Decolla vs building Windows Autopilot + Intune by hand
If you already provision Windows devices by creating profiles, policies, apps, ESP and enrolment directly in the Intune admin centre, you have full control and no dependency on anyone. Decolla is not a replacement platform — it is a plan-review-deploy layer on top of the same tenant. Here is an honest look at where each one wins.
Two routes to the same tenant
Both approaches end up in the same place: your own Microsoft Intune and Entra tenant, applying Windows Autopilot deployment profiles, configuration policies, compliance rules, apps and an Enrolment Status Page. The difference is how you get there.
Building by hand means working directly in the Intune admin centre — creating each deployment profile, tuning the ESP, assembling configuration profiles from the settings catalogue, and layering Microsoft's built-in security baselines where you want them. It is the native, first-party way to run Intune, it costs nothing beyond your existing licensing, and every skill you build transfers directly to Microsoft's own tooling.
Decolla sits on top of that same tenant. You define a build as a written, itemised plan, review it, then deploy it unattended through your tenant using delegated Graph consent. It is currently in early access, and it publishes the exact Graph scopes it requests before it connects. It does not take your tenant away from you — you can still manage everything directly in Intune whenever you want.
How they differ
The table below lays out the practical trade-offs. Neither column is uniformly "better" — manual gives you unmediated control, Decolla gives you a reviewable plan and per-item reversibility.
| Dimension | Decolla | Manual Autopilot + Intune |
|---|---|---|
| Approach | A written, itemised build plan you review before anything is applied | Hands-on configuration, profile by profile, directly in the Intune admin centre |
| Starting point | 377 curated build items across 29 sections, so you assemble from a catalogue rather than a near-empty tenant | A new tenant starts largely empty; Microsoft's built-in security baselines give a security starting point, but apps, custom policies, compliance and ESP are built by hand |
| Review before change | The plan is the review artefact — you see every item before it runs | Whatever review you document yourself; the admin centre has no native plan-and-approve step |
| Reversibility / rollback | Reversible per item — roll one item back without a wipe or rebuild | Edit or delete profiles manually; no built-in per-item versioning or one-click rollback, and baseline upgrades have removed custom settings without warning |
| Deployment | Unattended, but gated — nothing runs without explicit per-batch confirmation | You apply and assign each change yourself, when you choose |
| Needs Intune / Entra tenant | Yes — runs inside your tenant via delegated Graph consent | Yes — it is the tenant |
| Ongoing management | Same tenant; you can keep working directly in Intune alongside Decolla | Fully in your hands, with no extra layer |
| Learning curve | Learn Decolla's plan / review / deploy flow; your tenant sits underneath it | Requires fluency in Intune, the settings catalogue, ESP, deployment profiles and Autopilot |
| Dependency / control | Adds a tooling layer and a consent grant; early access | No third-party dependency; full, direct control of every setting Microsoft exposes |
When to use which
Be honest with yourself about the estate and the team before choosing.
Stick with building by hand when
- You have a tiny estate — one machine, or a handful you set up once and rarely touch. The overhead of any tooling layer is not worth it.
- Your team wants everything hand-built and understood setting-by-setting, with no abstraction between you and the admin centre.
- You need zero external dependency — no additional consent grant, no third-party tool in the provisioning path, purely first-party Microsoft.
- You are already fluent in Intune and change infrequently, so a written plan and per-item rollback would not save you meaningful time.
Consider Decolla when
- You provision or reconfigure devices often enough that a reviewable, itemised plan beats clicking through the admin centre each time.
- You want to roll back a single item without a wipe or rebuild, rather than manually unpicking changes.
- You want deployment to run unattended but gated, with explicit per-batch confirmation before anything applies.
- You would rather start from a curated catalogue of build items than assemble a fresh tenant profile-by-profile.
And if you have no Intune or Entra tenant at all, neither route applies — Decolla runs inside a tenant you already own, so that has to come first.
Where Decolla fits
Decolla is not trying to replace Intune, and it does not hide it. It is a layer for people who already run Autopilot and Intune and want three specific things the admin centre does not give you natively: a written plan to review before changes apply, per-item reversibility, and gated unattended deployment from a curated catalogue rather than a blank tenant.
If manual, hand-built control is exactly what you want — and for small or rarely-changing estates it often is — keep doing it. Decolla is currently in early access; if the review-and-rollback workflow sounds like it would save your team time, it is built to sit alongside the tenant you already own, not take it over.
See it on a real device.
Decolla is in private build — early-access members see a build defined, deployed and rolled back first.
Get early access