IT

How to Pre-Configure Laptops for Remote Employees (Guide for IT Teams)

15 minutes read
blog

A new hire in another city, another time zone, or another country opens a box on their first morning. Nobody from IT is in the room. What happens next decides whether their first day feels like a welcome or a support ticket.

Pre-configuring a laptop means every decision about that machine is made before it ships. Enrollment, identity, security policy, apps and recovery settings are already assigned, so the employee only powers on and signs in. This guide shows IT teams how to build that process step by step, which enrollment method fits each operating system, and what to check before a box leaves the warehouse.

Key Takeaways

  • Pre-configuration moves setup from the employee’s desk to a repeatable pipeline: procure, register, assign a profile, stage, ship, sign in.
  • Use the platform’s native zero-touch path: Windows Autopilot or Autopilot device preparation, Apple Automated Device Enrollment, and Android zero-touch enrollment.
  • Build the laptop in seven layers, from hardware and OS up to recovery, and define one baseline per role instead of per person.
  • Test every profile on a pilot device before it reaches an employee, and keep a written pre-ship checklist.
  • Pre-configuration is one stage of the device lifecycle. Registering serials at purchase and retiring devices cleanly matter as much as the setup itself.

What does it mean to pre-configure a laptop?

To pre-configure a laptop is to finish its setup before the employee ever touches it. The device is registered to your organization, enrolled in your management platform on first boot, and delivered with the apps, security settings and access it needs for the role.

That sounds like old-fashioned imaging, but it works differently. Traditional imaging wipes a machine and installs a custom Windows or macOS build, which means someone has to handle the device physically. Modern pre-configuration keeps the manufacturer’s clean OS and lets your management service apply everything over the internet during first setup.

Microsoft describes this approach for Windows Autopilot device preparation. Instead of re-imaging the device, the existing Windows installation is transformed into a “business-ready” state, so IT does not have to maintain custom images and drivers for every model. Apple takes the same approach: Automated Device Enrollment lets organizations configure and manage devices from the moment someone removes them from the box.

Three terms are often used loosely:

  • Pre-configuration is the whole outcome: a device that is ready on arrival.
  • Zero-touch enrollment is the mechanism that connects a device to your management service automatically on first boot. For a deeper explanation of the difference, read our guide to zero-touch IT deployment for remote teams.
  • Staging is any work done before shipment, whether by your team, a reseller or a logistics partner.

The comparison above shows where the effort moves. In the manual flow, the laptop travels twice and relies on a video call to finish setup. In the pre-configured flow, the work happens in your management console and the device travels once.

Why pre-configuration matters for remote teams

Remote hiring removes the one thing manual setup depends on: being in the same room as the laptop. Three published numbers explain why the stakes are high.

  • First impressions are weak at most companies. Gallup finds that only 12% of employees strongly agree their organization does a great job onboarding new employees. A laptop that does not work on day one is one of the most visible parts of that experience.
  • Breaches are expensive. IBM’s Cost of a Data Breach Report 2025 puts the global average at $4.44 million. Devices that were never enrolled or never received the security baseline are an avoidable part of that exposure.
  • Unpatched software is now the leading way in. The 2026 Verizon Data Breach Investigations Report says 31% of breaches now start with software vulnerabilities, ahead of stolen passwords. A laptop enrolled on day one receives patch policy on day one.

Practical reasons IT teams invest here:

  1. Consistency. Every machine for a given role matches the baseline, so troubleshooting starts from a known state.
  2. Security from the first boot. Encryption, firewall and endpoint protection are applied before the employee installs anything.
  3. Fewer tickets. Questions like “which VPN do I use?” disappear when the VPN profile is already on the device.
  4. IT time returned. Nobody unboxes, installs and re-boxes. Most device onboarding problems trace back to inconsistent setup.

The 6-step pre-configuration pipeline

Think of pre-configuration as a pipeline, not a task. Every laptop passes the same six stages, which keeps the outcome independent of who is on shift.

  1. Procure from an authorized channel and capture serial numbers.
  2. Register those serials or hardware identifiers against your tenant.
  3. Assign a profile that maps enrollment, identity and policy to the role.
  4. Stage apps, encryption and the security baseline.
  5. Ship directly to the employee with tracking.
  6. Day one: the employee signs in and the device finishes configuring itself.

The rule of thumb: steps one to four finish before the box leaves the warehouse. The employee only performs step six. The sections below walk through each stage.

Step 1: Define the baseline by role

Before you touch any tool, decide what “ready” means. A baseline is the standard configuration every laptop in a role receives. Defining it per role, not per person, is what makes automation possible.

Start with three to five role groups:

  • General knowledge worker: office suite, browser, chat, SSO, VPN or ZTNA.
  • Engineering: the general set plus developer tooling, managed admin elevation and stricter patch rings.
  • Sales and support: CRM, telephony and shared mailbox access.
  • Finance and HR: the general set plus tighter data-loss controls.
  • Executives and contractors: distinct profiles, because their risk and access differ.

Matching the device to the role also affects spec and budget. Our guides on device refresh cycles by role and laptop total cost of ownership help you set both.

The 7-layer baseline stack

Build each role’s baseline in layers, from the bottom up. If a lower layer is wrong, everything above it is unreliable.

Layer 1: Hardware and OS. The serial number is registered to your organization, the OS build is current, firmware is up to date and an asset tag or record exists. This layer is where procurement and IT inventory connect.

Layer 2: Management. The device enrolls in your MDM or UEM at first boot, is supervised where the platform allows it, and receives a compliance policy. If you are choosing a platform, our comparison of MDM, UEM and EMM explains how the categories differ.

Layer 3: Identity. The employee signs in with a single sign-on account, enrolls in MFA, and works as a standard user. Admin rights are the exception, not the default. Microsoft’s own tooling reflects this: Autopilot device preparation makes sure users are standard non-administrator users by default.

Layer 4: Network access. Wi-Fi settings, a VPN or zero-trust network access profile, device certificates and DNS filtering are delivered as policy. Remote staff rarely sit on a managed office network, so this layer carries more weight than it does in an office fleet.

Layer 5: Security baseline. Full-disk encryption, a host firewall, an endpoint detection agent, automatic update rings and screen-lock timers. Treat this as non-negotiable and identical across roles, with exceptions documented.

Layer 6: Productivity apps. Role-based app sets and SaaS access, including license assignment. Install only what the role needs. For help tying software access to devices, see our guide to best IT onboarding software.

Layer 7: Recovery. Escrow recovery keys centrally, enable remote lock and wipe, and define how a device returns to a clean state if the employee leaves or the machine fails. Recovery is the layer most teams forget until they need it.

Practical tip: Write each baseline as a one-page, versioned document. Bump the version and date whenever a policy changes; audits get far easier.

Step 2: Choose the right enrollment method

Each major operating system has a native zero-touch path. Your fleet mix decides which you need, and many remote companies run two or three side by side.

Windows: Autopilot and Autopilot device preparation

Windows offers two related families. Classic Windows Autopilot has several scenarios. Microsoft’s scenario guide lists user-driven, pre-provisioned, self-deploying, existing devices and reset. The three that matter most for remote employees are:

  • User-driven mode. The device ships straight to the employee, who signs in and runs the full deployment. It needs no work from IT, a reseller or an OEM, and it works on physical devices and virtual machines. The tradeoff is that the user waits longer, because they go through both the device and user phases of setup.
  • Pre-provisioned mode. IT, a reseller or an OEM completes the device phase first. The employee then runs a much shorter user phase. Microsoft says this scenario minimizes the time the user interacts with the deployment. It requires TPM attestation, so it only works on physical devices with a supported TPM.
  • Self-deploying mode. Fully automated with no user sign-in, which suits kiosks and shared devices rather than personal remote laptops.

Microsoft also offers Windows Autopilot device preparation, a newer approach that uses a single profile and “enrollment time grouping.” Its stated goals are to be simple, fast, observable and reliable. Per Microsoft’s documentation, it supports Microsoft Entra join only and needs a supported Windows 11 build. If you are standing up a new cloud-native Windows fleet, evaluate it first.

One caution on identity. Microsoft recommends deploying new devices as cloud-native using Microsoft Entra join, and notes that hybrid join needs a connection to a domain controller. A remote employee without a VPN cannot reach one during setup, which is a strong reason to prefer Entra join for distributed teams.

Apple: Automated Device Enrollment

For Macs, iPhones and iPads, use Automated Device Enrollment (ADE) through Apple Business Manager. Apple documents that ADE automatically supervises devices, preventing users from removing the enrollment profile, and that you can skip specific Setup Assistant panes to streamline setup.

The requirements matter. Per Apple, devices must be purchased through Apple or authorized resellers, their serial numbers must be registered in Apple’s business portal, and a compatible management service must administer the enrollment settings. A Mac bought from a general retailer cannot be added to ADE in the same way, which is a procurement decision, not an IT one.

If you manage a Mac-heavy team, our guides to endpoint management for remote teams and best mobile device management platforms cover the tooling.

Android: zero-touch enrollment

For company-owned Android phones and tablets, Google’s zero-touch enrollment lets resellers register device identifiers (IMEI or serial numbers) to your account. Admins then assign each device an enterprise mobility configuration, individually or in bulk by CSV. You need Android 9.0 or later on most devices, Google Mobile Services compatibility and a supporting EMM.

A simple selection rule

If your situation is…Prefer…
Windows fleet, no IT touch available, employees can wait during setupAutopilot user-driven
Windows fleet, want the shortest wait for the employeeAutopilot pre-provisioned (reseller or IT does the technician flow)
New cloud-native Windows 11 fleetAutopilot device preparation
Mac, iPhone or iPadApple ADE with devices bought through Apple or an authorized reseller
Company-owned AndroidAndroid zero-touch enrollment

Step 3: Procure and register devices

Pre-configuration quietly fails at procurement. If a laptop is bought from the wrong source or its serial is never captured, the zero-touch path does not exist.

Make three habits non-negotiable:

  1. Buy through channels that can register devices for you. Windows Autopilot registration needs the device’s hardware hash uploaded to the service and associated to your tenant. Microsoft notes this is ideally done by the OEM, reseller or distributor the device was bought from. Apple and Google follow the same logic with their reseller programs.
  2. Capture serial numbers at purchase, not on arrival. The registration record and your asset record should be created from the same order.
  3. Standardize your catalog. Fewer models mean fewer drivers, fewer exceptions and fewer surprises. Our hardware procurement automation guide shows how to automate approvals, ordering and tracking.

For distributed companies, procurement is also a geography problem. Different countries have different import rules, vendors and delivery times. Zenadmin’s IT procurement covers ordering across regions, and our guide to international IT equipment delivery for global teams explains the logistics.

Watch out: Do not register devices as Autopilot devices if they are already Microsoft Entra registered or MDM-only enrolled. Microsoft’s registration guidance says those device types are meant for personally owned devices and should be removed first.

Step 4: Build, assign and test profiles

With the baseline defined and devices registered, translate the baseline into configuration your management platform can deploy.

Build profiles from the baseline

Create one enrollment profile per platform and role group. Each should contain:

  • The join type and enrollment settings (for example Entra join for Windows).
  • Skip rules for first-run screens you do not need.
  • Compliance policy: encryption required, OS minimum version, firewall on.
  • App assignments that install automatically.
  • Network profiles, certificates and any required configuration payloads.
  • Recovery key escrow and remote-wipe capability.

Use groups, not individual assignments. Microsoft’s enrollment time grouping puts a device into a pre-defined security group during enrollment so that applications, scripts and policies assigned to the group deploy quickly. The same principle works in any platform: assign by group, and membership does the work.

Keep the first-boot payload small

Do not stuff every app into the first boot. Install only what the person needs to sign in and start work (identity, security agent, VPN, browser, chat, mail) and push the rest afterward. Microsoft’s design reflects this: with device preparation, only apps and scripts selected in the profile are deployed during setup, and anything else assigned to the group installs afterward.

Test with a pilot ring

Never send a new profile straight to employees. Use a pilot ring:

  1. Ring 0: an IT-owned device, tested from a home network, not the office.
  2. Ring 1: two or three willing employees across different regions and operating systems.
  3. Ring 2: general availability.

Test a slow connection, captive-portal Wi-Fi, a failed MFA setup, a missing license and a mid-setup reboot. Fix every failure in the profile, not in a support doc.

Step 5: Ship to the employee

Shipping is where the pipeline meets the real world. Decide who stages the device and how it travels.

Who does the staging?

There are three practical options: direct ship (the vendor ships to the employee and everything configures at first boot), reseller or OEM staging (the vendor completes part of the setup first, such as the Windows technician phase), and central IT staging (a team or partner kits the device, then ships it). Zero-touch alone covers most remote hires.

Ship checklist

  • Tracking and a delivery window sent to the employee in advance.
  • An unboxing note that says what to do first: connect to Wi-Fi, choose the language, sign in with the work account.
  • Accessories such as a monitor, headset or security key included or shipped separately, with matching tracking.
  • Insurance and signature rules appropriate to the value of the device and the country.
  • Return label prepared for offboarding, because shipping a laptop back is part of the same process.

Delivery planning gets harder across borders. Customs, power adapters and keyboard layouts all change. Our guide to factors to consider when choosing an IT logistics partner is a good starting point.

Step 6: Design the first-boot experience

The employee’s first thirty minutes with the laptop is the only part they see. Design it deliberately.

Before the box arrives, send a short email with the steps, the expected time, a help link and a named contact. Say that a few restarts are normal.

During setup, avoid prompts that need decisions. Skip optional screens. Show progress where the platform allows. Microsoft’s device preparation shows a percentage progress indicator during user-driven setup, which reduces the urge to power-cycle the device.

After setup, confirm three things: the device shows as compliant, the employee can reach their core apps, and MFA works on a second factor. Then send a first-week note on requesting software, reporting problems and returning the device.

Support readiness. Put first-boot failures in your helpdesk runbook: stuck enrollment, wrong time zone, missing license. Our IT helpdesk automation guide shows how to reduce these tickets.

Common mistakes to avoid

  1. Registering devices after they arrive. Zero-touch needs the serial or hardware ID registered before first boot. Late registration turns an automated flow into a manual one.
  2. Buying outside authorized channels. For Apple ADE, a device from the wrong source cannot be enrolled automatically.
  3. Defaulting to hybrid join for remote staff. It needs domain controller access during setup, which remote users rarely have.
  4. One profile for everyone. A single mega-profile under-secures sensitive roles or over-restricts the rest.
  5. Overloading the first boot. Too many apps mean long waits and more failures.
  6. Skipping the pilot ring. A bad policy reaching every new hire at once floods the helpdesk.
  7. No recovery plan. Without escrowed keys and a reset path, a locked laptop in another country becomes a shipping problem.
  8. Security as a later step. Encryption and endpoint protection belong in the baseline. See IT security for remote teams.
  9. Forgetting offboarding. Microsoft says a device that permanently leaves the organization should always be deregistered from Autopilot, in the right order, to avoid orphaned records.

The pre-ship checklist

Use this list as the final gate. If any item is unchecked, the box does not ship.

Before you buy

  • Role and device spec agreed.
  • Authorized reseller confirmed.
  • Serials registered to your tenant.
  • Destination country checked for import and power requirements.

Before you ship

  • Profile and policies assigned.
  • Encryption and endpoint protection policy ready.
  • Apps mapped to the role.
  • Compliance policy tested on a pilot device.
  • Asset record created.

Day one

  • Tracking sent to the employee.
  • Setup guide and helpdesk link sent.
  • Sign-in and MFA confirmed.
  • Device shows as compliant.
  • Return process documented.

Beyond day one: the full device lifecycle

Pre-configuration is one stage of a longer cycle. A laptop that is perfectly staged but never tracked, patched or retrieved becomes a risk later. Treat the pipeline as the front half of the device lifecycle.

Connecting these stages closes the usual gaps: a serial in procurement but not inventory, an enrolled but untracked laptop, a returned device that is never wiped.

How Zenadmin supports this workflow

Zenadmin’s device lifecycle page describes pre-shipment staging at scale, with asset tagging and assignment, so devices arrive ready to use without on-site IT setup. The same platform covers multi-vendor procurement with approval workflows, a unified inventory across macOS, Windows, iOS, Android and ChromeOS, return logistics with pre-paid labels, and certified data erasure. One workflow removes the handoffs where mistakes occur.

If you want to see how this works for your fleet, you can book a demo with Zenadmin.

Conclusion

Pre-configuring laptops is not a tooling project. It is a decision to make setup a pipeline instead of a favor. Define a baseline per role, pick the native zero-touch path for each platform, register devices at purchase, test every profile on a pilot ring, and gate every shipment with a checklist. The employee opens the box, signs in and starts work. IT never leaves their desk.

Start small: pick one role and one platform, build the baseline, and run your next three hires through it. Then expand. If you would rather not build and maintain that chain yourself, talk to Zenadmin about running it from a single platform.

FAQ

What is the difference between pre-configuring and imaging a laptop?

Imaging wipes a device and installs a custom OS build, which needs someone to handle the machine physically. Pre-configuration keeps the manufacturer’s clean OS and applies settings, apps and policies over the internet through your management service. Microsoft describes its approach as transforming the existing installation into a business-ready state rather than re-imaging it.

Do I need an MDM to pre-configure laptops?

Yes, in practice. Zero-touch enrollment connects a device to a management service automatically. Without MDM or UEM, there is nothing to assign policies, apps or compliance rules, so you would be back to manual setup.

How long does it take to set up a laptop with zero-touch enrollment?

It depends on the platform, the first-boot payload and the employee’s connection. Pre-provisioned Windows deployments shorten the wait because IT or a reseller completes the device phase in advance, and keeping first-boot apps minimal helps most.

Can I pre-configure laptops bought from a regular retailer?

For Apple devices, no. Apple requires purchase through Apple or authorized resellers for Automated Device Enrollment. For Windows, devices not registered by a vendor can still be registered by uploading hardware hashes manually, but this takes extra work. It is far easier to buy through channels that register devices for you.

Should remote employees’ laptops be Entra joined or hybrid joined?

For new devices, Microsoft recommends cloud-native Microsoft Entra join and does not recommend hybrid join for new deployments. Hybrid join needs a connection to a domain controller during setup, which remote workers often lack unless a VPN is available at that point.

How do I handle laptops for employees in other countries?

Use a vendor or platform that can source and deliver locally, capture serial numbers at purchase, and register them before shipping. Check import rules, power plugs and keyboard layouts for each country. Our guide to international IT equipment delivery covers the details.

What should I do when a remote employee leaves?

Retrieve the device, wipe it, and either redeploy or dispose of it. For Windows Autopilot devices, deregister the device from Intune and Autopilot in the correct order so no orphaned records remain. Plan the return label and process before the laptop ships.

blog

Want results like this?

See how ZenAdmin would run device lifecycle for your team

Tell us your fleet and workforce and we’ll show how the same lifecycle setup would work for you.

  • See how procurement, leasing and ITAM were set up in this story
  • Map it to your fleet size, locations and remote team
  • Get a clear plan for retrieval and refresh cycles

No commitment. No sales pressure.

Get my tailored demo

user-icon
mail-icon
building-icon
users-icon
Number of employees