Why Configure Security Updates During Windows OOBE?
The traditional Windows out-of-box experience leaves devices vulnerable during initial setup, as security updates typically install after users reach the desktop. Microsoft introduced a game-changing feature in January 2026 that allows Intune administrators to automatically install Windows quality updates during OOBE through the Enrollment Status Page, significantly reducing the security exposure window for new devices.
What Makes This Feature Critical for Enterprise Security?
This capability addresses a fundamental security gap in enterprise device deployment. Previously, devices provisioned through Windows Autopilot would complete OOBE and reach the desktop before installing critical security patches, potentially exposing them to threats during the initial hours or days of use. With ESP-controlled security updates, devices receive the latest monthly security updates before users gain access, ensuring a hardened security posture from first boot.
How Does ESP Security Update Integration Work?
The feature integrates seamlessly with existing Windows Autopilot and Intune workflows. When enabled in an ESP profile, the system performs a Windows Update scan after completing device and app provisioning but before presenting the desktop to users. The process respects Windows Update for Business policies, including deferral periods and maintenance windows, while providing real-time progress feedback during installation. This tutorial walks you through the complete configuration process, from verifying prerequisites to monitoring deployment success across your organization.



