> For the complete documentation index, see [llms.txt](https://docs.autopilotmonitor.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.autopilotmonitor.com/reference/settings.md).

# Settings Reference

Every tenant setting explained — access, device validation, notifications, agent behavior, diagnostics, data retention, and offboarding.

The **Settings / Configuration** area (managed by Tenant Admins; Operators and Viewers see it read-only with secrets redacted, except Bootstrap Sessions for Operators if granted) controls how Autopilot Monitor behaves for your tenant. Settings are grouped into **Tenant**, **Agent**, **Maintenance**, and **Reporting**.

{% hint style="info" %}
Two groups are tied to your [plan](/plans.md): **Bootstrap Sessions** and **Unrestricted Mode** are Pro-plan capabilities that are additionally activated on request — they only appear after the platform operators have enabled them for your tenant.
{% endhint %}

## Tenant

### Access Management

| Setting              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Team Members & Roles | Add members by UPN, assign **Admin**, **Operator**, or **Viewer**, enable/disable accounts, and grant bootstrap-token management. The first user to sign in becomes Admin automatically. Switch the form to **Service principal** to add an application from your Entra tenant (by application ID) as a read-only member for unattended MCP automation, or an app of your own whose users connect through it (always read-only for them). See [Roles & Permissions](/concepts/roles-and-permissions.md), [Service principals and automation](/integrations/ai-integration-mcp.md#service-principals-and-automation) and [Your own app on behalf of users](/integrations/ai-integration-mcp.md#your-own-app-on-behalf-of-users). |

### Enrollment Device Validation

| Setting                         | Default  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Autopilot Device Validation     | Disabled | Only devices registered as Windows Autopilot devices in your Intune tenant may register sessions. Requires admin consent for the Graph permission `DeviceManagementServiceConfig.Read.All` (read-only).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Corporate Identifier Validation | Disabled | Validates devices against Intune Corporate Device Identifiers (manufacturer, model, serial). Same Graph permission.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Device Association Validation   | Disabled | Validates devices against your tenant's [Windows Autopilot device association](https://learn.microsoft.com/autopilot/device-preparation/device-association/overview) list (Intune: Devices → Enrollment → Device association), matched by serial number. Same Graph permission. Details: [Autopilot Device Preparation](/getting-started/autopilot-device-preparation.md#device-association).                                                                                                                                                                                                                                                                                                   |
| Windows 365 Cloud PC Validation | Disabled | Fallback for Cloud PCs, which are never Autopilot-registered: validates the device against your tenant's Cloud PC inventory, matched by the Intune device id from the device's MDM certificate. Requires the optional add-on permission `CloudPC.Read.All` (feature `W365CloudPcValidation`, see [Optional Graph Permissions](/reference/optional-graph-permissions.md)). Details: [Windows 365 Cloud PCs](/getting-started/windows-365-cloud-pcs.md).                                                                                                                                                                                                                                          |
| Intune Enrollment Validation    | Disabled | Accepts every device enrolled in your tenant's Intune, matched by the Intune device id from the device's MDM certificate. No Autopilot registration, corporate identifier or device association is needed. Checked last, only when no other method matched. It reaches as far as your Intune enrollment restrictions: if personal devices may enroll, they are accepted too. Requires the optional add-on permission `DeviceManagementManagedDevices.Read.All` (feature `IntuneDeviceBinding`, see [Optional Graph Permissions](/reference/optional-graph-permissions.md)). Details: [Autopilot Device Preparation](/getting-started/autopilot-device-preparation.md#without-pre-registration). |

{% hint style="warning" %}
**At least one validation method must be enabled** — with all of them off, the backend rejects all agent requests. This is the consent gate described in [Portal Setup](/getting-started/portal-setup.md).
{% endhint %}

### Hardware Whitelist

| Setting               | Default                                      | Description                                                                                             |
| --------------------- | -------------------------------------------- | ------------------------------------------------------------------------------------------------------- |
| Allowed Manufacturers | `Dell*, HP*, Lenovo*, Microsoft Corporation` | Comma-separated manufacturer names permitted to register sessions; wildcards supported. `*` allows all. |
| Allowed Models        | `*`                                          | Same mechanics for device models, e.g. `Latitude*,EliteBook*`.                                          |

**Devices with Incompatible TPM** — this section additionally shows devices from the last 14 days whose TPM cannot produce the RSA-PSS signature that Windows 11 25H2 and later prefer for TLS client authentication. On such a device Windows withholds the Intune certificate, the agent can never authenticate, and the enrollment is therefore never monitored. Remediation is a TPM firmware update from the vendor, or replacing the device. The panel only appears when a device is affected, and the reported serial, manufacturer, and model are self-reported by the device before authentication — hence the *Unverified* label.

### Notifications

| Setting                             | Description                                                                                                                                                                                                                                                                                                                                                                                                         |
| ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Notification Provider               | **Microsoft Teams (Workflow Webhook)** — recommended, free, no Power Automate Premium needed · **Microsoft Teams (Legacy Connector)** — deprecated by Microsoft, existing configs keep working · **Slack** (Incoming Webhook) · **Generic JSON webhook** — stable JSON payload for ticketing/automation systems, supports custom HTTP headers (e.g. `Authorization`) · **Discord** (channel webhook, embed format). |
| Webhook URL                         | The URL generated during provider setup.                                                                                                                                                                                                                                                                                                                                                                            |
| Signing Secret                      | Generic JSON provider only, optional. When set, requests carry `X-AutopilotMonitor-Signature` (HMAC-SHA256) so the receiving endpoint can [verify authenticity](/integrations/notifications.md#verifying-signed-requests).                                                                                                                                                                                          |
| Notify on Start / Success / Failure | Which session events trigger a notification. Keep *Failure* on so broken enrollments surface without watching the portal.                                                                                                                                                                                                                                                                                           |
| Send Test Notification              | Fires a sample message to verify the configuration.                                                                                                                                                                                                                                                                                                                                                                 |

Setup walkthroughs per provider: [Notifications](/integrations/notifications.md).

### SLA Targets

Define your enrollment SLA thresholds (e.g. target duration and success rate); the [SLA Compliance](/portal-guide/sla-compliance.md) view reports against them.

### Contact

| Setting               | Description                                                                                                                                                                                                                                                                                                    |
| --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Contact email address | Where we reach your organization about the service itself — a technical problem affecting your tenant, a security matter, or a change that needs an administrator's attention. Used for nothing else: never for marketing, and never shared. A shared team mailbox is a better choice than a personal address. |
| Company               | The name of your organization as our support engineers should refer to it. Used only alongside the contact address for service and support matters; never shared.                                                                                                                                              |

On the Community plan both fields are optional; leaving them empty only means there is no way to reach you before acting on a problem affecting your tenant. Both are required before starting a Pro trial or moving to Pro — the Plan section tells you what is still missing — so a paying tenant is reachable and identifiable for support. If your organization gave a notification address during sign-up (tenant activation), that address is copied here once as the initial value and is yours to change from then on — it is not kept in sync afterwards.

### Optional Graph capabilities

Opt-in, per-tenant Microsoft Graph permission grants that unlock optional features (e.g. resolving Intune Platform Script + Remediation display names in timelines) without changing the published app manifest. Copy the ready-made grant command, run it as a tenant admin, and refresh the status here. Full walkthrough: [Optional Graph Permissions](/reference/optional-graph-permissions.md).

### Bootstrap Sessions *(Pro plan — on request)*

| Setting          | Description                                                                                                                                                                                                                                                                                                                                                                       |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Bootstrap Tokens | Create tokens that let devices register **before** device validation applies (pre-MDM scenarios). Each token has a short code + URL + ready-to-use PowerShell command, a validity of 1 h to 7 days, a status (Active / Expired / Revoked), and a usage count. Tokens can be revoked at any time. Details: [Bootstrap Script & Tokens](/reference/bootstrap-script-and-tokens.md). |

## Agent

### Agent Parameters

| Setting                            | Default  | Description                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Self-Destruct on Complete          | Enabled  | The agent removes its scheduled task and files after enrollment. Recommended — the agent is temporary by design.                                                                                                                                                                                                                                                         |
| Keep Log File                      | Disabled | Preserve the agent's local log through self-destruct (troubleshooting).                                                                                                                                                                                                                                                                                                  |
| Reboot on Complete                 | Disabled | Reboot when enrollment completes; **Reboot Delay** 0–3600 s (default 10 s).                                                                                                                                                                                                                                                                                              |
| Geo-Location Detection             | Enabled  | IP-based public IP / approximate location / ISP lookup at enrollment time. Disable if outbound third-party requests are prohibited.                                                                                                                                                                                                                                      |
| Set Timezone Automatically         | Disabled | Sets the device timezone from the geolocation result (`tzutil /s`). Requires Geo-Location Detection.                                                                                                                                                                                                                                                                     |
| Set Delivery Optimization Group ID | Disabled | Sets the `DOGroupId` policy to a GUID fingerprinted from the local network (default gateway IP + MAC), so devices behind the same gateway form one Delivery Optimization peering group. Only takes effect when your Intune configuration sets DO Download Mode to Group (2). An existing `DOGroupId` or `DOGroupIdSource` policy is never overwritten.                   |
| Keep Awake During User-ESP         | Disabled | Holds the device awake (system and display) during the User-ESP / Account Setup phase so idle standby or sleep cannot stall app installs and account provisioning. Reboots are unaffected; the hold is released when the User-ESP page closes, or after a safety cap derived from the ESP timeout.                                                                       |
| IME Pattern Match Log              | Disabled | Writes matched IME log lines to `%ProgramData%\AutopilotMonitor\Logs\ime_pattern_matches.log` — the debugging tool for [IME Log Patterns](/rules/ime-log-patterns.md).                                                                                                                                                                                                   |
| Show Script Output (stdout)        | Enabled  | Shows PowerShell script stdout in the timeline. Disable if scripts may print sensitive data; stderr is always shown.                                                                                                                                                                                                                                                     |
| Log Level                          | Info     | Agent's own log verbosity: Info · Debug · Verbose · Trace. Raise only while diagnosing an agent issue.                                                                                                                                                                                                                                                                   |
| Show Enrollment Summary            | Disabled | Shows the end user a visual summary dialog after enrollment (success and failure). Requires the SummaryDialog companion. Sub-settings: **Auto-Close Timeout** (default 60 s; 0 = manual close), **Launch Retry Timeout** (default 120 s — retries while credential UI like Windows Hello locks the desktop), **Branding Image URL** (HTTPS URL to a 540 × 80 px banner). |

### Agent Collectors

| Setting               | Default       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| --------------------- | ------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Performance Collector | Enabled, 30 s | Periodic CPU/memory/disk/network snapshots (interval 30–300 s). Core collectors (enrollment tracking, Windows Hello detector) are always active.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| RealmJoin Watcher     | Disabled      | Tracks the RealmJoin client during provisioning — client version and release channel, deployment-phase changes, and per-package start and completion — so RealmJoin packages appear as their own rows in [Install Progress](/portal-guide/session-details-and-diagnosis.md) and in the [Software](/portal-guide/software-inventory-and-vulnerabilities.md#installs) view, and the enrollment is not reported complete while a RealmJoin deployment is still running (bounded by a safety timeout that extends while packages are still installing). Enable only for tenants that provision devices with RealmJoin; elsewhere it produces no signal. |
| Hello Wait Timeout    | 300 s         | How long the agent waits for Windows Hello after the ESP closes before it completes the enrollment with Hello recorded as timed out (30–3600 s). Values up to 300 s use the built-in 5-minute wait; larger values extend it, up to one hour.                                                                                                                                                                                                                                                                                                                                                                                                        |

### Agent Analyzers

| Setting                                     | Default  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Local Admin Analyzer                        | Enabled  | Detects pre-enrollment local admin accounts (a known Autopilot bypass) at enrollment start and completion. **Allowed Local Accounts** defines your expected accounts; built-in Windows accounts are always allowed. Entries support wildcards — `*` matches any sequence of characters, `?` exactly one (e.g. `adm-*` for generated admin accounts); matching is case-insensitive and covers account names and profile folders. Disabled accounts are checked as well (a dormant account can be re-enabled after enrollment), and every account's membership in the local **Administrators** group is reported — an unexpected account with admin membership raises the finding's confidence. Feeds the ANALYZE-ID-002 rule. |
| Software Inventory & Vulnerability Analyzer | Disabled | Collects installed software at start and completion, detects during-enrollment deltas, and correlates against NVD CVEs, CISA KEV, MSRC, and FIRST EPSS exploitation scores. Feeds the [Software Inventory](/portal-guide/software-inventory-and-vulnerabilities.md) view and ANALYZE-ID-003.                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Integrity Bypass Analyzer                   | Enabled  | Detects Windows 11 installations whose hardware gates were bypassed — LabConfig TPM / Secure Boot / CPU / RAM / disk bypass keys, the MoSetup upgrade flag, and the PC Health Check eligibility override — and flags suspicious post-OOBE `SetupComplete.cmd` / `ErrorHandler.cmd` scripts. Findings are correlated with the device's current TPM and Secure Boot state.                                                                                                                                                                                                                                                                                                                                                     |
| Detect OOBE Console Access (Shift+F10)      | Enabled  | Flags an interactive command prompt opened during enrollment — the classic Shift+F10 OOBE bypass — as a Warning event with the process signature; a startup scan of the `cmd.exe` prefetch artifact also covers a console opened before the agent was installed. Detection stops once the user's desktop arrives and is best-effort: it reports the console, it cannot block it. Disable only if your support staff knowingly use Shift+F10 during enrollment.                                                                                                                                                                                                                                                               |

### Diagnostics Package

| Setting                        | Default                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------------ | --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Upload destination             | Your own Azure Blob Storage | **Your own Azure Blob Storage** — agents upload via a Container SAS URL you provide; data never leaves your Azure tenant. **Hosted storage** (opt-in) — uploads to the built-in storage under a per-tenant prefix using short-lived (15 min), blob-scoped, write-only tokens minted per upload; no long-lived credentials. Switching destinations always requires an explicit admin action.                                                                                                                                                                                                                                                                                                                                    |
| Blob Storage Container SAS URL | —                           | Only for the own-storage destination. Needs **Read, Write, Create** at container level. Stored securely in the backend, never sent to devices — agents request a short-lived upload URL per upload. The portal shows a green/amber/red expiry indicator for the SAS.                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Upload Mode                    | Off                         | **Off** · **Always** · **On Failure Only** (recommended when storage cost matters). Any mode other than *Off* also enables [on-demand log collection](/portal-guide/session-details-and-diagnosis.md#on-demand-log-collection) from a running session's detail page; on-demand collection works in every enabled mode, including *On Failure Only*. In pre-provisioning (White Glove) scenarios, *Always* additionally uploads an intermediate package when the technician phase completes.                                                                                                                                                                                                                                    |
| Additional Log Paths           | —                           | Extra folders, files or wildcard patterns for the diagnostics ZIP, on top of the built-in collection and the platform-wide global paths — both are listed read-only above your own entries (the built-in list is collapsed; RealmJoin entries are collected only while the RealmJoin Watcher is enabled, the Device Preparation event log only on Device Preparation enrollments). A folder path collects every file in that folder. Environment variables are expanded; wildcards only in the last path segment; `%LOGGED_ON_USER_PROFILE%` targets the signed-in user's `AppData\Local`/`Roaming`; **Include Subfolders** collects recursively. Paths are validated against an agent-side allow-list of known log locations. |

### Unrestricted Mode *(Pro plan — on request)*

Relaxes the [Gather Rule guardrails](/rules/gather-rules.md#security-guardrails): any registry path, WMI query, and PowerShell/system command becomes available; file and diagnostics paths open up except `C:\Users` (always blocked for privacy). Dangerous operations (downloads, user creation, boot manipulation, persistence mechanisms) remain hard-blocked. Requires the Pro plan and platform-side activation before the toggle is visible; if the tenant leaves the Pro plan, the guardrails re-arm automatically.

## Maintenance

### Data Management

| Setting               | Default                             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| --------------------- | ----------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Data Retention Period | 90 days (7–90 Community, 7–365 Pro) | Sessions and events are deleted automatically after this period. The minimum is 7 days; the maximum depends on your [plan](/plans.md) — 90 days on Community, 365 days on Pro. Values outside that range are rejected.                                                                                                                                                                                                                                                                                                 |
| Session Timeout       | 5 hours (1–12)                      | *In Progress* sessions inactive past this threshold are reclassified from the evidence rather than blanket-failed: if Device Setup already finished they become **Awaiting User**, otherwise they eventually settle as **Incomplete** (a non-completion, **not** counted as a failure), and a session that later completes is reconciled to **Succeeded**. See [Sessions & Statuses](/concepts/sessions-and-statuses.md#timeouts-what-happens-to-stuck-sessions). Set it to match or slightly exceed your ESP timeout. |

### Danger Zone

| Action          | Description                                                                                                                                                                        |
| --------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Offboard Tenant | **Irreversibly deletes all tenant data** — sessions, events, rules, audit logs, configuration, and all member accounts — and signs you out. Requires typing `OFFBOARD` to confirm. |

### Delegated Access

| Setting                  | Description                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Who can read this tenant | Every organization with delegated (MSP) read access to your tenant, with the people behind it. Self-service delegations can be ended here at once; operator-provisioned ones via support. While a Pro organization manages your tenant, your tenant is on Pro (badge "Pro (MSP)") — the section says so.                                                                                                    |
| Tenants you manage (Pro) | Slot usage, the tenants you manage, single-use invitation links (valid 7 days), and which of your own members hold the read-only access. Removing a tenant keeps its slot occupied for 24 hours. Reads into managed tenants draw on your own AI (MCP) budgets; every purchased slot beyond the two included extends them. See [Roles and Permissions](/concepts/roles-and-permissions.md#msp-fleet-access). |

### AI Integration

| Setting                | Description                                                                                                                                                                                                                                                                                                                                                |
| ---------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| AI Integration         | The MCP server URL for Claude, ChatGPT, VS Code and other hosted assistants. Nothing to register; each user signs in with their own account. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#client-setup).                                                                                                                                 |
| Self-hosted AI clients | Only for an AI client your organization hosts itself: its exact OAuth callback URL and the client ID to configure in the client. One registration per tenant, more on request; deleting it stops that client's sign-ins within about a minute. Tenant Admins only. See [AI Integration (MCP)](/integrations/ai-integration-mcp.md#self-hosted-ai-clients). |

## Reporting

| Page      | Description                                                                                                                                                                                                                                                                                                  |
| --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| MCP Usage | Usage reporting for the [AI integration (MCP)](/integrations/ai-integration-mcp.md) — your own request volumes against both quota budgets and, for tenant admins, the organization budget by account. Budgets extended by purchased delegation slots show the breakdown. Visible when MCP access is enabled. |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.autopilotmonitor.com/reference/settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
