entra hybrid joined

About this tag
The entra hybrid joined tag covers discussions about Windows 11 devices that are joined to both on-premises Active Directory and Microsoft Entra ID (formerly Azure AD). Recent threads focus on how Microsoft is rolling out the ability to install Windows quality and security updates during the out-of-box experience (OOBE) for Entra hybrid joined devices, controlled via the Enrollment Status Page (ESP) in Microsoft Intune. This change aims to reduce the post-provisioning patching gap, ensuring devices are compliant from first sign-in. IT administrators can opt devices in or out of this behavior through Intune policies. The tag is relevant for enterprise IT teams managing hybrid identity and device provisioning workflows.
  1. Windows 11: Quality Updates in OOBE with Autopilot and Intune ESP

    Microsoft is rolling a significant change to how new Windows 11 PCs are provisioned: eligible devices will now check for and install the latest quality and security updates during the out-of-box experience (OOBE) so users sign in on day one with a patched, compliant system. This shift, delivered...
  2. KB5065813: Windows 11 OOBE Quality Updates & Recovery Patch (22H2/23H2)

    Microsoft has published KB5065813 — an out‑of‑box experience (OOBE) update for Windows 11, versions 22H2 and 23H2 — on August 26, 2025, delivering two tightly related outcomes: first, a platform change that enables Windows quality updates to be taken during OOBE for eligible managed devices; and...
  3. Windows OOBE Now Installs Quality Updates via ESP for Entra-Joined Devices

    Microsoft is rolling the ability to install Windows quality updates during the Out‑Of‑Box Experience (OOBE) into enterprise provisioning flows, making it possible for eligible Entra‑joined and Entra hybrid‑joined Windows 11 devices to arrive at first sign‑in already patched — but only when...
  4. Quality Updates in Windows OOBE: ESP-Controlled Provisioning for Entra Joined Devices

    Microsoft will begin installing Windows quality updates during the out‑of‑box experience (OOBE) by default for eligible Microsoft Entra‑joined and Entra‑hybrid‑joined devices running Windows 11, version 22H2 and later, and administrators can control the behavior through an Enrollment Status Page...