Administrator access
- Microsoft 365 work or school administrator account
- Ability to grant tenant-wide admin consent
- Access to Microsoft Intune and Microsoft Entra
This guide explains how to connect a Microsoft 365 tenant, preview an Autopilot deployment, deploy Cloud or Hybrid configuration, and verify the resulting Microsoft Intune and Microsoft Entra objects.
Preview mode performs validation only. It does not create or modify tenant objects. After a successful preview, use Deploy now to queue the live deployment.
Confirm the tenant is ready before starting.
The portal requires the following permissions to perform deployment operations.
| Permission | Type | Purpose |
|---|---|---|
Application.ReadWrite.All |
Application | Create or update the optional Autopilot Registration Application. |
Directory.ReadWrite.All |
Application | Create and manage required directory objects and service principals. |
DeviceManagementConfiguration.ReadWrite.All |
Application | Create and update Intune configuration and Autopilot objects. |
DeviceManagementServiceConfig.ReadWrite.All |
Application | Read and update Intune enrollment and Autopilot service configuration. |
DeviceManagementScripts.ReadWrite.All |
Application | Create or update Intune Platform Scripts, including the optional N-central agent installer. |
Group.ReadWrite.All |
Application | Create dynamic Autopilot groups and configure required group ownership. |
User.Read |
Delegated | Sign in the administrator and read the signed-in user profile. |
If a permission is added to the portal app registration after a tenant has already connected, an administrator for that customer tenant must grant admin consent again.
The portal separates validation from live changes.
Sign in and grant the required Microsoft Graph permissions.
Select Cloud Autopilot, Hybrid Autopilot, or the registration application workflow.
Provide the customer short name, device groups, and deployment-specific values.
Run readiness and discovery checks. No tenant objects are changed.
Queue autopilot-base-deployment using the exact preview settings.
Review Created, Updated, Reused, Assigned, Warning, or Failed results.
For Microsoft Entra joined Windows devices.
CFHT Laptops
CFHT Workstations
CFHT Tablets
Profile names use the configured customer short name, not the full Microsoft 365 tenant name.
For devices that must join on-premises Active Directory and register with Microsoft Entra.
An existing Domain Join profile with a different computer prefix does not block Hybrid readiness. A missing Intune Connector for Active Directory still blocks Hybrid deployment.
Deployments are designed to reuse existing matching objects whenever possible.
| Object | Location | Behavior |
|---|---|---|
| Autopilot Preparation Device group | Microsoft Entra groups | Created if missing; required service principal is assigned as owner. |
| Device groups | Microsoft Entra groups | Created or reused based on the configured Autopilot group tags. |
| Autopilot deployment profiles | Intune → Windows enrollment → Deployment Profiles | Created or updated and assigned to matching groups. |
| Autopilot Enrollment settings | Intune configuration | Created or updated for Cloud and Hybrid deployments. |
| N-central Platform Script | Intune → Scripts and remediations → Platform scripts | Created or updated when N-central deployment is enabled. |
| Autopilot Registration Application | Microsoft Entra app registrations | Created or reused when the registration application option is selected. |
The standard Cloud device groups do not include the customer name.
| Device type | Standard group | Profile assignment |
|---|---|---|
| Laptops | grp_devices_laptops |
<SHORTNAME> Laptops |
| Workstations | grp_devices_workstations |
<SHORTNAME> Workstations |
| Tablets | grp_devices_tablets |
<SHORTNAME> Tablets |
The portal can use the standard groups shown above or customer-specific custom groups. When the custom option is selected, enter both the desired group display name and the corresponding Autopilot group tag for each device type.
| Custom field | Purpose | Example |
|---|---|---|
| Custom group name | The Microsoft Entra dynamic group display name created or reused by the deployment. | grp_devices_sales_laptops |
| Custom group tag | The Windows Autopilot OrderID / group tag used by the group's dynamic membership rule. | Sales-Laptops |
Custom names are left exactly as entered. The portal does not
add the customer short name, autopilot,
cloud, or hybrid to a custom group
name. The hard-coded preparation group remains
Autopilot Preparation Device group.
Created or updated after Cloud or Hybrid deployment.
Autopilot Enrollment settingsDisable user ESPDisable Winlogon Animation
| Setting | OMA-URI | Type | Value |
|---|---|---|---|
| Skip User Status Page | ./Vendor/MSFT/DMClient/Provider/MS DM Server/FirstSyncStatus/SkipUserStatusPage |
Boolean | True |
| Enable First logon Animation | ./Device/Vendor/MSFT/Policy/Config/WindowsLogon/EnableFirstLogonAnimation |
Integer | 0 |
Optional Intune Platform Script deployment after Autopilot configuration.
CUSTOMERIDREGISTRATION_TOKENThe customer registration token is sensitive. Protect the portal's private job directory and restrict access to the generated Intune Platform Script.
Optional Entra application for Autopilot registration automation.
The client secret belongs to the optional Autopilot Registration Application. It is not required for the Cloud Autopilot deployment profile itself.
Use the status page to understand exactly what happened.
The requested validation or deployment step completed successfully.
The deployment can continue, but the item needs review.
The step blocked deployment and must be corrected before retrying.
Validation completed. No tenant objects were created or modified.
autopilot-base-preview
autopilot-base-deployment
Common deployment conditions and what they mean.
This is expected. Preview is read-only. Select Deploy now after reviewing the preview results to queue the live deployment.
Hybrid deployment cannot proceed without an active Intune Connector for Active Directory. Install and register the connector, verify it appears in Intune, and rerun the preview.
Open step-by-step Intune Connector guide
The Solidice guide covers installation, registration,
the automatically created MSA* account,
OU delegation, Create/Delete Computer Object rights,
validation, and common ODJ failures.
An existing Hybrid Domain Join profile using a different computer prefix is reported as a warning rather than a readiness failure. Review the existing profile before deployment.
Confirm the portal app has the
DeviceManagementScripts.ReadWrite.All
application permission and that the customer tenant
granted admin consent after that permission was added.
Confirm Microsoft Intune licensing, MDM authority, and Windows enrollment are initialized. Verify the profile can be assigned to the target group manually in Intune.
Microsoft Entra can take time to replicate a newly
created application. The worker includes retry handling
for the NoBackingApplicationObject condition.
Protect the portal and deployment data as production infrastructure.
private/config.php outside the public web root.Validate the environment before making any changes.