This page will go through the steps of enrolling a device into Endpoint Manager and Autopilot.
You must bind the device being enrolled to the on prem AD Domain
Adding a Device record to Group Membership in Azure Active Directory
To access Azure Active Directory you can chose the Admin Tile within Office 365 or follow this LINK. After clicking on the link you will need to select Azure Active Directory.
To get to the main options for Azure AD click the Azure Active Directory on the left panel
First, let’s make sure that the device is in Azure AD after being bound to the on prem AD domain
Under the Manage selections chose “Devices”
Search for the computer name of the device we want to enroll
Click on “Azure Active Directory” on the left to go back to the original set of options
Select “Groups” from the panel to the right.
Search for the ManualAutoPilot group
Click on the ManualAutoPilot group to open up the options for that group
We want to add the device that is enrolling to this group so you will select “Members”
After selecting “Members” you should click the “+ Add Members”
Search for the computer name or Azure ID of the device you want to add to the group
Click on the device and then click on the blue “Select” button
You are ready to reset the device.
Reset the Device using Windows 10 Reset Options
Clicking the start button you can search Reset this PC.
Under Reset this PC, click Get started.
Follow the instructions on the screen.
You will want to “Remove Everything”
Chose Local Reinstall when applicable
Enrollment - First Login To Assigned User
You do not need to assign the user account to any special group anymore
The user assigned to the device should be the first to login to the device
After the device resets you will be at an Out Of Box Experience (OOBE). Select the following options:
Yes - United Stations (Region)
Yes - US (Keyboard Layout)
Skip - Skips the setup for a second keyboard layout
Accept - Accepts the Win 10 license
You should see one of the following screens:
For the first picture you will select “Set up for an organization”.
The Assigned User will login with their @co.ssd.k12.mo.us user account.
When you select "Next" it should go to the SSD Organizational sign in page
The Assigned User will put in their SSD Password.
The next screen should look like this:
Device Setup will begin. The page with the three stages is called the "Enrollment Status Page"
Device Preparation - Hardware Checks, Network Check, Registering with Endpoint Manager, Joining Azure AD
Device Setup - Computer/Computer Group based security, certificate and application installs/setup
A restart of the device may take place after this step
There's a Privacy Setting screen that may appear next. Select "Accept"
In some cases the system will present a generic Win 10 login screen
The Assigned User will need to sign in with their @co.ssd.k12.mo.us account again
User Setup - User/User Group based security, certificate and application installs/setup
You should see a "Continue anyway" button at the bottom right of the screen. The User may select this to go into Windows 10.
If this is selected there's still setup taking place that may cause the system to restart.
The device will log into Windows 10 after completion if you did not chose the "Continue Anyway" button.
There are some cases where a User may need to "Sign Out" and "Sign Back In" this is a normal operation linked to Credential Manager adding user authentication information.
Changing the Name of the Device
You will be working within Endpoint Manager. You can access Endpoint Manager through the Admin Tile in Office 365 or through this LINK.
Once you’re in Endpoint Manager you will select “Devices”
Select “Windows” as the platform
Search for the device by its serial number. In most cases (as of July 2021) it’ll show up as Desktop-RANDOMSTUFF
Select the device you’re working on. You should see a screen with the following information
To change the name select the three “…”'s to find a “Rename Device” selection
A new pane will open and you can type in SSD-SERIALNUMBER
Select “Yes” for restart after if you are with the system otherwise leave this option as “no”
If everything worked correctly you should see a Restart and Rename “Complete” Status in the device record
Add Device record to Autopilot via the ManualAutoPilot Group
Only add the Device record when the name change has completed and Azure Active Directory and Endpoint Manager displays the correct name. If either name is wrong then sync has not completed between the two and the Autopilot profile will not work correctly
Checking accuracy in Endpoint Manager - Under Devices → Windows you can search for the serial number of the device and see if the name is SSD-SERIALNUMBER
Checking accuracy in Azure Active Directory - Under Devices you can search for SSD-SERIALNUMBER. Because we are a Hybrid AD setup you should see two records that match.
If you see more than two you will need to stop and figure out where the rogue records came from.
If you only see one record then the device’s name update has not sync’d with Azure.
You will want to add the Endpoint Manager system to the ManualAutopilot group