catalog, templates and conflict management

Learn more

Win32 App Packaging

Packaging, detection rules and deployment that works

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy