Earlier quoted context omitted.
> IT never even has to be in the same zipcode as the new laptop or ever remotely connect to it to perform maintenance tasks. That sounds nice, but that's not exactly a feature specific to AD. All perfectly possible with a couple well placed scripts and some remote logins. > TPM-backed certificates/WebAuthn for securing web apps or anything behind MS-linked SSO Yeah this is the overengineered stuff that is therefore d…
How are you having Dell ship a brand new laptop to a non-technical user and having that machine configured/software installed with a couple of scripts? Autopilot locks Windows OOBE to your Intune instance based on the serial number. The user only has to know their email and a temp password if they're new, or existing login/otp if not. The device can be remotely wiped, and it will start back over at the OOBE (Windows…
Have the vendor ship your image?
Or provide your own bootstrap.
Probably something with netboots as well...
If your point is there is a heavy vendor presence, yeah, sure.
But yes, it is all scriptable. Someone has to provision the device, whether that's you or Dell, that's your choice as the customer, not some inherent superiority of one system over another.