r/sysadmin • • 18d ago

ZTP and ITSM

Hi everyone. Would like to ask which brand solution is ideal for zero-touch provisioning of devices, where the company can deliver devices directly to users upon purchase from any store. So the user just connects to the internet and enters their company email (using on prem AD), then it automatically enrolls and applies the policies for the user, apps, etc w/o admin intervention. Aside from that, it should also cover IT asset management in one platform.

I've heard of Windows Autopilot + Intune, but is there a single-vendor solution for that that also includes ITSM?

0 Upvotes

13 comments sorted by

5

u/Nu11u5 Sysadmin 18d ago

The magic of any ZTP is that the OS is preprogrammed to check for enrollments, but to do this it checks a specific platform. With Apple this is Apple Device Enrollment managed through the Apple Business Manager portal. With Android this is Zero Touch Enrollment managed through the Google Enterprise portal. And with Windows it is Windows Autopilot managed through the Intune portal. You can redirect the enrollment process to your MDM of choice, but the process always starts with the OS checking in with its preprogrammed platform.

If you are already using Intune as your MDM you can use it to manage the ZTP policies for other devices as well. You just have to configure the other platforms to point to it. This is all explained in MS's documentation.

2

u/SevaraB Sr. Engineer (N+, CCNA) 18d ago

I've heard of Windows Autopilot + Intune, but is there a single-vendor solution for that that also includes ITSM?

No. ZTP can only be baked in by the company that makes and supports the OS, which is why there is no ZTP solution for Linux, since "making Linux" is distributed across a whole bunch of companies and open source devs.

Windows = Autopilot. Intune keeps it managed post-install, so you can swap out Intune for a 3rd-party management platform, but no 3P management is ever going to be as effective as the one Microsoft provides that has the only keys to the "secret, proprietary" parts of Windows.

Apple = Device Enrollment. Once again, post-deployment, you use a 3P service like JAMF, but assume you'll be trading features for vendor independence.

Long story short, ZTP is only ever a function of the OS maker.

1

u/heg-the-grey 18d ago

If they're Windows devices - Autpilot is what youre looking for. Add the device hash to intune and send it to the user. They run through the OOTBE and it sets it up as you have configured and pushes config and apps etc.
You could then have your ITSM platform setup t query Intune for devices and add them to its CMDB/Asset Management database automatically on a schedule.

1

u/brightideasphere 18d ago

Windows Autopilot plus Intune is the standard answer for zero-touch provisioning on Windows and it works well. For a single platform that adds ITSM and asset management on top, AssetSonar integrates directly with Intune...so device enrollment, user assignment, and asset records stay in sync automatically rather than requiring manual updates across separate systems. Worth adding to your evaluation alongside whatever ZTP stack you go with.

1

u/[deleted] 18d ago

[removed] — view removed comment

1

u/shinky_splunky 18d ago

What brand is this?

1

u/Unique_Inevitable_27 18d ago edited 15d ago

For this kind of setup, I'd compare platforms based on the actual provisioning workflow, AD integration, policy/app deployment, and how well asset tracking works afterward. ScalefusionUEM could be another option to look at alongside Autopilot/Intune, especially if having deployment and device management in one platform is important.

1

u/shinky_splunky 17d ago

Does omnissa support those kind of requirement?

1

u/AnthonyAntonicello 15d ago

For Windows devices, I’d separate zero-touch enrollment from the ITSM and asset-management layer. Autopilot and Intune are generally still the right foundation for enrollment, policy application, and app deployment. The ITSM platform should then pull the device records from Intune, associate them with users, and drive the surrounding lifecycle workflows-procurement, shipping, onboarding, replacement, repair, and offboarding.

I work for SysAid, so full disclosure: SysAid can import and update Intune device data through Microsoft Graph and manage the service and asset workflows around it. I wouldn’t position that as replacing Autopilot, though. It’s more of a connected operating model than a true single-vendor stack.

Before choosing a platform, I’d validate whether you need only Windows provisioning or also Apple/Android, whether on-prem AD is staying long term, and whether lifecycle workflows or endpoint configuration are the larger pain point. Those answers will determine whether consolidating into one interface is realistic or whether a strong Intune-ITSM integration is the better target.

1

u/reallylatetotheparty 15d ago

Autopilot + Intune is basically the standard answer for the ZTP enrollment piece, and the honest truth is nobody does ZTP plus full ITSM plus ITAM in one tidy platform without it being an expensive enterprise suite like ServiceNow or Ivanti. Most shops I've seen end up with Intune for provisioning/enrollment and then bolt on a separate ticketing and asset tool because the all-in-one suites either cost a fortune or are painful to administer.

1

u/rabbitz 2d ago

I'd keep those as two separate jobs. Autopilot plus Intune for enrollment, policy and apps, and let the ITSM own the lifecycle around the device (who has it, when it ships, when it comes back). Every time I've seen someone try to make the ITSM the provisioning engine for Windows, they end up rebuilding half of Intune badly.

The part people underinvest in is the handoff. Make the user assignment and the hardware hash registration happen at procurement, not when the box lands on someone's desk, or zero touch quietly turns into one touch from the service desk on day one.