Decolla vs Windows Configuration Designer and provisioning packages (.ppkg)
Both set up Windows devices, but they work in fundamentally different ways. Windows Configuration Designer builds a one-shot provisioning package that runs on the device; Decolla deploys a reviewed, itemised build through your own Intune and Autopilot tenant and keeps managing it afterwards. Here is an honest look at where each fits. Decolla is currently in early access.
The short version
Microsoft's Windows Configuration Designer (WCD) creates a provisioning package — a .ppkg file that applies a bundle of settings to a Windows device, either during the out-of-box experience or by double-clicking it on a machine that is already running. It is free, works offline, and needs no cloud infrastructure.
Decolla takes a different approach. You define a Windows and Intune build as a written, itemised plan, review it, then deploy it unattended through your organisation's own Microsoft Autopilot and Intune tenant. Every item is reversible on its own, and the device stays under ongoing cloud management afterwards.
Neither is simply "better". A .ppkg is the right tool for offline or unmanaged scenarios; Decolla is built for fleets you want to review before deployment, roll back per item, and manage over time.
What Windows Configuration Designer and .ppkg actually do
Windows Configuration Designer is a free Microsoft tool, available in the Microsoft Store, for configuring devices without re-imaging. Microsoft describes it as best suited to small- to medium-sized deployments — from tens to a few hundred computers. See the provisioning packages overview for the official detail.
A provisioning package can:
- Set the device name, join a Wi-Fi network, and create a local administrator account
- Install Win32 and UWP applications, and deploy certificates
- Apply enterprise policies such as password rules, device lock, encryption and update settings
- Bulk-join Microsoft Entra ID with a bulk enrolment token, or enrol into a third-party MDM
- Be delivered on a USB stick or SD card, by email, from a network share, or via NFC tag or barcode — and applied with no network connection at all
These are genuine strengths. For a technician setting up a handful of machines, or an environment with no MDM at all, a .ppkg is quick, approachable and self-contained.
One limit is worth stating precisely, because it shapes the comparison. Microsoft notes that using a provisioning package for automatic enrolment into Intune is not supported; a package can bulk-join Entra ID, which may then trigger Intune enrolment through your own auto-enrolment policy, but the package itself is a runtime configuration bundle, not a cloud-management system.
How they differ
The core difference is one-shot runtime provisioning versus a reviewed, cloud-managed lifecycle. This table lays out the main dimensions honestly — including the ones where a provisioning package is the stronger choice.
| Dimension | Decolla | Windows Configuration Designer (.ppkg) |
|---|---|---|
| Approach | A reviewed, itemised build deployed through Intune and Autopilot | A self-contained package applied at runtime on the device |
| Reversibility | Per item — roll back a single change without a wipe or rebuild | Partial and package-level. Microsoft documents that Uninstall-ProvisioningPackage (Windows 11) reverts only a defined list of registry and CSP settings; installed apps and many changes are not undone |
| Needs Intune / Entra | Yes — it runs inside your own Intune and Entra/Autopilot tenant | No — works with no MDM or Entra at all; can optionally bulk-join Entra or enrol into an MDM |
| Ongoing management | Yes — devices stay cloud-managed through Intune after deployment | One-shot. The package applies once; ongoing management exists only if it hands the device off to an MDM |
| Review before change | A written plan is reviewed up front; deployment is gated per batch with explicit confirmation | You build and inspect the project in WCD, but the package runs as a bundle when applied — there is no per-item approval gate on the device |
| Learning curve | Plan-based; aims to lower the Intune and Graph learning curve | The simple wizards are approachable for basic setup; the advanced editor and raw CSP settings get more complex |
| Works offline / air-gapped | No — needs connectivity to the cloud tenant | Yes — designed to apply with no network connection |
| Cost | Early access — not yet publicly priced | Free tool (part of the Windows configuration tooling) |
When to use which
These tools solve overlapping problems from opposite ends. Pick by scenario, not by preference.
A provisioning package (WCD) is the right tool when…
- You have no Entra ID or Intune tenant and do not plan to run cloud management
- Devices are air-gapped or offline, so a USB-applied package is the only practical route
- You are configuring a small number of machines as a one-off — tens to a few hundred, in Microsoft's own guidance
- You need a bulk Entra join token, or a quick kiosk, HoloLens or Surface Hub setup from the built-in wizards
- You want a free, self-contained tool with nothing to subscribe to and full local control
Decolla is the better fit when…
- You already run — or are moving to — Intune and Entra/Autopilot
- You want a written build you can review and sign off before anything changes, deployed under a per-batch confirmation gate
- You need per-item rollback rather than a partial, package-level uninstall
- You are managing a fleet over time, not setting up one machine once
When not to use Decolla: if you have no Intune or Entra tenant, you are provisioning a single one-off machine, your devices are air-gapped, or you specifically want fully manual, local control, then a .ppkg from Windows Configuration Designer is the more sensible choice.
Where Decolla fits
Think of it as one-shot versus ongoing. Windows Configuration Designer packages a device once and hands it over; Decolla turns your build into a reviewed plan, deploys it through your own Intune and Autopilot tenant with an explicit confirmation gate, and keeps every change reversible per item so you can adjust without a rebuild.
If a provisioning package already covers your scenario, keep using it — it is a capable, free tool for exactly the offline and unmanaged cases it was designed for. If you are standing up or already running Intune and want review, reversibility and ongoing lifecycle management instead of a one-off package, that is where Decolla is designed to help. It is in early access today.
See it on a real device.
Decolla is in private build — early-access members see a build defined, deployed and rolled back first.
Get early access