Imaging and zero-touch deployment are the two main ways organizations prepare computers for employees. Imaging copies a standard, prepared build (operating system, settings and often applications) onto a machine, usually by IT or a provider before it reaches the user. Zero-touch deployment, sometimes called autopilot-style enrollment, ships a device straight from the reseller or manufacturer to the employee; during initial setup or activation it enrolls in the organization’s management platform and downloads its settings, security policies and apps over the internet. Both aim to give every user a consistent, secure, ready-to-work device without hours of manual setup.
Not to be confused with zero-touch provisioning (ZTP), which automatically configures network devices such as routers and switches when they are first connected.
At a glance
- Imaging applies a prepared build to a device; zero-touch deployment configures a device remotely during initial setup or activation, in a sequence that varies by platform.
- Zero-touch relies on a management platform, an identity provider and devices registered to your organization at purchase.
- Many organizations use zero-touch for new devices and keep imaging for rebuilds, labs and specialized machines.
- Done well, both produce consistent, secured devices and shorten the wait for new hires.
- Re-imaging or remote reset is also how devices are wiped and reissued between users.
What problem it solves
Setting up a computer by hand, installing the operating system updates, joining it to the directory, adding security tools and applications and applying settings, can take hours per device. Done by different people, it also produces machines that are each slightly different, which makes support and security harder. With remote and hybrid staff, there is the added cost of shipping devices to IT and then on to the user.
Imaging solved the consistency problem by making one known-good build and copying it. Zero-touch deployment goes further by removing, in many cases, the need for IT to handle the device at all: it can ship directly to a new hire’s home, and the user completes setup, typically with their work account, to get a managed, ready device. That supports fast onboarding during growth, consistent security baselines and fewer support tickets caused by configuration drift.
How it works
Imaging. IT or a provider builds a reference image with the operating system, drivers, settings and standard applications, then deploys it to devices over the network or from local media. Traditional “thick” images contain everything; many teams now use thinner images and add applications afterward to keep the image easier to maintain. Images need regular updating as operating systems and applications change.
Zero-touch deployment. Devices are registered to the organization in the operating system or manufacturer’s enrollment program, commonly by the reseller at purchase. During initial setup or activation, the device recognizes it belongs to the organization, enrolls in unified endpoint management (UEM) or mobile device management (MDM), and receives its configuration profiles, security policies and applications. Apple, Google (for Android and ChromeOS) and Microsoft (for Windows) each offer programs of this kind, and the exact authentication and enrollment sequence varies by platform: some enroll before the user signs in, others as part of the first work-account sign-in.
Reset and reissue. When an employee leaves or a device is compromised, it can be wiped and re-imaged, or remotely reset so zero-touch setup runs again for the next user. That ties deployment to joiner-mover-leaver (JML) processes and to the wider device lifecycle.
Exceptions. Specialized hardware, shared devices, kiosks and environments without reliable internet may still be imaged or staged by hand or by a provider.
When it matters for buyers
- When hiring quickly or opening new sites. Zero-touch deployment removes IT handling as a bottleneck.
- When most staff work remotely. Direct-to-user shipping saves freight, time and a trip through the office.
- When buying hardware. Ask resellers whether they can register devices to your enrollment program at purchase.
- When choosing a UEM platform or field support provider. Capabilities for imaging, enrollment and staging vary.
- When devices are retired or reissued. Reset and re-imaging steps should link to secure IT asset disposition (ITAD) for devices leaving the business.
Questions to ask vendors
- Can you register our devices to our enrollment program at the point of sale?
- Which operating systems and device types does your zero-touch process support?
- Do you offer imaging or staging for devices that can’t use zero-touch?
- What happens if enrollment fails at the user’s home, and who supports them?
- How are applications and updates delivered after initial setup?
- How do you wipe and reissue devices between users, and what records do we get?
Our unified endpoint management overview covers platforms that run zero-touch enrollment and ongoing device management.
How it differs from unified endpoint management
Unified endpoint management (UEM) is the platform that manages devices throughout their working life: policies, updates, apps, security settings and remote wipe. Imaging and zero-touch deployment are about getting a device into a known, managed state at the start, or back to one when it is reissued. Zero-touch deployment depends on a UEM or MDM platform to work, while imaging can be done with separate tools. For company-owned phones and tablets, the same enrollment programs underpin models such as corporate-owned, personally enabled (COPE) devices. Once enrolled, each laptop, desktop and phone deployed this way becomes one of your managed endpoints.
