Back to all articles
Technical Guide

Sample SOP for Laptop Deployment

D
Derek
Author & Contributor
September 12, 20265 min read
Table of Contents

Document ID: SOP-IT-042

Title: Provisioning New Laptop Hardware via USB ISO Image and Windows Configuration Designer

Category: IT Service Desk / Desktop Support

Version: 2.2

Target Audience: Tier 1 & Tier 2 Helpdesk Technicians

1. Purpose & Scope#

This Standard Operating Procedure outlines the required steps for Helpdesk technicians to flash an operating system ISO onto a bootable USB drive, deploy it to new or re-imaged laptops, and apply a Windows Configuration Designer (WCD) provisioning package (.ppkg).

Using Windows Configuration Designer automates local admin creation, Wi-Fi profile deployment, bloatware removal, and domain/Entra ID enrollment without needing to maintain monolithic custom disk images.

2. Prerequisites & Required Equipment#

Hardware

USB Flash Drive (16 GB or larger, USB 3.0+)

All existing data on this drive will be erased.

Hardware

Target Laptop & AC Power Adapter

Keep plugged into power throughout imaging.

Software

Approved Enterprise OS ISO File

Downloaded from internal deployment share or vendor portal.

Software

Flashing Utility (e.g., Rufus)

Rufus 4.x or later recommended.

Software / Config

Windows Configuration Designer (.ppkg)

Pre-built enterprise provisioning package stored on deployment share or root of USB.

Access

Administrator Rights

Required on the staging workstation.

3. Step-by-Step Procedure#

1.Prepare Bootable USB and Copy WCD Package:Destructive process - back up any files on the flash drive first.

Insert the USB flash drive into your staging workstation.

Launch Rufus with Administrator privileges.

Under Device, select your target USB flash drive.

Click Select under Boot selection and browse to the official OS .iso file.

Configure partition settings:

Partition scheme: GPT

Target system: UEFI (non CSM)

File system: NTFS

Click Start and allow Rufus to finish flashing.

Once complete, copy your enterprise Windows Configuration Designer package file (.ppkg) directly into the root folder of the newly flashed USB drive (e.g., D:\Corporate_Provisioning.ppkg).

Safely eject the USB drive.

2.Configure Target Laptop BIOS/UEFI Settings:Ensures hardware compatibility and secure boot authorization.

Connect the target laptop to AC power and insert the prepared USB drive into a USB 3.0 port.

Power on the laptop and immediately tap the vendor-specific BIOS setup key:

Dell: F2

Lenovo: F1 or Fn + F1

HP: F10

Navigate to Storage/SATA Configuration and verify controller mode:

Change from RAID / Intel VMD to AHCI if the Windows installer fails to detect the NVMe drive in later steps.

Ensure Secure Boot is enabled.

Save changes and exit setup.

3.Boot to USB and Install Base OS:Select the boot drive via the vendor one-time boot menu.

Power on the system while tapping the One-Time Boot Menu key:

Dell: F12

Lenovo: F12

HP: F9

Select the EFI USB device from the list and press Enter.

Choose Custom: Install Windows only (advanced) when prompted.

At the drive partition screen, delete all existing partitions on Drive 0 until only Drive 0 Unallocated Space remains.

Highlight Drive 0 Unallocated Space and click Next to begin OS installation.

4.Apply Provisioning Package via Windows Configuration Designer:Automates initial device customization and enrollment at the OOBE screen.

Allow the installer to complete and reboot into the initial Out-Of-Box Experience (OOBE) screen (where Windows asks to select a region/language).

Leave the USB drive containing your .ppkg file inserted into the laptop (or insert it now if disconnected).

Press the Windows Key 5 times rapidly.

When the Setup using a provisioning package screen appears, select the inserted USB drive and choose your .ppkg file.

If prompted, enter the decryption password for the package.

Click Yes, add it to confirm.

Windows Configuration Designer will apply configured policies, which may include:

Setting computer naming conventions

Creating local administrative accounts

Pre-configuring corporate Wi-Fi SSIDs/certificates

Joining Microsoft Entra ID / Active Directory

Installing core software packages

Wait for the automated setup to finish and reboot.

5.Post-Provisioning Verification:Complete final driver checks and service verification.

Log in using the local admin credentials or domain account created by the .ppkg file.

Open Settings > Accounts > Access work or school and confirm successful enrollment to Entra ID / MDM / Active Directory.

Run manufacturer update tools (Dell Command | Update, Lenovo System Update, etc.) to verify all system drivers and firmwares are fully updated.

Check Device Manager to ensure no unknown devices or warning indicators remain.

4. Troubleshooting Windows Configuration Designer (.ppkg)#

5-tap shortcut does not trigger provisioning menu

System is past the initial OOBE setup screen or Windows edition is Home.

Ensure you trigger the 5-tap shortcut on the very first region/keyboard selection screen. Verify Windows Enterprise or Pro edition is installed.

Error code 0x80070057 during package application

Invalid setting, expired certificate, or syntax conflict in .ppkg.

Re-open the project in Windows Configuration Designer, validate settings against target OS build, and rebuild the .ppkg.

Wi-Fi / Network profile fails to connect after provisioning

Incorrect SSID/security password or missing ROOT CA certificate in WCD project.

Ensure the root certificate and network keys are correctly embedded in the WCD project's Customizations > ConnectivityProfiles.