About

About Autopilot Monitor

What is Autopilot Monitor?

Autopilot Monitor is a free, open-source, real-time monitoring and troubleshooting platform for Windows Autopilot enrollments managed through Microsoft Intune. It gives IT administrators, helpdesk engineers, and MSPs complete visibility into every enrollment session — from the first boot through the Enrollment Status Page (ESP) to the user desktop — so issues can be detected and resolved before they impact end users.

Traditional Autopilot deployments are a black box. When a device fails or stalls, the only option is to manually dig through IME logs or wait for a user complaint. Autopilot Monitor changes that by streaming live telemetry from a lightweight agent deployed via Intune, feeding every event — app installs, policy applications, phase transitions, errors, and performance data — into a central dashboard with intelligent analysis built in.

Deployed by assigning a signed loader script in Intune, the platform requires no infrastructure changes and no additional certificates on end user devices. It runs entirely on Azure, authenticates via Microsoft Entra ID, and provides multi-tenant support with strict per-tenant data isolation.

Key Features

Every feature is designed around one goal: reducing the time between an Autopilot failure occurring and an IT admin understanding why.

Real-Time Enrollment Monitoring

Track every Windows Autopilot enrollment phase as it happens. Live push updates surface device registration, ESP progress, app installs, and user phase transitions without manual refreshing.

  • Live phase-by-phase tracking
  • Near real-time push updates via SignalR
  • Per-device event stream with timestamps

Intelligent Analyze Rules

Built-in and fully customizable analyze rules automatically detect enrollment failure patterns — from app install retry loops and ESP timeouts to detection-rule failures and IME log anomalies.

  • Community-driven built-in rules
  • Custom rule authoring
  • Confidence-scored findings per session

Fleet Health Dashboard

A high-level view across your entire device fleet. Monitor success rates, failure trends, average enrollment duration, and blocked devices — broken down by time range.

  • Success & failure rate trends
  • Average enrollment duration
  • Blocked device detection

Diagnostics Collection

Collect agent logs, IME logs, agent state, and device information as a ZIP bundle — automatically at the end of an enrollment, or on demand while one is still running — then download it from the session view without touching the device.

  • Configurable upload: off, always, or on failure
  • On-demand collection from a running enrollment
  • Agent, IME & device information bundle
  • Configurable additional log paths

Detailed Event Timeline

Full event timeline for every deployment session. Drill down into phase transitions, app install status, errors, warnings, and performance snapshots to pinpoint root causes fast.

  • Phase-by-phase breakdown
  • App install progress & details
  • Error & warning highlights

Audit Logging & Compliance

Complete audit trail of all administrative actions and configuration changes. Meet compliance requirements with detailed, tenant-scoped records and configurable data retention.

  • Admin action history
  • Configurable retention policies
  • Tenant-scoped audit log

Who Is It For?

Autopilot Monitor is built for anyone responsible for deploying or supporting Windows devices through Microsoft Intune and Autopilot.

IT Administrators

Gain full visibility into Autopilot deployments across your organization. Detect failures early, analyze patterns, and reduce helpdesk tickets from day-one device issues.

Helpdesk & Field Engineers

Immediately understand what happened on a specific device without touching it. Access event timelines, analyze rule findings, and download diagnostics on demand.

MSPs & Enterprise Teams

Autopilot Monitor is a multi-tenant service with strict per-tenant data isolation — telemetry, configuration, and diagnostics are partitioned and access-scoped to each tenant. MSPs can be granted delegated read access across several customer tenants from a single login.

How It Works

Autopilot Monitor uses a lightweight .NET agent deployed to devices via an Intune bootstrapper script. The agent monitors the enrollment process in real time and streams telemetry events — including ESP phases, app installs, performance snapshots, and custom gather rule data — to the Azure-hosted backend pipeline. The portal displays live session data, runs analyze rules automatically, and alerts on failure conditions.

  1. 1Assign the bootstrapper PowerShell script to your Autopilot device groups in Intune.
  2. 2The bootstrapper installs the Autopilot Monitor Agent on each enrolling device.
  3. 3The agent captures live enrollment events and uploads them to the backend pipeline.
  4. 4The portal displays real-time session data, analyze rule results, and fleet health metrics.
  5. 5On completion, the agent uploads a diagnostics bundle if configured, then removes itself.

Technology & Platform

Autopilot Monitor is built on modern, enterprise-grade technology designed to scale with large device fleets and multi-tenant deployments.

Backend

  • Azure Functions (.NET Isolated, Flex Consumption) — serverless, scalable API
  • Azure Table Storage — high-throughput event ingestion
  • Azure Blob Storage — diagnostics and log bundle storage
  • Azure SignalR Service — real-time push to the portal

Portal (Web Frontend)

  • Next.js (React) + TypeScript — fast, statically delivered web app
  • Microsoft Entra ID (MSAL) — secure authentication
  • Role-based access control (Admin / Operator / Viewer)
  • Multi-tenant architecture with delegated MSP access

Agent

  • .NET binary — lightweight, low-overhead monitoring
  • Runs via scheduled task (no Windows service — easy, residue-free removal)
  • Deployed via a signed Intune platform script (PowerShell loader); for Autopilot Device Preparation additionally as a thin MSI line-of-business app
  • Mutual TLS using the existing Intune MDM device certificate
  • Self-destruct on enrollment completion (on by default — removes task and files)

Integrations

  • Microsoft Intune — agent deployment target
  • Microsoft Teams, Slack, Discord & generic JSON webhooks — start, success, failure, hardware rejection and SLA alerts
  • Intune Management Extension (IME) log — event source for log pattern detection
  • WMI & Registry — extended data gather rules

Open Source & Free to Use

Autopilot Monitor is fully open source and free to use. The complete source code is available on GitHub under an open license. Contributions, bug reports, and feature requests from the community are welcome — especially for Analyze Rules, which are designed to be shared and extended by the wider Windows Autopilot community.

Autopilot Monitor was created and is maintained by Oliver Kieselbach, a Microsoft MVP and long-time contributor to the Windows Autopilot and Microsoft Intune community. The project is driven by real-world enterprise deployment experience and community feedback.

The hosted service is operated by glueckkanja AG — see the Imprint for company details and the Terms of Use for what each plan does and does not commit to.

Common Questions

Short answers to what IT admins ask most often. The full FAQ lives in the documentation.

What is Autopilot Monitor?

Autopilot Monitor is a free, open-source monitoring and troubleshooting platform for Windows Autopilot enrollments managed through Microsoft Intune. A lightweight, temporary agent runs on each device during enrollment and streams events to a web portal, where IT admins watch progress live, get failures analyzed automatically, and review historical sessions and fleet-wide reports.

Can I follow a Windows Autopilot enrollment live?

Yes. Assign the Autopilot Monitor bootstrapper script to your Autopilot device groups in Intune. During enrollment the agent captures Enrollment Status Page (ESP) phases, app downloads and installs, errors, reboots, and performance snapshots and pushes them to the portal as they happen. You see every device's progress without refreshing the page or touching the device.

Why did my Autopilot enrollment fail, and how do I find out without touching the device?

Open the session in the portal. Analyze rules flag known failure patterns automatically: app install error codes such as 1603, detection-rule failures that break the ESP (0x87D1041C), blocking-app timeouts, content download and proxy failures, TPM attestation and MDM enrollment error codes, hybrid join problems, failed Windows updates, and low disk space or battery. Guided Diagnosis names the primary suspect with a copyable quick fix, and a diagnostics bundle with agent and IME logs can be uploaded automatically or on demand.

Can failed enrollments be analyzed automatically instead of reading IME logs by hand?

Yes. Dozens of built-in, community-maintained analyze rules run automatically on every session and report confidence-scored findings with remediation steps. You can write your own rules, add Intune Management Extension (IME) log patterns, and gather registry, file, or WMI data on any event. Regression detection alerts tenant admins when a rule starts firing more often than usual.

How do I get alerted when an Autopilot enrollment fails?

Configure a notification channel for Microsoft Teams, Slack, Discord, or a generic JSON webhook and choose which triggers fire: enrollment start, success, or failure. The same channel carries SLA breach and resolution alerts, consecutive-failure alerts, and hardware rejection notices. Configuration and hardware alerts also appear as bell notifications in the portal.

Is there reporting on Autopilot deployments, such as success rate, duration, and failing apps?

Yes. Fleet Health shows the success rate, average enrollment time, a daily enrollments timeline, top failure reasons, the slowest and most-failing device models and apps with their exit codes, and a first-time-right rate that reveals devices that needed several attempts. SLA Compliance reports against your own targets for success rate, P95 duration, and app install success, with a list of violating sessions.

Why does enrollment take so long, and which app is slowing it down?

Every finished session gets a time attribution bar that splits the enrollment into device preparation, apps, identity and Windows Hello, user ESP, and desktop handoff, and lists the apps that blocked the ESP with their install times. Fleet Health aggregates the same data per enrollment class and ranks the apps that cost the most time. Geographic Performance finds slow sites and shows how much content came from Delivery Optimization peers.

Can end users or field technicians check a device's enrollment status without portal access?

Yes. The Progress Portal shows a device's enrollment status by serial number: a color-coded status, a progress bar, the enrollment steps, and what is currently downloading or installing, all updating live. No portal role is required, the serial number acts as the access key, and the view is strictly read-only with no access to timelines or device internals.

Is Autopilot Monitor free and open source?

Yes. The Community plan is free, stays free, and is meant for production fleets, not just labs: live monitoring, the full rules engine including custom rules, fleet analytics, notifications, diagnostics, and AI integration through MCP within usage limits, with 90-day data retention. The source code is on GitHub: the agent under the MIT license, the backend, portal, and MCP server under AGPL-3.0. The optional Pro plan, sold through Microsoft Marketplace and Cleverbridge, adds 365-day retention, higher API and AI usage limits, delegated administration across customer tenants, OOBE bootstrap sessions, reliability commitments, and priority support; a tenant administrator can try it free for 30 days.

How is the agent deployed, and does it stay on the device?

The agent is a small .NET binary installed by an Intune platform script (PowerShell bootstrapper); for Autopilot Device Preparation it ships as a thin MSI line-of-business app. It runs as a scheduled task, not a Windows service, authenticates with the existing Intune MDM device certificate, and exists only for the duration of the enrollment: by default it removes its task and files on completion, and it never runs longer than six hours.

Which Autopilot scenarios are supported?

User-driven, pre-provisioned (white glove), and self-deploying or kiosk Autopilot flows, for Microsoft Entra joined and Hybrid joined devices alike. Autopilot Device Preparation is supported, with device association or corporate identifiers as validation methods, or without any pre-registration by validating the device's Intune enrollment. Windows 365 Cloud PCs can be enabled per tenant.

Where is my enrollment data stored?

In Germany. All customer data and all compute that touches it run in the Azure region Germany West Central. Only the static portal front-end is served from West Europe, and it stores no customer data. Retention is configurable per tenant with a 90-day default, diagnostics packages can be kept in your own Azure Blob Storage, and a tenant can offboard and irreversibly delete all its data at any time.

Can a managed service provider monitor several customer tenants?

Yes. Delegated administration gives an MSP read-only access to a defined set of customer tenants from a single login, with fleet analytics scoped to exactly those tenants. Secrets are redacted, write operations are structurally unavailable, and every grant or revoke is written to the customer's own audit log. The managing tenant needs the Pro plan; customer tenants can be on any plan.

Can I ask an AI assistant about my enrollments?

Yes. Autopilot Monitor exposes a Model Context Protocol (MCP) server. Connect Claude, ChatGPT, VS Code with GitHub Copilot, or a command-line client such as Claude Code, Codex or Gemini CLI, and ask questions like "show me all failed enrollments from the last 24 hours" or "why did this session fail?". An AI client your organization hosts itself is registered once by a Tenant Admin. Access follows your portal role, with usage limits tied to the tenant's plan.

Who builds and operates Autopilot Monitor?

Autopilot Monitor was created and is maintained by Oliver Kieselbach, a Microsoft MVP and long-time contributor to the Windows Autopilot and Microsoft Intune community. The hosted service is operated by glueckkanja AG, a German company certified to ISO/IEC 27001, which is also the contracting party for the Pro plan.

Explore Further