A new hire in another city, another time zone, or another country opens a box on their first morning. Nobody from IT is in the room. What happens next decides whether their first day feels like a welcome or a support ticket.
Pre-configuring a laptop means every decision about that machine is made before it ships. Enrollment, identity, security policy, apps and recovery settings are already assigned, so the employee only powers on and signs in. This guide shows IT teams how to build that process step by step, which enrollment method fits each operating system, and what to check before a box leaves the warehouse.
Key Takeaways
To pre-configure a laptop is to finish its setup before the employee ever touches it. The device is registered to your organization, enrolled in your management platform on first boot, and delivered with the apps, security settings and access it needs for the role.
That sounds like old-fashioned imaging, but it works differently. Traditional imaging wipes a machine and installs a custom Windows or macOS build, which means someone has to handle the device physically. Modern pre-configuration keeps the manufacturer’s clean OS and lets your management service apply everything over the internet during first setup.
Microsoft describes this approach for Windows Autopilot device preparation. Instead of re-imaging the device, the existing Windows installation is transformed into a “business-ready” state, so IT does not have to maintain custom images and drivers for every model. Apple takes the same approach: Automated Device Enrollment lets organizations configure and manage devices from the moment someone removes them from the box.
Three terms are often used loosely:

The comparison above shows where the effort moves. In the manual flow, the laptop travels twice and relies on a video call to finish setup. In the pre-configured flow, the work happens in your management console and the device travels once.
Remote hiring removes the one thing manual setup depends on: being in the same room as the laptop. Three published numbers explain why the stakes are high.

Practical reasons IT teams invest here:
Think of pre-configuration as a pipeline, not a task. Every laptop passes the same six stages, which keeps the outcome independent of who is on shift.
The rule of thumb: steps one to four finish before the box leaves the warehouse. The employee only performs step six. The sections below walk through each stage.

Before you touch any tool, decide what “ready” means. A baseline is the standard configuration every laptop in a role receives. Defining it per role, not per person, is what makes automation possible.
Start with three to five role groups:
Matching the device to the role also affects spec and budget. Our guides on device refresh cycles by role and laptop total cost of ownership help you set both.
Build each role’s baseline in layers, from the bottom up. If a lower layer is wrong, everything above it is unreliable.

Layer 1: Hardware and OS. The serial number is registered to your organization, the OS build is current, firmware is up to date and an asset tag or record exists. This layer is where procurement and IT inventory connect.
Layer 2: Management. The device enrolls in your MDM or UEM at first boot, is supervised where the platform allows it, and receives a compliance policy. If you are choosing a platform, our comparison of MDM, UEM and EMM explains how the categories differ.
Layer 3: Identity. The employee signs in with a single sign-on account, enrolls in MFA, and works as a standard user. Admin rights are the exception, not the default. Microsoft’s own tooling reflects this: Autopilot device preparation makes sure users are standard non-administrator users by default.
Layer 4: Network access. Wi-Fi settings, a VPN or zero-trust network access profile, device certificates and DNS filtering are delivered as policy. Remote staff rarely sit on a managed office network, so this layer carries more weight than it does in an office fleet.
Layer 5: Security baseline. Full-disk encryption, a host firewall, an endpoint detection agent, automatic update rings and screen-lock timers. Treat this as non-negotiable and identical across roles, with exceptions documented.
Layer 6: Productivity apps. Role-based app sets and SaaS access, including license assignment. Install only what the role needs. For help tying software access to devices, see our guide to best IT onboarding software.
Layer 7: Recovery. Escrow recovery keys centrally, enable remote lock and wipe, and define how a device returns to a clean state if the employee leaves or the machine fails. Recovery is the layer most teams forget until they need it.
Practical tip: Write each baseline as a one-page, versioned document. Bump the version and date whenever a policy changes; audits get far easier.
Each major operating system has a native zero-touch path. Your fleet mix decides which you need, and many remote companies run two or three side by side.

Windows offers two related families. Classic Windows Autopilot has several scenarios. Microsoft’s scenario guide lists user-driven, pre-provisioned, self-deploying, existing devices and reset. The three that matter most for remote employees are:
Microsoft also offers Windows Autopilot device preparation, a newer approach that uses a single profile and “enrollment time grouping.” Its stated goals are to be simple, fast, observable and reliable. Per Microsoft’s documentation, it supports Microsoft Entra join only and needs a supported Windows 11 build. If you are standing up a new cloud-native Windows fleet, evaluate it first.
One caution on identity. Microsoft recommends deploying new devices as cloud-native using Microsoft Entra join, and notes that hybrid join needs a connection to a domain controller. A remote employee without a VPN cannot reach one during setup, which is a strong reason to prefer Entra join for distributed teams.
For Macs, iPhones and iPads, use Automated Device Enrollment (ADE) through Apple Business Manager. Apple documents that ADE automatically supervises devices, preventing users from removing the enrollment profile, and that you can skip specific Setup Assistant panes to streamline setup.
The requirements matter. Per Apple, devices must be purchased through Apple or authorized resellers, their serial numbers must be registered in Apple’s business portal, and a compatible management service must administer the enrollment settings. A Mac bought from a general retailer cannot be added to ADE in the same way, which is a procurement decision, not an IT one.
If you manage a Mac-heavy team, our guides to endpoint management for remote teams and best mobile device management platforms cover the tooling.
For company-owned Android phones and tablets, Google’s zero-touch enrollment lets resellers register device identifiers (IMEI or serial numbers) to your account. Admins then assign each device an enterprise mobility configuration, individually or in bulk by CSV. You need Android 9.0 or later on most devices, Google Mobile Services compatibility and a supporting EMM.
| If your situation is… | Prefer… |
| Windows fleet, no IT touch available, employees can wait during setup | Autopilot user-driven |
| Windows fleet, want the shortest wait for the employee | Autopilot pre-provisioned (reseller or IT does the technician flow) |
| New cloud-native Windows 11 fleet | Autopilot device preparation |
| Mac, iPhone or iPad | Apple ADE with devices bought through Apple or an authorized reseller |
| Company-owned Android | Android zero-touch enrollment |
Pre-configuration quietly fails at procurement. If a laptop is bought from the wrong source or its serial is never captured, the zero-touch path does not exist.
Make three habits non-negotiable:
For distributed companies, procurement is also a geography problem. Different countries have different import rules, vendors and delivery times. Zenadmin’s IT procurement covers ordering across regions, and our guide to international IT equipment delivery for global teams explains the logistics.
Watch out: Do not register devices as Autopilot devices if they are already Microsoft Entra registered or MDM-only enrolled. Microsoft’s registration guidance says those device types are meant for personally owned devices and should be removed first.
With the baseline defined and devices registered, translate the baseline into configuration your management platform can deploy.
Create one enrollment profile per platform and role group. Each should contain:
Use groups, not individual assignments. Microsoft’s enrollment time grouping puts a device into a pre-defined security group during enrollment so that applications, scripts and policies assigned to the group deploy quickly. The same principle works in any platform: assign by group, and membership does the work.
Do not stuff every app into the first boot. Install only what the person needs to sign in and start work (identity, security agent, VPN, browser, chat, mail) and push the rest afterward. Microsoft’s design reflects this: with device preparation, only apps and scripts selected in the profile are deployed during setup, and anything else assigned to the group installs afterward.
Never send a new profile straight to employees. Use a pilot ring:
Test a slow connection, captive-portal Wi-Fi, a failed MFA setup, a missing license and a mid-setup reboot. Fix every failure in the profile, not in a support doc.
Shipping is where the pipeline meets the real world. Decide who stages the device and how it travels.
There are three practical options: direct ship (the vendor ships to the employee and everything configures at first boot), reseller or OEM staging (the vendor completes part of the setup first, such as the Windows technician phase), and central IT staging (a team or partner kits the device, then ships it). Zero-touch alone covers most remote hires.
Delivery planning gets harder across borders. Customs, power adapters and keyboard layouts all change. Our guide to factors to consider when choosing an IT logistics partner is a good starting point.
The employee’s first thirty minutes with the laptop is the only part they see. Design it deliberately.
Before the box arrives, send a short email with the steps, the expected time, a help link and a named contact. Say that a few restarts are normal.
During setup, avoid prompts that need decisions. Skip optional screens. Show progress where the platform allows. Microsoft’s device preparation shows a percentage progress indicator during user-driven setup, which reduces the urge to power-cycle the device.
After setup, confirm three things: the device shows as compliant, the employee can reach their core apps, and MFA works on a second factor. Then send a first-week note on requesting software, reporting problems and returning the device.
Support readiness. Put first-boot failures in your helpdesk runbook: stuck enrollment, wrong time zone, missing license. Our IT helpdesk automation guide shows how to reduce these tickets.
Use this list as the final gate. If any item is unchecked, the box does not ship.

Before you buy
Before you ship
Day one
Pre-configuration is one stage of a longer cycle. A laptop that is perfectly staged but never tracked, patched or retrieved becomes a risk later. Treat the pipeline as the front half of the device lifecycle.

Connecting these stages closes the usual gaps: a serial in procurement but not inventory, an enrolled but untracked laptop, a returned device that is never wiped.
Zenadmin’s device lifecycle page describes pre-shipment staging at scale, with asset tagging and assignment, so devices arrive ready to use without on-site IT setup. The same platform covers multi-vendor procurement with approval workflows, a unified inventory across macOS, Windows, iOS, Android and ChromeOS, return logistics with pre-paid labels, and certified data erasure. One workflow removes the handoffs where mistakes occur.
If you want to see how this works for your fleet, you can book a demo with Zenadmin.
Pre-configuring laptops is not a tooling project. It is a decision to make setup a pipeline instead of a favor. Define a baseline per role, pick the native zero-touch path for each platform, register devices at purchase, test every profile on a pilot ring, and gate every shipment with a checklist. The employee opens the box, signs in and starts work. IT never leaves their desk.
Start small: pick one role and one platform, build the baseline, and run your next three hires through it. Then expand. If you would rather not build and maintain that chain yourself, talk to Zenadmin about running it from a single platform.
Imaging wipes a device and installs a custom OS build, which needs someone to handle the machine physically. Pre-configuration keeps the manufacturer’s clean OS and applies settings, apps and policies over the internet through your management service. Microsoft describes its approach as transforming the existing installation into a business-ready state rather than re-imaging it.
Yes, in practice. Zero-touch enrollment connects a device to a management service automatically. Without MDM or UEM, there is nothing to assign policies, apps or compliance rules, so you would be back to manual setup.
It depends on the platform, the first-boot payload and the employee’s connection. Pre-provisioned Windows deployments shorten the wait because IT or a reseller completes the device phase in advance, and keeping first-boot apps minimal helps most.
For Apple devices, no. Apple requires purchase through Apple or authorized resellers for Automated Device Enrollment. For Windows, devices not registered by a vendor can still be registered by uploading hardware hashes manually, but this takes extra work. It is far easier to buy through channels that register devices for you.
For new devices, Microsoft recommends cloud-native Microsoft Entra join and does not recommend hybrid join for new deployments. Hybrid join needs a connection to a domain controller during setup, which remote workers often lack unless a VPN is available at that point.
Use a vendor or platform that can source and deliver locally, capture serial numbers at purchase, and register them before shipping. Check import rules, power plugs and keyboard layouts for each country. Our guide to international IT equipment delivery covers the details.
Retrieve the device, wipe it, and either redeploy or dispose of it. For Windows Autopilot devices, deregister the device from Intune and Autopilot in the correct order so no orphaned records remain. Plan the return label and process before the laptop ships.