A quiet but important update appeared on the Windows 365 What’s New page this week: Autopilot Device Preparation (DPP) has reached general availability for Windows 365 Government environments. If you manage Cloud PCs in GCC High or DoD tenants, this is the update that finally brings your provisioning experience closer to parity with commercial environments.

What Changed

As of the week of August 10, 2026, Autopilot Device Preparation is now generally available for Windows 365 Enterprise and Windows 365 Flex (dedicated mode) in Government environments — specifically GCC High and DoD.

IT administrators can use device preparation policies to ensure required Intune apps and scripts are applied to Cloud PCs during provisioning, before they’re made available to users. Cloud PCs show a “Preparing” status while setup is in progress.

Why This Matters for Government Customers

Government cloud environments have historically lagged behind commercial environments when it comes to provisioning automation. The legacy Autopilot (v1) was never available in GCC High. Autopilot Device Preparation (v2) was designed from the ground up to meet government cloud requirements, and Microsoft has been progressively expanding its availability over the past year.

With this GA, government organizations running Windows 365 can now:

  • Standardize Cloud PC provisioning — attach a DPP policy to your Windows 365 provisioning policy so every new Cloud PC automatically receives required apps, security configurations, and PowerShell scripts before users connect
  • Reduce custom image dependency — use standard gallery images and layer on required software via Intune policies instead of maintaining bloated custom images
  • Improve provisioning reliability — Cloud PCs stay in a “Preparing” state until all required apps and scripts are installed and validated, reducing the chance users connect to an incompletely configured Cloud PC
  • Streamline compliance — security tools, compliance configurations, and management agents are installed during provisioning, ensuring every Cloud PC meets organizational requirements from first boot

The Government Cloud Catch: What’s Still Not Available

DPP in GCC High and DoD has important limitations compared to commercial environments. Admins planning government Cloud PC deployments should be aware of these constraints:

Supported

  • User-driven deployments
  • Microsoft Entra ID (Azure AD) join only — no Hybrid Join
  • Required app installation during provisioning
  • PowerShell script execution during provisioning
  • Linking DPP policies to Windows 365 Enterprise and Flex dedicated provisioning policies

Not Available in GCC High/DoD

  • Self-deploying mode — kiosk-style automated deployment without user interaction
  • Pre-provisioning mode — technician-led pre-staging before user delivery
  • Hardware hash registration — pre-registering device IDs is not supported
  • Windows 365 Flex shared mode — not supported for GCCH and DoD
  • Windows Autopatch — feature updates, quality updates, expedite updates, and driver updates are not available
  • OOBE customization — customizing the out-of-box experience is not available

These limitations mean that while DPP significantly improves the government Cloud PC provisioning experience, government admins still need a more hands-on approach than their commercial counterparts. Specifically, you can’t pre-register devices via hardware hash, so provisioning relies on user-driven enrollment triggered when a target user signs in.

How to Set Up DPP for Windows 365 Government Cloud PCs

Prerequisites

  1. Windows 11 version 24H2 or later (or 23H2 with KB5035942 or later)
  2. Microsoft Entra ID join — hybrid join is not supported in GCC High
  3. Intune enrollment — automatic MDM enrollment must be configured
  4. Appropriate licensing — Windows 365 Enterprise or Flex dedicated + Intune
  5. Government cloud tenant — GCC High or DoD

Configuration Steps

  1. Create a device group in Microsoft Entra ID. This group will receive devices as they complete provisioning. Assign your Intune device policies (security baselines, compliance policies, app deployments) to this group.

  2. Create a user group in Microsoft Entra ID. Only users in this group will trigger the Device Preparation policy during provisioning.

  3. Create a Device Preparation Policy in Intune:

    • Navigate to Devices > Windows > Windows enrollment > Device preparation policies > Create
    • Set deployment mode to User-driven
    • Set join type to Microsoft Entra joined
    • Set user account type to Standard User (or Administrator if required)
    • Add required applications that should install before the user reaches the desktop
    • Assign to the user group from step 2
  4. Assign required apps to the device group. Even though apps are listed in the DPP policy, Intune still needs those apps deployed as “Required” to the device group for them to actually push down.

  5. Link the DPP policy to your Windows 365 provisioning policy. In the Intune admin center, go to Provision Cloud PCs > Provisioning policies, select your policy, and link the Device Preparation policy.

  6. Pilot first. Test with a small batch (5–10 Cloud PCs) before scaling to validate that your DPP policy, app assignments, and network configuration work correctly. Monitor the “Preparing” status and watch for any Cloud PCs that get stuck — a misconfigured DPP policy can leave Cloud PCs in an indefinite preparing state.

Practical Scenarios for Government Cloud PC Deployments

Scenario 1: Agency-Wide Standardization

A federal agency running Windows 365 Enterprise in GCC High wants every new Cloud PC to arrive with their standard security toolset — CrowdStrike agent, required PowerShell modules, M365 apps, and a custom compliance script — without maintaining a custom image. With DPP GA, they attach a device preparation policy to their provisioning policy. New Cloud PCs provision from the standard gallery image, install all required apps and scripts during the “Preparing” phase, and only become available to users once everything is validated.

Scenario 2: Defense Contractor Onboarding

A defense contractor operating in a DoD environment needs to rapidly provision 200 Cloud PCs for a new classified project. Using Windows 365 Flex dedicated mode with DPP, they create a provisioning policy linked to a DPP policy that installs project-specific security tools and compliance scripts. The 200 Cloud PCs provision in bulk, each going through the DPP-guided preparation phase before being released to users.

Scenario 3: Compliance-Driven Refresh

A government organization needs to ensure all Cloud PCs meet updated security baselines. Instead of reimaging existing Cloud PCs, they update the DPP policy with the new required security tools. New Cloud PCs provisioned after the policy update automatically receive the updated toolset. Existing Cloud PCs can be deprovisioned and re-provisioned to go through the updated DPP flow.

What Admins Should Do Now

  1. Update your government Cloud PC provisioning documentation. If your runbooks still mention the lack of DPP support in GCC High/DoD, it’s time to update them.

  2. Audit your custom images. If you’re maintaining custom images for government Cloud PCs primarily to include required apps, evaluate whether DPP policies can replace that need. Standard gallery images + DPP policy is a more maintainable approach.

  3. Plan your DPP policy architecture. Map out which apps, scripts, and configurations should be in the DPP policy vs. assigned separately via Intune. Remember: apps in the DPP policy must also be assigned as “Required” to the device group.

  4. Pilot with a small group. Start with 5–10 Cloud PCs to validate your DPP configuration. Monitor provisioning time — DPP adds time to provisioning since apps install before the Cloud PC is marked as ready.

  5. Check your Intune government service matrix. Review the Microsoft Intune Government Service documentation for the latest feature availability in GCC High/DoD, as capabilities continue to evolve.

Looking Ahead

This GA brings Windows 365 Government provisioning closer to commercial parity, but gaps remain. Self-deploying mode, pre-provisioning, and hardware hash registration are still on the roadmap. Microsoft has indicated these features are “in planning” for GCC High/DoD, so government admins should watch for future updates.

The broader trend is clear: Microsoft is systematically closing the feature gap between commercial and government clouds for Windows 365. Each quarterly update brings government environments closer to the experience commercial customers have enjoyed for months. For organizations that have been holding back on Windows 365 deployments in GCC High due to provisioning automation limitations, DPP GA removes a significant blocker.


Need help deploying Windows 365 in GCC High or DoD environments? Big Hat Group specializes in Microsoft cloud deployments for government and regulated industries. Follow the conversation on X for daily Windows 365 updates.