Where Them
Logs App
WTLA-01

Windows Autopilot

10 log locations · Windows

Microsoft Corporation · Vendor documentation

Where Windows Autopilot keeps its logs

Windows Autopilot logs to Event Viewer > Applications and Services Logs > Microsoft > Windows > ModernDeployment-Diagnostics-Provider > Autopilot on Windows. 9 other Windows log locations are recorded below, including paths for Hybrid join connector server.

Paths are printed exactly as Windows Autopilot writes them. Environment variables like %LOCALAPPDATA% and $XDG_STATE_HOME are never expanded, so a path can be pasted straight into a shell. Where a path differs between installer types or shipping flavours, each one is racked as its own card below - why that happens.

Finding your way around Windows.

WIN

Windows Autopilot - Windows

Microsoft Corporation
Autopilot profile and OOBE eventsEvent Viewer > Applications and Services Logs > Microsoft > Windows > ModernDeployment-Diagnostics-Provider > Autopilot
MDM enrollment eventsEvent Viewer > Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin
MDM enrollment debug eventsEvent Viewer > Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Debug- Off by default. Enable it in Event Viewer with View > Show Analytic and Debug Logs, then right-click Debug > Enable Log.
MDM diagnostics reportC:\Users\Public\Documents\MDMDiagnostics- Written by mdmdiagnosticstool.exe or Settings > Accounts > Access work or school > Info > Create report.
Microsoft Entra join events%windir%\System32\winevt\Logs\Microsoft-Windows-AAD%4Operational.evtx
Provisioning events%windir%\System32\winevt\Logs\Microsoft-Windows-Provisioning-Diagnostics-Provider%4Admin.evtx
DiagnosticLog CSP traces%ProgramData%\Microsoft\DiagnosticLogCSP\Collectors\*.etl
MDM client logs%windir%\system32\config\systemprofile\AppData\Local\mdm\*.log
WIN

Windows Autopilot - Windows (Hybrid join connector server)

Hybrid join connector serverMicrosoft Corporation
Intune Connector for Active DirectoryEvent Viewer > Applications and Services Logs > Microsoft > Intune > ODJConnectorService
ODJConnectorUI.logC:\Program Files\Microsoft Intune\ODJConnector\ODJConnectorEnrollmentWizard

How to turn on debug logging for Windows Autopilot

  1. Windows 11: in the Intune ESP profile, set Show app and profile configuration progress to Yes.
  2. Windows 11: in the same profile, set Turn on log collection and diagnostics page for end users to Yes.
  3. For more MDM detail, open Event Viewer and choose View > Show Analytic and Debug Logs.
  4. Go to Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider, right-click Debug and choose Enable Log.
  5. Remotely, set ./Vendor/MSFT/DiagnosticLog/EtwLog/Channels/Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%2FDebug/State to true with the DiagnosticLog CSP.
  6. Automatic capture on Autopilot failure is on by default. Check it in the Intune admin center under Tenant administration > Device diagnostics.

How to collect Windows Autopilot logs

  1. Windows 11, during the ESP: select View Diagnostics or press Ctrl+Shift+D, then export the logs.
  2. When the ESP times out, select Collect logs and copy the files to a USB drive.
  3. During OOBE, press Shift+F10 to open a command prompt.
  4. User-driven mode: run mdmdiagnosticstool.exe -area Autopilot -cab <pathToOutputCabFile>.
  5. Self-deploying, pre-provisioning or any physical device: run mdmdiagnosticstool.exe -area Autopilot;TPM -cab <pathToOutputCabFile>.
  6. Enrollment and provisioning together: run mdmdiagnosticstool.exe -area "DeviceEnrollment;DeviceProvisioning;Autopilot" -zip "c:\users\public\documents\MDMDiagReport.zip".
  7. After sign-in: open Settings > Accounts > Access work or school, select the account, choose Info > Create report, then Export.
  8. Open C:\Users\Public\Documents\MDMDiagnostics to find the report.
  9. Intune: open Devices > All devices, select the device and choose Diagnostics > Download for logs captured after an Autopilot failure.
  10. To read a cab, run Install-Script -Name Get-AutopilotDiagnostics -Force, then Get-AutopilotDiagnostics -CABFile <pathToOutputCabFile>.