autopilot pre-provisioning timing out at the esp screen
Fixes Autopilot pre-provisioning that stalls or times out on the Enrollment Status Page. Covers reading the on-device diagnostics to find the hanging app or policy, tuning the ESP timeout, and moving problem apps out of the required path. Use when technicians watch the ESP spinner past the timeout during white-glove provisioning. Not for user-driven Autopilot failures after first sign-in.
TL;DR
The ESP blocks sign-in until every required item finishes, so one hanging app or policy poisons the whole run. Open the Autopilot diagnostics on the device to see exactly which step is stuck, then move that app out of the device-setup phase or fix its install. Re-run pre-provisioning and watch all three phases go green. Almost never a device problem; almost always one bad installer.
Steps
- On the stuck device, open the Autopilot diagnostics view from the ESP screen to see the three phases: device preparation, device setup, and account setup, with per-item status. Expected: one app or policy shows stuck while the clock runs past your timeout.
- Confirm which ESP profile applies: Intune admin center / Devices / Enrollment / Enrollment Status Page, and note the error timeout value. Expected: you know whether the timeout is the 60-minute default or a custom value.
- Find the hanging item: Intune admin center / Devices / the device / Managed apps shows which app is still installing. Reassign that app to install in user context, or remove it from the ESP-required list. Expected: the next run passes the phase that was hanging.
- Check the bench network: pre-provisioning needs sustained downloads, and captive portals or aggressive proxies stall them. Use wired connections for the provisioning bench. Expected: downloads complete without stalling.
- Wipe or reset the device from the diagnostics page and re-run pre-provisioning. Expected: green checkmarks through all three phases and the device ready for handoff.
Use this when
- Pre-provisioning (white glove) stalls on the ESP screen past the timeout
- The diagnostics page shows an app stuck installing during device setup
- Multiple devices hang at the same ESP phase after a policy change
Not for this skill when
- Autopilot fails during user-driven enrollment after first sign-in (different phase, different logs)
- The device never reaches the ESP screen at all (check Autopilot registration and network first)
- The hang is in account setup for one specific user (likely a user-targeted app, not the ESP profile)
Compatibility
- Windows 10 1903+ and Windows 11; Autopilot pre-provisioning flow
- Intune-managed ESP profiles
Variants
Hang in device preparation
That phase covers TPM attestation and device prep. Check the TPM is ready and the device is properly registered in Autopilot; re-register the hardware hash if needed.
Hangs only on the Wi-Fi bench
Some access points throttle or interrupt the long downloads. Move provisioning to wired and keep Wi-Fi as the fallback, not the primary path.
Why it happens
The ESP is a gate: it refuses to release the device until every required item reports success. Installers that wait on user input, need a reboot mid-phase, or download slowly in device context never report success, so the gate never opens. The fix is always to find the hanging item and take it out of the required path.
Edge cases
- Win32 apps that require user interaction hang forever in device context; repackage them silent or move them to user context.
- Raising the ESP timeout hides the problem instead of fixing it. Tune the timeout to your real provisioning time, then fix the hanging item.
- Log a ticket pattern when several devices hang on the same app after an app update; the app package changed, not your ESP profile.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst1lZbT9f6KxgjTpPKt2Zmw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.