Home › What's new
What's new

Proven end-to-end — a whole machine, from one USB

Built on real hardware. Our provisioning USB now takes a bare laptop all the way to a finished, hardened, correctly-named Windows machine with its managed admin account ready — proven end to end on real hardware.

A black box on every stick. Every provisioning USB now carries a one-touch diagnostic: if a build ever hiccups, a single click captures everything support needs — no commands, no guesswork.

Coming next (in design): machines that enrol themselves into Intune and Autopilot on first boot — they just appear in your portal, managed.

The offline provisioning engine

Provisioning USB. Build a bootable stick from your own licensed Windows install file (16 GB+ USB) that installs Windows unattended, applies your Decolla profile — device name, timezone, hardening, managed local admin — and installs your apps offline. No internet needed on the target machine.

Any language, natively. Use the Windows install file for your country (Windows 11 ships in 38 languages) for a native-language build with zero prompts. A language-pack store can slipstream a language into the image as a fallback, with every file size-verified before use.

Offline image servicing. Optionally bake the latest Windows update into the image, inject a per-model driver pack (boot-critical storage and network drivers included, so Setup can see the disk on unusual hardware), and strip consumer apps with a guarded blocklist — the Store, security and enrolment components are hard-protected, and removals survive Windows feature updates. Every servicing pass is verified before it's committed; a failed pass is discarded, never shipped.

Image cache. The serviced image is cached locally after the first build. Repeat sticks with the same settings are a pure copy — roughly 10–15 minutes. Your licensed Windows never leaves your machine.

Double-click GUI builder. No command line: file-picker pop-ups for the Windows file and your client profile (it remembers the last one), two yes/no choices (bake updates / strip consumer apps), a readable suggested admin password, and a "USB READY" pop-up with the login when it's done.

Standalone and Autopilot-prep modes. Pick per profile in the cockpit's "USB / offline build" card. Standalone skips the Windows welcome screens and finishes at a known admin login, with automatic disk encryption held off (an offline machine has nowhere to escrow a recovery key). Autopilot-prep keeps the sign-in screens so the device joins Entra and enrols into Intune/Autopilot, which then own naming, admin and encryption.

Guarded throughout. The builder auto-detects the USB, shows you the exact disk and its contents, and only proceeds when you type ERASE plus that disk number — anything else aborts untouched. Builds are verify-gated end to end, and each build writes a full log with per-step elapsed times. At first sign-in on a standalone machine, a rename prompt lets you apply your own printed-label device name on the spot.

Full walkthrough: the Build a Decolla provisioning USB guide at decolla.app/guides.

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access