{"id":8,"date":"2026-03-13T07:52:47","date_gmt":"2026-03-13T07:52:47","guid":{"rendered":"https:\/\/vanbeekcloud.nl\/?p=8"},"modified":"2026-03-21T09:28:03","modified_gmt":"2026-03-21T09:28:03","slug":"autopilot-pre-provisioning-the-complete-troubleshooting-guide","status":"publish","type":"post","link":"https:\/\/vanbeekcloud.nl\/index.php\/2026\/03\/13\/autopilot-pre-provisioning-the-complete-troubleshooting-guide\/","title":{"rendered":"Autopilot Pre-Provisioning: The Complete Troubleshooting Guide"},"content":{"rendered":"\n\n                <!-- Table of Contents -->\n                <div class=\"p-6 bg-slate-50 dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-xl toc\">\n                    <h4 class=\"font-heading font-semibold text-slate-900 dark:text-white text-sm mb-4\">In this article<\/h4>\n                    <ol class=\"space-y-2 text-sm list-decimal list-inside\">\n                        <li><a href=\"#what-is-pre-provisioning\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">What is pre-provisioning (white glove)?<\/a><\/li>\n                        <li><a href=\"#how-it-works\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">How the process works under the hood<\/a><\/li>\n                        <li><a href=\"#prerequisites\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Prerequisites checklist<\/a><\/li>\n                        <li><a href=\"#common-failures\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Common failures and how to fix them<\/a><\/li>\n                        <li><a href=\"#collecting-logs\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Collecting and reading diagnostic logs<\/a><\/li>\n                        <li><a href=\"#esp-deep-dive\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">ESP timeout deep dive<\/a><\/li>\n                        <li><a href=\"#tpm-attestation\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">TPM attestation failures<\/a><\/li>\n                        <li><a href=\"#hybrid-join\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Hybrid Azure AD join issues<\/a><\/li>\n                        <li><a href=\"#network\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Network and proxy pitfalls<\/a><\/li>\n                        <li><a href=\"#community-script\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Get-AutopilotDiagnosticsCommunity<\/a><\/li>\n                        <li><a href=\"#final-checklist\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Final pre-flight checklist<\/a><\/li>\n                    <\/ol>\n                <\/div>\n\n                <!-- 1. What is pre-provisioning -->\n                <div id=\"what-is-pre-provisioning\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">1. What is pre-provisioning?<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Pre-provisioning (formerly known as white glove) allows IT teams or hardware vendors to fully configure a Windows device <em>before<\/em> the end user ever touches it. The device goes through Autopilot enrollment, installs all required apps, applies all policies and reaches a ready-to-use state \u2014 all without any user interaction.\n                    <\/p>\n                    <p class=\"text-sm leading-relaxed\">\n                        The benefit is obvious: the user opens the laptop lid, signs in, and everything is already there. No waiting for apps to install. No &#8220;please wait while we set up your device&#8221; spinning for 45 minutes. The challenge? When pre-provisioning fails, it can be incredibly frustrating to diagnose because the error messages are often vague and the logs are buried deep.\n                    <\/p>\n                <\/div>\n\n                <!-- 2. How it works -->\n                <div id=\"how-it-works\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">2. How the process works under the hood<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Understanding the flow is essential for troubleshooting. Pre-provisioning runs through these phases in order:\n                    <\/p>\n                    <div class=\"space-y-3\">\n                        <div class=\"flex gap-4 items-start\">\n                            <div class=\"flex-shrink-0 w-8 h-8 rounded-full bg-sky-100 dark:bg-sky-500\/10 border border-sky-200 dark:border-sky-500\/20 flex items-center justify-center\">\n                                <span class=\"text-xs font-mono font-bold text-sky-600 dark:text-sky-400\">1<\/span>\n                            <\/div>\n                            <div>\n                                <p class=\"text-sm font-semibold text-slate-900 dark:text-white\">TPM attestation<\/p>\n                                <p class=\"text-xs text-slate-500 dark:text-slate-400\">The device proves its identity to the Autopilot service using the TPM chip. A hardware hash is matched against the registered device in your tenant.<\/p>\n                            <\/div>\n                        <\/div>\n                        <div class=\"flex gap-4 items-start\">\n                            <div class=\"flex-shrink-0 w-8 h-8 rounded-full bg-sky-100 dark:bg-sky-500\/10 border border-sky-200 dark:border-sky-500\/20 flex items-center justify-center\">\n                                <span class=\"text-xs font-mono font-bold text-sky-600 dark:text-sky-400\">2<\/span>\n                            <\/div>\n                            <div>\n                                <p class=\"text-sm font-semibold text-slate-900 dark:text-white\">Entra ID join (or hybrid join)<\/p>\n                                <p class=\"text-xs text-slate-500 dark:text-slate-400\">The device registers in Entra ID. For hybrid scenarios, the Intune Connector creates a computer object in on-premises AD and the device waits for the sync to complete.<\/p>\n                            <\/div>\n                        <\/div>\n                        <div class=\"flex gap-4 items-start\">\n                            <div class=\"flex-shrink-0 w-8 h-8 rounded-full bg-sky-100 dark:bg-sky-500\/10 border border-sky-200 dark:border-sky-500\/20 flex items-center justify-center\">\n                                <span class=\"text-xs font-mono font-bold text-sky-600 dark:text-sky-400\">3<\/span>\n                            <\/div>\n                            <div>\n                                <p class=\"text-sm font-semibold text-slate-900 dark:text-white\">MDM enrollment<\/p>\n                                <p class=\"text-xs text-slate-500 dark:text-slate-400\">The device enrolls in Intune and receives its management profile.<\/p>\n                            <\/div>\n                        <\/div>\n                        <div class=\"flex gap-4 items-start\">\n                            <div class=\"flex-shrink-0 w-8 h-8 rounded-full bg-sky-100 dark:bg-sky-500\/10 border border-sky-200 dark:border-sky-500\/20 flex items-center justify-center\">\n                                <span class=\"text-xs font-mono font-bold text-sky-600 dark:text-sky-400\">4<\/span>\n                            <\/div>\n                            <div>\n                                <p class=\"text-sm font-semibold text-slate-900 dark:text-white\">Device ESP \u2014 policies and apps<\/p>\n                                <p class=\"text-xs text-slate-500 dark:text-slate-400\">The Enrollment Status Page tracks the installation of all device-targeted policies, certificates, network profiles and required Win32\/LOB apps.<\/p>\n                            <\/div>\n                        <\/div>\n                        <div class=\"flex gap-4 items-start\">\n                            <div class=\"flex-shrink-0 w-8 h-8 rounded-full bg-emerald-100 dark:bg-emerald-500\/10 border border-emerald-200 dark:border-emerald-500\/20 flex items-center justify-center\">\n                                <span class=\"text-xs font-mono font-bold text-emerald-600 dark:text-emerald-400\">&#10003;<\/span>\n                            <\/div>\n                            <div>\n                                <p class=\"text-sm font-semibold text-slate-900 dark:text-white\">Reseal<\/p>\n                                <p class=\"text-xs text-slate-500 dark:text-slate-400\">The device reseals back to the OOBE screen. The technician presses the power button and the device is ready for the user.<\/p>\n                            <\/div>\n                        <\/div>\n                    <\/div>\n                    <div class=\"callout-info rounded-lg p-4 mt-6\">\n                        <p class=\"text-xs leading-relaxed\"><strong class=\"text-sky-700 dark:text-sky-300\">Key insight:<\/strong> Pre-provisioning only runs the <em>device<\/em> ESP phase. The user ESP (user-targeted apps and policies) runs after the end user signs in. If you are assigning apps in user context, they will not install during pre-provisioning \u2014 this is by design, not a bug.<\/p>\n                    <\/div>\n                <\/div>\n\n                <!-- 3. Prerequisites -->\n                <div id=\"prerequisites\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">3. Prerequisites checklist<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Before you even start troubleshooting a failure, verify that these are all in place. Missing one of these is the root cause in the majority of cases I see:\n                    <\/p>\n                    <div class=\"space-y-2\">\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Device hardware hash is imported in the Autopilot service and assigned to the correct Autopilot deployment profile<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Autopilot profile has <code class=\"inline\">Allow pre-provisioned deployment<\/code> set to <strong>Yes<\/strong><\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Enrollment Status Page (ESP) is configured and assigned \u2014 tracking at least Win32 apps<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Device has a stable internet connection with access to all required Microsoft endpoints<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>TPM 2.0 is enabled in BIOS\/UEFI and firmware is up to date<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>For hybrid join: Intune Connector for Active Directory is installed, running and the service account has permissions to create computer objects in the target OU<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Windows 10 1903+ or Windows 11 \u2014 fully patched with latest cumulative updates<\/span>\n                        <\/label>\n                    <\/div>\n                <\/div>\n\n                <!-- 4. Common failures -->\n                <div id=\"common-failures\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">4. Common failures and how to fix them<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Here is a quick-reference table of the failures I encounter most often. Detailed walkthroughs for the trickiest ones follow in dedicated sections below.\n                    <\/p>\n                    <div class=\"overflow-x-auto\">\n                        <table class=\"w-full text-xs border border-slate-200 dark:border-slate-700 rounded-lg overflow-hidden\">\n                            <thead>\n                                <tr class=\"bg-slate-100 dark:bg-slate-800\">\n                                    <th class=\"text-left p-3 font-semibold text-slate-900 dark:text-white\">Symptom<\/th>\n                                    <th class=\"text-left p-3 font-semibold text-slate-900 dark:text-white\">Likely cause<\/th>\n                                    <th class=\"text-left p-3 font-semibold text-slate-900 dark:text-white\">Fix<\/th>\n                                <\/tr>\n                            <\/thead>\n                            <tbody class=\"divide-y divide-slate-200 dark:divide-slate-700\">\n                                <tr>\n                                    <td class=\"p-3\">Red screen \u2014 &#8220;Something went wrong&#8221; with error <code class=\"inline\">0x800705B4<\/code><\/td>\n                                    <td class=\"p-3\">ESP timeout (default 60 min)<\/td>\n                                    <td class=\"p-3\">Reduce required apps or increase timeout. See <a href=\"#esp-deep-dive\" class=\"text-sky-500 hover:underline\">ESP deep dive<\/a><\/td>\n                                <\/tr>\n                                <tr>\n                                    <td class=\"p-3\">Red screen \u2014 TPM attestation failed<\/td>\n                                    <td class=\"p-3\">TPM firmware outdated, hardware hash mismatch, or TPM not cleared<\/td>\n                                    <td class=\"p-3\">See <a href=\"#tpm-attestation\" class=\"text-sky-500 hover:underline\">TPM section<\/a><\/td>\n                                <\/tr>\n                                <tr>\n                                    <td class=\"p-3\">Stuck at &#8220;Joining your organization&#8217;s network&#8221;<\/td>\n                                    <td class=\"p-3\">Hybrid AD join \u2014 Intune Connector issue or Entra Connect sync delay<\/td>\n                                    <td class=\"p-3\">See <a href=\"#hybrid-join\" class=\"text-sky-500 hover:underline\">Hybrid join section<\/a><\/td>\n                                <\/tr>\n                                <tr>\n                                    <td class=\"p-3\">ESP shows &#8220;Identifying&#8221; for 10+ minutes<\/td>\n                                    <td class=\"p-3\">Device not recognized by Autopilot service \u2014 hash not imported or profile not assigned<\/td>\n                                    <td class=\"p-3\">Re-import hash, wait for profile assignment, verify in Intune portal<\/td>\n                                <\/tr>\n                                <tr>\n                                    <td class=\"p-3\">App installation fails during ESP<\/td>\n                                    <td class=\"p-3\">Win32 app dependency issue, download failure or detection rule mismatch<\/td>\n                                    <td class=\"p-3\">Check IME logs, verify detection rules, test app install manually<\/td>\n                                <\/tr>\n                                <tr>\n                                    <td class=\"p-3\">Error <code class=\"inline\">0x81036502<\/code><\/td>\n                                    <td class=\"p-3\">Device not found in Autopilot service<\/td>\n                                    <td class=\"p-3\">Verify hardware hash is uploaded and synced. Deregister and re-register if needed<\/td>\n                                <\/tr>\n                            <\/tbody>\n                        <\/table>\n                    <\/div>\n                <\/div>\n\n                <!-- 5. Collecting logs -->\n                <div id=\"collecting-logs\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">5. Collecting and reading diagnostic logs<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        When pre-provisioning fails and you are staring at a red screen, your first move should be collecting logs. Press <code class=\"inline\">Shift + F10<\/code> during the ESP to open a command prompt, then run:\n                    <\/p>\n                    <pre class=\"code-block\"><code><span class=\"code-comment\"># Collect Autopilot diagnostics (Windows 11)<\/span>\n<span class=\"code-cmdlet\">mdmdiagnosticstool<\/span> <span class=\"code-param\">-area<\/span> <span class=\"code-string\">Autopilot<\/span> <span class=\"code-param\">-cab<\/span> <span class=\"code-string\">C:\\temp\\autopilot-diag.cab<\/span>\n\n<span class=\"code-comment\"># Alternative: collect full MDM diagnostics<\/span>\n<span class=\"code-cmdlet\">mdmdiagnosticstool<\/span> <span class=\"code-param\">-out<\/span> <span class=\"code-string\">C:\\temp\\mdm-diag<\/span>\n\n<span class=\"code-comment\"># Export event logs for Autopilot and enrollment<\/span>\n<span class=\"code-cmdlet\">wevtutil<\/span> <span class=\"code-param\">epl<\/span> <span class=\"code-string\">Microsoft-Windows-Provisioning-Diagnostics-Provider\/AutoPilot<\/span> <span class=\"code-string\">C:\\temp\\autopilot-events.evtx<\/span>\n<span class=\"code-cmdlet\">wevtutil<\/span> <span class=\"code-param\">epl<\/span> <span class=\"code-string\">Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider\/Admin<\/span> <span class=\"code-string\">C:\\temp\\mdm-events.evtx<\/span><\/code><\/pre>\n\n                    <p class=\"text-sm leading-relaxed mt-4 mb-4\">\n                        The key log files to look at inside the diagnostic cab:\n                    <\/p>\n                    <ul class=\"space-y-2 text-sm\">\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><code class=\"inline\">TpmHliInfo_Output.txt<\/code> \u2014 TPM health and attestation status. Check for readiness and endorsement key issues<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><code class=\"inline\">DiagnosticLogCSP_Collector_Autopilot_*<\/code> \u2014 the ETL traces that contain the actual enrollment flow and where it broke<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><code class=\"inline\">MdmDiagReport_RegistryDump.reg<\/code> \u2014 contains the ESP tracking state, enrolled policies, and applied configurations<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><code class=\"inline\">IntuneManagementExtension.log<\/code> \u2014 located in <code class=\"inline\">C:\\ProgramData\\Microsoft\\IntuneManagementExtension\\Logs<\/code>. Essential for tracking Win32 app installations<\/span>\n                        <\/li>\n                    <\/ul>\n                <\/div>\n\n                <!-- 6. ESP deep dive -->\n                <div id=\"esp-deep-dive\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">6. ESP timeout deep dive<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        The Enrollment Status Page is where most pre-provisioning failures surface. The ESP tracks three categories during the device phase: security policies, certificate profiles, and apps. If any tracked item fails to install within the timeout window, the whole process fails.\n                    <\/p>\n\n                    <div class=\"callout-warning rounded-lg p-4 mb-4\">\n                        <p class=\"text-xs leading-relaxed\"><strong class=\"text-amber-700 dark:text-amber-300\">Common trap:<\/strong> If you have a Win32 app marked as <em>required<\/em> and assigned to a device group, but the app&#8217;s detection rule does not match after installation, the ESP will keep retrying until timeout. Always verify detection rules match the actual installed state.<\/p>\n                    <\/div>\n\n                    <p class=\"text-sm leading-relaxed mb-4\">Strategies to reduce ESP timeouts:<\/p>\n                    <ul class=\"space-y-2 text-sm\">\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Minimize tracked apps<\/strong> \u2014 only mark apps as required if they truly need to be installed before first login. Move non-critical apps to the user ESP or assign them as available.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Use app dependencies wisely<\/strong> \u2014 chain apps in the correct dependency order. Circular dependencies will cause deadlocks.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Pre-cache content<\/strong> \u2014 for large apps (like Microsoft 365 Apps), consider using Delivery Optimization or a connected cache server to avoid slow downloads.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Increase the timeout<\/strong> \u2014 the default ESP timeout is 60 minutes. For environments with many required apps, bumping this to 90 or 120 minutes can help \u2014 but it is a band-aid, not a solution.<\/span>\n                        <\/li>\n                    <\/ul>\n\n                    <p class=\"text-sm leading-relaxed mt-4\">To check which specific app or policy is blocking the ESP, run this from the command prompt during the stuck screen:<\/p>\n                    <pre class=\"code-block\"><code><span class=\"code-comment\"># Check ESP tracking state in the registry<\/span>\n<span class=\"code-cmdlet\">reg query<\/span> <span class=\"code-string\">\"HKLM\\SOFTWARE\\Microsoft\\Enrollments\"<\/span> <span class=\"code-param\">\/s<\/span> | <span class=\"code-cmdlet\">findstr<\/span> <span class=\"code-string\">\"EnrollmentState\"<\/span>\n\n<span class=\"code-comment\"># Check which policies\/apps are still being tracked<\/span>\n<span class=\"code-cmdlet\">reg query<\/span> <span class=\"code-string\">\"HKLM\\SOFTWARE\\Microsoft\\Windows\\Autopilot\\EnrollmentStatusTracking\"<\/span> <span class=\"code-param\">\/s<\/span><\/code><\/pre>\n                <\/div>\n\n                <!-- 7. TPM attestation -->\n                <div id=\"tpm-attestation\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">7. TPM attestation failures<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        TPM attestation happens right at the start of pre-provisioning. If it fails, you never even get to the ESP. The device shows a red error screen almost immediately after pressing the Windows key five times to enter pre-provisioning mode.\n                    <\/p>\n\n                    <div class=\"callout-danger rounded-lg p-4 mb-4\">\n                        <p class=\"text-xs leading-relaxed\"><strong class=\"text-red-700 dark:text-red-300\">Important:<\/strong> TPM attestation is <em>required<\/em> for pre-provisioning. Unlike regular (user-driven) Autopilot, you cannot skip this step. The device must have a TPM 2.0 chip that the Autopilot service can verify.<\/p>\n                    <\/div>\n\n                    <p class=\"text-sm leading-relaxed mb-3\">Common causes and fixes:<\/p>\n                    <ul class=\"space-y-3 text-sm\">\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">TPM firmware outdated<\/strong> \u2014 some manufacturers ship with old TPM firmware that does not support attestation. Update via BIOS\/UEFI or the manufacturer&#8217;s firmware update tool. This is especially common on Lenovo and HP devices.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">TPM not cleared<\/strong> \u2014 if the device was previously enrolled or used, the TPM may hold old keys. Clear the TPM in BIOS or via <code class=\"inline\">tpm.msc<\/code> and re-run provisioning.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Hardware hash mismatch<\/strong> \u2014 if you replaced a motherboard or TPM module, the hardware hash has changed. Delete the old Autopilot device record and re-import the new hash.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Network blocking attestation<\/strong> \u2014 the device needs to reach <code class=\"inline\">ztd.dds.microsoft.com<\/code> and several other endpoints. Firewalls or proxies often block these. See the <a href=\"#network\" class=\"text-sky-500 hover:underline\">network section<\/a>.<\/span>\n                        <\/li>\n                    <\/ul>\n\n                    <p class=\"text-sm leading-relaxed mt-4\">Quick TPM health check from a command prompt:<\/p>\n                    <pre class=\"code-block\"><code><span class=\"code-comment\"># Check TPM status<\/span>\n<span class=\"code-cmdlet\">Get-Tpm<\/span> | <span class=\"code-cmdlet\">Format-List<\/span>\n\n<span class=\"code-comment\"># Verify TPM is ready for attestation<\/span>\n<span class=\"code-cmdlet\">Confirm-SecureBootUEFI<\/span>\n<span class=\"code-cmdlet\">Get-TpmEndorsementKeyInfo<\/span> <span class=\"code-param\">-Hash<\/span> <span class=\"code-string\">SHA256<\/span><\/code><\/pre>\n                <\/div>\n\n                <!-- 8. Hybrid join -->\n                <div id=\"hybrid-join\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">8. Hybrid Azure AD join issues<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Hybrid join adds a whole extra layer of complexity. The device needs to join both on-premises Active Directory and Entra ID. This requires the Intune Connector for Active Directory to be installed on a server that can reach a domain controller.\n                    <\/p>\n\n                    <p class=\"text-sm leading-relaxed mb-3\">The most frequent hybrid join problems:<\/p>\n                    <ul class=\"space-y-3 text-sm\">\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Intune Connector service not running<\/strong> \u2014 check <code class=\"inline\">services.msc<\/code> on the connector server for the &#8220;Intune Connector&#8221; service. Restart it and check the event log under <code class=\"inline\">Application and Services &gt; Microsoft &gt; Intune &gt; ODJConnectorSvc<\/code>.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">OU permissions<\/strong> \u2014 the connector service account needs permission to create computer objects in the target OU. This is the single most common hybrid join failure. Verify with <code class=\"inline\">dsacls<\/code> or the AD delegation wizard.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Entra Connect sync delay<\/strong> \u2014 after the connector creates the AD computer object, Entra Connect needs to sync it to Entra ID. If your sync cycle is 30 minutes, the device sits waiting. Consider triggering a delta sync manually or reducing the sync interval.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-sky-500 mt-1 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M9 5l7 7-7 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Domain profile not found<\/strong> \u2014 the Autopilot profile must specify the correct domain and OU. Double-check the domain join configuration in your deployment profile.<\/span>\n                        <\/li>\n                    <\/ul>\n\n                    <div class=\"callout-success rounded-lg p-4 mt-4\">\n                        <p class=\"text-xs leading-relaxed\"><strong class=\"text-emerald-700 dark:text-emerald-300\">Pro tip:<\/strong> If you are deploying new environments, seriously consider going cloud-native (Entra ID join only) and skipping hybrid join entirely. It removes an entire category of failure points and is the direction Microsoft is pushing.<\/p>\n                    <\/div>\n                <\/div>\n\n                <!-- 9. Network -->\n                <div id=\"network\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">9. Network and proxy pitfalls<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Network issues are the silent killer of Autopilot deployments. The device needs access to a long list of Microsoft endpoints during provisioning. Corporate networks with aggressive firewalls or proxy servers frequently break one or more of these connections.\n                    <\/p>\n\n                    <p class=\"text-sm leading-relaxed mb-3\">Critical endpoints that must be reachable:<\/p>\n                    <div class=\"overflow-x-auto\">\n                        <table class=\"w-full text-xs border border-slate-200 dark:border-slate-700 rounded-lg overflow-hidden\">\n                            <thead>\n                                <tr class=\"bg-slate-100 dark:bg-slate-800\">\n                                    <th class=\"text-left p-3 font-semibold text-slate-900 dark:text-white\">Endpoint<\/th>\n                                    <th class=\"text-left p-3 font-semibold text-slate-900 dark:text-white\">Purpose<\/th>\n                                <\/tr>\n                            <\/thead>\n                            <tbody class=\"divide-y divide-slate-200 dark:divide-slate-700\">\n                                <tr><td class=\"p-3\"><code class=\"inline\">ztd.dds.microsoft.com<\/code><\/td><td class=\"p-3\">Autopilot deployment service<\/td><\/tr>\n                                <tr><td class=\"p-3\"><code class=\"inline\">cs.dds.microsoft.com<\/code><\/td><td class=\"p-3\">Autopilot deployment service<\/td><\/tr>\n                                <tr><td class=\"p-3\"><code class=\"inline\">login.microsoftonline.com<\/code><\/td><td class=\"p-3\">Entra ID authentication<\/td><\/tr>\n                                <tr><td class=\"p-3\"><code class=\"inline\">enterpriseregistration.windows.net<\/code><\/td><td class=\"p-3\">Entra ID device registration<\/td><\/tr>\n                                <tr><td class=\"p-3\"><code class=\"inline\">enrollment.manage.microsoft.com<\/code><\/td><td class=\"p-3\">Intune MDM enrollment<\/td><\/tr>\n                                <tr><td class=\"p-3\"><code class=\"inline\">*.dl.delivery.mp.microsoft.com<\/code><\/td><td class=\"p-3\">Windows Update &amp; app content delivery<\/td><\/tr>\n                                <tr><td class=\"p-3\"><code class=\"inline\">ekop.intel.com<\/code> \/ <code class=\"inline\">ekcert.spserv.microsoft.com<\/code><\/td><td class=\"p-3\">TPM attestation (manufacturer-dependent)<\/td><\/tr>\n                            <\/tbody>\n                        <\/table>\n                    <\/div>\n\n                    <div class=\"callout-warning rounded-lg p-4 mt-4\">\n                        <p class=\"text-xs leading-relaxed\"><strong class=\"text-amber-700 dark:text-amber-300\">SSL inspection:<\/strong> Many enterprise proxies perform SSL inspection. This breaks certificate pinning for several Microsoft services. If you are using SSL inspection, you <em>must<\/em> exclude all <code class=\"inline\">*.microsoft.com<\/code> and <code class=\"inline\">*.windows.net<\/code> endpoints from inspection. This is the most common network-related pre-provisioning failure I see.<\/p>\n                    <\/div>\n\n                    <p class=\"text-sm leading-relaxed mt-4\">Quick connectivity test from the OOBE command prompt:<\/p>\n                    <pre class=\"code-block\"><code><span class=\"code-comment\"># Test critical endpoints<\/span>\n<span class=\"code-cmdlet\">Test-NetConnection<\/span> <span class=\"code-string\">ztd.dds.microsoft.com<\/span> <span class=\"code-param\">-Port<\/span> <span class=\"code-string\">443<\/span>\n<span class=\"code-cmdlet\">Test-NetConnection<\/span> <span class=\"code-string\">login.microsoftonline.com<\/span> <span class=\"code-param\">-Port<\/span> <span class=\"code-string\">443<\/span>\n<span class=\"code-cmdlet\">Test-NetConnection<\/span> <span class=\"code-string\">enrollment.manage.microsoft.com<\/span> <span class=\"code-param\">-Port<\/span> <span class=\"code-string\">443<\/span>\n\n<span class=\"code-comment\"># Check if a proxy is configured<\/span>\n<span class=\"code-cmdlet\">netsh<\/span> <span class=\"code-param\">winhttp<\/span> <span class=\"code-string\">show proxy<\/span><\/code><\/pre>\n                <\/div>\n\n                <!-- 10. Get-AutopilotDiagnosticsCommunity -->\n                <div id=\"community-script\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">10. Get-AutopilotDiagnosticsCommunity<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        If you have ever tried to make sense of raw Autopilot logs and registry dumps, you know it is not a fun experience. That is exactly why the <strong class=\"text-slate-900 dark:text-white\">Get-AutopilotDiagnosticsCommunity<\/strong> script exists \u2014 a community-maintained PowerShell script published on the <a href=\"https:\/\/www.powershellgallery.com\/packages\/Get-AutopilotDiagnosticsCommunity\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">PowerShell Gallery<\/a>.\n                    <\/p>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        The script is a successor to Michael Niehaus&#8217;s original <code class=\"inline\">Get-AutopilotDiagnostics<\/code> and has been expanded with additional checks, better output formatting and support for the latest Autopilot and ESP changes. It is the single most useful tool in my troubleshooting toolkit and the first thing I run when a pre-provisioning attempt fails.\n                    <\/p>\n\n                    <h4 class=\"font-heading text-base font-semibold text-slate-900 dark:text-white mb-3\">Installation<\/h4>\n                    <pre class=\"code-block\"><code><span class=\"code-comment\"># Install from the PowerShell Gallery<\/span>\n<span class=\"code-cmdlet\">Install-Script<\/span> <span class=\"code-param\">-Name<\/span> <span class=\"code-string\">Get-AutopilotDiagnosticsCommunity<\/span> <span class=\"code-param\">-Force<\/span>\n\n<span class=\"code-comment\"># Run the script<\/span>\n<span class=\"code-cmdlet\">Get-AutopilotDiagnosticsCommunity<\/span>\n\n<span class=\"code-comment\"># Run with -Online to resolve app names, policy names, etc. from Graph API<\/span>\n<span class=\"code-comment\"># Without this flag you only see GUIDs \u2014 with it you get human-readable names<\/span>\n<span class=\"code-cmdlet\">Get-AutopilotDiagnosticsCommunity<\/span> <span class=\"code-param\">-Online<\/span>\n\n<span class=\"code-comment\"># Combine with -Verbose for maximum detail<\/span>\n<span class=\"code-cmdlet\">Get-AutopilotDiagnosticsCommunity<\/span> <span class=\"code-param\">-Online<\/span> <span class=\"code-param\">-Verbose<\/span><\/code><\/pre>\n\n                    <h4 class=\"font-heading text-base font-semibold text-slate-900 dark:text-white mt-6 mb-3\">What it does<\/h4>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Instead of manually digging through registry keys, event logs and MDM diagnostic files, this script does the heavy lifting for you. Here is what it covers:\n                    <\/p>\n                    <ul class=\"space-y-2 text-sm\">\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Autopilot profile details<\/strong> \u2014 shows the assigned profile, deployment mode, join type and whether pre-provisioning is enabled.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">ESP status breakdown<\/strong> \u2014 lists every tracked policy, app and certificate with its current installation state. Instantly tells you what is blocking the ESP.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">App installation status<\/strong> \u2014 for each tracked Win32 and LOB app, it shows whether it downloaded, installed and passed detection \u2014 including error codes if it failed.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Policy processing<\/strong> \u2014 shows configuration profiles, compliance policies and their delivery status.<\/span>\n                        <\/li>\n                        <li class=\"flex gap-3\">\n                            <span class=\"text-emerald-500 mt-0.5 shrink-0\"><svg class=\"w-4 h-4\" fill=\"none\" stroke=\"currentColor\" viewBox=\"0 0 24 24\"><path stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 13l4 4L19 7\"\/><\/svg><\/span>\n                            <span><strong class=\"text-slate-900 dark:text-white\">Timeline of events<\/strong> \u2014 a chronological overview of the enrollment flow, making it easy to spot where things went wrong and how long each step took.<\/span>\n                        <\/li>\n                    <\/ul>\n\n                    <div class=\"callout-success rounded-lg p-4 mt-4\">\n                        <p class=\"text-xs leading-relaxed\"><strong class=\"text-emerald-700 dark:text-emerald-300\">Pro tip:<\/strong> You can run this script during a stuck ESP by pressing <code class=\"inline\">Shift + F10<\/code> to open a command prompt. It works in both OOBE and desktop context, and gives you a clear, readable summary instead of having to parse raw logs. Save yourself 30 minutes of digging \u2014 run this first.<\/p>\n                    <\/div>\n\n                <\/div>\n\n                <!-- 12. Final checklist -->\n                <div id=\"final-checklist\">\n                    <h3 class=\"font-heading text-xl font-semibold text-slate-900 dark:text-white mb-3\">11. Final pre-flight checklist<\/h3>\n                    <p class=\"text-sm leading-relaxed mb-4\">\n                        Before kicking off pre-provisioning, run through this list. It takes two minutes and saves hours of troubleshooting:\n                    <\/p>\n                    <div class=\"space-y-2\">\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Hardware hash is imported and profile status shows &#8220;Assigned&#8221; in the Intune portal<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Deployment profile has &#8220;Allow pre-provisioned deployment&#8221; enabled<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>ESP is configured, assigned, and timeout value is realistic for the number of tracked apps<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>All required Win32 apps have been tested individually and detection rules are verified<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>Network has internet access \u2014 all critical Microsoft endpoints are reachable on port 443<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>SSL inspection is disabled for Microsoft endpoints (if applicable)<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>TPM firmware is up to date and TPM has been cleared (for refurbished\/reused devices)<\/span>\n                        <\/label>\n                        <label class=\"flex items-start gap-3 text-sm p-3 bg-white dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-lg\">\n                            <input type=\"checkbox\" class=\"mt-1 accent-sky-500\" disabled>\n                            <span>For hybrid: Intune Connector is online, service account has OU permissions, Entra Connect is syncing<\/span>\n                        <\/label>\n                    <\/div>\n                <\/div>\n\n                <!-- Closing -->\n                <div class=\"pt-4 border-t border-slate-200 dark:border-slate-800\">\n                    <p class=\"text-sm leading-relaxed\">\n                        Autopilot pre-provisioning is powerful when it works \u2014 and painful when it does not. The key to success is a solid checklist, knowing where to find the right logs, and understanding the flow well enough to pinpoint where the process broke down. If you are still stuck after going through everything above, feel free to reach out on <a href=\"https:\/\/www.linkedin.com\/in\/stevenvanbeek\/\" class=\"text-sky-500 hover:underline\" target=\"_blank\" rel=\"noopener noreferrer\">LinkedIn<\/a> \u2014 happy to help.\n                    <\/p>\n                <\/div>\n\n                <!-- Tech stack summary -->\n                <div class=\"p-6 bg-slate-50 dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-xl\">\n                    <h4 class=\"font-heading font-semibold text-slate-900 dark:text-white text-sm mb-3\">Technologies covered<\/h4>\n                    <div class=\"flex flex-wrap gap-2\">\n                        <span class=\"px-2 py-0.5 text-[11px] font-mono bg-sky-50 dark:bg-sky-500\/10 text-sky-600 dark:text-sky-400 rounded border border-sky-200 dark:border-sky-500\/20\">Windows Autopilot<\/span>\n                        <span class=\"px-2 py-0.5 text-[11px] font-mono bg-sky-50 dark:bg-sky-500\/10 text-sky-600 dark:text-sky-400 rounded border border-sky-200 dark:border-sky-500\/20\">Microsoft Intune<\/span>\n                        <span class=\"px-2 py-0.5 text-[11px] font-mono bg-sky-50 dark:bg-sky-500\/10 text-sky-600 dark:text-sky-400 rounded border border-sky-200 dark:border-sky-500\/20\">Entra ID<\/span>\n                        <span class=\"px-2 py-0.5 text-[11px] font-mono bg-sky-50 dark:bg-sky-500\/10 text-sky-600 dark:text-sky-400 rounded border border-sky-200 dark:border-sky-500\/20\">TPM 2.0<\/span>\n                        <span class=\"px-2 py-0.5 text-[11px] font-mono bg-sky-50 dark:bg-sky-500\/10 text-sky-600 dark:text-sky-400 rounded border border-sky-200 dark:border-sky-500\/20\">ESP<\/span>\n                        <span class=\"px-2 py-0.5 text-[11px] font-mono bg-sky-50 dark:bg-sky-500\/10 text-sky-600 dark:text-sky-400 rounded border border-sky-200 dark:border-sky-500\/20\">PowerShell<\/span>\n                        <span class=\"px-2 py-0.5 text-[11px] font-mono bg-sky-50 dark:bg-sky-500\/10 text-sky-600 dark:text-sky-400 rounded border border-sky-200 dark:border-sky-500\/20\">Hybrid AD Join<\/span>\n                    <\/div>\n                <\/div>\n\n                <!-- References -->\n                <div class=\"p-6 bg-slate-50 dark:bg-slate-900\/50 border border-slate-200 dark:border-slate-800 rounded-xl\">\n                    <h4 class=\"font-heading font-semibold text-slate-900 dark:text-white text-sm mb-3\">References &amp; further reading<\/h4>\n                    <ul class=\"space-y-2 text-sm\">\n                        <li class=\"flex gap-2\">\n                            <span class=\"text-sky-500 shrink-0\">&#8594;<\/span>\n                            <a href=\"https:\/\/learn.microsoft.com\/mem\/autopilot\/pre-provision\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Microsoft Learn \u2014 Windows Autopilot pre-provisioning<\/a>\n                        <\/li>\n                        <li class=\"flex gap-2\">\n                            <span class=\"text-sky-500 shrink-0\">&#8594;<\/span>\n                            <a href=\"https:\/\/learn.microsoft.com\/mem\/autopilot\/troubleshooting\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Microsoft Learn \u2014 Troubleshoot Autopilot device enrollment<\/a>\n                        <\/li>\n                        <li class=\"flex gap-2\">\n                            <span class=\"text-sky-500 shrink-0\">&#8594;<\/span>\n                            <a href=\"https:\/\/learn.microsoft.com\/mem\/autopilot\/networking-requirements\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Microsoft Learn \u2014 Autopilot networking requirements<\/a>\n                        <\/li>\n                        <li class=\"flex gap-2\">\n                            <span class=\"text-sky-500 shrink-0\">&#8594;<\/span>\n                            <a href=\"https:\/\/learn.microsoft.com\/mem\/intune\/enrollment\/windows-enrollment-status\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"text-sky-600 dark:text-sky-400 hover:underline\">Microsoft Learn \u2014 Enrollment Status Page overview<\/a>\n                        <\/li>\n                    <\/ul>\n                <\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A practical, no-nonsense guide to diagnosing and fixing the most common Windows Autopilot pre-provisioning failures from ESP timeouts to TPM attestation issues.<\/p>\n","protected":false},"author":1,"featured_media":37,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,3],"tags":[],"class_list":["post-8","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-intune","category-troubleshooting"],"_links":{"self":[{"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/posts\/8","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/comments?post=8"}],"version-history":[{"count":8,"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/posts\/8\/revisions"}],"predecessor-version":[{"id":25,"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/posts\/8\/revisions\/25"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/media\/37"}],"wp:attachment":[{"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/media?parent=8"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/categories?post=8"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vanbeekcloud.nl\/index.php\/wp-json\/wp\/v2\/tags?post=8"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}