Solidice Autopilot Deployment Portal

Deployment documentation

This guide explains how to connect a Microsoft 365 tenant, preview an Autopilot deployment, deploy Cloud or Hybrid configuration, and verify the resulting Microsoft Intune and Microsoft Entra objects.

Preview first, deploy second.

Preview mode performs validation only. It does not create or modify tenant objects. After a successful preview, use Deploy now to queue the live deployment.

01

Prerequisites

Confirm the tenant is ready before starting.

Administrator access

  • Microsoft 365 work or school administrator account
  • Ability to grant tenant-wide admin consent
  • Access to Microsoft Intune and Microsoft Entra

Tenant readiness

  • Microsoft Intune licensing is active
  • Microsoft Intune is configured as the MDM authority
  • Windows enrollment is initialized
  • For Hybrid: an Intune Connector for Active Directory is installed and active
02

Required Microsoft Graph permissions

The portal requires the following permissions to perform deployment operations.

Permission Type Purpose
Application.ReadWrite.All Application Create or update the optional Autopilot Registration Application.
Directory.ReadWrite.All Application Create and manage required directory objects and service principals.
DeviceManagementConfiguration.ReadWrite.All Application Create and update Intune configuration and Autopilot objects.
DeviceManagementServiceConfig.ReadWrite.All Application Read and update Intune enrollment and Autopilot service configuration.
DeviceManagementScripts.ReadWrite.All Application Create or update Intune Platform Scripts, including the optional N-central agent installer.
Group.ReadWrite.All Application Create dynamic Autopilot groups and configure required group ownership.
User.Read Delegated Sign in the administrator and read the signed-in user profile.
New permissions require new tenant consent.

If a permission is added to the portal app registration after a tenant has already connected, an administrator for that customer tenant must grant admin consent again.

03

Deployment workflow

The portal separates validation from live changes.

1

Connect tenant

Sign in and grant the required Microsoft Graph permissions.

2

Choose deployment

Select Cloud Autopilot, Hybrid Autopilot, or the registration application workflow.

3

Enter settings

Provide the customer short name, device groups, and deployment-specific values.

4

Preview

Run readiness and discovery checks. No tenant objects are changed.

5

Deploy now

Queue autopilot-base-deployment using the exact preview settings.

6

Verify results

Review Created, Updated, Reused, Assigned, Warning, or Failed results.

04

Cloud Autopilot deployment

For Microsoft Entra joined Windows devices.

Cloud deployment creates or updates

  • Autopilot preparation group and required owner
  • Dynamic device groups for the selected device types
  • Cloud Windows Autopilot deployment profiles
  • Assignments from each profile to its matching device group
  • Autopilot Enrollment settings Intune configuration
  • Optional N-central Windows Agent Platform Script
  • Optional Autopilot Registration Application
Example profile naming
CFHT Laptops
CFHT Workstations
CFHT Tablets

Profile names use the configured customer short name, not the full Microsoft 365 tenant name.

05

Hybrid Autopilot deployment

For devices that must join on-premises Active Directory and register with Microsoft Entra.

Required Hybrid components

  • Active Intune Connector for Active Directory
  • Reachable Active Directory domain
  • Valid target OU
  • Connector account permissions to create computer objects in the target OU

Portal validation

  • Intune Connector status
  • Domain Join / ODJ profile readiness
  • Computer name prefix
  • Hybrid readiness result
Prefix mismatch is a warning.

An existing Domain Join profile with a different computer prefix does not block Hybrid readiness. A missing Intune Connector for Active Directory still blocks Hybrid deployment.

06

Tenant objects created or updated

Deployments are designed to reuse existing matching objects whenever possible.

Object Location Behavior
Autopilot Preparation Device group Microsoft Entra groups Created if missing; required service principal is assigned as owner.
Device groups Microsoft Entra groups Created or reused based on the configured Autopilot group tags.
Autopilot deployment profiles Intune → Windows enrollment → Deployment Profiles Created or updated and assigned to matching groups.
Autopilot Enrollment settings Intune configuration Created or updated for Cloud and Hybrid deployments.
N-central Platform Script Intune → Scripts and remediations → Platform scripts Created or updated when N-central deployment is enabled.
Autopilot Registration Application Microsoft Entra app registrations Created or reused when the registration application option is selected.
07

Standard groups and profile assignments

The standard Cloud device groups do not include the customer name.

Device type Standard group Profile assignment
Laptops grp_devices_laptops <SHORTNAME> Laptops
Workstations grp_devices_workstations <SHORTNAME> Workstations
Tablets grp_devices_tablets <SHORTNAME> Tablets
Custom group option

The portal can use the standard groups shown above or customer-specific custom groups. When the custom option is selected, enter both the desired group display name and the corresponding Autopilot group tag for each device type.

Custom field Purpose Example
Custom group name The Microsoft Entra dynamic group display name created or reused by the deployment. grp_devices_sales_laptops
Custom group tag The Windows Autopilot OrderID / group tag used by the group's dynamic membership rule. Sales-Laptops

Custom names are left exactly as entered. The portal does not add the customer short name, autopilot, cloud, or hybrid to a custom group name. The hard-coded preparation group remains Autopilot Preparation Device group.

08

Autopilot Enrollment settings

Created or updated after Cloud or Hybrid deployment.

Name
Autopilot Enrollment settings
Description
Disable user ESP
Disable Winlogon Animation
Setting OMA-URI Type Value
Skip User Status Page ./Vendor/MSFT/DMClient/Provider/MS DM Server/FirstSyncStatus/SkipUserStatusPage Boolean True
Enable First logon Animation ./Device/Vendor/MSFT/Policy/Config/WindowsLogon/EnableFirstLogonAnimation Integer 0
09

N-central Windows Agent deployment

Optional Intune Platform Script deployment after Autopilot configuration.

Required values

  • CUSTOMERID
  • REGISTRATION_TOKEN

Platform Script settings

  • Runs as System
  • Runs in 64-bit PowerShell
  • Signature enforcement disabled
  • Assigned to the selected Autopilot device groups
Registration token security

The customer registration token is sensitive. Protect the portal's private job directory and restrict access to the generated Intune Platform Script.

10

Autopilot Registration Application

Optional Entra application for Autopilot registration automation.

Client secret behavior

  • New application: a new client secret is created.
  • Existing application without rotation: the current secret is kept.
  • Existing application with rotation requested: a new secret is created.
  • Microsoft Entra does not allow an existing secret value to be retrieved later.
Cloud Autopilot does not require this secret.

The client secret belongs to the optional Autopilot Registration Application. It is not required for the Cloud Autopilot deployment profile itself.

11

Status and result meanings

Use the status page to understand exactly what happened.

Success

The requested validation or deployment step completed successfully.

Warning

The deployment can continue, but the item needs review.

Failed

The step blocked deployment and must be corrected before retrying.

Preview completed

Validation completed. No tenant objects were created or modified.

Deployment job types
autopilot-base-preview
autopilot-base-deployment
12

Troubleshooting

Common deployment conditions and what they mean.

Preview says “No tenant objects were created or modified.”

This is expected. Preview is read-only. Select Deploy now after reviewing the preview results to queue the live deployment.

Missing Intune Connector for Active Directory

Hybrid deployment cannot proceed without an active Intune Connector for Active Directory. Install and register the connector, verify it appears in Intune, and rerun the preview.

Open step-by-step Intune Connector guide

The Solidice guide covers installation, registration, the automatically created MSA* account, OU delegation, Create/Delete Computer Object rights, validation, and common ODJ failures.

Autopilot profile prefix does not match

An existing Hybrid Domain Join profile using a different computer prefix is reported as a warning rather than a readiness failure. Review the existing profile before deployment.

Platform Script returns 403 Forbidden

Confirm the portal app has the DeviceManagementScripts.ReadWrite.All application permission and that the customer tenant granted admin consent after that permission was added.

Autopilot profile assignment fails

Confirm Microsoft Intune licensing, MDM authority, and Windows enrollment are initialized. Verify the profile can be assigned to the target group manually in Intune.

Registration application service principal creation is delayed

Microsoft Entra can take time to replicate a newly created application. The worker includes retry handling for the NoBackingApplicationObject condition.

13

Security notes

Protect the portal and deployment data as production infrastructure.

  • Keep private/config.php outside the public web root.
  • Protect the private job queue from direct web access.
  • Restrict file permissions on worker keys, certificates, and job files.
  • Keep the worker API key private.
  • Do not expose client secrets or N-central registration tokens in logs.
  • Run only one production worker against the active job queue during migrations.
Ready to deploy

Start with a tenant preview.

Validate the environment before making any changes.

Start deployment