Skip to content
Browse all topics

What should be in the Windows Autopilot must-install app list?

Keep the must-install (ESP-blocking) list to only what genuinely has to be on the device before the user starts working — most Autopilot complaints about slow provisioning or stalled Enrollment Status Pages trace back to an oversized must-install list, not a problem with Autopilot itself. Everything else should be assigned separately so it installs quietly in the background after the user is already at their desktop.

What belongs on the blocking list

  • Security baselines and compliance policies the device needs before it's considered managed.
  • The one or two apps a user cannot start their first session without.

What doesn't

  • Line-of-business apps with driver dependencies that can install after first sign-in.
  • Anything with a slow or unreliable install — a single flaky app in the blocking list can stall every device in a rollout.

Read next

  • Intune Windows AutopilotWindows Autopilot provisions new PCs straight to the end user with zero IT touch. Here's how it works.
  • Microsoft Intune and device managementMicrosoft Intune explained: what it manages, how policies work, how enrollment and compliance fit together, and where it sits in Microsoft 365.

Other questions