For organizations that deliver Windows 365 Cloud PCs through Citrix, provisioning has always had a gap. Standard Windows 365 Cloud PCs — Enterprise, Flex, and Reserve — could leverage Autopilot Device Preparation (DPP) to ensure apps and scripts were installed before users sign in. But Cloud PCs configured for Citrix integration? They were left out of that workflow.

That changes with Microsoft’s latest update, announced the week of July 27, 2026. Autopilot Device Preparation is now supported for Cloud PCs with Citrix integration, bringing the Citrix provisioning experience in line with every other supported Windows 365 deployment scenario.

Let’s break down what this feature does, why it matters, and how to prepare your environment.


What Is Autopilot Device Preparation?

Autopilot Device Preparation (AP-DP) is Microsoft’s lightweight, cloud-native deployment method in Intune. Unlike traditional Autopilot — which was designed for physical device enrollment — AP-DP is purpose-built for cloud workloads like Windows 365 Cloud PCs. It works by holding a Cloud PC in a “Preparing” state during provisioning while required Intune apps, PowerShell scripts, and configurations are installed. Only when those requirements are met is the Cloud PC marked as provisioned and made available to users.

AP-DP was initially available for Windows 365 Frontline shared mode. It later expanded to Enterprise, Flex Dedicated, Cloud Apps, and Windows 365 Reserve. Now, with this update, it extends to Cloud PCs with Citrix integration — closing the last major gap in DPP coverage across Windows 365 scenarios.


How It Works

The workflow is straightforward and mirrors the existing DPP experience for standard Cloud PCs:

1. Create a Device Preparation Policy in Intune

Navigate to Devices → Windows → Enrollment → Device preparation policies in the Microsoft Intune admin center. Choose Automatic mode (the mode used for Cloud PC scenarios), then configure:

  • Required apps — up to 10 Intune apps that must install successfully
  • Required scripts — up to 10 PowerShell scripts that must run successfully
  • Other supported configurations — security agents, configuration baselines, etc.

When creating or editing a Windows 365 provisioning policy for Citrix-integrated Cloud PCs, on the Configuration tab, select the Autopilot Device Preparation policy you created. Configure:

  • Minutes allowed before device preparation fails — a timeout for the DPP phase
  • Prevent users from connecting to Cloud PC upon installation failure or time-out — optionally gate sign-in on success

3. Provisioning Flow

When Windows 365 provisions a Citrix-integrated Cloud PC:

  1. The Cloud PC is created as usual
  2. DPP automatically kicks off, installing required apps and scripts
  3. The Cloud PC shows a “Preparing” status in Intune
  4. On success, the Cloud PC is marked as Provisioned and users can sign in
  5. On failure or timeout, the Cloud PC is either marked Failed (if gating is enabled) or Provisioned with warnings (if gating is disabled)

4. Monitor in Intune

Device Preparation deployment status is visible at Devices → Enrollment → Monitor → Windows Autopilot Device Preparation deployment status in the Intune admin center.


Why This Matters for Citrix Environments

Consistent Baselines Across All Cloud PCs

Organizations using Citrix to deliver Windows 365 Cloud PCs can now guarantee that every Cloud PC meets the same app and configuration baselines before first user logon. This eliminates “day-one drift” — the scenario where users receive a half-configured desktop and software arrives later through background Intune processing.

Reduced Reliance on Custom Images

One of the key benefits Microsoft has highlighted for DPP across all Cloud PC scenarios is the ability to move app installation and configuration logic into Intune rather than baking it into custom images. For Citrix environments — where custom image management has historically been more complex due to layering and provisioning concerns — this is particularly valuable. You can maintain a smaller image set and use AP-DP to apply apps and configurations at provisioning time, simplifying lifecycle management.

Security Gating Before Access

With DPP gating enabled, Citrix-integrated Cloud PCs are not available to users until all required security tools — EDR agents, VPN clients, configuration baselines, hardening scripts — are installed and validated. This ensures that every Cloud PC exposed through Citrix meets your organization’s security compliance requirements before it’s accessible.

Unified Management Model

For organizations running a mix of physical endpoints (Autopilot-managed), standard Cloud PCs, and Citrix-delivered Cloud PCs, DPP provides a unified, Intune-centric deployment model. The same Device Preparation policy framework works across all scenarios, reducing administrative complexity and training overhead.


Requirements

To use DPP with Citrix-integrated Cloud PCs:

  • OS: Windows 11 24H2 with KB5052093 or later (gallery images already include this update)
  • Custom images: Must be based on Windows 11 24H2 media dated March 2025 or later with KB5052093 included
  • Intune subscription with appropriate licenses
  • Citrix integration configured for Windows 365

What IT Admins Should Do

1. Inventory Your Citrix Cloud PC Provisioning Scripts

Identify every app and script that currently runs during or immediately after provisioning for Citrix-integrated Cloud PCs. Classify each as required (must-install before access) vs. nice-to-have (can install later). Move the required items into a Device Preparation policy.

In Intune, create a Device Preparation policy in Automatic mode with your required apps and scripts. Then link it to your existing Windows 365 provisioning policy for Citrix Cloud PCs on the Configuration tab.

3. Decide on Gating Behavior

Choose whether to block sign-in on DPP failure. For most organizations, the answer should be yes — if required security tools or apps fail to install, users should not be able to access the Cloud PC. Set the timeout to a value that gives your scripts enough time to complete without being so long that failed provisioning goes unnoticed.

4. Test with a Pilot Group

Before rolling out broadly, test the DPP-enabled provisioning with a small group of Citrix Cloud PCs. Monitor the “Preparing” status, verify app installation, and confirm that the end-user experience on first sign-in is smooth.

5. Update Provisioning Documentation

Update your runbooks and provisioning documentation to reflect the new DPP workflow for Citrix Cloud PCs. Document the required apps/scripts, the linked DPP policy, the timeout value, and the gating behavior.

6. Monitor Provisioning Success Rates

After enabling DPP, watch for any increase in provisioning failures or extended “Preparing” states. Use the Device Preparation deployment status dashboard in Intune to identify and troubleshoot issues.


Preparation Checklist

TaskPriorityNotes
Inventory Citrix Cloud PC provisioning apps/scriptsCriticalClassify as required vs. optional
Create DPP policy in Intune (Automatic mode)CriticalInclude required apps and scripts only
Link DPP policy to Citrix Cloud PC provisioning policyCriticalConfigure on the Configuration tab
Enable sign-in gating on failureHighBlock access if required apps fail to install
Set appropriate timeout valueHighBalance script completion time vs. failure detection
Test with pilot groupHighValidate before broad rollout
Update provisioning documentationMediumDocument DPP workflow, timeout, gating
Monitor provisioning success rates post-enablementMediumWatch for extended “Preparing” states or failures
Review custom image requirementsLowEnsure Windows 11 24H2 with KB5052093 if using custom images

The Bigger Picture

This update is part of Microsoft’s broader strategy to make Autopilot Device Preparation the standard provisioning quality gate across all Windows 365 scenarios. What started as a Frontline shared mode feature has now expanded to Enterprise, Flex, Reserve, Cloud Apps, and — with this update — Citrix-integrated Cloud PCs. The message is clear: every Cloud PC, regardless of how it’s delivered, should be fully configured and secure before users ever sign in.

For organizations running Citrix alongside Windows 365, this closes a meaningful gap. No longer do you need to choose between the delivery flexibility of Citrix and the provisioning reliability of DPP. You can have both — a Citrix-delivered Cloud PC that’s been validated, secured, and configured to your organization’s baseline before it’s ever available to a user.

That’s a significant step toward truly consistent, secure Cloud PC lifecycle management — regardless of the delivery mechanism.


For more information, see the Windows 365 What’s New documentation, Use Autopilot device preparation with Cloud PCs, and Overview of Windows Autopilot Device Preparation.

Follow @kkaminski on X for daily Windows 365 updates and analysis.