Autopilot is the polished route into Intune, but it needs hardware hashes uploaded in advance and a network path to the Autopilot service during OOBE. When you inherit a batch of existing Windows 11 machines, refurbish laptops, or need to enroll devices in a lab without touching each user account, a provisioning package (.ppkg) with a bulk enrollment token gets the job done in one step. This guide covers Windows 11 24H2, 25H2 and 26H1 and Intune tenants with the MDM authority set.
Table of Contents
Short answer: Install Windows Configuration Designer, create a “Provision desktop devices” project, sign in under “Enrol in Azure AD” to fetch a bulk token that is valid for up to 180 days, export the .ppkg, and apply it during OOBE by inserting a USB stick or afterwards through Settings » Accounts » Access work or school » Add or remove a provisioning package. Each device joins Entra ID as the package_<GUID> bulk account and enrolls in Intune automatically.
Prerequisites
- An Intune licence and the MDM user scope set so the bulk account can enroll (Entra ID » Mobility » Microsoft Intune » MDM user scope).
- The account creating the token needs to be able to join devices; check Entra ID » Devices » Device settings » “Users may join devices to Microsoft Entra”.
- Enrollment restrictions that allow Windows MDM and the enrollment device limit must accommodate a single bulk account joining many devices. Bulk tokens use a special account of the form package_<GUID>@tenant.onmicrosoft.com, and Intune exempts it from the per-user limit, but the Entra ID “Maximum number of devices per user” setting still applies. Set it to Unlimited for that account or use multiple packages.
- Windows Configuration Designer from the Microsoft Store on a Windows 11 workstation.
Build the package
Open Windows Configuration Designer and choose “Provision desktop devices”. Give the project a name, then work through the wizard:
- Set up device: device name pattern such as
LAB-%SERIAL%, and optionally the product key and “Remove pre-installed software”. - Set up network: leave off for wired deployments, or add a Wi-Fi profile.
- Account management: choose “Enrol in Azure AD”, set the token expiry (maximum 180 days), and click “Get bulk token”. Sign in with an account that has the right to create the token. The status turns to “Bulk Token Fetched Successfully”.
- Add applications and certificates: optional; most teams leave app deployment to Intune.
- Finish: choose whether to encrypt the package. Unencrypted packages contain the bulk token in the clear, so encrypt them for anything leaving the building.
Click Create. The .ppkg lands in the project folder together with a .cat file.
Advanced editor users can also confirm the token under Runtime settings » Accounts » Azure » BPRT, and set Runtime settings » Policies » ApplicationManagement or DeviceLock values in the same package if you want baseline hardening before Intune policies arrive.
Apply during OOBE
Copy the .ppkg to the root of a USB stick. Boot the device to the first OOBE screen (region selection) and insert the stick; Windows detects the package and offers “Set up device?” with the package name. Accept it, and the device joins Entra ID, enrolls in Intune and lands at the sign-in screen. If the prompt does not appear, press the Windows key five times to trigger detection.
Apply on an existing installation
On a running Windows 11 machine that is not domain joined, either double-click the .ppkg or use PowerShell:
Install-ProvisioningPackage -PackagePath "C:\ppkg\LabEnroll.ppkg" -ForceInstall -QuietInstall
Get-ProvisioningPackage
To script it silently across many devices, run the command from an elevated context; the enrollment happens in the background and the machine may prompt for a restart.
Verify enrollment
On the device:
dsregcmd /status
Get-ProvisioningPackage | Format-List PackageName, PackageId, IsInstalled
AzureAdJoined should read YES and the MDM enrollment URL should be populated. In Intune » Devices » All devices the machine appears with “Enrolled by” showing the package_ account. Assign policies by device group rather than user group for these devices, because the primary user is the bulk account, not a person.
Common pitfall
The token expires on the date chosen in the wizard, and after that every device applying the package fails with 0x801c03ea or 0x80180014. The fix is to reopen the project, fetch a new token and rebuild the package; there is no way to extend an existing one. Keep the expiry date in your change calendar. The other frequent issue is a device that was previously enrolled under the same serial: retire the old Intune object first, as described in Fix Windows Autopilot enrollment errors 80180003 and 80180014.
Rotate packages every six months, delete the bulk account’s stale device objects from Entra ID quarterly, and store the encrypted .ppkg with the password in your team’s secret store rather than on a shared drive.
Intune bulk enrollment at a glance

Official documentation: Microsoft Intune documentation, Windows client documentation, Windows Server documentation.
Related guides: Fix Windows Autopilot enrollment errors 80180003 and 80180014 · Deploy Win32 apps with Intune: IntuneWinAppUtil packaging and detection rules · Change a domain controller’s IP address without breaking replication.
Frequently asked questions
Does bulk enrollment also work for Windows 10 or Windows Server?
Windows 10 Pro, Enterprise and Education accept the same package. Windows Server does not support Entra ID join through a provisioning package, so servers need Azure Arc or a different management route.
How long does the bulk token remain valid?
The wizard allows up to 180 days from the moment the token is fetched. Devices already enrolled stay enrolled after expiry; only new applications of the package fail.
Can I remove a provisioning package after enrollment?
Yes, Remove-ProvisioningPackage -PackageId <GUID> or Settings » Accounts » Access work or school » Add or remove a provisioning package removes it, but that does not unenroll the device. To leave Intune, disconnect the work account or retire the device from the Intune portal.