Knowledge Article

Intune vs. Autopilot: What Each One Actually Does

See Venn first in Google Search

Add as a preferred source on Google

What Is the Difference Between Intune and Autopilot?

Microsoft Intune and Windows Autopilot are not competing tools; they work together. Autopilot is the front-end deployment service that sets up and pre-configures brand-new devices out of the box, while Intune is the unified endpoint management platform that handles long-term, day-to-day security, apps, and policy control.

Autopilot comes with Windows and requires no separate license to run. Intune requires its own license and does the ongoing work most people mean when they say “device management.” In practice, most organizations use both; Autopilot to onboard the device and Intune to run it – which is exactly why the two get conflated.

Core differences at a glance:

  • Windows Autopilot: Provisioning and deployment. It runs once, during the initial Out-of-Box Experience (OOBE) on a brand-new or factory-reset device, joining it to Microsoft Entra ID and applying a deployment profile without IT manually imaging the drive.
  • Microsoft Intune: Endpoint management, covering both MDM and MAM. It runs for the rest of the device’s lifecycle, pushing continuous security baselines, compliance policies, and line-of-business apps, and wiping corporate data remotely when needed.

How Autopilot and Intune work together:

  • Step 1, register: IT registers the device’s hardware ID and assigns an Autopilot deployment profile via Microsoft Intune.
  • Step 2, provision: The user unboxes the laptop, connects to Wi-Fi, and signs in with their corporate credentials, and Autopilot intercepts the setup and configures the device automatically.
  • Step 3, manage: Once the setup screens complete, Intune takes over ongoing management, pushing updates, security compliance rules, and software packages for the rest of the device’s lifespan.

For a closer look at the management half of that pairing, see our guide to Microsoft Intune.

Secure the Data, Not the Device

Protect company data on unmanaged laptops without locking down the entire device.

Windows Autopilot: What It Does and How It Provisions Devices

Windows Autopilot is a set of provisioning technologies for setting up and pre-configuring new Windows devices so they’re ready for productive use. Instead of IT building and maintaining a custom image for every hardware model, Autopilot transforms the OEM-installed version of Windows already on the device – applying settings, installing apps, and even upgrading the Windows edition – without a re-image. It only operates at one moment in the device’s life: during the initial Out-of-Box Experience (OOBE), on a brand-new or factory-reset machine.

How Autopilot Registers Devices Using the Hardware Hash

Before any of that can happen, a device has to be registered with the Autopilot service using a unique hardware hash tied to your tenant; a string containing the manufacturer, model, and serial numbers, among other identifying details. Ideally, the OEM, reseller, or distributor captures and uploads this hash automatically at purchase, but IT can also harvest and upload hashes manually for existing devices. Either way, registration creates a corresponding Microsoft Entra ID object, which Autopilot needs before anyone signs in.

Autopilot Deployment Modes: User-Driven, Pre-Provisioned, Self-Deploying, and Reset

Autopilot supports a handful of deployment modes. User-driven mode is the most common: the end user connects to a network, signs in with their own credentials, and Autopilot handles the rest. Self-deploying mode needs little to no user interaction; it’s built for kiosk-style or shared devices, and Entra-join-only. Pre-provisioned deployment lets a technician complete the time-consuming steps in advance, leaving the end user a lightweight final step. Autopilot Reset can separately return an existing device to a business-ready state for a new user or a break/fix repair, without a full re-image.

What the Deployment Profile Controls, Including Admin Privileges

The deployment mode is one setting inside a broader Autopilot deployment profile, and the profile is what actually shapes the device the user receives. It skips the consumer OOBE screens, applies a naming convention, and sets the user account type to either standard user or local administrator. Choosing standard user is what people mean when they say Autopilot locks down admin privileges.

That is a provisioning-time default rather than an enforcement mechanism, which is a distinction worth keeping straight. If a device never receives its Autopilot profile, it falls through to an ordinary Entra ID join and the first user can end up in the local administrators group anyway. Keeping admin rights locked down over time is Intune’s job, through account protection policies and Endpoint Privilege Management.

What Autopilot Does Not Do: Imaging, Patching, and Ongoing Policy

Autopilot’s job ends once the device reaches the desktop. It doesn’t maintain a custom OS image, push ongoing patches, enforce compliance over time, or manage apps after initial installation. Those are Intune’s job – and a device that’s only been through Autopilot, with no MDM enrollment behind it, has no mechanism for ongoing policy at all.

Microsoft Intune: What It Does After the Device Is Provisioned

Once a device is enrolled, Microsoft Intune becomes the system of record for how it’s configured, secured, and kept compliant for the rest of its working life. It is the unified endpoint management platform for that stage, and it works on two levels: mobile device management (MDM) for the device itself, and mobile application management (MAM) for corporate data inside apps.

Configuration Profiles, Compliance Policies, and Conditional Access

Intune configuration profiles set the baseline for a device, including password requirements, VPN and Wi-Fi settings, encryption, and dozens of other OS-level controls. Compliance policies check devices against that baseline continuously, flagging or blocking ones that fall out of line. Paired with Microsoft Entra ID Conditional Access, compliance status can gate access to email or SharePoint, cutting off a non-compliant device until it’s fixed. Alongside custom profiles, Intune also pushes continuous security baselines: Microsoft’s recommended pre-configured settings for Windows, Microsoft Edge, and Defender, deployable as-is or tuned per environment.

App Deployment, Update Rings, and Remote Wipe

Beyond policy, Intune pushes and updates applications like Win32, Microsoft Store, or line-of-business and manages Windows Update through staggered update rings. If a device is lost, stolen, or the employee leaves, Intune can also remotely wipe company data or the entire device, depending on how it was enrolled.

What Intune Does Not Do: Out-of-Box Setup and Device Registration

Intune has no native way to turn a fresh, OEM-imaged laptop into a joined, configured device on its own. It doesn’t register hardware hashes, and it has no out-of-box provisioning workflow. That’s the gap Autopilot exists to fill. A device still has to arrive at Intune already joined to Entra ID and enrolled before any policy can apply.

Intune vs Autopilot: Side-by-Side Comparison

Primary Role: One-Time Provisioning vs Continuous Management

Autopilot runs once, at setup. Intune runs continuously, for the life of the device. That single distinction explains most of the confusion between the two: they’re not competing tools, they’re sequential ones.

The distinction matters most when something breaks. If a new laptop won’t join Entra ID or gets stuck on a setup screen, the issue lives in Autopilot; a bad hardware hash, a missing group membership, or a profile that never got assigned. If a device joins fine but later fails a compliance check, doesn’t receive a required app, or won’t take an update, that’s an Intune problem; Autopilot finished its job the moment the desktop appeared. Knowing which tool owns the failure keeps a support ticket from bouncing between the wrong logs.

Which Devices and Join Types Each One Supports

Autopilot works with new or reset Windows PCs and HoloLens 2 devices, supporting both Microsoft Entra join and Microsoft Entra hybrid join, depending on the deployment mode and version in use. Intune manages a much broader range of endpoints, regardless of how – or whether – a device was ever provisioned through Autopilot:

  • Windows 10 and Windows 11 (Home, Pro, Enterprise, Education, and IoT Enterprise editions), plus Windows 10/11 LTSC
  • macOS 14 and later
  • iOS and iPadOS 17 and later
  • Android 10 and later, including AOSP devices
  • Ubuntu Desktop 24.04 and 26.04 LTS with a GNOME desktop environment

Join-type support isn’t uniform across Autopilot’s own two versions, either. Classic Autopilot supports both Entra join and Entra hybrid join, which is why it remains the only option for organizations with on-premises Active Directory dependencies. Windows Autopilot device preparation, the newer version, is Entra-join only; a hybrid-joined fleet has no path onto device preparation until that dependency is resolved.

Licensing and Cost for Each

Autopilot itself comes with Windows at no added cost. But auto-enrollment into an MDM service — the profile-assignment step that actually makes Autopilot useful — requires a Microsoft Entra ID P1 or P2 subscription, which most organizations already hold if they’re running Intune. The real cost of “Autopilot” is really the cost of the licenses sitting underneath it.

Intune pricing is licensed in three tiers:

  • Intune Plan 1 — $8 per user, per month standalone; already bundled into Microsoft 365 E3, E5, Business Premium, and Enterprise Mobility + Security E3/E5
  • Intune Plan 2 — adds specialty and shared-device support (frontline and firstline worker scenarios) for an additional $4 per user, per month, on top of Plan 1
  • Intune Suite — bundles Plan 2 with advanced capabilities like Endpoint Privilege Management, remote help, and advanced endpoint analytics, for $10 per user, per month total

Microsoft has been folding some of those Suite add-ons directly into E3 and E5 starting in mid-2026, narrowing the gap between the standalone and bundled paths. It’s worth checking Intune’s current licensing tiers against whatever M365 entitlements the organization already has before buying anything separately — the added cost is often smaller than it first looks.

Visibility and Reporting Gaps in Each Tool

Reporting is uneven between the two tools, and it’s uneven within Autopilot itself. Classic Autopilot device profiles have no built-in reporting dashboard in the Intune admin center at all — checking on a stalled deployment means pulling status through Microsoft Graph API or PowerShell, a real gap if a rollout to a batch of new hires fails quietly overnight. Windows Autopilot device preparation, by contrast, reports through Intune’s Device Monitor with near-real-time deployment status, showing device names and enrollment timestamps as they happen — one reason Microsoft is steering organizations toward device preparation for standard Windows 11 rollouts.

Intune’s own reporting, once a device is enrolled, is far more granular: compliance reports, app-install status, feature-update reports, and Endpoint analytics for startup performance all exist. But all of it starts after enrollment succeeds. Neither Autopilot nor Intune gives IT any visibility into a device before it’s registered — precisely the blind spot that matters once unmanaged, contractor-owned, or BYOD hardware enters the picture, since those devices may never get registered at all.

How Autopilot and Intune Work Together

Why Autopilot Requires Intune or Another MDM to Function

Autopilot can join a device to Microsoft Entra ID on its own, but joining isn’t managing. Without Intune or another MDM enrolled behind it, a freshly provisioned device has no way to receive ongoing configuration, compliance checks, or app assignments. Autopilot hands the device off; Intune has to be there to catch it.

The Three-Step Handoff, from Registration to Ongoing Management

In practice, the handoff breaks down into three steps:

  • Register (Autopilot): IT registers the device’s hardware ID and assigns an Autopilot profile via Microsoft Intune.
  • Provision (Autopilot): The user unboxes the laptop, connects to Wi-Fi, and signs in with their corporate credentials. Autopilot intercepts the setup and configures the device automatically.
  • Manage (Intune): Once the setup screen completes, Intune takes over ongoing management, pushing necessary updates, security compliance rules, and software packages for the rest of the device’s lifespan.

Nothing in that sequence self-corrects. If the hardware ID was never uploaded in the first step, the device still boots and still joins Entra ID when the user signs in; it just never receives the profile the next two steps assume is there.

The Enrollment Status Page and What It Blocks During Setup

The Enrollment Status Page (ESP) is the visible link between the two. It shows setup progress while apps, policies, certificates, and network connections are installed. It can also be configured to block the user from the desktop until everything required is in place, which is the difference between a device that’s merely joined and one that’s actually compliant before anyone touches company data on it.

Classic Autopilot vs Autopilot Device Preparation (v2)

Microsoft has been rolling out a re-architected version of Autopilot, called Windows Autopilot device preparation, alongside the classic version, and the two aren’t interchangeable.

Profile Delivery Before Login vs After Entra ID Sign-In

Classic Autopilot applies its deployment profile and works through the Enrollment Status Page largely before or during the initial sign-in. Device preparation restructures that sequence for a faster, more consistent provisioning experience, with near real-time monitoring that classic Autopilot’s reporting doesn’t offer.

When to Use Classic Autopilot and When to Use Device Preparation

The two aren’t feature-equivalent yet, and Microsoft’s own comparison of the two paths lays out the tradeoffs. Device preparation skips device registration entirely, supports Government Community Cloud High and DoD environments, and can deploy line-of-business and Win32 apps in the same rollout – but it’s Entra-join-only, requires Windows 11, and caps out at 25 apps and 10 scripts during setup. Classic Autopilot still covers what device preparation doesn’t: hybrid join, self-deploying and pre-provisioned modes, HoloLens and Teams Rooms devices, and Autopilot Reset. For standard Windows 11 rollouts, device preparation is the simpler option; anything involving hybrid join or specialty hardware still needs classic Autopilot.

Secure the Data, Not the Device

Protect company data on unmanaged laptops without locking down the entire device.

How to Set Up Autopilot in Intune

Prerequisites: Intune Licenses, Entra ID Groups, and MDM Authority

Before registering a single device, an organization needs Intune licenses assigned to the users who’ll enroll devices, correct MDM authority set in the tenant, and Entra ID groups in place to scope deployment profiles and app assignments. Getting the group structure right up front saves rework later, since profiles and apps are assigned to groups, not individual devices.

Importing Hardware Hashes and Assigning a Deployment Profile

With prerequisites in place, IT imports hardware hashes – ideally uploaded automatically by the OEM, or harvested manually for existing hardware – into the Intune admin center. Once a device shows up as registered, it gets assigned to a deployment profile and an Enrollment Status Page configuration, and it’s ready to ship straight to the end user.

Where Intune and Autopilot Fall Short: BYOD, Contractors, and Unmanaged Devices

Why Autopilot Only Works on Corporate-Purchased Windows Hardware

Autopilot’s entire model assumes the company owns the device. Registration ties a specific hardware hash — manufacturer, model, and serial number, tied permanently to the tenant — to that one machine, and the practical channels for getting a hash into the system (an OEM or reseller uploading it at purchase, or IT harvesting it directly off the hardware) only exist for machines the company bought or physically has in hand. There’s no path for a contractor’s personal laptop to enter that pipeline unless IT takes physical possession of it, which defeats the point of letting someone use their own hardware in the first place.

Microsoft’s own documentation makes the intent explicit: personally owned or “workplace joined” devices shouldn’t be registered as Autopilot devices at all. That’s a reasonable boundary for a fleet of company-issued laptops, where the organization controls procurement end to end. But it’s a dead end for a contractor, freelancer, or remote employee working from their own machine; exactly the population Autopilot’s registration model was never built to include.

Enrollment Friction and Privacy Objections on Personally Owned Laptops

That gap is only getting more expensive to ignore. More than a quarter of U.S. knowledge workers now freelance or work independently – over 20 million people, by Upwork’s count – and most are working on hardware the company never touched. Full MDM enrollment on a personal laptop gives IT the ability to wipe the entire device, not just company data, and plenty of contractors reasonably refuse that trade. Even where enrollment is technically possible, the resulting privacy fight slows onboarding and generates support tickets nobody wants.

Intune’s app-level half is not an escape hatch here either: MAM without enrollment, which protects corporate data inside managed apps while leaving the rest of the device alone, is supported on iOS and Android, and Windows Information Protection, the closest Windows equivalent, has been retired. On a personally owned PC, that leaves full MDM enrollment as the only Intune path.

An Alternative for Unmanaged Devices: Blue Border™ by Venn

Organizations facing this gap need an approach that secures the work without asking to own the device. Blue Border™ is the secure workspace that protects company data, applications, and AI workflows on any computer – without VDI or fully managing the endpoint. Installing Blue Border on a contractor’s or remote employee’s own PC or Mac creates a company-controlled secure enclave directly on the device: business activity runs inside it, protected and isolated, while the rest of the device and the user’s privacy stay untouched. A broader rundown of endpoint DLP options built for unmanaged devices covers this tradeoff in more depth, and Venn’s BYOD program guidance covers the policy side.

FAQ

Do I Need Intune to Use Windows Autopilot?

You need an MDM behind Autopilot for it to be useful, and Intune is the one Microsoft builds Autopilot around, though Autopilot can technically hand off to Microsoft Configuration Manager or another compatible MDM instead. Without any MDM enrolled, a device that’s been through Autopilot is joined to Entra ID but has no ongoing management, which defeats most of the point of provisioning it that way.

Can Autopilot Enroll a BYOD or Personally Owned Laptop?

Not by design. Autopilot registration is meant for corporate-owned hardware, and Microsoft explicitly excludes personally owned or workplace-joined devices from it. Organizations securing work on personal or contractor-owned laptops typically look outside the unified endpoint management tools category entirely – toward VDI or a secure workspace approach – rather than forcing BYOD hardware through a workflow it wasn’t built for.

Conclusion

Autopilot and Intune aren’t competitors; they’re two halves of the same Windows device lifecycle. One handles setup and the other handles everything after. Knowing which tool owns which job makes troubleshooting faster, licensing decisions clearer, and the classic-versus-device-preparation choice easier to make correctly the first time. But for organizations with contractors, freelancers, or BYOD employees in the mix, both tools run into the same wall: they were built for hardware the company owns. That’s worth planning for before a hiring push outpaces the laptop budget, not after. If unmanaged devices are already part of the workforce, it’s worth mapping out which ones actually need full device management and which just need their work activity secured.