ConfigureAdvancedTutorialsUpdated July 14, 2026

How to Configure Windows Security Updates During OOBE with Intune ESP

Enable Install Windows quality updates in Intune ESP to patch Autopilot devices during OOBE. Covers configuration, Update ring alignment, and troubleshooting.

Emanuel De Almeida May 14, 2026 5 min read
Difficulty
Advanced
Time
15 minutes
Steps
6
Last tested
July 14, 2026

Starting January 2026, the Intune ESP includes Install Windows quality updates. When Yes, devices check for and install monthly security updates at the end of OOBE before the desktop.

Works with Windows 11 22H2+ on Pro, Enterprise, Education, SE. Requires device-targeted ESP. Respects Update ring deferral settings when the ring targets the same devices.

New ESP profiles default to Yes. Existing profiles default to No and must be edited. Updates run during user phase, not technician phase for pre-provisioned deployments.

Before you start

What you will learn

  • How to enable quality updates during OOBE via Intune ESP so Autopilot devices are patched before desktop.
  • Devices provisioned through Autopilot traditionally reached the desktop unpatched. This feature closes that gap.

Requirements

  • intune.microsoft.com with Intune Administrator role.
  • Windows 11 22H2+ Pro/Enterprise/Education/SE enrolled via Autopilot.
  • Intune Administrator

Good to know

  • ESP config takes 15 minutes. OOBE update adds 20-40 minutes to provisioning.
  • Verified against Microsoft Learn and Windows IT Pro Blog. Feature GA January 2026.

Quick answer

Set Install Windows quality updates to Yes and Block device use to Yes in a device-targeted ESP profile. Assign Update ring to same devices.

Intune > Devices > Device onboarding > Enrollment > Enrollment Status Page

Step-by-step tutorial

6 steps
2

Enable Install Windows quality updates

Turn on quality updates during OOBE.

ESP profile > Settings

Edit or create a device-targeted profile. Set Install Windows quality updates to Yes. Set Block device use to Yes so ring settings sync first.

Expected resultQuality updates Yes, Block device use Yes.

Only monthly security releases install. Not feature updates or drivers.

3

Assign to Autopilot device groups

Target devices for quality update support.

ESP > Assignments

Assign to device groups or All devices. Don't use user groups.

Expected resultDevice groups in Included groups.

Only device-targeted profiles install quality updates.

4

Align Update ring to same devices

Ensure deferral settings are honored.

Intune > Update rings

Assign your Windows Update ring to the same device group. ESP syncs ring settings during device phase. Set quality deferral to 0 for immediate updates.

Expected resultRing and ESP target same devices.

Without matching assignments, deferrals may not apply during OOBE.

5

Test on an Autopilot device

Validate updates install during OOBE.

Reset a test device. Boot through OOBE. After setup phases, you'll see Installing quality updates. Verify with winver after reaching desktop. For diagnostics, Ctrl+Shift+D during OOBE.

Cmd
winver
Expected resultwinver shows latest cumulative update.

Total: 30-90 min. Update phase: 20-40 min.

6

Monitor and troubleshoot

Track completion and resolve issues.

Intune > Devices > Monitor

Check ESP Device status in Intune. Verify registry InstallQualityUpdates (value 1). Check C:\Windows\Logs\ESPLogs for errors.

Expected resultSucceeded. Devices report current updates.

Windows 10 and Autopilot device preparation don't support this.

How to Confirm Updates During OOBE

Run winver after OOBE. Build should reflect latest cumulative update. Registry InstallQualityUpdates shows 1. ESP shows Succeeded.

  • winver shows latest update. ESP Succeeded.
  • Unpatched after OOBE. Check targeting, ring, internet.
  • Auto-enabled.
  • Edit to enable.
  • Ring syncs before check.

Troubleshooting

Updates don't install

Cause: User-targeted ESP or wrong Windows version.

Verify device-targeted ESP. Confirm Win 11 22H2+ Pro/Enterprise/Education/SE.

ESP stuck at update phase

Cause: Large update or slow internet.

Allow 40 min. Check internet. Increase ESP timeout.

Deferrals not honored

Cause: Update ring not targeting same devices.

Assign ring to same device group. ESP syncs ring during device phase.

Device exits before updates

Cause: Block device use is No.

Set Block device use to Yes.

Updates install when set to No

Cause: Higher-priority ESP profile with Yes.

Review ESP profiles and priority. Check registry InstallQualityUpdates.

Frequently asked questions

Does this work with Windows 10?

No. Requires Windows 11 22H2+ Pro/Enterprise/Education/SE.

How much time does it add?

20 to 40 minutes depending on update size and hardware.

Does it run during White Glove technician phase?

No. Runs during user phase after sign-in. Use Win32 app approach for technician-phase patching.

What updates are installed?

Only monthly security releases. Not feature updates, drivers, or expedited updates.

What about existing ESP profiles?

Default to No. Edit and set to Yes. New profiles after Jan 2026 default to Yes.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles