Home › Setup guides › Before you build a provisioning USB - kit, space, time and downloads
Setup guide · from scratch
Before you build a provisioning USB - kit, space, time and downloads
Everything to have ready BEFORE your first stick, so nothing surprises you mid-build: a 16 GB+ USB stick (the whole stick is erased; on sticks over 32 GB the boot partition is capped at ~30 GB - that is normal), a Windows 10/11 PC with admin rights and about 30 GB free disk, the Windows ISO downloaded in YOUR machines' language, and honest time expectations: the first build does one-off preparation (roughly 35-90 minutes depending on options), every build after that is about 10-15 minutes, and the target machine's install takes another 20-40 minutes.
Decolla provisioning USB (read this first)
≈ 15 min
Windows — Autopilot & USB provisioning · step 1 of 12 · ≈ 15 minNext ›
Do these first — this guide assumes you already have:
A Decolla cockpit account and a downloaded client profile; a Windows 10/11 PC with admin rights and a 16 GB+ USB stick.
The Decolla way — skip the clicks.
Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.
⏱ By hand: about 15 min of clicking, every build. The Decolla way: part of one tenant connect, then automatic.
Before you start
A dedicated 16 GB+ USB stick you are happy to wipe completely - not one holding files you want to keep.
A Windows 10/11 build PC where you can run as administrator, with roughly 30 GB free on C:.
Your Decolla cockpit sign-in, to download the client profile file the builder reads.
Broadband and 15-60 minutes' patience for the 6-8 GB Windows ISO download in your machines' language.
Step 1. USB stick: 16 GB minimum (the flat floor - the Windows media alone is ~5.5 GB plus your apps). ANY brand works. The ENTIRE stick is erased at build time - use a dedicated stick, not one holding files you care about. Sticks over 32 GB are fine: the boot partition is capped at ~30 GB (a Windows FAT32 limit) and the rest stays unused - that is normal, not a fault.
Screenshot: A plain USB stick next to the ERASE confirmation prompt. (captured during a live customer build — coming to this page)
Why: 16 GB is the flat floor because the Windows media alone is ~5.5 GB, and your apps go on top of that.
Watch for: Over 32 GB the boot partition stops at ~30 GB and the remainder sits empty - that is the FAT32 limit, not a duff stick.
Don’t: Do NOT use a stick holding anything you care about - the ENTIRE stick is erased at build time.
Step 2. Build PC: any Windows 10/11 machine where you can run as administrator (the builder self-elevates and asks). It needs roughly 30 GB free disk: the ISO (~6-8 GB), a working copy of the Windows image (~8 GB), the reusable image cache (~7 GB - this is what makes repeat builds fast), and optional updates (~1 GB).
Screenshot: Explorer showing free disk space on C:. (captured during a live customer build — coming to this page)
Why: The ~7 GB image cache is what makes repeat builds fast - service once, and every later stick is a copy of it.
Watch for: The 30 GB is working room, not the finished stick - the ISO, a working image copy and the cache all sit on C: at once.
Step 3. Download the Windows 11 ISO from microsoft.com/software-download/windows11 - and pick the LANGUAGE YOUR MACHINES SHOULD USE (38 languages are published: for the UK choose 'English (United Kingdom)', not plain 'English' which is US). The download is 6-8 GB - on typical broadband allow 15-60 minutes. This is the customer's own licensed Windows; Decolla never supplies it.
Screenshot: The Microsoft download page language dropdown. (captured during a live customer build — coming to this page)
Why: The language you download here becomes the machines' display language - it is set by the ISO, not fixed up afterwards.
Watch for: Plain 'English' is the US build; for UK display pick 'English (United Kingdom)' from the 38 published languages.
Don’t: Do NOT wait for Decolla to supply Windows - this is the customer's own licensed copy and you download it.
Step 4. Region, keyboard and timezone come from your Decolla profile automatically - the ISO language sets the DISPLAY language. Different country = download that country's language ISO; everything else is profile-driven.
Screenshot: The cockpit profile's country/language fields. (captured during a live customer build — coming to this page)
Why: Region, keyboard and timezone all come from your one Decolla profile, so the ISO language is the only per-country choice you make.
Don’t: Do NOT try to set region or timezone on the stick - they are profile-driven; a different country just means a different-language ISO.
Step 5. Time expectations - first build: roughly 35-90 minutes depending on the options you tick (stripping consumer apps and baking updates take longer). The console shows a running +elapsed clock on every line, and a full log is kept at %LOCALAPPDATA%\Decolla\logs.
Screenshot: Console lines with the +hh:mm:ss stamps. (captured during a live customer build — coming to this page)
Why: Every console line is stamped with +elapsed, so a slow stage looks different from a hung one - stamps still ticking means it is still working.
Watch for: Stripping consumer apps and baking in updates are the options that push a first build toward the 90-minute end.
Step 6. Every build AFTER the first with the same ISO + options: about 10-15 minutes - the prepared image is cached on your build PC and simply copied. Building five sticks for a rollout costs one preparation, not five.
Screenshot: The 'IMAGE CACHE HIT' console line. (captured during a live customer build — coming to this page)
Why: The prepared image is cached on the build PC, so a five-stick rollout costs one preparation, not five.
Watch for: The fast copy only holds while the inputs match - change the ISO or any option and that build services in full again.
Step 7. The target machine: must boot UEFI from USB (any business machine from the last ~8 years). Have its one-time boot menu key handy (commonly F12 Dell, F9 HP, F12 Lenovo). Plug an ETHERNET cable in for first boot where possible - no Wi-Fi prompts, and anything not baked in arrives without obstacles.
Screenshot: One-time boot menu with the USB entry highlighted. (captured during a live customer build — coming to this page)
Why: An ethernet cable at first boot means no Wi-Fi prompts, and anything not baked into the image arrives without obstacles.
Watch for: The boot-menu key is per-make - F12 on Dell and Lenovo, F9 on HP - so know the target's key before you power it on.
Step 8. Target machine install time: 20-40 minutes hands-off after you pick the USB in the boot menu. Then the first-logon name prompt appears (type the machine's printed-label name or keep the automatic serial-based one), and you sign in with the admin password you chose at build time.
Screenshot: The Decolla machine-name pop-up at first logon. (captured during a live customer build — coming to this page)
Why: You type the same admin password you set at build time - that is why step 9 tells you to keep it readable.
Watch for: The first-logon prompt is your moment to set the printed-label name; press through to keep the automatic serial-based one.
Step 9. Keep to hand: your Decolla profile file (downloaded from the cockpit), the admin password you set (you type it at the machine's login screen - keep it readable), and the machine's printed label if you name machines by sticker.
Screenshot: The builder's profile file-picker dialog. (captured during a live customer build — coming to this page)
Watch for: The printed label only matters if you name machines by sticker - otherwise the automatic serial name stands.
Don’t: Do NOT lock the admin password away where you cannot read it back - you type it by hand at the machine's login screen.
If it goes wrong
The failures people actually hit on this process, each with the diagnosis and fix:
Intune policies taking 8 hours? Check WNS first — Intune delivers policy changes in minutes via WNS; the 8-hour sync is only a safety net. If WNS is blocked at the firewall, here's how to fix it.