Proven end-to-end — a whole machine, from one USB
Built on real hardware. Our provisioning USB now takes a bare laptop all the way to a finished, hardened, correctly-named Windows machine with its managed admin account ready — proven end to end on real hardware.
A black box on every stick. Every provisioning USB now carries a one-touch diagnostic: if a build ever hiccups, a single click captures everything support needs — no commands, no guesswork.
Coming next (in design): machines that enrol themselves into Intune and Autopilot on first boot — they just appear in your portal, managed.
The offline provisioning engine
Provisioning USB. Build a bootable stick from your own licensed Windows install file (16 GB+ USB) that installs Windows unattended, applies your Decolla profile — device name, timezone, hardening, managed local admin — and installs your apps offline. No internet needed on the target machine.
Any language, natively. Use the Windows install file for your country (Windows 11 ships in 38 languages) for a native-language build with zero prompts. A language-pack store can slipstream a language into the image as a fallback, with every file size-verified before use.
Offline image servicing. Optionally bake the latest Windows update into the image, inject a per-model driver pack (boot-critical storage and network drivers included, so Setup can see the disk on unusual hardware), and strip consumer apps with a guarded blocklist — the Store, security and enrolment components are hard-protected, and removals survive Windows feature updates. Every servicing pass is verified before it's committed; a failed pass is discarded, never shipped.
Image cache. The serviced image is cached locally after the first build. Repeat sticks with the same settings are a pure copy — roughly 10–15 minutes. Your licensed Windows never leaves your machine.
Double-click GUI builder. No command line: file-picker pop-ups for the Windows file and your client profile (it remembers the last one), two yes/no choices (bake updates / strip consumer apps), a readable suggested admin password, and a "USB READY" pop-up with the login when it's done.
Standalone and Autopilot-prep modes. Pick per profile in the cockpit's "USB / offline build" card. Standalone skips the Windows welcome screens and finishes at a known admin login, with automatic disk encryption held off (an offline machine has nowhere to escrow a recovery key). Autopilot-prep keeps the sign-in screens so the device joins Entra and enrols into Intune/Autopilot, which then own naming, admin and encryption.
Guarded throughout. The builder auto-detects the USB, shows you the exact disk and its contents, and only proceeds when you type ERASE plus that disk number — anything else aborts untouched. Builds are verify-gated end to end, and each build writes a full log with per-step elapsed times. At first sign-in on a standalone machine, a rename prompt lets you apply your own printed-label device name on the spot.
Full walkthrough: the Build a Decolla provisioning USB guide at decolla.app/guides.
See it on a real device.
Decolla is in private build — early-access members see a build defined, deployed and rolled back first.
Get early access