Windows 11 quality updates during OOBE coming to Microsoft Entra joined devices



 Windows IT Pro Blog

Editor's note 12.9.2025: This policy will be available starting with the January 2026 security update and will no longer be enabled by default. We have reflected this change in the post below and added clarification about device targeting.

Editor's note 9.8.2025: This capability has been delayed by a couple of months to help ensure delivery of the best possible experience. You can start configuring the new setting on the Enrollment Status Page (ESP), but you won't see the new user interface yet. We'll update this post with a revised timeline as soon as it's available.

Get the latest Windows quality updates during the out-of-box experience (OOBE) by default. This much awaited improvement is coming to your eligible Microsoft Entra joined or Microsoft Entra hybrid joined devices running Windows 11, version 22H2 and later. It will be available starting with the September 2025 Windows security update.

You can manage this new capability with a policy setting. With Windows Autopilot and Microsoft Intune (or alternative management solutions), you can maintain seamless control over quality update behavior during provisioning, while ensuring alignment with organizational security and compliance requirements.

Manage your OOBE update experience in Microsoft Intune​

When Windows quality update support is available in the Windows Autopilot Enrollment Status Page (ESP) at the end of August 2025, you’ll see the new quality update setting enabled by default.

You’ll be able to control whether updates are installed during OOBE if you meet these criteria:
  • Your devices are on Windows 11, version 22H2 or later and on any of the following SKUs: Pro, Enterprise, Education, or SE.
  • You use Microsoft Intune to manage Windows quality updates.
  • You’ve assigned a Windows Autopilot Enrollment Status Page (ESP) profile to devices using either Windows Autopilot preregistered device group or using the “All devices” assignment.
  • Your devices have one of the following required updates that include the new setting:
    • Devices that get the August 2025 OOBE zero-day patch (ZDP) update will have this capability.
    • Devices imaged with the June 2025 Windows non-security update or later already include the new setting.

Note: At this time, if you’re not using device ESP, you won’t be able to turn off Windows updates during OOBE. This might be the case if you enroll devices using Windows Autopilot device preparation policies. These devices will have updates applied by default.


The new setting​

The new setting is available to you to confirm or control this experience:
  1. Go to the Microsoft Intune admin center.
  2. Navigate to Devices > Enrollment > Enrollment Status Page.
  3. Select the ESP profile you wish to check or create a new one and go to its Settings tab.
  4. Locate the new setting called Install Windows quality updates (might restart the device). If its value is set to “Yes,” you’re set to install quality updates during provisioning!

Note: Preexisting ESP profiles will have Install Windows quality updates set to “No.” You can edit this setting to enable the updates. New ESP profiles will default to “Yes.”


Screenshot showing Enrollment Status Page (ESP) profile settings in the Microsoft Intune admin center, with a new setting to Install Windows quality updates set to “Yes.”

The Enrollment Status Page (ESP) profile settings in the Microsoft Intune admin center, with a new setting to Install Windows quality updates set to “Yes.”

As we’ve preannounced, the device will check Windows Update at the last page of OOBE and install any applicable quality updates. That way, the user will start out with the latest security and quality updates at first sign in.

Screenshot of the final OOBE screen with in-progress Windows update message. Background is the Windows bloom in gradients of blue with white Microsoft logo in middle of screen.

The final OOBE screen shows the message for an in-progress Windows update.

Recommendation for pause and deferral settings​

Want to ensure that quality updates during OOBE respect pause and deferral settings? Assign your Windows Update rings profile to the same Windows Autopilot preregistered device group as your ESP profile or using the “All devices” assignment.

During the device phase of provisioning, the ESP will ensure that the settings from the Windows Update rings policy are synchronized prior to exiting the page. That way, settings are in place before the final Windows Update page checks for updates. Note: If these requirements aren’t met, the pause and deferral settings might be inconsistently applied during OOBE.

Alternative management solutions for OOBE updates​

Some non-Microsoft mobile device management (MDM) solutions are also capable of using the ESP functionality. How can you determine if that’s the case for you? Check if your MDM provider has developed its own ESP functionality using features or protocols offered by Microsoft to reliably deliver certain policies during OOBE. If they have selected the ESP profile as eligible to be applied, designate the ESP profile as a tracked policy when creating it. You must enable ESP to ensure that the latest Windows quality updates indeed get installed during OOBE.

Ready for an improved OOBE?​

With this new default experience, you can:
  • Complete the devices’ OOBE with the latest approved quality updates already applied.
  • Enhance security from day 1.
  • Reduce post-deployment update overhead.
Thank you again for your feedback and helping us make Windows better!


 Source:

 
Last edited:
Note: At this time, if you’re not using device ESP, you won’t be able to turn off Windows updates during OOBE. This might be the case if you enroll devices using Windows Autopilot device preparation policies. These devices will have updates applied by default.

Everyone who isn't an AutoPilot customer, and installing from any 22H2 or later ISO which isn't patched to the latest Monthly Update, will be forced to sit through Windows update during OOBE.

If you're preparing Windows ISO's, you need to use one of two workarounds presented in this thread:
Coming soon: Quality updates during out-of-box experience (OOBE) for Windows 11
 

My Computer

System One

  • OS
    Windows 7
Editor's note 12.9.2025: This policy will be available starting with the January 2026 security update and will no longer be enabled by default. We have reflected this change in the post below and added clarification about device targeting.

Starting with the January 2026 security update, the AllowOOBEUpdates CSP policy will be available to IT admins and disabled by default. It shows up as a new setting on the Windows Autopilot Enrollment Status Page (ESP). This policy allows you to install the latest Windows quality updates during the out-of-box experience (OOBE) on eligible devices. Devices must be Microsoft Entra joined or Microsoft Entra hybrid joined and running Windows 11, version 22H2 or later. Read the updated announcement in Get ready for Windows quality updates out of the box as well as its accompanying documentation.

 

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    TerraMaster F8 SSD Plus NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Amazon Basics Wired Full Keyboard MD005
    Mouse
    Logitech MX Master 4
    Internet Speed
    2 Gbps Download and 100 Mbps Upload
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
Back
Top Bottom