Provisioning computers
From a bare computer to a managed endpoint: what to prepare, how to start a job, what it does, how to follow it.
Provisioning installs Windows on a computer that has nothing usable on it — new, or to be reinstalled — and hands it over as a managed endpoint: named, joined to your directory, with its drivers, its software and its Windows updates. The computer needs a network cable and the IdolBe USB media; nobody types anything on it.
Before the first computer
Prepare these once, in this order.
| What | Where | Notes |
|---|---|---|
| A Windows image | Provisioning → Images | The ISO or the install.wim of the Windows you install. The upload resumes if it stops; the image is verified before it can be used. |
| Driver packs | Configuration → Driver Packs | Optional. The vendor's pack for a model (.cab), or a .zip of its .inf folders. |
| Hardware profiles | Provisioning → Hardware profiles | Optional. Says which packs a model gets. A model without a profile installs with the drivers Windows carries. |
| A domain join account | Configuration → Domain Join Accounts | Optional. An Active Directory account allowed to create computer accounts, or an Entra ID bulk enrollment package (.ppkg). |
| Bundles | Provisioning → Bundles | Optional. Lists of software several profiles share. |
| A profile | Provisioning → Profiles | The recipe: image and edition, language, keyboard, time zone, computer name pattern, endpoint group, directory, bundles, software, scripts. |
| The USB media | Configuration → Boot Media | Create a key, download its bootstrap.json, and build the stick with Build-BootMedia.ps1 (it needs the Windows ADK). The key is shown once. |
Provision a computer
- Plug the network cable and the USB media in, and start the computer on the media.
- The computer shows a reference in large characters and appears in Provisioning → Devices within a few seconds.
- Click Provision on its row. Choose the profile, check the computer name, give its location, untick the software this computer does not need.
- Tick the confirmation: the disk of the computer is entirely erased. Your name is recorded with it.
- Follow the job in Provisioning → Jobs. Remove the USB media when the computer asks for it.
The computer restarts by itself several times. When the job reads Completed, the computer is in Endpoints, in the group of its profile.
Computers announced in advance
In Provisioning → Devices, *Expected devices* lets you declare a computer before it arrives — by serial number, UUID or MAC address — with its profile, its name and its location. When that computer starts on the media, its job starts without a click. The consent to erase the disk is given when the computer is declared.
What a job does
| Step | Where it runs |
|---|---|
| Disk erased and partitioned, Windows image downloaded and applied, drivers injected | on the USB media |
| Windows Setup: name, language, time zone | in Windows, first start |
| Agent installed, local Administrator password replaced | in Windows |
| Directory join, bundles, software, scripts, Windows updates, restart | through the agent |
Software is installed one item at a time, in the order of the profile: the bundles first, then the profile's own software and scripts, then Windows updates. An item that fails is tried again by itself, three times at most. A required item that still fails fails the job; an optional one is only reported. Retry software on the job tries the failed items again once their cause is corrected.
Windows updates
A bundle may ask for Windows updates: every update Windows offers is installed, in up to three rounds separated by a restart — a restart uncovers the updates that depended on the ones just installed. Updates you declined in Update Approval are left out. Allow one to two hours on a computer installed from an old image.
The local Administrator password
Each job draws its own password for the built-in Administrator account. It is kept encrypted, shown only on request (Reveal admin password on the job), and every reveal is written to the Audit Trail.
Following the activity
- Dashboard: computers provisioned over the last 30 days, share that succeeded at the first attempt, average duration.
- Provisioning → Jobs: filters by status, profile, country, site, department, author and date; Export CSV writes the jobs listed, one row per job.
- Endpoints: the *General* tab of a provisioned computer links back to its job.
When something goes wrong
| What you see | What to do |
|---|---|
| The computer does not appear in Devices | Check the cable. The screen of the computer says what it is waiting for: an address, the console, the time. |
| The job stops at *Downloading the Windows image* | The download resumes by itself when the network comes back. |
| *No news from the device for two hours* | The computer was switched off or the media removed too early. Use Provision again and start it on the media. |
| A package fails | Open its History link on the job: the agent's output says why. Correct the package, then Retry software. |
| The directory join fails | The message names the cause: DNS, password, rights on the organizational unit, expired package. A join is never tried twice by itself, so that a wrong password does not lock the account. |
Lost or stolen USB media
Revoke its key in Configuration → Boot Media: a stick built with it no longer declares computers. A key only lets a computer declare itself; it opens no image, no software and no secret.
Retention
Finished jobs are deleted after the period set in Advanced → Data → Provisioning Job Retention (365 days by default), with their step log and the Administrator password they keep. The endpoint stays. A device that showed up on the media and was never provisioned leaves the list after 30 days without news.
