BlogScreenshots on your device
How to Capture Screenshots During Windows 11 Autopilot Deployment
Capture Windows 11 Autopilot and OOBE evidence with Snipping Tool, diagnostics exports, event logs, and reliable troubleshooting steps.
Capture the visible Windows 11 Autopilot screen with Windows+Shift+S when the Snipping Tool surface is available. For deployment evidence, pair that image with an Autopilot Diagnostics export opened with Ctrl+Shift+D during OOBE, then preserve both using the same timestamp.
1. Prepare Autopilot diagnostics before deployment
Configure diagnostics before you start the deployment so a failure does not leave you without logs.
- In the Windows Autopilot Enrollment Status Page (ESP) profile, enable Show app and profile configuration progress.
- Enable Turn on log collection and diagnostics page for end users.
- Use a Windows 11 user-driven deployment with a work or school account. Microsoft documents the diagnostics page for this mode.
- Prepare a clearly labeled USB flash drive for exported logs.
- Start a timestamped evidence record. Write down the device name or serial number, deployment profile, UTC time, and the milestone or error shown on screen.
Enabling the ESP progress view makes it easier to match a screenshot to the phase that was running. Diagnostics settings do not guarantee that the Snipping Tool capture surface will appear on every OOBE or ESP screen.
2. Capture an image of the deployment screen
Windows+Shift+S image capture
- Wait until the screen shows the milestone or error you need to document.
- Press Windows+Shift+S.
- Choose a rectangle, freeform, window, or full-screen snip.
- Select the deployment area, then save the result in Snipping Tool.
- Record the capture time in your evidence log.
Windows 11 documentation also describes automatic saving to the Screenshots folder. Check the actual image location on your target build instead of assuming that behavior is enabled.
Video evidence with Windows+Shift+R
Press Windows+Shift+R to start a rectangular video snip when video capture is supported on the image. Use this for a transition, repeated error, or long wait that a still image cannot explain. Video capture can interrupt the deployment surface, so use it only when the extra evidence is worth the operational disruption.
3. Open the Autopilot Diagnostics Page
- At the OOBE failure or milestone, press Ctrl+Shift+D.
- If the interface provides it, select View Diagnostics.
- Review the deployment information shown on the Diagnostics Page.
- Export the diagnostics to the prepared USB flash drive.
- Keep the exported files with the screenshot and timestamp from the same event.
Microsoft states that Windows Autopilot Diagnostics are available in OOBE and that Ctrl+Shift+D opens the Diagnostics Page during OOBE. The export can include a CSV hardware hash, so protect the USB drive and store it with the rest of the device record.
4. Use a command shell when the interface is stuck
At an OOBE sign-in prompt, press Shift+F10 to open Command Prompt. If you need PowerShell, run:
powershell.exe
Use the shell to inspect the state or gather additional troubleshooting information according to your organization’s procedures. A command window is evidence of the troubleshooting step, not a replacement for the diagnostics export.
5. Review event evidence after the run
After Windows is available, open Event Viewer and navigate to:
Application and Services Logs
└── Microsoft
└── Windows
└── ModernDeployment-Diagnostics-Provider
└── Autopilot
Export or record relevant events with their timestamps. Match those times to the screenshot filename and the diagnostics export so another administrator can reconstruct the sequence.
6. Build an evidence package that can be audited
| Evidence | What it proves | How to pair it |
|---|---|---|
| Still screenshot | What was visible at a specific milestone | Use UTC timestamp and device identifier in the filename |
| Video snip | How a transition, wait, or error repeated | Record start and end time and the ESP phase |
| Diagnostics export | Autopilot state and deployment details | Keep on the labeled USB drive with the screenshot record |
| Hardware-hash CSV | Device registration evidence included in the export | Restrict access and retain according to your device process |
| Event Viewer records | Post-run deployment events | Filter by the same time window as the capture |
A practical filename pattern is device-serial_2026-10-01T143012Z_esp-error.png. Keep the original file and avoid editing the evidence image after capture.
7. What to do when shortcuts do not work
Snipping Tool does not open
- Verify that the Windows shell and Snipping Tool are available in the current image.
- Try the full-screen or host capture function if you are running the deployment in a virtual machine.
- Use an external camera as an operational fallback. This is a practical fallback, not an Autopilot feature.
Ctrl+Shift+D shows nothing
- Confirm that you are still in Windows OOBE and that the deployment uses a supported Windows 11 user-driven mode.
- Confirm that the ESP profile has log collection and the diagnostics page enabled.
- Capture the visible error with the host screenshot function and continue with Event Viewer after the run.
Shift+F10 is blocked
- Make sure focus is on an OOBE sign-in prompt.
- Check the keyboard layout and function-key behavior on the device.
- If policy or hardware prevents the shell, use the diagnostics export and an external image capture.
The screenshot is present but cannot be matched to logs
- Use UTC timestamps consistently.
- Include the device serial number or another approved identifier in every filename.
- Record the exact ESP phase and visible error before moving to another screen.
8. Coverage and operational trade-offs
| Method | Coverage | Persistence | Availability | Disruption |
|---|---|---|---|---|
| Windows+Shift+S | Region, window, freeform, or full screen | Snipping Tool file and possibly Screenshots folder | Requires the capture surface on that OOBE/ESP build | Low |
| Windows+Shift+R | Rectangular video | Saved recording | Only where supported | Medium |
| Ctrl+Shift+D export | Diagnostics and deployment evidence | USB flash drive | Windows 11 OOBE in supported user-driven mode | Low |
| VM host capture | Entire guest display | Host image file | Depends on the virtualization console | Low |
| External camera | Entire physical display | Camera storage | Works when software capture is unavailable | Low |
9. Reliability, performance, and retention notes
- Capture at milestones rather than continuously. This reduces storage and keeps the evidence set reviewable.
- Use a powered, writable USB drive and verify that the export completed before leaving OOBE.
- Keep the screenshot, diagnostics export, and event records under one case identifier.
- Do not treat a successful screenshot as proof that deployment succeeded; pair it with diagnostics and event evidence.
- Limit access to exported hardware hashes and deployment logs according to your organization’s retention policy.
10. Or skip the browser setup
ScreenshotNeo is a website screenshot API, so it cannot capture the physical Windows OOBE or ESP surface. It is useful for capturing web-based deployment dashboards, runbooks, and status pages without setting up a browser. See the ScreenshotNeo API documentation.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://screenshotneo.com/docs/ -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://screenshotneo.com/docs/"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://screenshotneo.com/docs/' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Before the shot, cookie or consent banners are accepted and removed along with more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing status. An MCP server provides take_screenshot, get_page_info, and capture_pdf for AI agents. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots.
Create a free ScreenshotNeo account to capture web evidence with 1,000 shots per month and no card.
11. FAQ
Can I capture the ESP screen with Snipping Tool?
Sometimes. Microsoft documents the Snipping Tool shortcuts for Windows 11, but does not guarantee that the capture UI is available on every OOBE or ESP surface. Verify the target image and keep a VM host capture or external camera available.
Where do Autopilot diagnostics go?
Use the Diagnostics Page during OOBE and export the logs to a thumb drive. The export can include a CSV hardware hash.
Does Ctrl+Shift+D work after OOBE?
The documented shortcut opens the Autopilot Diagnostics Page during OOBE. After the run, use Event Viewer and the exported files for review.
What is the best way to prove when a failure occurred?
Pair a timestamped screenshot with the diagnostics export and the Autopilot event log entries from the same time window.
Can ScreenshotNeo replace an OOBE screenshot?
No. ScreenshotNeo captures web pages through its API; use Snipping Tool, host capture, or a camera for the physical OOBE display.


