Out-of-Box Experience (OOBE) enrollment enables organizations to provision Windows devices directly during the initial setup process. With IBM MaaS360, administrators can automate device enrollment, apply security policies, deploy applications, and enforce compliance from the very first boot.
What is Windows OOBE Enrollment?
Windows OOBE Enrollment allows users to enroll devices into an Mobile Device Management (MDM) solution during the Windows setup wizard. Instead of manually configuring devices after setup, OOBE enrollment streamlines provisioning by connecting the device directly to the organization’s device management platform.
Prerequisites
- Access to IBM MaaS360 portal
- Access to Microsoft Entra ID (Azure AD)
- Windows 10 or 11 laptop
- Microsoft Entra ID Premium P1 or P2 License
Azure Portal Configuration for MaaS360 OOBE Enrollment
Step 1: Configure MDM Enrollment Tenant ID
1. Sign in to the Microsoft Entra Admin Center

2. Navigate to Microsoft Entra ID and copy the tenant ID shown on Home page

3. Login to the IBM MaaS360 Portal and Navigate to: Devices → Enrollments → Other Enrollment Options
4. Select: Other Enrollement Options → Windows → Windows OOBE & Autopilot

5. Update the Microsoft Entra Tenant ID field with the Tenant ID copied from the Microsoft Entra ID home page.
6. Copy the MDM TERMS OF USE URL and MDM DISCOVERY URLs to update them in azure portal
Step 2: Configure Automatic MDM Enrollment
To enable Windows OOBE enrollment with MaaS360, configure the required MDM discovery URLs in Microsoft Entra ID.
1. Sign in to the Microsoft Entra Admin Center
2. Navigate to Microsoft Entra ID → Mobility (MDM and MAM)
3. Click: Add Application
4. Select: IBM MaaS360
5. Update the links copied in above step
6. MDM User Scope
| Option |
Usage |
| None |
Disables auto enrollment |
| Some |
Selected users/groups only |
| All |
Recommended for enterprise rollout |

Disable MDM Enrollment When Adding a Work or School Account on Windows
This setting controls whether Windows devices are automatically enrolled into MaaS360 when a user adds a work or school account through Windows settings.
| Setting |
Behaviour |
| No (Recommended) |
Automatically enrolls the device into MaaS360 when a user adds a work or school account. This enables seamless device management and is required for most enterprise deployments. |
| Yes |
Prevents automatic MDM enrollment when a user adds a work or school account. Users can authenticate with Microsoft Entra ID, but the device will not automatically enroll into MaaS360. |
Enrol a Windows Device Using OOBE
Now the environment is ready to enrol the devices to MaaS360 Device Management solution.
- Start a new or factory-reset Windows device
- Proceed through the Windows setup screens.
- Connect the device to the internet.
- At the sign-in screen, enter the corporate email address.
- Windows detects the organization’s MDM configuration.
- Authenticate using organizational credentials.
- Accept company policies and enrollment prompts.
- The device automatically enrolls into MaaS360.
Post Enrollment Validation
- Verify the device appears in the MaaS360 portal. Devices → Device Inventory
- On Windows Device navigate to: Settings → Accounts → Access work or school

Benefits of Windows OOBE with MaaS360
- One-touch deployment
- Faster device provisioning
- Improved compliance
- Automated policy deployment
- Better end-user experience
- Centralized device management
Common Troubleshooting Scenarios
| Issue |
Possible Cause |
Remediation |
| Device not discovering MDM |
Incorrect or missing MDM Discovery URL configuration in Microsoft Entra ID |
Verify the MaaS360 MDM Discovery URL and MDM Terms of Use URL configured in Microsoft Entra ID. Ensure the URLs are accessible and correctly configured. |
| Authentication Failure |
User account not licensed, missing permissions, or not synchronized with Microsoft Entra ID |
Confirm that the user has the required Microsoft Entra ID and MaaS360 licenses assigned. Verify user synchronization and permissions in Microsoft Entra ID. Refer to Assign Licenses to Users and Groups and Microsoft Entra Roles and Permissions for detailed guidance. |
| Enrollment Stuck During Setup |
Network connectivity issues or MaaS360 service unavailability |
Verify internet connectivity on the device. Confirm that MaaS360 services are operational and that firewall or proxy settings are not blocking enrollment traffic. |
Conclusion
Windows OOBE Enrollment with IBM MaaS360 simplifies enterprise device onboarding by automating enrollment, policy deployment, and compliance enforcement. By integrating Microsoft Entra ID with MaaS360 and configuring the required MDM discovery settings, organizations can deliver a seamless zero-touch deployment experience for end users
Official References
· Microsoft Entra Admin Center
· MaaS360 Documentation