For organizations that deliver Windows 365 Cloud PCs through Citrix, provisioning has always had a gap. Standard Windows 365 Cloud PCs — Enterprise, Flex, and Reserve — could leverage Autopilot Device Preparation (DPP) to ensure apps and scripts were installed before users sign in. But Cloud PCs configured for Citrix integration? They were left out of that workflow.
That changes with Microsoft’s latest update, announced the week of July 27, 2026. Autopilot Device Preparation is now supported for Cloud PCs with Citrix integration, bringing the Citrix provisioning experience in line with every other supported Windows 365 deployment scenario.
Let’s break down what this feature does, why it matters, and how to prepare your environment.
What Is Autopilot Device Preparation?
Autopilot Device Preparation (AP-DP) is Microsoft’s lightweight, cloud-native deployment method in Intune. Unlike traditional Autopilot — which was designed for physical device enrollment — AP-DP is purpose-built for cloud workloads like Windows 365 Cloud PCs. It works by holding a Cloud PC in a “Preparing” state during provisioning while required Intune apps, PowerShell scripts, and configurations are installed. Only when those requirements are met is the Cloud PC marked as provisioned and made available to users.
AP-DP was initially available for Windows 365 Frontline shared mode. It later expanded to Enterprise, Flex Dedicated, Cloud Apps, and Windows 365 Reserve. Now, with this update, it extends to Cloud PCs with Citrix integration — closing the last major gap in DPP coverage across Windows 365 scenarios.
How It Works
The workflow is straightforward and mirrors the existing DPP experience for standard Cloud PCs:
1. Create a Device Preparation Policy in Intune
Navigate to Devices → Windows → Enrollment → Device preparation policies in the Microsoft Intune admin center. Choose Automatic mode (the mode used for Cloud PC scenarios), then configure:
- Required apps — up to 10 Intune apps that must install successfully
- Required scripts — up to 10 PowerShell scripts that must run successfully
- Other supported configurations — security agents, configuration baselines, etc.
2. Link the Policy to Your Windows 365 Provisioning Policy
When creating or editing a Windows 365 provisioning policy for Citrix-integrated Cloud PCs, on the Configuration tab, select the Autopilot Device Preparation policy you created. Configure:
- Minutes allowed before device preparation fails — a timeout for the DPP phase
- Prevent users from connecting to Cloud PC upon installation failure or time-out — optionally gate sign-in on success
3. Provisioning Flow
When Windows 365 provisions a Citrix-integrated Cloud PC:
- The Cloud PC is created as usual
- DPP automatically kicks off, installing required apps and scripts
- The Cloud PC shows a “Preparing” status in Intune
- On success, the Cloud PC is marked as Provisioned and users can sign in
- On failure or timeout, the Cloud PC is either marked Failed (if gating is enabled) or Provisioned with warnings (if gating is disabled)
4. Monitor in Intune
Device Preparation deployment status is visible at Devices → Enrollment → Monitor → Windows Autopilot Device Preparation deployment status in the Intune admin center.
Why This Matters for Citrix Environments
Consistent Baselines Across All Cloud PCs
Organizations using Citrix to deliver Windows 365 Cloud PCs can now guarantee that every Cloud PC meets the same app and configuration baselines before first user logon. This eliminates “day-one drift” — the scenario where users receive a half-configured desktop and software arrives later through background Intune processing.
Reduced Reliance on Custom Images
One of the key benefits Microsoft has highlighted for DPP across all Cloud PC scenarios is the ability to move app installation and configuration logic into Intune rather than baking it into custom images. For Citrix environments — where custom image management has historically been more complex due to layering and provisioning concerns — this is particularly valuable. You can maintain a smaller image set and use AP-DP to apply apps and configurations at provisioning time, simplifying lifecycle management.
Security Gating Before Access
With DPP gating enabled, Citrix-integrated Cloud PCs are not available to users until all required security tools — EDR agents, VPN clients, configuration baselines, hardening scripts — are installed and validated. This ensures that every Cloud PC exposed through Citrix meets your organization’s security compliance requirements before it’s accessible.
Unified Management Model
For organizations running a mix of physical endpoints (Autopilot-managed), standard Cloud PCs, and Citrix-delivered Cloud PCs, DPP provides a unified, Intune-centric deployment model. The same Device Preparation policy framework works across all scenarios, reducing administrative complexity and training overhead.
Requirements
To use DPP with Citrix-integrated Cloud PCs:
- OS: Windows 11 24H2 with KB5052093 or later (gallery images already include this update)
- Custom images: Must be based on Windows 11 24H2 media dated March 2025 or later with KB5052093 included
- Intune subscription with appropriate licenses
- Citrix integration configured for Windows 365
What IT Admins Should Do
1. Inventory Your Citrix Cloud PC Provisioning Scripts
Identify every app and script that currently runs during or immediately after provisioning for Citrix-integrated Cloud PCs. Classify each as required (must-install before access) vs. nice-to-have (can install later). Move the required items into a Device Preparation policy.
2. Create and Link a DPP Policy
In Intune, create a Device Preparation policy in Automatic mode with your required apps and scripts. Then link it to your existing Windows 365 provisioning policy for Citrix Cloud PCs on the Configuration tab.
3. Decide on Gating Behavior
Choose whether to block sign-in on DPP failure. For most organizations, the answer should be yes — if required security tools or apps fail to install, users should not be able to access the Cloud PC. Set the timeout to a value that gives your scripts enough time to complete without being so long that failed provisioning goes unnoticed.
4. Test with a Pilot Group
Before rolling out broadly, test the DPP-enabled provisioning with a small group of Citrix Cloud PCs. Monitor the “Preparing” status, verify app installation, and confirm that the end-user experience on first sign-in is smooth.
5. Update Provisioning Documentation
Update your runbooks and provisioning documentation to reflect the new DPP workflow for Citrix Cloud PCs. Document the required apps/scripts, the linked DPP policy, the timeout value, and the gating behavior.
6. Monitor Provisioning Success Rates
After enabling DPP, watch for any increase in provisioning failures or extended “Preparing” states. Use the Device Preparation deployment status dashboard in Intune to identify and troubleshoot issues.
Preparation Checklist
| Task | Priority | Notes |
|---|---|---|
| Inventory Citrix Cloud PC provisioning apps/scripts | Critical | Classify as required vs. optional |
| Create DPP policy in Intune (Automatic mode) | Critical | Include required apps and scripts only |
| Link DPP policy to Citrix Cloud PC provisioning policy | Critical | Configure on the Configuration tab |
| Enable sign-in gating on failure | High | Block access if required apps fail to install |
| Set appropriate timeout value | High | Balance script completion time vs. failure detection |
| Test with pilot group | High | Validate before broad rollout |
| Update provisioning documentation | Medium | Document DPP workflow, timeout, gating |
| Monitor provisioning success rates post-enablement | Medium | Watch for extended “Preparing” states or failures |
| Review custom image requirements | Low | Ensure Windows 11 24H2 with KB5052093 if using custom images |
The Bigger Picture
This update is part of Microsoft’s broader strategy to make Autopilot Device Preparation the standard provisioning quality gate across all Windows 365 scenarios. What started as a Frontline shared mode feature has now expanded to Enterprise, Flex, Reserve, Cloud Apps, and — with this update — Citrix-integrated Cloud PCs. The message is clear: every Cloud PC, regardless of how it’s delivered, should be fully configured and secure before users ever sign in.
For organizations running Citrix alongside Windows 365, this closes a meaningful gap. No longer do you need to choose between the delivery flexibility of Citrix and the provisioning reliability of DPP. You can have both — a Citrix-delivered Cloud PC that’s been validated, secured, and configured to your organization’s baseline before it’s ever available to a user.
That’s a significant step toward truly consistent, secure Cloud PC lifecycle management — regardless of the delivery mechanism.
For more information, see the Windows 365 What’s New documentation, Use Autopilot device preparation with Cloud PCs, and Overview of Windows Autopilot Device Preparation.
Follow @kkaminski on X for daily Windows 365 updates and analysis.