Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Intune»Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs
    Intune

    Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs

    Peter KlapwijkBy Peter KlapwijkApril 13, 2025Updated:April 14, 202534 Mins Read

    In this blog post, we take a look at the possibility of using Windows Autopilot device preparation together with Windows 365 Frontline shared mode.

    Windows Autopilot device preparation is used to set up and configure new devices, getting them ready for productive use. Windows Autopilot device preparation aims to simplify device deployment by delivering consistent configurations, enhancing the overall setup speed, and improving troubleshooting capabilities.

    Using Windows 365 cloud PCs in combination with device preparation makes sure the device is ready for the end-user when the user signs in for the first time to the Cloud PC. Device preparation prohibits the user from signing in to a recently provisioned Cloud PC before the required applications and platform scripts are applied to the device. This provides a better user experience, as the user has all required applications immediately available.

    Conceptual diagram of Autopilot Device Preparation Policy integrating into Windows 365 Provisioning Policies to provision and prepare Cloud PCs. Source.

    This is a welcome addition to setting up Windows 365 cloud PC, as using the original Windows Autopilot/ enrollment Status Page feature didn’t work (well) with cloud PC.

    So let’s see how we can set this all up to give our end-users a better user experience.

    Set up the Windows Autopilot device preparation policy

    We start by setting up the device preparation (DP) policy first, as we need to select the DP policy later in the Windows 365 Frontline shared provisioning policies.

    We first need to create a static (assigned) Entra ID device group to which the DP policy adds the provisioned cloud PCs. We need to assign the service principal Intune Provisioning Client as an owner to the group, to allow the service to add members to the group.

    In some tenants, this service principal is called Intune Autopilot ConfidentialClient.

    When the Entra group is created, we switch to the Intune admin center to set up the device preparation policy.

    Browse to Devices, Windows, Enrollment, and select Device preparation policies. Here, click on Create and select Automatic (Preview).

    Add a Name and Description (optional) to the policy.

    On the Device group tab, search for the previously created Entra ID device group and add it to the policy.

    On the Configuration settings tab, we add the applications and scripts that need to be tracked by the DP policy. These apps and scripts need to be applied to the cloud PC before the user is allowed to sign in to the cloud PC.

    Under the Apps section, click Add and start adding the applications.

    Note; make sure these applications are assigned as required to the previously created Entra group.

    Repeat this step for the scripts the DP policy should track.

    There is no need (and no option) to assign the device preparation policy to an Entra group.

    Set up the Windows 365 Frontline Cloud PC provisioning policy

    Now that the device preparation policy is set up, we can configure our Windows 365 Frontline Cloud PC provisioning policy.

    Browse to Device, Windows, Windows 365, Provisioning policies.

    Here, select Create policy.

    Enter a Name and Description (optional) for the provisioning policy.
    Select Frontline as the license type and select Shared as the Frontline type.

    Make your choice for Language & Region and Device name template.

    And most importantly, select the previously created Autopilot device preparation policy.

    On the Assignments tab, add an Entra ID group that holds your Frontline users and select the available Cloud PCs. Add an Assignment name and enter the number of cloud PCs for this assignment.

    Our provisioning policy is ready.

    The end-result

    By finishing the setup of the provisioning policy, our cloud PCs start provisioning.

    After some time the status of the cloud PC will change to Preparing.

    When we click on Preparing, we are redirected to the Windows Autopilot device preparation deployments report (this report can also be found under Devices, Monitor).

    Here we see the status of the deployment. We can track the installation status of the tracked applications.

    The applications are installed.

    And the script is executed.

    And when the user signs in to the Frontline cloud PC for the first time, we see the applications are installed.

    After testing device preparation and Frontline shared cloud PCs, I can say, this works very well! We finally have a way to ensure that, also on our cloud PCs, we have a good option to ensure the installation of applications is done before the user signs in for the first time. Let’s hope device preparation will also become available for the other cloud PC modes.

    One thing to be aware of is this bug in device preparation, in case you want to edit the device preparation policy.

    Thanks for reading!

    Intune Microsoft Endpoint Manager Windows Windows 365 Windows Autopilot
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Automatically deploy Windows 365 boot devices

    October 4, 2024

    Configure Cloud Site List Management for IE mode

    October 21, 2021

    How to setup an Android Enterprise kiosk device with Microsoft Intune

    April 25, 2019
    View 3 Comments

    3 Comments

    1. John M on May 8, 2025 23:04

      Hey Peter, I’m not seeing any options when creating the W365 Provisioning Profiles to associate the Windows Autopilot Device Preparation policy. Do you know if this is currently only available as an opt-in feature? Thanks!

      Reply
      • Peter Klapwijk on May 9, 2025 10:36

        Hi John,

        No, this should be available in every tenant. It is shared by Microsoft in this article https://techcommunity.microsoft.com/discussions/windows365discussions/windows-365-frontline-cloud-pc-in-shared-mode-%E2%80%93-quick-start-guide/4399905

        Reply
        • John M on May 14, 2025 22:01

          Ahh I misunderstood that this is exclusive to Frontline CPCs in Shared mode. I was too optimistic thinking it would also apply to dedicated and/or Enterprise CPCs. I appreciate the write-up!

          Reply
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Create deployment ring groups for Microsoft Intune

    June 27, 2025

    Update Windows Defender during Windows Autopilot enrollments

    May 16, 2025

    Hide the “Turn on an ad privacy feature” pop-up in Chrome with Microsoft Intune

    April 19, 2025

    How to set Google as default search provider with Microsoft Intune

    April 18, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    • Bluesky 1.5K
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Teams Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Parth Savjadiya on Using Visual Studio with Microsoft Endpoint Privilege Management, some notes
    • Chris Johnson on Assign Deny Local Log On user right to an (Azure) AD group by using Microsoft Intune
    • Northernsky on Automatically wipe a Windows 10 device after a number of authentication failures
    • Henrik on Intune Driver update for Windows – Get applicable devices
    • Adam on Get notified on expiring Azure App Registration client secrets
    most popular

    Application installation issues; Download pending

    October 1, 2024

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How to change the Windows 11 language with Intune

    November 11, 2022

    Update Microsoft Edge during Windows Autopilot enrollments

    July 9, 2024
    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS Bluesky
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}