A Windows deployment approach where a device's hardware identity is pre-registered with the organisation's tenant, so a brand-new machine configures itself over the internet at first boot — joining Entra ID, enrolling in Intune and applying policy without an image or on-site IT. Variants include user-driven, pre-provisioning and self-deploying modes, the latter relying on TPM attestation to authenticate the device itself.