StageReady vs Microsoft Intune

Intune runs the device. We get the device to Intune.

Intune isn't a competitor — it's the destination. Its job starts the moment a device is enrolled. Everything before that, from a blank disk to a machine Autopilot recognises, is still manual work. That's the gap StageReady closes.

The day-zero gap

Four things Intune can't do yet, because the device isn't there yet

None of this is a knock on Intune. It's what sits between an unboxed laptop and the first moment Intune has anything to manage.

Something still has to install Windows

Intune has no OS or disk imaging. Autopilot provisions a device that already has Windows on it. A blank disk, a wiped machine, or a returned laptop means a technician standing there with a USB stick and an ISO before Intune is even in the picture.

Autopilot has to know the device already

Classic Autopilot needs each device's hardware hash: boot the machine, run the script, export a CSV, import it. Registration through the OEM or CSP channel avoids that — but only for hardware bought that way. Off-the-shelf, refurbished and returned stock falls back to doing it by hand.

Firmware is largely out of reach

Intune's BIOS configuration profile currently supports Dell only, and only once the device is enrolled with the OEM's agent app deployed. DFCI covers Surface, Acer, Asus, Dynabook, Fujitsu and Panasonic — not HP, not Lenovo. StageReady applies HP and Dell BIOS settings in WinPE, before Windows installs.

Nothing runs before enrollment

Every Intune policy, script and app waits for the device to be enrolled. The work that is cheapest to do before that — driver packs, region and keyboard baked into OOBE, the computer name, a local admin, a machine certificate, defaults for every new user — is all day-zero work.

Side by side

Where each one starts and stops

DimensionStageReadyMicrosoft Intune
Starting pointA blank disk — or a device that already has Windows on itA device already running Windows
Installing WindowsInstalls Windows 11 from bare metal, with the right OEM driver pack injectedNo OS or disk imaging — Autopilot provisions a device that already has Windows installed
Autopilot registrationCaptures the hardware hash and registers the device through Graph, during the buildThe hash has to reach Intune first: capture it per device and import a CSV, or register through the OEM / CSP channel
Hybrid and domain-joined clientsDomain join is a step like any other, and runs independently of Autopilot registrationAutopilot device preparation (v2) is Microsoft Entra join only — hybrid join still needs classic Autopilot, and classic Autopilot still needs the hash
BIOS & OEM firmwareHP and Dell BIOS settings applied in WinPE, before Windows installs — Secure Boot, TPM, boot order, and moreThe BIOS configuration profile currently supports Dell only, and needs the device already enrolled with the OEM's agent app deployed first
Apps before first sign-inInstalled machine-wide, as SYSTEM, while Windows is still setting itself upNothing installs until the device is enrolled and the Intune Management Extension arrives
App packagingPicked from a catalogue; MSI/EXE downloaded from the vendor's own URL and signature-verifiedWin32 apps are repackaged into .intunewin with the Content Prep Tool and uploaded — per tenant
How many apps during setupA whole list, each with its own timeout; one app failing doesn't stop the restDevice preparation allows up to 10 apps and 10 scripts; the classic Enrollment Status Page has a blocking-app list and a timeout
Across many client tenantsOne template, then a profile per client that layers add-on templates, sets that client's own values, and inherits from a parent — children store only the differencesPolicies, apps and profiles are configured in each tenant
LicensingNo client licence needed unless the profile enrolls the device into MicrosoftRequires an Intune licence per user
Ongoing managementNot its jobA core strength — policy, patching, compliance, reporting
Every claim in the Intune column comes from Microsoft's own documentation — sources are listed at the bottom of this page.
About applications

It's a question of when, not whether

Intune installs applications well. What it can't do is install them before the device is enrolled — and on a fresh build, that's the window that matters.

Before first sign-in

StageReady

  • MSI/EXE straight from the vendor's official URL, Authenticode-verified — nothing re-hosted
  • Installed machine-wide, as SYSTEM, while Windows is still setting itself up
  • No repackaging, no upload, no per-tenant work — one catalogue serves every client
  • Each app has its own timeout; one bad download doesn't sink the build
After enrollment

Microsoft Intune

  • Per-user apps, Microsoft Store and MSIX packages
  • Ongoing updates, supersedence, uninstall
  • Compliance and installation reporting across the fleet
  • This is Intune's ground, and we don't try to take it
Neither, honestly

Both draw the same line

  • Installers with no unattended mode at all
  • Intune states plainly that it doesn't support interactive installations
  • Nor do we — setup runs with no screen and nobody to click a wizard
  • An installer that only works through its wizard has to be repackaged first
Some apps genuinely aren't ours to install — Microsoft Store and per-user packages arrive after someone signs in. We say so in the docs rather than shipping a default that quietly fails.
Using both

Provision with StageReady, manage with Intune

A device flows from one to the other: StageReady takes it from a blank disk to registered in the client's Autopilot, then Intune manages it for the rest of its life. We make Autopilot fire more often — including on hybrid-joined clients and hardware that never came through the CSP channel.

Day zero

StageReady builds & registers

Day two

Intune enrolls & manages

FAQ

StageReady and Microsoft Intune

See the day-zero half in action.

Book a demo