Skip to content
Sandbox IT Solutions
Sandbox IT Solutions

Technical blog focused on Microsoft and related technologies

  • Home
  • Consulting Services
  • About Me
  • Contact Me
  • Disclaimer
Sandbox IT Solutions

Technical blog focused on Microsoft and related technologies

Streamline Your Device Deployment: New Windows Quality Update Controls in Microsoft Intune’s OOBE Experience

SandboxIT, September 5, 2025September 5, 2025

Microsoft is introducing a game-changing feature for IT administrators managing Windows device deployments. Coming at the end of August 2025, you’ll gain unprecedented control over Windows quality updates during the Out-of-Box Experience (OOBE) through Microsoft Intune’s Enrollment Status Page (ESP). This enhancement promises to revolutionize how organizations handle device provisioning and ensure users start with the most secure, up-to-date systems from day one.

Update: This feature is now appearing in Intune tenants! I can confirm that the new quality update setting has started rolling out, as it appeared in my tenant today. If you haven’t seen it yet, check your Enrollment Status Page settings – it should be available now or coming soon to your environment.

Microsoft Intune OOBE Updates Autopilot

Table of Contents

  • What's New in Windows Autopilot?
  • Prerequisites: Is Your Environment Ready?
    • Device Requirements
    • Infrastructure Requirements
    • Configuring the New Quality Update Setting
      • Step-by-Step Configuration
    • OOBE Experience with Windows Updates
  • Conclusion
  • Reference

What’s New in Windows Autopilot?

The upcoming update introduces native Windows quality update support directly within the Windows Autopilot Enrollment Status Page. This means that instead of devices potentially missing critical updates during initial setup, they can now receive and install the latest security patches and quality improvements as part of the provisioning process.

The most significant aspect of this update is that the new quality update setting will be enabled by default for new ESP profiles, ensuring that organizations benefit from enhanced security posture without requiring additional configuration. However, if you already have an ESP profile set up, this setting will be disabled by default – you’ll need to manually enable it to take advantage of the new capability.

Prerequisites: Is Your Environment Ready?

Before you can take advantage of this new capability, your environment must meet specific criteria:

Device Requirements

  • Operating System: Windows 11, version 22H2 or later
  • Supported SKUs: Pro, Enterprise, Education, or SE editions
  • Update Status: Devices must have either: The August 2025 OOBE zero-day patch (ZDP) update, or
  • Be imaged with the June 2025 Windows non-security update or later

Infrastructure Requirements

  • Management Platform: Microsoft Intune for Windows quality update management Autopilot Configuration: Windows Autopilot Enrollment Status Page (ESP) profile assigned via:
    • Windows Autopilot preregistered device group, or
    • “All devices” assignment

Configuring the New Quality Update Setting

Managing this new feature is straightforward through the Microsoft Intune admin center:

Step-by-Step Configuration

  1. Login to the Microsoft Intune Admin Center.
  2. Go to Devices > Enrollment > Enrollment Status Page.
  3. Select your ESP profile or create a new one.
  4. In the Settings section, toggle to Yes or No for Install Windows quality updates (might restart the device).
Intune Autopilot ESP Windows Update

OOBE Experience with Windows Updates

When this feature is enabled, the Windows update process becomes seamlessly integrated into the device setup experience. During the final stages of OOBE, users will see a dedicated screen indicating that Windows is checking for and installing quality updates. The interface provides clear progress information, letting users know that their device is being optimized with the latest security patches and improvements before they begin using it. This transparent approach ensures users understand why the setup process may take a few additional minutes, while reinforcing that they’re receiving a fully updated and secure device from the moment they first sign in.

Windows 11 OOBE Update Experience

Conclusion

The introduction of Windows quality update controls in Microsoft Intune’s OOBE experience marks a significant step forward in enterprise device management. By enabling automatic quality updates during Windows Autopilot provisioning, organizations can enhance their security posture while maintaining streamlined deployment processes.

As you prepare for this August 2025 release, take time to evaluate your current ESP configurations and consider how this new capability can strengthen your overall device deployment strategy. With proper planning and implementation, this feature will help ensure that your users start their Windows experience with the most secure and up-to-date foundation possible.

Ready to get started? Begin by reviewing your current Microsoft Intune ESP profiles and identifying which devices in your environment will benefit from this enhanced OOBE update experience.

Reference

https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-quality-updates-out-of-the-box/4434498

Spread the love
Autopilot Intune Windows Updates

Post navigation

Previous post

Leave a Reply Cancel reply

You must be logged in to post a comment.

Recent Posts

  • Streamline Your Device Deployment: New Windows Quality Update Controls in Microsoft Intune’s OOBE Experience
  • Understanding the Stolen Device Protection Challenge with Microsoft Intune Manual Enrollment
  • Microsoft AI Tour 2025-2026: A Global Journey of AI Innovation
  • LAPS for macOS Is Here: Managing Admin Passwords with Intune
  • New in Intune: Platform-Level Targeting for Device Cleanup Rules

Recent Comments

  1. Mike B on Moving Teams Android Devices to AOSP Device Management
  2. Johnny s on Third-Party Application Patching: Ivanti vs. Patch My PC
  3. SandboxIT on Exploring Windows Sandbox: Application Install and PowerShell Script Testing
  4. John on Resolving Windows 11 24H2 Defender Enrollment Issues
  5. Barry Johns on New Outlook January 2025 – Microsoft 365 Business Standard/Premium

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • January 2025
  • December 2024
  • October 2024
  • September 2024

Categories

  • AI
  • Apple
  • Autopilot
  • BIOS
  • Conditional Access
  • Configuration Manager
  • Defender for Endpoint
  • Entra ID
  • Events
  • Intune
  • iOS/iPadOS
  • Learning
  • Lenovo
  • macOS
  • Manufacturers
  • MDM
  • Microsoft Certifications
  • Microsoft Security
  • Microsoft Teams
  • Patching
  • PowerShell
  • Security
  • Uncategorized
  • Windows
  • Windows Updates
©2025 Sandbox IT Solutions | WordPress Theme by SuperbThemes