About Windows Autopilot
Autopilot targets corporate devices that are registered with the Windows Autopilot service and assigned an Autopilot deployment profile through Intune. Iru Endpoint supplies the MDM Terms of Use URL, MDM Discovery URL, and enrollment defaults (including Blueprint assignment) in the wizard under Integrations → Windows. Device registration in Intune and Autopilot deployment profiles are Microsoft-side steps; they determine OOBE behavior before the user reaches the sign-in that triggers management enrollment.How It Works
Run the Autopilot configuration wizard in Iru Endpoint to create or bind the Entra app registration and verify an Iru-managed domain. When a registered device comes online, Windows runs OOBE, applies your Autopilot deployment profile from Intune, then continues to Entra sign-in. Successful authentication enrolls the device into Iru Endpoint using the default Blueprint or Blueprint Routing, depending on what you configured in the final wizard step.Prerequisites
- Windows platform enabled for your tenant. If it is not on yet, turn it on in Organization first. See Windows Setup.
- Microsoft Entra ID permissions: Ability to add custom domains, configure Mobility (MDM and WIP), and create or edit app registrations (including API permissions and admin consent)
- Microsoft Entra admin center access for your tenant
- Microsoft licensing that covers Windows Autopilot and MDM auto-enrollment for your scenario
- Windows 11 devices that meet Iru Endpoint Windows requirements (24H2 or 25H2 only; supported editions)
- Autopilot registration path in place for your devices (OEM pre-registration, partner/CSP registration, or manual import) and Intune access to assign an Autopilot deployment profile
Create the MDM Application and Enter Credentials
Entra guidance appears on the left of the wizard; credential and flow fields are on the right. Start in Iru Endpoint, use the Microsoft Entra ID tab for the Microsoft Entra admin center steps, then return to Iru Endpoint when the steps below tell you to.- Iru Endpoint
- Microsoft Entra ID
Prepare the Autopilot wizard
Open Integrations
Select Windows
Configure Autopilot
Copy the MDM URLs from Instructions
Enter MDM credentials in the Autopilot wizard
Paste IDs and secret
- Application (client) ID
- Directory (tenant) ID
- Secret value
- Secret ID
Select Next
Update pasted values after Entra changes
Blueprint Settings and Finish Setup
Select Next after Application ID URI
Choose default Blueprint or Blueprint Routing
Finish setup
Microsoft Intune: Device Registration and Deployment Profiles
For how these Microsoft-side steps fit the full Autopilot flow with Iru Endpoint, see Considerations → Microsoft Intune and Autopilot end-to-end.Register devices with Windows Autopilot
Registration associates the device hardware hash with your tenant so Windows knows to run Autopilot OOBE. When a registered device first connects to the internet, Windows identifies it as an Autopilot device and starts that flow. Depending on how devices are purchased, you may not need to register devices manually at all. Common registration paths:- OEM pre-registration: Hardware manufacturers can register devices with Autopilot at purchase time.
- Partner (CSP) registration: Cloud Solution Providers can register devices for you.
- Manual registration: For existing devices, you can capture hardware hashes with PowerShell, export to CSV, and import into Intune.
Configure an Autopilot deployment profile
The deployment profile controls which OOBE screens appear, including privacy settings, EULA, Windows Hello, and personal Microsoft account blocking. In Intune, create the profile and assign it to a Microsoft Entra device group whose members are your Autopilot-registered devices. The profile must be targeted at devices, not at users only, so Windows can apply it during OOBE before Microsoft Entra sign-in. The device does not need an active Intune MDM enrollment for Autopilot to hand off to Iru Endpoint as your MDM; the profile shapes OOBE only. Deployment mode options: On the Out-of-box experience (OOBE) page in Intune, set Deployment mode to one of the following values:- User-driven: The device is associated with the user who enrolls it. That user must supply their credentials during OOBE before enrollment can complete.
- Self-deploying: The device is not associated with a user for that enrollment path, and user credentials are not required to enroll the device through Autopilot. With no user on the device in that state, user-based compliance policies do not apply; only compliance policies targeted at the device apply.
- Privacy settings: Hide or show the privacy settings page.
- End user license agreement (EULA): Skip the license screen when appropriate for your policy.
- Account change: Block switching to a personal Microsoft account during setup.
- Windows Hello: Skip or defer Hello setup.
- OEM registration: Skip manufacturer-specific prompts.
Considerations
Microsoft Intune and Autopilot end-to-end
Microsoft Intune and Autopilot end-to-end
- Autopilot device registration: Devices are registered with the Windows Autopilot service (for example by an OEM, a partner, or your team in Intune).
- Autopilot deployment profile: A deployment profile exists in Intune and is assigned to a Microsoft Entra device group that contains your Autopilot-registered devices. Use User-driven deployment mode only; Iru Endpoint does not support Autopilot self-deploying mode (see Configure an Autopilot deployment profile above).
Blueprint defaults, routing, and sync
Blueprint defaults, routing, and sync
- Default Blueprint: Applies to new Autopilot enrollments going forward. Changing the default later does not retroactively move devices that already synced.
- Blueprint Routing: Must be fully configured before you can save when Routing is selected as the default. If you cannot save on the last step, complete Routing setup from the warning link first.
App registration and client secret
App registration and client secret
- Client secret lifetime: Secrets expire on the date you choose in Entra. Before expiry, create a new secret and update Secret value and Secret ID in Integrations → Windows → Autopilot configuration so enrollment keeps working.
- Admin consent: API permissions need Grant admin consent for the tenant. Without consent, Iru cannot complete Graph operations required for the integration.
- Entra MDM access tokens: Iru Endpoint accepts both v1 and v2 tokens issued for the custom MDM application. New apps created after July 1, 2026 use v2 by default; existing apps may still issue v1 tokens.
Microsoft Entra hybrid join
Microsoft Entra hybrid join
- Not supported with Autopilot for Iru: Iru Endpoint does not support Microsoft Entra hybrid joined devices enrolling through this Windows Autopilot flow. Plan for Microsoft Entra joined devices when using Autopilot with Iru Endpoint.
Best Practices
Configure Blueprint Routing early
Track secret expiration
Confirm admin consent
Validate licensing
Troubleshooting
Devices do not enroll after Autopilot completes
Devices do not enroll after Autopilot completes
- Every Autopilot wizard step completed successfully in Iru Endpoint.
- MDM Terms of Use URL and MDM Discovery URL in Entra match Step 6 in Instructions on the Iru wizard page (paste exactly).
- Admin consent is granted for every Graph application permission on the Iru Endpoint Management registration.
- Autopilot registration and deployment profile assignments in Intune cover the device.
- The Autopilot deployment profile uses User-driven mode. Iru Endpoint does not support Autopilot self-deploying mode.
- Microsoft licensing supports Autopilot and MDM enrollment for the user.
Autopilot device enrolled in the wrong MDM instead of Iru Endpoint
Autopilot device enrolled in the wrong MDM instead of Iru Endpoint
Cannot save on the final wizard step
Cannot save on the final wizard step