What each Enrollment Status Page setting does, from blocking apps and time limits to quality updates during OOBE, and where to create profiles.
From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)
The Enrollment Status Page (ESP) shows provisioning progress and can hold the user at OOBE until required apps and policies are installed. It works with Microsoft Entra join during default OOBE and every classic Autopilot scenario, but not with device preparation and not with devices enrolled through Group Policy.
ESP profiles are created at Devices > Enrollment > Windows > Windows Autopilot > Enrollment Status Page; a tenant can have 51 (the default plus 50).
| Setting | Notes |
|---|---|
| Show app and profile configuration progress | No hides the ESP; Yes unlocks the other settings |
| Show an error when installation takes longer than specified number of minutes | Default 60 |
| Show custom message when time limit or error occur | Otherwise a standard “Setup could not be completed” message |
| Turn on log collection and diagnostics page for end users | Shows a Collect logs button on failure and the Autopilot diagnostics page on Windows 11 |
| Only show page to devices provisioned by OOBE | Yes shows the user phase only to the first user |
| Install Windows quality updates (might restart the device) | Installs the monthly security update at the end of OOBE; Windows 11 only; default Yes on new profiles, No on existing ones; adds 20 to 40 minutes |
| Block device use until all apps and profiles are installed | Yes needed for quality updates and update ring settings to apply in OOBE |
| Allow users to reset device / use device if installation error occurs | Escape options on failure |
| Block device use until these required apps are installed | All or Selected (up to 100 blocking apps) |
| Only fail selected blocking apps in technician phase | Pre-provisioning only; default for pre-provisioned deployments |
model, manufacturer, osVersion, operatingSystemSKU, deviceOwnership and enrollmentProfileName.
Common trap: Looking in the Autopilot deployment profile for the option that lets users collect logs when setup fails - it is the ESP setting Turn on log collection and diagnostics page for end users.
This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · MD-102 terms in the glossary · All MD-102 study notes
How Microsoft Entra registered, Entra joined and hybrid joined devices differ in ownership, sign-in, management and the scenarios each one suits.
The tenant-wide compliance settings and per-platform policies behind Intune compliance, and how a device's overall status is worked out.
Which devices can back up a local admin password to Entra ID or Active Directory, and how to build the Windows LAPS policy in Intune.
The six ways Intune manages Android devices, from personal work profiles to fully managed, dedicated and AOSP, and how to choose between them.
How user-driven, pre-provisioned and self-deploying Autopilot modes differ in join type, user interaction and TPM requirements.
Which Intune remote action keeps personal data and which resets the device, with platform support, wipe options and daily limits.
How Intune update rings set quality and feature update deferrals, deadlines, grace periods and restart behaviour for groups of Windows devices.
How Intune app protection policies protect work data inside apps on enrolled and personal devices, and the three-level data protection framework.