Do You Know the Difference Between Autopilot Deployment Modes in Intune ? (Self-Deploying and User-Driven)

When deploying Windows devices using Windows Autopilot, understanding the difference between Self-Deploying and User-Driven profiles is essential. Both deployment modes simplify provisioning and ensure consistent configuration , but they serve different use cases and behave very differently during setup.

Let’s break it down :

Windows Autopilot Deployment Modes : Full Comparison

CriteriaUser-Driven ModeSelf-Deploying Mode
Primary purposeDeploy devices for end users
(personal assigned devices)
Deploy devices without user interaction
(shared or kiosk devices)
User interactionRequired : user signs in during OOBENone : fully automatic deployment
Target device typeUser-assigned laptops & desktopsKiosks, shared PCs, POS, Teams Rooms, digital signage, IoT-like devices
AuthenticationUser authentication (Azure AD or Hybrid)Device-based authentication
Azure AD Join supportYesYes
Hybrid Azure AD Join supportYesNo
Intune enrollmentBased on the user who signs inDevice enrolls as a device object
(not linked to a user)
TPM requirementRecommended but not mandatoryTPM 2.0 required for hardware attestation
Minimum OS versionWindows 10 version 1809+Windows 10 version 1903+
OOBE experienceUser sees login screen, region selection, privacy settings, etc.OOBE screens are skipped automatically
Wi-Fi configurationSupported : user can enter Wi-Fi during setupNot supported : requires wired Ethernet
App & Policy assignmentUser-targeted policies and appsDevice-targeted policies and apps
BitLocker supportYesYes
Device namingCan use username-based variables (e.g., PC-%USERNAME%)Must use static or pattern-based naming (no user variable)
Assigned Access / Kiosk ModeNot designed for thisPrimary use case
Pre-Provisioning (White Glove)SupportedNot supported
Autopilot ResetYesYes
Network prerequisitesAny Internet connectionMust have Ethernet for deployment
Typical Use Cases– Employee onboarding
– Personal assigned devices
– Remote workers
– Kiosks- Lobby check-in PCs
– Conference room devices
– Shared terminals

Quick Summary

Key AspectUser-DrivenSelf-Deploying
Deployment TypeUser onboardingZero-touch automated setup
IdentityUser-basedDevice-based
Join TypeAzure AD / HybridAzure AD only
Best ForEmployees with assigned devicesShared devices / kiosks
Setup RequirementsUser sign-inTPM 2.0 + wired network

Thanks

Aymen EL JAZIRI (Microsoft MVP)
Aymen EL JAZIRI (Microsoft MVP)

Hi, I’m Aymen El Jaziri , a passionate System Administrator and Microsoft MVP, with years of hands-on experience in managing and securing modern IT infrastructures.
This blog is where I share technical guides, automation scripts, product reviews, and real-world solutions that help IT professionals simplify their day-to-day work and stay ahead in a fast-evolving cloud ecosystem.
Whether you’re here to troubleshoot an issue, improve your automation game, or learn new best practices , welcome in my blog !
Let’s build a stronger, smarter IT community together.
Feel free to connect with me on LinkedIn for more content, discussions, or collaboration opportunities.

Thanks

Aymen

Articles: 154