## TL;DR
Open the Enrollment Status Page details to see exactly which app or policy is stuck, then fix that item (usually a failing Win32 app install or a network timeout). Do not reboot mid-enrollment unless the ESP itself is frozen; most stalls resolve by fixing the blocking app.

## The error
```text
Device setup: please wait while we set up your device. (Hangs for 30+ minutes.)
```

## Steps
1. Click "show details" on the ESP screen to see per-item status. Expected: the stuck item is named (an app, a policy, or "identifying"). This turns a mystery hang into a specific failure.
2. If an app is stuck installing: check the Intune app install status for that device. Expected: error code. Common causes are bad detection rules or installer flags.
3. Check network: the device needs stable internet for app downloads. Expected: connected. Captive portals and proxies break ESP silently.
4. If the ESP is completely frozen (no progress for 60+ minutes), reboot once and let it resume. Expected: resumes from the last completed step. ESP is resumable; a single reboot is safe.
5. Fix the blocking item (correct the app package, fix the detection rule, or exclude the device from the bad policy), then let ESP complete. Expected: enrollment finishes.

## When to use
- Autopilot stalls during device setup
- ESP shows a stuck app or policy

## When not to use
- Device never reaches OOBE/Autopilot (registration issue)
- User-driven sign-in failures

## Compatibility
- Windows 10/11 Autopilot with Enrollment Status Page enabled

## Variants
### Stuck at "account setup" instead
User-phase issue; check user-targeted apps and policies.
### White glove pre-provisioning stalls
Same diagnosis; the technician sees the same ESP.

## Why it happens
ESP waits for every targeted app and policy before releasing the device. One broken app package holds the entire enrollment hostage, which is why the fix is always "find the blocking item".

## Edge cases
- Set ESP timeouts so a broken app fails the enrollment instead of hanging forever; then fix the app.
- Keep a known-good test device to validate app packages before wide deployment.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_nxLptgJmA1NhsLs8A8Vkkw
