Step reference
Domain join
Join the device to an on-premises Active Directory domain, with the service credential resolved from the vault — never stored on the USB.
What it does
Joins the device to an on-premises Active Directory domain. The service-account credential used to perform the join is fetched from the vault at runtime and never written to the USB or the template. Domain join requires a restart, so this step triggers a reboot and the setup resumes automatically afterwards.
Options
| Option | What it controls |
|---|---|
| Domain (FQDN) | The fully-qualified domain name to join, e.g. corp.acme.local. Required. |
| OU path | Optional. Place the computer object in a specific organisational unit. |
| Service account password | The vault secret for the account permitted to join machines to the domain. Required. |
Good to know
- For clients without Autopilot Hybrid Join. If the client uses Autopilot Hybrid Azure AD Join, Intune performs the domain join through the Hybrid Join profile — use that instead of this step.
- A reboot is part of the step. That's expected; the setup picks up where it left off once the machine is back.
- If the join fails, the setup stops by default.
Part of the step catalogue.
Related
Install Windows 11
True bare-metal Windows 11 install with the right OEM driver pack injected automatically. Skips cleanly if the device already has Windows.
OOBE configuration
Auto-answer the out-of-box screens (region, keyboard, device name, EULA, optional Wi-Fi) and optionally skip the account screen so the device lands ready — no duplicate admin.
Language & region
Set the display language, keyboard layout, regional format, home location and timezone for the installed Windows and every new user. Autopilot-compatible.