Microsoft is rolling a significant change to how new Windows 11 PCs are provisioned: eligible devices will now check for and install the latest quality and security updates during the out-of-box experience (OOBE) so users sign in on day one with a patched, compliant system. This shift, delivered...
22h2
autopilot
azure ad
bandwidth
delivery optimization
deployment
device imaging
device provisioning
education
enrollment status page
enterprise
enterprise deployment
enterprise it
entraentrahybridjoined
esp
esp-toggle
first sign-in
fleet management
intune
it admin
mdm
microsoft entra
oobe
patch management
provisioning
quality updates
rollout
security hardening
security updates
tap
vendor imaging
windows
windows 11
windows update
windows update for business
windows update rings
zero trust
zero-day updates
Microsoft has published KB5065813 — an out‑of‑box experience (OOBE) update for Windows 11, versions 22H2 and 23H2 — on August 26, 2025, delivering two tightly related outcomes: first, a platform change that enables Windows quality updates to be taken during OOBE for eligible managed devices; and...
22h2
23h2
autopilot
azure ad
cloud reinstall
enrollment status page
entraentrahybridjoined
esp
intune
lcu
mdm
oobe
quality updates
recovery patch
remotewipe
reset
ssu
windows 11
windows update for business
Microsoft is rolling the ability to install Windows quality updates during the Out‑Of‑Box Experience (OOBE) into enterprise provisioning flows, making it possible for eligible Entra‑joined and Entra hybrid‑joined Windows 11 devices to arrive at first sign‑in already patched — but only when...
autopilot
deployment
device provisioning
enrollment status page
enterprise it
entraentrahybridjoined
group policy
intune
mdm
oobe provisioning
os updates
patch management
quality updates
security updates
windows 11 22h2
windows oobe
windows update for business
Microsoft will begin installing Windows quality updates during the out‑of‑box experience (OOBE) by default for eligible Microsoft Entra‑joined and Entra‑hybrid‑joined devices running Windows 11, version 22H2 and later, and administrators can control the behavior through an Enrollment Status Page...