Provision PCs with common settings for initial deployment (desktop wizard)
- Windows 10
This topic explains how to create and apply a provisioning package that contains common enterprise settings to a device running all desktop editions of Windows 10 except Windows 10 Home.
You can apply a provisioning package on a USB drive to off-the-shelf devices during setup, making it fast and easy to configure new devices.
You can configure new devices without reimaging.
Works on both mobile and desktop devices.
No network connectivity required.
Simple to apply.
What does the desktop wizard do?
The desktop wizard helps you configure the following settings in a provisioning package:
- Set device name
- Upgrade product edition
- Configure the device for shared use
- Remove pre-installed software
- Configure Wi-Fi network
- Enroll device in Active Directory or Azure Active Directory
- Create local administrator account
- Add applications and certificates
You must run Windows Configuration Designer on Windows 10 to configure Azure Active Directory enrollment using any of the wizards.
Provisioning packages can include management instructions and policies, installation of specific apps, customization of network connections and policies, and more.
Use the desktop wizard to create a package with the common settings, then switch to the advanced editor to add other settings, apps, policies, etc.
Create the provisioning package
Use the Windows Configuration Designer tool to create a provisioning package. Learn how to install Windows Configuration Designer.
Open Windows Configuration Designer (by default, %windir%\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Imaging and Configuration Designer\x86\ICD.exe).
Click Provision desktop devices.
Name your project and click Finish. The pages for desktop provisioning will walk you through the following steps.
When you build a provisioning package, you may include sensitive information in the project files and in the provisioning package (.ppkg) file. Although you have the option to encrypt the .ppkg file, project files are not encrypted. You should store the project files in a secure location and delete the project files when they are no longer needed.
Enter a name for the device.
(Optional) Select a license file to upgrade Windows 10 to a different edition. See the permitted upgrades.
Toggle Yes or No to Configure devices for shared use. This setting optimizes Windows 10 for shared use scenarios. Learn more about shared PC configuration.
You can also select to remove pre-installed software from the device.
Toggle On or Off for wireless network connectivity. If you select On, enter the SSID, the network type (Open or WPA2-Personal), and (if WPA2-Personal) the password for the wireless network.
Enable account management if you want to configure settings on this page.
You can enroll the device in Active Directory, enroll in Azure Active Directory, or create a local administrator account on the device
To enroll the device in Active Directory, enter the credentials for a least-privileged user account to join the device to the domain.
Before you use a Windows Configuration Designer wizard to configure bulk Azure AD enrollment, set up Azure AD join in your organization. The maximum number of devices per user setting in your Azure AD tenant determines how many times the bulk token that you get in the wizard can be used. To enroll the device in Azure AD, select that option and enter a friendly name for the bulk token you will get using the wizard. Set an expiration date for the token (maximum is 30 days from the date you get the token). Click Get bulk token. In the Let's get you signed in window, enter an account that has permissions to join a device to Azure AD, and then the password. Click Accept to give Windows Configuration Designer the necessary permissions.
To create a local administrator account, select that option and enter a user name and password.
Important: If you create a local account in the provisioning package, you must change the password using the Settings app every 42 days. If the password is not changed during that period, the account might be locked out and unable to sign in.
You can install multiple applications, both Windows desktop applications (Win32) and Universal Windows Platform (UWP) apps, in a provisioning package. The settings in this step vary according to the application that you select. For help with the settings, see Provision PCs with apps.
To provision the device with a certificate, click Add a certificate. Enter a name for the certificate, and then browse to and select the certificate to be used.
You can set a password to protect your provisioning package. You must enter this password when you apply the provisioning package to a device.
After you're done, click Create. It only takes a few seconds. When the package is built, the location where the package is stored is displayed as a hyperlink at the bottom of the page.
Next step: How to apply a provisioning package
Watch the video: Provisioning Windows 10 Devices with New Tools
Watch the video: Windows 10 for Mobile Devices: Provisioning Is Not Imaging
- Provisioning packages for Windows 10
- How provisioning works in Windows 10
- Install Windows Configuration Designer
- Create a provisioning package
- Apply a provisioning package
- Settings changed when you uninstall a provisioning package
- Use a script to install a desktop app in provisioning packages
- PowerShell cmdlets for provisioning Windows 10 (reference)
- NFC-based device provisioning
- Use the package splitter tool
- Windows Configuration Designer command-line interface (reference)
- Create a provisioning package with multivariant settings