| # | Action | Notes |
|---|---|---|
| 1 | Confirm the employee has been officially rehired by HR | Do not proceed on a verbal request alone |
| 2 | Locate the ServiceNow New Joiner form or HR request ticket | This must exist before any account changes are made |
| 3 | Note the confirmed start date | This governs when sign-in is re-enabled in Phase 4 |
| 4 | Record the approved job title, department, manager, and office location | Required for attribute updates in Phase 2 |
2.1 — Remove from Disabled Mailboxes group (Intune)
| # | Action | Notes |
|---|---|---|
| 1 | Open Microsoft Intune Admin Center | intune.microsoft.com |
| 2 | Navigate to Groups | |
| 3 | Locate the Disabled Mailboxes group | Search by group name |
| 4 | Remove the user from the group | Members tab → select user → Remove |
2.2 — Enable the user account (Entra ID)
| # | Action | Notes |
|---|---|---|
| 1 | Open Entra ID Admin Center | entra.microsoft.com |
| 2 | Search for the user account | Search by name, UPN, or employee ID |
| 3 | Open the user record and set Account Enabled = Yes | Properties tab → Edit → Account enabled toggle |
2.3 — Clear old authentication data
| # | Action | Notes |
|---|---|---|
| 1 | In Entra ID, open the user record and navigate to Security → Authentication Methods | |
| 2 | Remove all existing MFA methods | Delete each registered method (Authenticator app, phone, email, etc.) |
| # | Action | Notes |
|---|---|---|
| 1 | In Microsoft 365 Admin Center, open the user profile | admin.microsoft.com → Users → Active Users |
| 2 | Toggle Block sign-in: ON | The account is configured but inaccessible |
| # | Action | Notes |
|---|---|---|
| 3 | In Entra ID, remove the user from any MFA enforcement groups | e.g. CA-MFA-AllUsers or similar Security Group–based MFA groups |
| 4 | Confirm the user is not targeted by any active MFA Conditional Access policies | Check Entra ID → Security → Conditional Access |
5.1 — Generate temporary password for build
| # | Action | Notes |
|---|---|---|
| 1 | In Entra ID or M365 Admin Center, generate a temporary password for the account | |
| 2 | Ensure "Require password change at next sign-in" is UNCHECKED | If checked, Autopilot will fail at OOBE — the forced change prompt cannot be completed during the build |
5.2 — Build the laptop via Autopilot
| # | Action | Notes |
|---|---|---|
| 1 | Power on the device and proceed through the Out-of-Box Experience (OOBE) | Autopilot will intercept and redirect to the R&R deployment profile |
| 2 | Sign in with the user's UPN and temporary password | No MFA prompt should appear (MFA groups removed in Step 4) |
| 3 | Allow Autopilot to complete — loading user profile, baseline apps, and Intune configurations | Do not interrupt the build process |
| 4 | Once the build completes, do not allow further sign-in to the device | The device is now ready for the user — no additional IT sign-in needed |
| # | Action | Notes |
|---|---|---|
| 1 | Return to Microsoft 365 Admin Center → Block sign-in: ON | Re-block immediately after build completes |
| 2 | Enable "Require password change at next sign-in" | User will be forced to set their own password when they first log in on day one |
| 3 | Do NOT add the user back to MFA groups yet | MFA re-registration happens at device collection — not before |
7.1 — Issue a new temporary password
| # | Action | Notes |
|---|---|---|
| 1 | Generate a new temporary password in M365 Admin Center | Different from the Autopilot build password |
| 2 | Provide this password to the user in person during the handover meeting | Do not send via email to an external address |
7.2 — Unblock sign-in & add to MFA groups
| # | Action | Notes |
|---|---|---|
| 1 | In M365 Admin Center, toggle Block sign-in: OFF | Do this immediately before handing over the device |
| 2 | In Entra ID, add the user back to MFA enforcement group(s) | The same groups they were removed from in Step 4 |
7.3 — User logs in and completes setup
| # | Action | Notes |
|---|---|---|
| 1 | User signs in with the temporary password | |
| 2 | User is prompted to change their password | Enforced by the setting applied in Step 6 |
| 3 | User is prompted to register MFA | Triggered by Conditional Access targeting the MFA group |
| 4 | Device becomes fully operational | Compliance and CA policies will apply on next sync |
Soft-deleted mailbox — If the mailbox was soft-deleted during offboarding, recover it from Exchange Admin Center → Deleted Mailboxes before enabling the account. Otherwise a new empty mailbox is created and historical data is lost.
Conflicting CA rules — Check for any residual Conditional Access rules targeting terminated or inactive accounts (e.g. a "Block leaver" named location or device state policy). These may still apply and block the user post-reactivation.
Autopilot profile — Ensure a valid Autopilot deployment profile exists and is assigned to the device or the user's group before starting the build. A missing profile causes OOBE to proceed as a standard Windows setup, bypassing Intune enrolment.
Replication delay — Allow 20–30 minutes after major attribute changes (department, licences, group memberships) before verifying downstream effects in Teams, SharePoint, and dynamic groups.