The documentation now explicitly states that Available assignments can target device groups for Win32 apps and apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices. The documentation date changed from 12/03/2025 to 08/06/2026.
Keep up with Microsoft Intune
Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →
Intune guidance flags registry exposure, approval boundaries, and macOS enrollment risks
The 7 August period is documentation-heavy: all 32 recorded items are updates, with no new, removed, or Message Center entries. The most consequential changes clarify security exposure, Multi Admin Approval scope, macOS enrollment prerequisites, Microsoft Tunnel installation requirements, and Windows Autopilot network endpoints. The supplied evidence does not establish a new feature launch, general availability change, retirement, or broad product behavior change.
- Registry inventory data is explicitly identified as sensitive configuration information
Intune · Windows
The Collect Device Properties guidance now states that collected registry key data is accessible through existing Device Inventory permissions and may expose sensitive device configuration information. This is security and privacy guidance, not evidence that the permission model changed; review access and handling of the collected data.
- Multi Admin Approval guidance defines delegated and app-authenticated Graph coverage
Intune · Fundamentals
The guidance now clarifies that MAA applies to delegated actions and app-authenticated Microsoft Graph API calls when policies are configured. Per-policy enterprise application exclusions for app-auth calls are limited to 50 applications, require second-admin approval, and are audited; excluded applications can bypass approval for the affected resource type.
- Userless macOS ADE devices should not receive PSSO registration profiles
Intune · Device enrollment
The Automated Device Enrollment guidance warns that targeting userless ADE devices with PSSO configuration profiles that enable PSSO registration during Setup Assistant can cause unexpected enrollment behavior and loss of expected device affinity. Review assignments and exclude those devices.
- Microsoft Tunnel on RHEL 9.8 requires manual ip_tables loading
Intune · Device security
The prerequisites now list Red Hat Enterprise Linux 9.8 with Podman 5.8.2 or later as the default. Because RHEL 9.8 does not automatically load the ip_tables kernel module, administrators must load it manually before installing Microsoft Tunnel.
- Windows Autopilot diagnostics guidance replaces regional upload endpoints
Windows Autopilot · Windows
The Endpoints page replaces the previous regional lgmsape...blob.core.windows.net entries with a larger list of amsu...lmsas.blob.core.windows.net endpoints. Administrators managing outbound firewall or allowlist rules should review the new list to support Windows Autopilot diagnostics uploads.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
32 updates
Microsoft Intune
22 updatesAssign Apps
UpdatedThe article now retains the instruction to create an iOS app configuration policy but removes the linked Sophos Intercept X managed-settings reference.
Managed Apps Android
UpdatedThe AIP mobile apps description no longer includes the sentence linking to Google Play for the mobile viewer app. The supported viewing description remains.
Blackberry
UpdatedThe BlackBerry Intune documentation no longer includes the link to BlackBerry UES documentation.
Ref Protected Apps
UpdatedThe protected apps reference no longer includes the Klaxoon for Intune entry.
Licensing
UpdatedThe licensing documentation now states that Intune device-only subscriptions support eligible shared-device and no-user-affinity enrollment scenarios. It also clarifies that an unlicensed signed-in user does not prevent device-targeted policies, apps, or management actions from processing.
Setup Automated Macos
UpdatedThe macOS Automated Device Enrollment documentation now warns against targeting userless ADE devices with PSSO configuration profiles that enable PSSO registration during Setup Assistant. This can cause unexpected enrollment behavior and loss of expected device affinity.
Add Apps Unenrolled Devices
UpdatedThe page now links only to the general Android and iOS store-app instructions; the direct CylancePROTECT Google Play and Apple App Store URLs were removed.
Index
UpdatedThe page now notes that enrollment time grouping is available for iOS/iPadOS and macOS, along with the new Apple enrollment policies experience, and links to a previous blog post.
Mam Android
UpdatedThe page refreshes links for Intune App SDK certificate trust management, including the MAMCertTrustWebViewClient reference, which now points to GitHub documentation.
The setup page removes the external BlackBerry UES documentation link from step 8 and now instructs administrators to sign in with their Microsoft Entra account and complete setup.
The prerequisites documentation date changed from June 24, 2026 to August 6, 2026. It adds Red Hat Enterprise Linux 9.8 with Podman 5.8.2 or later as the default, noting that RHEL 9.8 does not automatically load the ip_tables kernel module.
Collect Device Properties
UpdatedThe documentation now notes that collected registry key data is accessible through existing Device Inventory permissions and may expose sensitive device configuration information.
Government Service
UpdatedThe Remediations link now points to the deploy-remediations.md page instead of deploy-remediations.
Government Service
UpdatedThe government service page now lists Remediations, marked “n/a.”
The documentation now clarifies that MAA covers delegated actions and app-authenticated Microsoft Graph API calls when policies are already configured. It also documents per-policy enterprise application exclusions for app-auth calls, including a 50-application limit, second-admin approval, and audit logging.
The documentation now states that missing approval headers return HTTP 400, while a pending approval returns HTTP 412 (Precondition Failed) with a Microsoft Graph `BadRequest` code and an `x-msft-approval-code` header. It also instructs readers to save the original method, URL, and body for resubmission.
Device Action: Sync
UpdatedThe sync page now states that its described behavior and Device sync status tab apply only to Windows devices, and instructs administrators to turn on the “Preview new device view” toggle in the top-right of the Intune admin center to see the new device sync improvements.
Index
UpdatedThe What's new page now documents new Windows App and OneDrive settings, a package-removal subsetting, the Disable Get Started setting, and refreshed Visual Studio administrative templates including Disable MCP. These entries apply to Windows.
Create Custom Role
UpdatedThe custom role documentation now shows the Android Enterprise “Manage zero touch enrollment” permission and its Microsoft Intune admin center link.
The PKCS profiles article was updated with a note that device configuration profiles, including PKCS certificate profiles, aren’t supported on Microsoft Teams devices running AOSP. The document date changed from November 19, 2024, to August 6, 2026.
Collect Diagnostics
UpdatedThe documentation replaces the previous regional upload URLs with region-specific endpoint lists and directs administrators to Tenant Administration > Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center.
Windows Autopilot
3 updatesThe page title was capitalized and its description now states that it covers gathering hardware hashes and importing, editing, and deleting device records in the Intune admin center.
Add Devices
UpdatedThe documentation was updated to reformat three existing labels while keeping their names unchanged: M365-modern-desktop, m365initiative-coredeploy, and essentials-manage.
Endpoints
UpdatedThe endpoints documentation replaces the previous regional `lgmsape...blob.core.windows.net` entries with a larger list of `amsu...lmsas.blob.core.windows.net` endpoints.
Microsoft Configuration Manager
7 updatesThe Service Connection Tool documentation updates the proxy example heading and command to use `itproxy.contoso.com:8080` instead of only the proxy hostname.
What's new in version 2603
UpdatedThe documentation updates its date and clarifies that SQLSysClrTypes.msi and SharedManagementObjects.msi are no longer included in the Configuration Manager package. It also retains the update from SQL Server 2014 components to SQL Server 2025 versions (SMO 17).
The documentation now refers to the “CMG SUP server” instead of the “CGM SUP server” when configuring a boundary group.
The manual Azure AD app registration article no longer instructs administrators to set `oauth2AllowIdTokenImplicitFlow` to `true` in the app manifest. The article date changed from 03/11/2022 to 08/06/2026.
Whats New In Version 2603
UpdatedThe version 2603 documentation clarifies that SQL Server Management Objects and SQL Server System CLR Types use the SQL Server 2025 versions (SMO 17), while the related MSI files are no longer included in Configuration Manager media.
Azure Virtual Desktop
UpdatedThe documentation now says Azure Virtual Desktop must be deployed in an Azure subscription associated with the same Entra ID tenant as Intune. The previous wording also referenced being in the same region.
Software Center User Guide
UpdatedThe page title was capitalized, and its description now states that Software Center supports installing apps, software updates, and Windows upgrades, while directing users to the required setting.