← Previous day

Keep up with Microsoft Intune

Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →

Day in brief

Intune guidance flags registry exposure, approval boundaries, and macOS enrollment risks

The 7 August period is documentation-heavy: all 32 recorded items are updates, with no new, removed, or Message Center entries. The most consequential changes clarify security exposure, Multi Admin Approval scope, macOS enrollment prerequisites, Microsoft Tunnel installation requirements, and Windows Autopilot network endpoints. The supplied evidence does not establish a new feature launch, general availability change, retirement, or broad product behavior change.

  • The Collect Device Properties guidance now states that collected registry key data is accessible through existing Device Inventory permissions and may expose sensitive device configuration information. This is security and privacy guidance, not evidence that the permission model changed; review access and handling of the collected data.

  • The guidance now clarifies that MAA applies to delegated actions and app-authenticated Microsoft Graph API calls when policies are configured. Per-policy enterprise application exclusions for app-auth calls are limited to 50 applications, require second-admin approval, and are audited; excluded applications can bypass approval for the affected resource type.

  • The Automated Device Enrollment guidance warns that targeting userless ADE devices with PSSO configuration profiles that enable PSSO registration during Setup Assistant can cause unexpected enrollment behavior and loss of expected device affinity. Review assignments and exclude those devices.

  • The prerequisites now list Red Hat Enterprise Linux 9.8 with Podman 5.8.2 or later as the default. Because RHEL 9.8 does not automatically load the ip_tables kernel module, administrators must load it manually before installing Microsoft Tunnel.

  • The Endpoints page replaces the previous regional lgmsape...blob.core.windows.net entries with a larger list of amsu...lmsas.blob.core.windows.net endpoints. Administrators managing outbound firewall or allowlist rules should review the new list to support Windows Autopilot diagnostics uploads.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

32 updates

5

Assign Apps to Groups in Microsoft Intune

Updated

The documentation now explicitly states that Available assignments can target device groups for Win32 apps and apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices. The documentation date changed from 12/03/2025 to 08/06/2026.

Assign Apps

Updated

The article now retains the instruction to create an iOS app configuration policy but removes the linked Sophos Intercept X managed-settings reference.

Managed Apps Android

Updated

The AIP mobile apps description no longer includes the sentence linking to Google Play for the mobile viewer app. The supported viewing description remains.

Blackberry

Updated

The BlackBerry Intune documentation no longer includes the link to BlackBerry UES documentation.

Ref Protected Apps

Updated

The protected apps reference no longer includes the Klaxoon for Intune entry.

4

Licensing

Updated

The licensing documentation now states that Intune device-only subscriptions support eligible shared-device and no-user-affinity enrollment scenarios. It also clarifies that an unlicensed signed-in user does not prevent device-targeted policies, apps, or management actions from processing.

Setup Automated Macos

Updated

The macOS Automated Device Enrollment documentation now warns against targeting userless ADE devices with PSSO configuration profiles that enable PSSO registration during Setup Assistant. This can cause unexpected enrollment behavior and loss of expected device affinity.

Add Apps Unenrolled Devices

Updated

The page now links only to the general Android and iOS store-app instructions; the direct CylancePROTECT Google Play and Apple App Store URLs were removed.

Index

Updated

The page now notes that enrollment time grouping is available for iOS/iPadOS and macOS, along with the new Apple enrollment policies experience, and links to a previous blog post.

3

Mam Android

Updated

The page refreshes links for Intune App SDK certificate trust management, including the MAMCertTrustWebViewClient reference, which now points to GitHub documentation.

Prerequisites the Microsoft Tunnel VPN for Microsoft Intune

Updated

The prerequisites documentation date changed from June 24, 2026 to August 6, 2026. It adds Red Hat Enterprise Linux 9.8 with Podman 5.8.2 or later as the default, noting that RHEL 9.8 does not automatically load the ip_tables kernel module.

3

Collect Device Properties

Updated

The documentation now notes that collected registry key data is accessible through existing Device Inventory permissions and may expose sensitive device configuration information.

Government Service

Updated

The Remediations link now points to the deploy-remediations.md page instead of deploy-remediations.

Government Service

Updated

The government service page now lists Remediations, marked “n/a.”

2

Use Multi Admin Approval in Intune

Updated

The documentation now clarifies that MAA covers delegated actions and app-authenticated Microsoft Graph API calls when policies are already configured. It also documents per-policy enterprise application exclusions for app-auth calls, including a 50-application limit, second-admin approval, and audit logging.

Use Multi Admin Approval with the Microsoft Graph API

Updated

The documentation now states that missing approval headers return HTTP 400, while a pending approval returns HTTP 412 (Precondition Failed) with a Microsoft Graph `BadRequest` code and an `x-msft-approval-code` header. It also instructs readers to save the original method, URL, and body for resubmission.

2

Device Action: Sync

Updated

The sync page now states that its described behavior and Device sync status tab apply only to Windows devices, and instructs administrators to turn on the “Preview new device view” toggle in the top-right of the Intune admin center to see the new device sync improvements.

Index

Updated

The What's new page now documents new Windows App and OneDrive settings, a package-removal subsetting, the Disable Get Started setting, and refreshed Visual Studio administrative templates including Disable MCP. These entries apply to Windows.

1

Create Custom Role

Updated

The custom role documentation now shows the Android Enterprise “Manage zero touch enrollment” permission and its Microsoft Intune admin center link.

1
1

Collect Diagnostics

Updated

The documentation replaces the previous regional upload URLs with region-specific endpoint lists and directs administrators to Tenant Administration > Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center.

2

Add Devices

Updated

The documentation was updated to reformat three existing labels while keeping their names unchanged: M365-modern-desktop, m365initiative-coredeploy, and essentials-manage.

1

Endpoints

Updated

The endpoints documentation replaces the previous regional `lgmsape...blob.core.windows.net` entries with a larger list of `amsu...lmsas.blob.core.windows.net` endpoints.

5

Use The Service Connection Tool

Updated

The Service Connection Tool documentation updates the proxy example heading and command to use `itproxy.contoso.com:8080` instead of only the proxy hostname.

What's new in version 2603

Updated

The documentation updates its date and clarifies that SQLSysClrTypes.msi and SharedManagementObjects.msi are no longer included in the Configuration Manager package. It also retains the update from SQL Server 2014 components to SQL Server 2025 versions (SMO 17).

Manually register Microsoft Entra apps

Updated

The manual Azure AD app registration article no longer instructs administrators to set `oauth2AllowIdTokenImplicitFlow` to `true` in the app manifest. The article date changed from 03/11/2022 to 08/06/2026.

Whats New In Version 2603

Updated

The version 2603 documentation clarifies that SQL Server Management Objects and SQL Server System CLR Types use the SQL Server 2025 versions (SMO 17), while the related MSI files are no longer included in Configuration Manager media.

1

Azure Virtual Desktop

Updated

The documentation now says Azure Virtual Desktop must be deployed in an Azure subscription associated with the same Entra ID tenant as Intune. The previous wording also referenced being in the same region.

1

Software Center User Guide

Updated

The page title was capitalized, and its description now states that Software Center supports installing apps, software updates, and Windows upgrades, while directing users to the required setting.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.