FREE STUDY NOTES · MD-102

Intune Enrollment Status Page (ESP) settings explained

What each Enrollment Status Page setting does, from blocking apps and time limits to quality updates during OOBE, and where to create profiles.

From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)

The Enrollment Status Page (ESP) shows provisioning progress and can hold the user at OOBE until required apps and policies are installed. It works with Microsoft Entra join during default OOBE and every classic Autopilot scenario, but not with device preparation and not with devices enrolled through Group Policy.

ESP profiles are created at Devices > Enrollment > Windows > Windows Autopilot > Enrollment Status Page; a tenant can have 51 (the default plus 50).

Setting Notes
Show app and profile configuration progress No hides the ESP; Yes unlocks the other settings
Show an error when installation takes longer than specified number of minutes Default 60
Show custom message when time limit or error occur Otherwise a standard “Setup could not be completed” message
Turn on log collection and diagnostics page for end users Shows a Collect logs button on failure and the Autopilot diagnostics page on Windows 11
Only show page to devices provisioned by OOBE Yes shows the user phase only to the first user
Install Windows quality updates (might restart the device) Installs the monthly security update at the end of OOBE; Windows 11 only; default Yes on new profiles, No on existing ones; adds 20 to 40 minutes
Block device use until all apps and profiles are installed Yes needed for quality updates and update ring settings to apply in OOBE
Allow users to reset device / use device if installation error occurs Escape options on failure
Block device use until these required apps are installed All or Selected (up to 100 blocking apps)
Only fail selected blocking apps in technician phase Pre-provisioning only; default for pre-provisioned deployments

Priority and tracking

The Enrollment Status Page moves through three phases: Device preparation, Device setup (device-targeted certificates, Wi-Fi and VPN profiles, device-context apps) and Account setup (user-targeted items). Underneath are the blocking-apps setting (All or up to 100 selected) and a timer that defaults to 60 minutes. The timer leads to two outcomes: everything installs in time, or an error offers a message, Collect logs and reset or use-device options.
Figure 6.2: The three phases the Enrollment Status Page tracks

Known pitfalls

Common trap: Looking in the Autopilot deployment profile for the option that lets users collect logs when setup fails - it is the ESP setting Turn on log collection and diagnostics page for end users.

Get the whole book

This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · MD-102 terms in the glossary · All MD-102 study notes

More MD-102 study notes