Home › Setup guides
Setup guides

Every manual step, from scratch — one track per platform

Most of an Intune build can be automated — but each platform keeps a few one-time human steps. Follow your platform's track top to bottom: every step says what it depends on, so nothing is out of order.

Every device platform is a separate track. Pick your platform and work straight down it — each guide lists what must already be in place before it. Apple, Google and Windows never mix; the one thing they share is Microsoft Intune.

New to the acronyms (ABM, ADE, VPP, ESP…)? See the device-management glossary — every term in plain English.

Start here — Microsoft foundation

Before any platform: get the Microsoft 365 tenant and Intune licence that everything else plugs into. ≈ 1h 05m across 3 guides.

Apple — iPhone, iPad & Mac

The whole Apple journey, in order — from an Apple Business Manager account to silent app deployment. Work straight down. ≈ 3h 35m across 12 guides.

1Sign up for Apple Business Manager and create the admin Managed Apple Account
Create your organisation's free Apple Business Manager account — the portal that owns every Apple token and app licence. Needs a brand-new work email and D-U-N-S verification (allow several business days), so start this FIRST. · 10 steps · ≈ 30 min · assisted · one-time human step
2Create the Apple MDM Push certificate (required for all Apple management)
The MDM Push certificate is the master key that lets Intune manage ANY iPhone, iPad or Mac. Download a request from Intune, sign it at Apple's push portal, upload it back. Renew yearly with the SAME Apple ID or every device re-enrols. · 7 steps · ≈ 20 min · assisted · one-time human step
3Create the Apple ADE (Automated Device Enrolment) program token
ADE builds the trust between Intune and Apple Business Manager so corporate iPhones/iPads enrol themselves out of the box. You swap a public key and a server token between the two. KEEP THE INTUNE TAB OPEN the whole time. · 12 steps · ≈ 20 min · assisted · one-time human step
4Create the Apple ADE enrolment policy (out-of-box experience)
This policy controls what a corporate iPhone/iPad shows during first-boot setup and locks it to management. Set it as the token's Default Policy or synced devices fail with 'Invalid Profile'. · 11 steps · ≈ 15 min
5Download the Apple location (VPP content) token from ABM
The .vpptoken lets Intune push App Store apps silently with no personal Apple ID. It lives in ABM under Payments and Billing > Content Tokens. One token per Location, per MDM; valid 12 months — diarise renewal. · 7 steps · ≈ 10 min · assisted · one-time human step
6Get / buy app licences in ABM Apps and Books
Before Intune can deploy an Apple app you must 'Get' its licences in ABM against the SAME Location as your uploaded token. Free apps still need a licence quantity; that count becomes your ceiling in Intune. · 7 steps · ≈ 5 min · assisted · one-time human step
7Upload the VPP/location token into Intune
Creates the Apple VPP connector in Intune from the .vpptoken you downloaded in ABM. The Apple Account you enter MUST exactly match the Managed Apple ID that owns the token or it shows invalid. · 9 steps · ≈ 10 min
8Sync the token and assign a VPP app with silent device licensing
After upload, sync so ABM apps appear in Intune, then assign them Required with DEVICE licensing to an Entra group for a silent, Apple-ID-less install. Never mix device and user licensing on the same target. · 7 steps · ≈ 15 min
9Deploy Company Portal for iOS as a required VPP app
ADE devices need the VPP/device-licensed Company Portal, NOT the App Store version (which is incompatible with ADE and won't auto-update). Assign it Required with device licensing. · 6 steps · ≈ 15 min
10Add a free iOS App Store app by URL (no VPP)
For genuinely free apps where an Apple ID on the device is acceptable, add straight from the App Store — no token needed. Not silent and no licence tracking; paid apps must use VPP. · 7 steps · ≈ 5 min
11Enrol a test iPhone or iPad via Apple ADE
Take an ADE-assigned iPhone or iPad from a factory-reset state through Setup Assistant to fully enrolled, supervised and compliant in Intune — the visible payoff of all the Apple token work. The trap: the enrolment profile must already be assigned and synced to the device's serial before you switch it on, or first boot skips the Remote Management screen entirely and there is nothing to sign into. · 10 steps · ≈ 25 min · assisted
12Enrol a Mac (macOS) via Apple ADE
Turns a corporate-owned Mac into a supervised, Intune-managed device the moment it's switched on — zero-touch, straight from the box. The trap: a Mac that syncs from Apple Business Manager with no enrolment policy assigned fails Setup Assistant outright, so set a Default Policy before anyone powers one on. · 11 steps · ≈ 45 min · assisted

Google — Android

Android Enterprise, in order. Unlike Apple there is no separate Google account to create — the binding is made from inside Intune. ≈ 1h 45m across 5 guides.

1Connect Intune to Managed Google Play (Android Enterprise binding)
One-time, effectively permanent binding that unlocks Android Enterprise. Sign in with an organisational Entra account that has a working mailbox (NOT personal Gmail). Path is Devices > Enrollment > Android > Prerequisites, NOT Connectors and tokens. · 12 steps · ≈ 15 min · assisted · one-time human step
2Approve Managed Google Play store apps (in-Intune iframe)
Approve Android apps in the embedded Google Play store inside Intune — one action both approves and syncs. Set 'keep approved' for new permissions, and remember approving is not enough: you must also assign to a group. · 8 steps · ≈ 15 min
3Create an Android Enterprise corporate enrolment profile (QR/token)
Generates the QR code/token that provisions a factory-reset corporate Android as fully managed, COPE or dedicated. Pick the mode by device ownership — fully managed wipes the whole device. BYOD work profile needs no token. · 7 steps · ≈ 15 min
4Create an Entra dynamic device group for corporate Android Enterprise devices
Targets corporate Android devices automatically by attribute. Enrol one canary device FIRST and read its real deviceOSType — 'AndroidEnterprise' catches fully managed/dedicated but misses BYOD work profile ('AndroidForWork'). · 6 steps · ≈ 20 min
5Enrol a test Android device (fully managed QR + BYOD work profile)
Prove your Android enrolment actually works by putting one device through each path: a factory-reset corporate phone provisioned fully managed by tapping the first setup screen several times to open the QR scanner, and a personal phone self-enrolled through the Company Portal app. The trap: fully managed DEMANDS a genuine factory-reset, out-of-box device, and you must NOT restart it mid-provisioning — do either and it can look enrolled in Intune while being completely unmanaged. · 10 steps · ≈ 40 min · assisted

Windows — Autopilot & USB provisioning

Building and provisioning Windows machines with the Decolla USB, plus Autopilot device targeting. ≈ 2h 23m across 12 guides.

1Before you build a provisioning USB - kit, space, time and downloads
Everything to have ready BEFORE your first stick, so nothing surprises you mid-build: a 16 GB+ USB stick (the whole stick is erased; on sticks over 32 GB the boot partition is capped at ~30 GB - that is normal), a Windows 10/11 PC with admin rights and about 30 GB free disk, the Windows ISO downloaded in YOUR machines' language, and honest time expectations: the first build does one-off preparation (roughly 35-90 minutes depending on options), every build after that is about 10-15 minutes, and the target machine's install takes another 20-40 minutes. · 9 steps · ≈ 15 min
2Choose the USB / offline build options in the cockpit (Deploy plan)
The Deploy-plan screen's 'USB / offline build' card decides how your provisioning stick behaves: Standalone vs Autopilot-prep, Wi-Fi, debloat (remove consumer apps), bake in the latest Windows update, and which disk the stick erases. You set them once here; they flow into the downloaded plan and the builder obeys them without asking again. · 10 steps · ≈ 5 min
3Build a provisioning USB with a double-click (Decolla USB Builder)
The no-command-line way to build a provisioning stick: double-click the builder, pick your Windows ISO and client profile in two pop-ups, answer two yes/no questions, set the admin password, and type ERASE at the one deliberate safety stop. It ends with a USB READY pop-up showing the login for the machines it builds. · 11 steps · ≈ 10 min
4Build a Decolla provisioning USB (Windows + build config + apps)
Make ONE bootable stick that installs Windows unattended, applies the build config, and installs the apps offline. You supply the customer's own LICENSED Windows ISO (we never redistribute Windows) and a plain 16 GB+ USB. BEST: download the ISO in your profile's LANGUAGE (Windows 11 ships in 38 languages - e.g. English UK) so the media natively matches: zero prompts, nothing to inject. Fallback: the builder can slipstream the language pack (~143 MB, auto-fetched) into the image - but NOT on 25H2 (26200) media, where offline language injection has a known Microsoft defect. The image can also be serviced offline: latest Windows update baked in, per-model drivers injected, consumer apps stripped (guarded blocklist). Pick the mode in the cockpit: Standalone (fully offline, known admin login) or Autopilot-prep (OOBE stays so the device Entra-joins and Intune-enrols). The build is silent + guarded; boot-test on a spare machine (it wipes the target's disk). · 14 steps · ≈ 20 min
5USB build speed: service the image once, every stick after is a fast copy
The FIRST build with servicing options (language, updates, app-stripping) does real image surgery - expect roughly 35-90 minutes depending on options and hardware. The result is cached, so every later stick with the same inputs is a pure file copy, roughly 10-15 minutes. Cache and per-build logs stay on your machine only - licensed Windows never leaves it. · 9 steps · ≈ 10 min
6How machines get their names (auto serial names + the first-logon rename pop-up)
One stick names many machines: the profile's device prefix becomes a pattern like JAY-{SERIAL} and each machine fills in its own BIOS serial number. At first logon a pop-up lets you swap that for the printed-label name (e.g. JAY624) - or cancel to keep the auto name. Sequential auto-numbering is a coming-soon design. · 8 steps · ≈ 5 min
7Upload your own app (MSI/EXE) - install it via Intune, the USB stick, or both
For apps not in the store - your RMM agent, a VPN client, a line-of-business installer. Point the cockpit at your MSI/EXE: an MSI's name, publisher and silent install are read from the file itself, the binary uploads straight to your organisation's private Decolla storage, and you choose whether it installs via Intune, from the USB stick, or both. Any token stays private to your build. · 10 steps · ≈ 8 min
8Boot a machine from the Decolla stick, and open a command prompt during Setup
How to reach the one-time boot menu on each laptop brand, and how to open the hidden Setup command prompt with Shift+F10 - including the Fn-key trap that makes Shift+F10 do nothing on most modern laptops. · 8 steps · ≈ 10 min · assisted
9Capture logs from a failed build (run Decolla-Diag)
If a build fails at any stage, run the one-touch Decolla-Diag tool on the USB. It captures every Windows Setup and Decolla log onto the stick for support - no commands to memorise, nothing changed on the machine. · 6 steps · ≈ 10 min · assisted
10Create a dynamic Autopilot device group (touchless Windows targeting)
Targets Autopilot Windows devices before OOBE. Build the rule ONLY on Autopilot attributes (ZTDId or group-tag OrderID) — they populate only after registration. Requires Entra ID P1. · 6 steps · ≈ 10 min
11Create a Windows Autopilot deployment profile and Enrollment Status Page
Creates the deployment profile that shapes a registered device's out-of-box experience, assigns it to your dynamic Autopilot group, and configures the Enrollment Status Page that gates first sign-in until apps and policies land. The trap: the profile only ever reaches a device through that group, and membership can lag hours behind registration, so confirm Profile Status reads Assigned before you touch the machine. Since Aug 2026 the Decolla build zone does the reading and matching for you: an Autopilot-prep build lists your tenant's deployment profiles matched by what they DO (join type, single-user vs shared, standard vs administrator user, pre-provisioning, hash harvesting, the OOBE screens) - never by name - and offers to link the match or, on your press only, create one under a name you choose and verify it by a separate read. This guide remains the manual route and the reference for what each setting means. · 12 steps · ≈ 20 min
12Register Windows devices into Autopilot (hardware hash)
This is how a Windows device actually gets into Autopilot: you capture its hardware hash, upload that hash to Intune, and the Autopilot service now recognises the machine so it can be zero-touch provisioned at next reset. The trap that catches almost everyone: only ever touch the hash CSV in a plain-text editor like Notepad. Open or save it in Excel and the file is silently mangled, the import fails, and the error message won't tell you why. · 11 steps · ≈ 20 min · assisted

Across every platform

Ongoing management that applies once devices — from any platform — are enrolled. ≈ 35 min across 2 guides.

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access