Microsoft Intune
General

What's new in Microsoft Intune

In brief

Updated Microsoft Intune documentation in intune/whats-new/index.md.

What Intune admins need to know

Review the underlying documentation change to determine whether it affects tenant configuration or rollout plans.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Open the full-page diff for complete context.

-->

Week of July 27, 2026 (Service release 2607)

Device configuration

Samsung Knox E-FOTA firmware update management for Android Enterprise devices

Microsoft Intune now integrates with Samsung Knox E-FOTA (Firmware Over-The-Air), so you can manage firmware updates for corporate-owned Samsung devices directly in the Microsoft Intune admin center. Control which firmware version each device receives, deploy updates without user interaction, and schedule downloads and installations to reduce downtime.

For more information, see Samsung Knox E-FOTA integration with Microsoft Intune.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate-owned dedicated (COSU)
  • Android Enterprise corporate-owned fully managed (COBO)
  • Android Enterprise corporate-owned with a work profile (COPE)

New settings available in the Windows settings catalog

Microsoft Intune now includes new settings in the Windows settings catalog for Windows devices. You can configure options for camera behavior, Keyboard Filter controls (for Windows Insider devices), and Windows Subsystem for Linux (WSL). To find them, go to Devices > Manage devices > Configuration > Create > New policy > Windows 10 and later > Settings catalog.

[!div class="checklist"] Applies to:

  • Windows 11
  • Windows 10

New Microsoft Edge settings in the Windows settings catalog

The Microsoft Edge administrative templates were refreshed to Microsoft Edge 149 (version 149.0.4022.21), which adds the latest Microsoft Edge 148 and 149 policy settings to the Windows settings catalog. The new settings are:

For the full list of policies, see the Microsoft Edge policies reference.

[!div class="checklist"] Applies to:

  • Windows

Device enrollment

Skip Setup Assistant screens for tvOS and visionOS enrollment

Microsoft Intune now supports hiding or showing new Setup Assistant screens during automated device enrollment (ADE) for tvOS and visionOS devices. When you configure an enrollment profile, you can choose which screens, such as Apple ID, Diagnostics Data, and Location Services, appear during setup. By default, these screens are shown.

For more information, see Set up ADE for tvOS and Set up ADE for visionOS.

[!div class="checklist"] Applies to:

  • tvOS
  • visionOS

Dedicated RBAC permission for zero-touch enrollment

Microsoft Intune now provides a dedicated role-based access control (RBAC) permission for Google zero-touch enrollment portal access. Previously, the zero-touch enrollment iframe in the Microsoft Intune admin center required the Update app sync permission, which also grants rights to manage Managed Google Play app sync. With the dedicated permission, you can grant zero-touch enrollment portal access independently from app management permissions.

For more information, see Enroll by using Google Zero Touch.

[!div class="checklist"] Applies to:

  • Android Enterprise

Device management

Collect Windows registry data with the properties catalog

Microsoft Intune now lets you collect Windows registry data through the properties catalog. When you create a device inventory policy, you can define specific registry keys and values to collect from enrolled Windows devices, including a single value, all values directly under a key, or the same value across subkeys under HKEY_LOCAL_MACHINE. This gives you richer device state visibility and advanced querying without custom scripts.

For more information, see Use the Intune properties catalog to get device hardware properties.

[!div class="checklist"] Applies to:

  • Windows

Improved on-demand device sync for Windows devices

Microsoft Intune now supports a more comprehensive on-demand sync for Windows devices. When you select the Sync device action in the Microsoft Intune admin center, Intune initiates a full synchronization across key workloads, including configuration policies, apps, and scripts, so devices reflect your latest changes faster. This capability is especially useful during troubleshooting, incident response, and high-priority rollouts.

For more information, see Device action: sync.

[!div class="checklist"] Applies to:

  • Windows

Device security

Custom compliance settings for macOS

Microsoft Intune now supports custom compliance settings for macOS. As an admin, you can define compliance checks using scripts and JSON rules, similar to existing support for Windows and Linux. This capability lets you evaluate device configuration, security posture, and other custom attributes not covered by built-in settings. Results appear alongside standard compliance reporting in the Intune admin center.

For more information, see Custom compliance settings in Microsoft Intune.

[!div class="checklist"] Applies to:

  • macOS

Controlled Configuration for Microsoft Defender antivirus settings (preview)

In preview, Microsoft Intune now supports Controlled Configuration for Microsoft Defender antivirus settings. When you enable it, the Defender antivirus settings delivered by Intune or Microsoft Defender for Endpoint security settings management become authoritative and override configurations from other channels, such as Group Policy, Configuration Manager, and local scripts. Extending Tamper Protection, this capability locks settings to your defined values for consistent and predictable device states.

For more information, see Controlled configuration for Microsoft Defender settings.

[!div class="checklist"] Applies to:

  • Windows

Intune apps

Regional support for Microsoft Store apps

Microsoft Intune now supports regional selection for Microsoft Store apps. When you add a Microsoft Store app, you can choose the region (market) whose Store catalog to search and deploy from. Previously, Intune searched only the United States catalog. Now you can deploy apps published for specific markets, such as Japan or Spain, that aren't available in the US catalog.

For more information, see Add Microsoft Store apps to Microsoft Intune.

[!div class="checklist"] Applies to:

  • Windows

Week of July 13, 2026

App management

  • Android Enterprise personally owned devices with a work profile

Improvements to the new Intune single device page (public preview)(preview)

In the Intune admin center, the Devices > All Devices > select a device page is redesigned and available for you to preview. This feature was available in the 2604 service release2604 service release.

After the initial 2604 release, we made the following improvements:

Device management

Detect and block Shadow AI using the properties catalog, device query, and a security baseline (public preview)(preview)

Using Intune, you can detect and block a Local AI Agent, like OpenClaw, on Windows devices enrolled in Intune. Specifically, you can:

This feature is in preview.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate-owned fully managed
  • Android Enterprise corporate-owned work profile

Vulnerability Remediation Agent now uses Microsoft Entra agentic identity (public preview)(preview)

This feature is rolling out to tenants gradually and may take several weeks to become available in your environment.

The Vulnerability Remediation Agent is now available to all customers in public preview. Previously, the agent was available only to a select group of customers in a limited preview.

The Vulnerability Remediation Agent now uses Microsoft Entra agentic identity instead of a human user identity. When you set up a new agent instance, the setup process automatically provisions an agentic identity in your tenant's Entra directory. The agent runs under the permissions delegated to this agentic user, providing a more secure and scalable identity model.

Microsoft Intune now supports Ubuntu 26.04 LTS. Support for Ubuntu 22.04 LTS ends in August 2026. Devices already enrolled on Ubuntu 22.04 remain enrolled, but you should notify users to upgrade to a supported Ubuntu version. You can identify devices running Ubuntu 22.04 in the Intune admin center by going to Devices > All devices, filtering by Linux, and adding the OS version column. For more information, see Enroll Linux desktop devices in Microsoft Intune.

Preview the new device page in the Intune admin center (public preview)(preview)

In the Intune admin center, when you go to Devices > All Devices and select a device, you can see device-specific info, like device properties.

Tenant administration

Change Review Agent suggestions available inline in Multi Admin Approval (public preview)(preview)

The Change Review Agent now provides risk-based recommendations directly in the Multi Admin Approval experience for Windows PowerShell scripts. On the My requests and All requests tabs, a new Agent Response column displays when a suggestion is available. You can then select the suggestion to open and complete the Change Review Agent's approval workflow for that request without leaving the Multi Admin Approval node.

Role-based access control

Scoped permissions for Role-based access control (public preview)(preview)

Intune now includes an opt-in public preview to enable Scoped permissions, making your role-based access control (RBAC) configuration more precise. Enabling Scoped permissions is a one-time choice that can't be undone. In the future, this will become the default behavior for all tenants.

Previously, when an admin had multiple role assignments using different scope tags for the same permission category, Intune merged permissions across those assignments, which could unintentionally grant broader access than intended. With Scoped permissions enabled, each role assignment's permissions apply only within its own scope tag context, so admins receive exactly the access you intended.

To help you prepare before enabling this change, Intune includes a new Permissions Assessment Report. The report details your tenant's current permissions and shows how they will change after enabling Scoped permissions. You can rerun the report as often as needed, adjust role assignments, and communicate any changes to affected admins before opting in.

For more information about the current default behavior, the Scoped permissions opt-in public preview, and the new report, see Permission behavior across role assignments.

Week of March 24, 2026

Device enrollment

New setting controls MDM enrollment during account registration on Windows (public preview)(preview)

A new setting that affects the Microsoft Entra account registration experience on Windows is available in the Microsoft Intune admin center. The setting, Disable MDM enrollment when adding work or school account on Windows, controls whether devices enroll in MDM during the account registration flow. The default setting is set to No, which allows MDM enrollment. No action is required unless you want to change the default enrollment behavior. This Microsoft Entra setting is in public preview. For more information, see Enable MDM automatic enrollment for Windows.

Device management

Week of January 12, 2026

App management

PowerShell script installer for Win32 apps

When adding a Win32 app, you can upload a PowerShell script to serve as the installer instead of specifying a command line. Intune packages the script with the app content and runs it in the same context as the app installer, enabling richer setup workflows like prerequisite checks, configuration changes, and post-install actions. Installation results appear in the Intune admin center based on the script's return code.

For more information, see Win32 app management in Microsoft Intune.

[!div class="checklist"] Applies to:

  • Windows

Week of December 8, 2025

Device enrollment

ACME protocol support for iOS/iPadOS and macOS enrollment

As we prepare to support managed device attestation in Intune, we are starting a phased rollout of an infrastructure change for new enrollments that includes support for the Automated Certificate Management Environment (ACME) protocol. Now when new Apple devices enroll, the management profile from Intune receives an ACME certificate instead of a SCEP certificate. ACME provides better protection than SCEP against unauthorized certificate issuance through robust validation mechanisms and automated processes, which helps reduce errors in certificate management.

Existing OS and hardware eligible devices do not get the ACME certificate unless they re-enroll. There is no change to the end user's enrollment experience, and no changes to the Microsoft Intune admin center. This change only impacts enrollment certificates and has no impact on any device configuration policies.

ACME is supported for Apple Device Enrollment (BYOD), Apple Configurator enrollment, and automated device enrollment (ADE) methods. Eligible OS versions include:

  • iOS 16.0 or later

  • iPadOS 16.1 or later

  • macOS 13.1 or later

New Setup Assistant screens now generally available for iOS/iPadOS and macOS automated device enrollment profiles

You can hide or show 12 new Setup Assistant screens during automated device enrollment (ADE). The default is to show these screens in Setup Assistant.

The screens you can skip during iOS/iPadOS enrollment, and the applicable versions, include:

  • App Store (iOS/iPadOS 14.3+)
  • Camera button (iOS/iPadOS 18+)
  • Web content filtering (iOS/iPadOS 18.2+)
  • Safety and handling (iOS/iPadOS 18.4+)
  • Multitasking (iOS/iPadOS 26+)
  • OS Showcase (iOS/iPadOS 26+)

The screens you can skip during macOS enrollment include:

  • App Store (macOS 11.1+)
    • Get Started (macOS 15+)
    • Software update (macOS 15.4+)
    • Additional privacy settings (macOS 26+)
    • OS Showcase (macOS 26.1+)
    • Update completed (macOS 26.1+)

For more information about available Setup Assistant skipkeys, see:

For previous months, see the What's new archive.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.