Most zero-touch deployment failures do not start with the MDM platform. They start weeks earlier, when a company buys the wrong devices, leaves enrollment accounts unfinished, or assumes the network and device configuration will sort themselves out later.
That is why zero-touch deployment readiness should be checked before you sign a contract or place a large hardware order.
The idea behind zero-touch deployment is simple: a new employee receives a company device, turns it on, connects to the internet, signs in, and the organization’s policies, applications, and security controls are applied without IT having to manually configure the machine first. But that experience depends on several systems working together.
If you are still learning how zero-touch deployment works, our guide to zero-touch deployment covers the underlying concept. And if you are already comparing platforms, our guide to the best zero-touch deployment software covers the selection side.
This article focuses on the step in between: Are you actually ready to buy and implement it?
The Prerequisite Nobody Thinks Is an IT Problem: Your Procurement Channel
One of the easiest ways to break a zero-touch rollout is to purchase a device through a channel that cannot register it correctly for automated enrollment.
This is where procurement and IT need to work together.
For Apple devices, organizations can use Apple Business, which is Apple’s current name for the capabilities previously provided through Apple Business Manager. Devices purchased directly from Apple or through participating Apple Authorized Resellers or authorized carriers can be automatically added to an organization’s account when the required supplier relationship is configured.
Windows works differently. Windows Autopilot devices can be registered by participating OEMs or Cloud Solution Provider partners, with the organization authorizing the relevant partner to register devices on its behalf. Microsoft also supports manual registration for devices that do not arrive through an eligible channel, but that process requires additional device information and hands-on work.
Android zero-touch enrollment similarly depends on supported devices being purchased through a partner reseller and associated with the organization’s zero-touch account.
This creates an important operational distinction: Buying a device and making a device zero-touch ready are not necessarily the same thing.
A procurement team may see a good price from a retailer and place the order. IT may only discover later that the devices need to be manually registered before they can follow the intended deployment process.
That does not always make the device unusable. However, it can turn an automated workflow into a manual one, which defeats much of the operational benefit you were trying to create.
Before you buy, confirm:
☐ Which enrollment system you are using for each operating system
☐ Which manufacturers and resellers are eligible
☐ Whether your chosen supplier can register devices on your behalf
☐ Whether the supplier has the organization’s required account information
☐ Whether the device registration will happen before shipment
☐ Who owns the process if registration fails
For a distributed workforce, this should be part of the procurement process rather than a technical detail discovered after the invoice is paid.
Account and Enrollment Prerequisites by Platform
Once the procurement channel is confirmed, the next question is whether the organization’s accounts and enrollment infrastructure are ready.
The exact requirements differ by platform, so a mixed fleet should not be treated as one universal zero-touch setup.
Apple: Apple Business and Automated Device Enrollment
Apple now refers to Apple Business Manager as Apple Business. Its Automated Device Enrollment capability allows organization-owned Apple devices to be configured and managed from the initial setup experience.
Before rollout, IT should verify:
☐ The organization’s Apple Business account is established and verified
☐ The relevant Apple Customer Number or authorized reseller relationship is configured
☐ The device supplier has been added correctly
☐ The MDM service is connected to Apple Business
☐ The appropriate device management service is assigned
☐ Enrollment and configuration profiles are ready
Apple also requires an Apple Push Notification service certificate when connecting a device management service, and device-management service tokens need to be maintained. This is worth checking well before the first shipment — a device can arrive physically on time and still create an onboarding problem if the enrollment relationship behind it has not been configured.
Windows: Autopilot and Intune
For Windows, the equivalent preparation usually involves Windows Autopilot and an endpoint management platform such as Microsoft Intune.
Microsoft recommends that the OEM or authorized partner register eligible devices. Organizations can also register devices manually, but manual registration requires collecting hardware information and importing it into the Autopilot service.
Before devices ship, verify:
☐ The Microsoft tenant is configured
☐ Windows Autopilot registration is confirmed
☐ The OEM or CSP has authorization to register devices
☐ Autopilot profiles are configured
☐ Enrollment Status Page settings are ready where applicable
☐ Required policies and applications are assigned
☐ Device groups are working as expected
Microsoft’s own deployment workflow places device registration, grouping, profile configuration, and enrollment preparation before the device reaches the employee.
Android: Zero-Touch Enrollment
Android zero-touch enrollment uses a different ecosystem. Supported devices purchased through authorized partners can be associated with an organization’s zero-touch account. The organization’s EMM or device-management console then provides the configuration that is applied during the device’s setup process.
Before rollout, confirm:
☐ The organization has the appropriate zero-touch customer account
☐ The reseller is participating in the program
☐ Devices are correctly assigned to the organization
☐ The EMM supports zero-touch enrollment
☐ The correct provisioning configuration has been created
☐ Device identifiers are being transmitted accurately
Google’s provisioning documentation also makes clear that the reseller is an important part of the device-claiming process. Devices must be associated with the customer before the zero-touch configuration can take effect.
Related Reads
Each stage of zero-touch readiness has a deeper guide if you want to go further before committing to a rollout:
- Zero-Touch Deployment: How It Works for Remote Teams — the concept and mechanics, before the readiness question.
- Best Zero-Touch Deployment Software — platform comparison to run after the readiness checklist is clear.
- Device Procurement Best Practices — making the eligible-channel decision part of standard procurement.
- Best Mobile Device Management Software — choosing the MDM the devices will enroll into.
- Global Laptop Procurement Checklist — the broader procurement process that the channel decision sits inside.
- Remote Employee Onboarding: Getting Hardware to Distributed Teams — the employee experience zero-touch is designed to protect.
- Laptop Fleet Management at Scale — managing the fleet after deployment is complete.
Network Readiness: The Prerequisite Most Checklists Skip
Even when the accounts and devices are correctly configured, the first-boot experience still depends on connectivity. A zero-touch process cannot magically configure a device that cannot reach the services responsible for enrollment.
For example, Apple’s Automated Device Enrollment documentation specifies that the device needs access to the device-management service through an internal network or the internet.
That means IT should consider:
- DNS resolution
- DHCP configuration
- Internet access
- Firewall restrictions
- Proxy requirements
- Required provisioning endpoints
- MDM accessibility
For office-based deployments, this is relatively straightforward because IT controls the network.
Remote employees are different. A new employee may be setting up a laptop from a home Wi-Fi connection, a coworking space, or another location that IT does not control. Trying to manually engineer every employee’s home network is neither practical nor scalable for a distributed team.
Instead, the goal should be to make the deployment process resilient enough that a normal internet connection can support enrollment.
That is also why a pilot should include at least some remote users rather than testing exclusively inside the corporate office.
Configure the MDM Before the Devices Arrive
This sounds obvious, but it is one of the easiest mistakes to make.
Zero-touch deployment does not mean the device configures itself without instructions. It means the configuration is delivered automatically once the device is correctly enrolled.
The policies, applications, configuration profiles, security settings, and enrollment rules therefore need to exist in the MDM platform before the device reaches the employee.
For Apple, the device management service needs to be linked and configured before automated enrollment can deliver the intended management experience.
For Windows, Autopilot profiles and enrollment configuration need to be prepared as part of the deployment workflow. Microsoft’s documentation specifically includes profile creation and assignment as steps in the Autopilot deployment process.
Before ordering hundreds of devices, test:
Device registration → enrollment → policy application → application installation → employee sign-in
If that sequence does not work reliably with one device, increasing the order size will only multiply the problem.
Your Zero-Touch Deployment Readiness Checklist
Before you approve a rollout, use this as the final pre-purchase check.
Procurement
☐ The device manufacturer supports the required zero-touch enrollment method — if not, local sourcing through an eligible partner resolves this.
☐ The selected reseller or supplier is eligible for the relevant enrollment program.
☐ Supplier authorization or account relationships are complete.
☐ Device registration will happen before shipment.
☐ Someone has been assigned responsibility for resolving registration failures.
Enrollment Accounts
☐ Apple Business is verified and connected to the MDM, if managing Apple devices.
☐ Windows Autopilot and the relevant Microsoft tenant are configured.
☐ Android zero-touch customer and reseller relationships are established.
☐ Device identifiers are being assigned correctly.
☐ MDM/EMM enrollment profiles are tested.
MDM Configuration
☐ Security policies are configured.
☐ Required applications are packaged and assigned.
☐ Configuration profiles are ready.
☐ Device groups or assignments are working.
☐ Enrollment restrictions have been reviewed.
☐ Remote lock and wipe policies have been tested.
Network
☐ Devices can reach required enrollment services.
☐ DNS and DHCP requirements have been checked.
☐ Firewall or proxy restrictions have been documented.
☐ Remote-user connectivity has been tested.
☐ The deployment does not depend on access to an internal office network unless that is intentional.
Pilot
☐ A small pilot group has been selected.
☐ At least one remote employee is included.
☐ The complete process has been tested from unopened device to productive employee.
☐ Failure scenarios have been tested.
☐ IT knows how to recover a failed enrollment without rebuilding the entire process.
If any of these boxes are still unclear, the organization is probably not ready for a large zero-touch rollout.
The Most Important Test: Can You Trace the Entire Device Journey?
A successful zero-touch deployment is not just about whether a laptop enrolls.
It is about whether the entire device lifecycle workflow makes sense.
Ask what happens when a device is:
Purchased → registered → shipped → enrolled → assigned → managed → retrieved → redeployed
If procurement owns the first step, IT owns the second, a reseller owns the third, another system owns the asset record, and nobody owns retrieval, you may have technically automated deployment while leaving the broader device lifecycle fragmented.
That is where many distributed IT teams eventually run into trouble. The deployment process may be automated, but the physical device operations around it remain manual.
For companies already formalizing their broader procurement process, this is also where our device procurement best practices guide can help connect procurement decisions with the rest of the device lifecycle.
Where Zero-Touch Readiness Meets Procurement
The biggest lesson from the readiness checklist is that zero-touch deployment starts before the device reaches IT.
The procurement channel determines whether the device can be registered automatically. The enrollment account determines whether the organization can manage it. The MDM configuration determines what happens after enrollment. The network determines whether the device can actually complete the process.
That means procurement, IT, security, and operations cannot treat zero-touch deployment as an isolated MDM project.
For distributed teams, the sourcing decision becomes even more important because devices may be purchased in different countries and through different suppliers.
This is one reason global organizations increasingly look at procurement and deployment as a connected workflow rather than separate projects.
Remoasset can support that operational model by combining device procurement with deployment workflows, so zero-touch requirements can be considered at the sourcing stage rather than discovered after devices have already been purchased.
The objective is simple: the device should arrive ready to enroll, rather than arrive as a problem for IT to fix.
Zero-Touch Deployment Is a Chain, Not a Switch
Zero-touch deployment is often presented as something you enable inside an MDM platform.
In reality, it is a chain of dependencies.
- The procurement channel has to be right.
- The device registration has to be right.
- The enrollment accounts have to be ready.
- The MDM configuration has to exist.
- The network has to allow the device to connect.
And the entire flow needs to be tested before hundreds of employees depend on it.
Once those pieces are in place, zero-touch deployment can remove a significant amount of repetitive device setup from IT teams. More importantly, it gives distributed organizations a repeatable way to get employees productive without requiring IT to physically handle every laptop.
The best time to discover a missing prerequisite is before you buy the devices, not after they are sitting in a warehouse waiting to be deployed.
If the procurement side of zero-touch readiness is still unresolved, book a demo to see how Remoasset handles the channel requirement automatically as part of sourcing.
Frequently Asked Questions
Why does zero-touch deployment fail?
Common causes include incorrect device registration, purchasing through an unsupported channel, incomplete MDM configuration, missing enrollment profiles, account authorization issues, and connectivity problems during first boot.
What do I need before setting up zero-touch deployment?
At minimum, you need an eligible device and procurement channel, the appropriate enrollment account, a supported MDM/EMM configuration, required policies and applications, and a tested network path to the enrollment services.
Does it matter where I buy laptops for zero-touch enrollment?
Yes. The purchasing channel can determine whether a device is automatically registered with the relevant enrollment service. Apple, Windows, and Android each have their own supplier and registration requirements.
What is Apple Business and do I need it for zero-touch deployment?
Apple Business is Apple’s current name for the capabilities previously associated with Apple Business Manager. For organization-owned Apple devices, it provides the infrastructure used for Automated Device Enrollment and integration with device-management services.
Can zero-touch deployment work for remote employees?
Yes. The entire purpose is to reduce the need for IT to physically prepare each device. However, the device still needs internet connectivity and must be correctly registered and configured before shipment. For truly distributed onboarding, the procurement-channel requirement is especially important.
Should I test zero-touch deployment before buying devices in bulk?
Absolutely. A small pilot can reveal procurement, registration, application, policy, or connectivity issues before they affect a larger deployment. Test the complete journey, including at least one remote employee, rather than testing only the MDM console.
Can an incorrectly purchased device still be enrolled?
Sometimes. Windows supports manual Autopilot registration for certain devices, although that introduces additional manual work. For Apple, devices can also be manually added in certain scenarios using Apple Configurator, but that is different from the automated workflow. In either case, resolving this retroactively is significantly more work than getting the channel right at procurement.

