(Updated) Plan for Change: Windows quality updates during the out-of-box experience

Message Center ID: MC1134168
Microsoft Intune
Plan for Change
User impact Admin impact
August 2025

Summary

Windows 11 (22H2+) devices will install quality updates by default during out-of-box experience (OOBE). Intune’s August release adds an "Install Windows updates" setting in Enrollment Status Page (ESP) to control this. Update rings can manage update timing; devices without ESP cannot block updates during OOBE.

Details

Update: The timing of this change has been delayed, review the Windows blog announcement for additional details.

In an upcoming Windows security update, quality updates will get installed by default during the out-of-box experience (OOBE) for devices that are on Windows 11, version 22H2 or later.

Expected in Intune’s August (2508) service release, we will introduce a new setting "Install Windows updates" in the Enrollment Status Page (ESP) to allow you to manage the installation of quality updates during OOBE. Stay tuned to What’s new in Intune for the release.

[How this will affect your organization:]

If you are using Windows Autopilot and ESP, the Install Windows updates setting will be automatically set to “Yes” for new ESP profiles and “No” for existing profiles. If the ESP setting is set to “Yes”, updates will be delivered during OOBE. When configured to “No”, updates will be prevented during OOBE. Additionally, update rings settings (if assigned, as defined below) will be delivered during the ESP and the quality updates page will be shown while the update is applied after ESP completes.

Important: Devices enrolling with Windows Autopilot device preparation or with ESP disabled, cannot prevent Windows updates during OOBE and will receive the latest published security updates.

[What you need to do to prepare:]

Update your documentation and user guidance as needed. To manage quality updates installed during OOBE for devices using ESP:

  1. In the ESP profile, set Install Windows updates to “Yes” to allow updates or “No” to prevent updates.
  2. (Recommended) Use or create an update rings policy to manage pause and deferral settings for quality updates. Quality updates installed during OOBE will follow this policy.
  3. Assign the ESP profile and the update rings policy to “All devices” or device groups with devices registered for Windows Autopilot.

[Related information:]

Change History

September 9, 2025 at 10:30 PM Updated
Title
Previous
Plan for Change: Windows quality updates during the out-of-box experience
New
(Updated) Plan for Change: Windows quality updates during the out-of-box experience
Summary
Previous
Starting September 2025, Windows 11 (22H2+) devices will install quality updates by default during out-of-box experience (OOBE). Intune's August release adds an "Install Windows updates" setting in Enrollment Status Page (ESP) to control this. Update rings policies can manage update timing during OOBE.
New
Windows 11 (22H2+) devices will install quality updates by default during out-of-box experience (OOBE). Intune’s August release adds an "Install Windows updates" setting in Enrollment Status Page (ESP) to control this. Update rings can manage update timing; devices without ESP cannot block updates during OOBE.
Last Updated Date
Previous
2025-08-12T22:59:52.720Z
New
2025-09-09T21:51:27.217Z
Tags
Previous
User impact,Admin impact
New
Updated message,User impact,Admin impact
Body Content
Previous

Beginning with the September 2025 Windows security update, quality updates will get installed by default during the out-of-box experience (OOBE) for devices that are on Windows 11, version 22H2 or later.

Expected in Intune’s August (2508) service release, we will introduce a new setting "Install Windows updates" in the Enrollment Status Page (ESP) to allow you to manage the installation of quality updates during OOBE. Stay tuned to What’s new in Intune for the release.

[How this will affect your organization:]

If you are using Windows Autopilot and ESP, the Install Windows updates setting will be automatically set to “Yes” for new ESP profiles and “No” for existing profiles. If the ESP setting is set to “Yes”, updates will be delivered during OOBE. When configured to “No”, updates will be prevented during OOBE. Additionally, update rings settings (if assigned, as defined below) will be delivered during the ESP and the quality updates page will be shown while the update is applied after ESP completes.

Important: Devices enrolling with Windows Autopilot device preparation or with ESP disabled, cannot prevent Windows updates during OOBE and will receive the latest published security updates.

[What you need to do to prepare:]

Update your documentation and user guidance as needed. To manage quality updates installed during OOBE for devices using ESP:

  1. In the ESP profile, set Install Windows updates to “Yes” to allow updates or “No” to prevent updates.
  2. (Recommended) Use or create an update rings policy to manage pause and deferral settings for quality updates. Quality updates installed during OOBE will follow this policy.
  3. Assign the ESP profile and the update rings policy to “All devices” or device groups with devices registered for Windows Autopilot.

[Related information:]

New

Update: The timing of this change has been delayed, review the Windows blog announcement for additional details.

In an upcoming Windows security update, quality updates will get installed by default during the out-of-box experience (OOBE) for devices that are on Windows 11, version 22H2 or later.

Expected in Intune’s August (2508) service release, we will introduce a new setting "Install Windows updates" in the Enrollment Status Page (ESP) to allow you to manage the installation of quality updates during OOBE. Stay tuned to What’s new in Intune for the release.

[How this will affect your organization:]

If you are using Windows Autopilot and ESP, the Install Windows updates setting will be automatically set to “Yes” for new ESP profiles and “No” for existing profiles. If the ESP setting is set to “Yes”, updates will be delivered during OOBE. When configured to “No”, updates will be prevented during OOBE. Additionally, update rings settings (if assigned, as defined below) will be delivered during the ESP and the quality updates page will be shown while the update is applied after ESP completes.

Important: Devices enrolling with Windows Autopilot device preparation or with ESP disabled, cannot prevent Windows updates during OOBE and will receive the latest published security updates.

[What you need to do to prepare:]

Update your documentation and user guidance as needed. To manage quality updates installed during OOBE for devices using ESP:

  1. In the ESP profile, set Install Windows updates to “Yes” to allow updates or “No” to prevent updates.
  2. (Recommended) Use or create an update rings policy to manage pause and deferral settings for quality updates. Quality updates installed during OOBE will follow this policy.
  3. Assign the ESP profile and the update rings policy to “All devices” or device groups with devices registered for Windows Autopilot.

[Related information:]

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.