What's new in Microsoft Intune
In brief
The documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.
What Intune admins need to know
Administrators can use these options to support remote troubleshooting, app deployment, device security, and platform configuration. No mandatory action is stated.
This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: What's new in Microsoft Intune
description: Find out what's new in Microsoft Intune.
ms.date: 07/27/08/24/2026
ms.topic: whats-new
ai-usage: ai-assisted
ms.collection:
-->
Week of August 25, 2026 (Service release 2608)
Advanced capabilities (formerly "Microsoft Intune Suite")
Unattended Remote Help sessions for Windows devices
Microsoft Intune now supports unattended Remote Help sessions on physical Windows devices. Authorized helpdesk agents can sign in to a remote device with their own credentials without requiring the user to be present or take action. Helpers can view and control the device to troubleshoot issues and complete support tasks remotely.
For more information, see Planning for Remote Help.
[!div class="checklist"] Applies to:
- Windows
App management
Newly available protected apps for Intune
The following protected apps are now available for Microsoft Intune:
- Notion by Notion Labs
- Superhuman Mail by Superhuman Labs
- Calven by Calven Pty Limited
- Heijmans by Heijmans
- Notability by Ginger Labs, Inc. (iOS)
- Ben for Intune by Thanks Ben Ltd
- SDP - On Premises | Intune by Zoho Corporation
For more information about protected apps, see Microsoft Intune protected apps.
Declarative Device Management for Apple volume purchase program apps
Microsoft Intune now supports Apple Declarative Device Management (DDM) for required volume purchase program (VPP) apps on devices running iOS/iPadOS 17.2 and later and macOS 26 and later. By changing the management type to DDM when you upload a new VPP token, you can deploy and configure apps using Apple's policy-based model, which improves delivery efficiency, provides real-time app status, and adds new per-app settings such as automatic app updates.
[!div class="checklist"] Applies to:
- iOS/iPadOS
- macOS
Device configuration
Configure screen timeout for corporate Android devices
Microsoft Intune now supports a Screen timeout setting in the Android Enterprise settings catalog, letting you specify how many seconds pass before the screen turns off. Configure it under Devices > Manage devices > Configuration > Create > New policy > Android Enterprise > Settings catalog. The value must stay at or below Time to lock screen and applies to fully managed and dedicated devices on Android 9 and later, and corporate-owned work profile devices on Android 15 and later.
[!div class="checklist"] Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Separate device and work profile passwords on Android Enterprise devices
Microsoft Intune now supports the Block one lock for device and work profile setting in the Android Enterprise settings catalog, letting you require separate locks for the device and work profile instead of a shared one. Set it to True after configuring a work profile password requirement. The default, False, allows a common lock. The setting supports Android 9 and later.
[!div class="checklist"] Applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE)
Limit how long an Android work profile can stay off
Microsoft Intune now supports the Number of days work profile is allowed to be switched off setting in the Android Enterprise settings catalog, so you can limit how long a work profile stays turned off. Enter the maximum number of days, with a minimum of three, or enter 0 to disable the restriction. There's no documented upper limit, giving you flexibility for your organization's needs.
[!div class="checklist"] Applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE)
Remove eSIMs during a device wipe with a settings catalog policy
Microsoft Intune now supports the Remove all eSIMs during a device wipe setting in the Android Enterprise settings catalog. Set it to True to request removal of all eSIMs when a corporate-owned device is wiped while the policy applies. The default, False, doesn't request removal, although the operating system might still remove eSIMs when required. The setting supports Android 15 and later.
[!div class="checklist"] Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
New updates to the Apple settings catalog
Microsoft Intune now supports new Settings Catalog options for testing on the OS 27 betas, covering Declarative Device Management areas such as App Settings, Web Content Filter, and Siri Settings for iOS/iPadOS and macOS. Configure them under Devices > Manage devices > Configuration > Create > New policy > iOS/iPadOS or macOS > Settings catalog. This lets you test upcoming Apple management controls ahead of general availability.
For more information, see Create a policy using settings catalog.
[!div class="checklist"] Applies to:
- iOS/iPadOS
- macOS
Keep Android device screens on while charging
Microsoft Intune now includes a settings catalog option for keeping fully managed and dedicated Android device screens on while charging. Select one or more modes - AC, USB, or Wireless - to control when the screen stays on. AC and USB support Android 6.0 and later; wireless charging requires Android 8.1 and later. No modes are selected by default.
[!div class="checklist"] Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
New policy settings for Windows
Microsoft Intune now includes new Windows settings catalog options across several administrative template refreshes. Highlights include Turn on Protected Mode controls for Internet Explorer security zones, new Microsoft Edge policies from the Edge 150 template refresh, and a Disconnect if a Remote Desktop Services session when no smart card is present option for interactive logon. The Microsoft Office templates also gained new settings. Create a Windows settings catalog profile to configure them.
[!div class="checklist"] Applies to:
- Windows
Device enrollment
Skip new Apple Setup Assistant panes during enrollment
Microsoft Intune now includes Apple OS 27 Setup Assistant skip keys for Liquid Glass and Accessibility Appearance in Automated Device Enrollment profiles. You can hide these panes to reduce setup interactions and provide a more consistent enrollment experience on supported iPhone, iPad, and Mac devices.
[!div class="checklist"] Applies to:
- iOS/iPadOS
- macOS
Device management
New single device page in the Intune admin center
The new single device page is turned on by default for all customers. You can use the Preview new device view toggle to turn it off and return to the original device page.
In the Intune admin center, when you go to Devices > All devices and select a device, you can see device-specific information, including device properties, device activity, tools, and reports.
Where to find common device information and actions in the new single device view:
- Change the management name, primary user, or device category: Go to Devices > All devices > select a device > Properties > Edit.
- View hardware and operating system information: Go to Devices > All devices > select a device > Device details. The Device details tab was previously called Hardware.
- Perform device actions: Go to Devices > All devices and select a device. Some actions are organized in the Remote actions, Secure, and Remove data menus on the device command bar. The available actions depend on the device platform, management type, ownership, permissions, and supported capabilities.
- View the status of device actions: Go to Devices > All devices > select a device > Device action status.
- View the status of Remediations: Go to Devices > All devices > select a device > Tools > Remediations.
- View scope tags: Go to Devices > All devices > select a device > Properties.
Return to the original device page:
If you prefer to use the original device page, you can turn off the new experience:
- In the Intune admin center, go to Devices > All devices.
- Move the Preview new device view toggle to Off.
[!div class="checklist"] Applies to:
- Android
- iOS/iPadOS
- macOS
- Windows
Operating system version property in assignment filters is generally available
The operatingSystemVersion property in assignment filters is now generally available for managed devices and managed apps. Use this property to create filter rules that scope your app and policy assignments to devices running a specific OS version or build range. For example, create an assignment filter that pilots a configuration on a newer build before rolling it out broadly or excludes devices that haven't yet updated.
You can build rules using the rule editor or the rule syntax text box, with the same operators available for other filter properties. Existing assignments continue to work without changes.
For more information, see:
- Use assignment filters to assign apps, policies, and profiles
- App and device properties, operators, and rule editing when creating assignment filters
Collect enhanced diagnostic logs from supervised Apple devices
Microsoft Intune now supports Apple's Enhanced Logging device action on supported supervised devices running a compatible OS release. Administrators can start an AppleCare diagnostic-log collection session using an AppleCare-provided token and monitor device-reported status through Declarative Device Management, reducing the need to coordinate manual log collection with the device user.
[!div class="checklist"] Applies to:
- iOS/iPadOS
- macOS
View expanded SIM inventory for corporate-owned Android devices
Microsoft Intune now surfaces expanded SIM inventory for corporate-owned Android Enterprise devices, including EIDs, multiple ICCIDs, and activation state. View these details under Devices > All devices > select a device > Hardware, and use the reported ICCID to identify the correct eSIM for a removal action. EID reporting requires Android 13 and later; full inventory requires Android 15 and later.
[!div class="checklist"] Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Activate an eSIM on a corporate-owned Android device
Microsoft Intune now supports single-device eSIM activation for corporate-owned Android Enterprise devices running Android 15 and later. Turn on Preview new device view, select the device, then select Activate eSIM and enter the carrier activation code. Intune sends the request without first blocking it based on reported eSIM slot capacity and surfaces errors returned by Google. Personally owned work profile devices aren't supported.
[!div class="checklist"] Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Remove an individual eSIM from a corporate-owned Android device
Microsoft Intune now lets you remove a single eSIM from a corporate-owned Android Enterprise device without wiping it. Turn on Preview new device view, select the device, copy the eSIM's ICCID from device inventory, then select Remove eSIM and enter the ICCID. The action supports fully managed and dedicated devices on Android 15 and later, and work profile devices on Android 17 and later.
[!div class="checklist"] Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Choose whether to remove eSIMs when wiping one corporate-owned Android device
Microsoft Intune now lets you choose whether to preserve or remove eSIMs when wiping one corporate-owned Android Enterprise device. Turn on Preview new device view, select the device, then select Wipe. By default, the wipe preserves eSIMs; select the eSIM removal option only when you want the wipe to remove them. Personally owned work profile devices aren't supported.
[!div class="checklist"] Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Device inventory for personally owned devices on Android Enterprise
Microsoft Intune now supports device inventory for personally owned Android Enterprise devices with a work profile managed by Android Management API. View these devices from the device's Inventory page alongside corporate-owned devices in Resource Explorer, and query them with Multi-Device Query. Inventory data is a subset of corporate-owned data; properties such as IMEI, ICCID, and MAC address aren't available. This gives you more consistent analytics across mixed corporate and BYOD environments.
[!div class="checklist"] Applies to:
- Android Enterprise personally owned devices with a work profile using Android Management API
Device security
Audit mode for the Microsoft Defender Antivirus template for Linux
The Microsoft Defender Antivirus template for Linux, which is part of Intune's Endpoint Security Antivirus policy, now includes a new Audit value for the Enforcement level setting. When you set Enforcement level to Audit, the antivirus engine detects threats in real time but doesn't automatically remediate them. Malware detections are reported as alerts in the Microsoft Defender portal through real-time scanning, without quarantining the malicious files. Audit mode gives you visibility into the threat landscape before you turn on full protection.
The Microsoft Defender Antivirus template for Linux is supported for devices managed by Intune, and for devices managed only by Defender through the Microsoft Defender for Endpoint security settings management scenario (MDE attach).
[!div class="checklist"] Applies to:
- Linux
Windows 365 for Agents security baseline
Microsoft Intune now includes a security baseline for Windows 365 for Agents Cloud PCs. Administrators can deploy and customize recommended, device-scoped settings for Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint to establish a consistent security posture for agentic workloads.
For more information, see Manage security baseline profiles in Microsoft Intune and What is Windows 365 for Agents?.
[!div class="checklist"] Applies to:
- Windows 365 for Agents Cloud PCs running Windows 11 and later
Memory scan setting for Microsoft Defender Antivirus on Linux
Microsoft Intune now supports a memory scan setting in the Microsoft Defender Antivirus template for Linux endpoint security antivirus policies. You can manage memory scan behavior on Linux devices managed through Microsoft Defender for Endpoint security settings management, giving you finer control over how Defender inspects memory on your Linux endpoints.
[!div class="checklist"] Applies to:
- Linux
Week of July 27, 2026 (Service release 2607)
Device configuration
- Clearer error messages
Some query error messages have been updated to provide clearer, more descriptive guidance when queries are invalid.
Week of February 9, 2026 (Service release 2601)
Advanced capabilities
Endpoint Privilege Management support on Azure Virtual Desktop
Endpoint Privilege Management (EPM) elevation policies now support deployment to users on Azure Virtual Desktop (AVD) single-session virtual machines.
For information about using EPM, see Plan and Prepare for Endpoint Privilege Management Deployment.
App management
Lenovo Device Orchestration (LDO) link in the Intune admin center
Microsoft Intune now includes a direct link to Lenovo Device Orchestration (LDO) in the Intune admin center. This integration expands the Partner portals experience by giving IT admins a single, secure entry point to manage supported Lenovo devices.
From the Intune admin center, IT admins can open the Lenovo Device Orchestration portal directly to access Lenovo-specific device management capabilities.
[!div class="checklist"] Applies to:
Windows 11
Newly available protected apps for Intune
The following protected apps are now available for Microsoft Intune:
Clarity Express for Intune by Rego Consulting CorporationDatadog by Datadog Inc.Qlik Analytics by QlikTier1 for Intune by SS&C Technologies, Inc. (iOS)
For more information about protected apps, see Microsoft Intune protected apps.
Device configuration
New settings in the Windows settings catalog
There are new settings in the Windows settings catalog. To see and configure these settings in Intune, create a Windows settings catalog profile (Devices > Configuration profiles > Create profile > Windows 10 and later > Settings catalog).
The new policies include:
Microsoft Edge - Includes the latest Microsoft Edge browser policies, up to version 143.0.3650.23, including:Allow sharing tenant-approved browsing history with Microsoft 365 Copilot SearchEnable RAM (memory) resource controlsSpecifies whether to opt out of Local Network access restrictions
Due to differences in release cadences between Microsoft Edge and Intune, there can be a one-to-two-week delay in the settings catalog.Experience >Disable Share App Promotions- This policy setting allows IT admins to control if promotional apps are shown in the Windows Share Sheet. If you enable this policy, Windows doesn't show promotional apps in the Share Sheet.Licensing >Enable ESU Subscription Check: This policy is deprecated and only works on Windows 10. Setting this policy has no effect on other supported Windows versions. This policy enables or disables subscription check for Windows 10 Extended Security Updates. If enabled, the device check for the ESU subscription status of the signed-in Microsoft Entra ID user account.Windows AI - Includes the following new settings that are available to Windows Insiders:Disable Agent Workspaces- Enables or disables Agent Workspaces.Disable Agent Connectors- Enables or disables Agent Connectors.Disable Remote Agent Connectors- Enables or disables remote Agent Connectors.Agent Connector Minimum Policy- Configures the minimum policy value that controls how agent connectors run on the machine.
Google Chrome - Includes the Google Chrome ADMX browser policies, up to version 141.0.7390.108.Due to differences in release cadences between Chrome and Intune, Intune can be one to two versions behind the latest released Chrome version.Firewall >Enable Audit Mode- If enabled, the target machine goes into Firewall audit mode.Microsoft Visual Studio > Copilot settings >Disable agent mode- This existing Copilot setting is updated to include localization. This setting prevents users from using GitHub Copilot agent mode.Windows Components > Internet Explorer > Internet Control Panel > Security Page:Turn on automatic detection of intranet- This policy setting enables intranet mapping rules to be applied automatically if the computer belongs to a domain. If you enable this policy setting, automatic detection of the intranet is turned on, and intranet mapping rules are applied automatically if the computer belongs to a domain.Intranet Sites: Include all sites that bypass the proxy server- This policy setting controls whether sites which bypass the proxy server are mapped into the local Intranet security zone. If you enable this policy setting, sites which bypass the proxy server are mapped into the Intranet Zone.
[!div class="checklist"] Applies to:
Windows
To learn more about the settings catalog, see Use the Intune settings catalog to configure settings.
New supported OEMConfig apps for Android Enterprise
The following OEMConfig apps are available in Intune for Android Enterprise:
FCNT - Senior Care |com.fcnt.mobile_phone.seniorcareconfigFCNT - Schema |com.fcnt.mobile_phone.schematestSonim |com.sonim.oemappconfig
For more information about OEMConfig, see Use and manage Android Enterprise devices with OEMConfig in Microsoft Intune.
Filter by Android management mode in the settings catalog
The settings catalog includes hundreds of settings that you can configure. There are built-in features that help filter the available settings.
When you create an Android settings catalog policy, there's a management mode filter option that filters the available settings by their enrollment type, including:
Fully managedCorporate-owned work profileDedicated
To learn more about the settings catalog, see:
New updates to the Apple settings catalog
The Settings Catalog lists all the settings you can configure in a device policy, and all in one place. For more information about configuring Settings Catalog profiles in Intune, see Create a policy using settings catalog.
There is a new setting in the Settings Catalog. To see this setting, in the [Microsoft Intune admin center], go to Devices > Manage devices > Configuration > Create > New policy > iOS/iPadOS for platform > Settings catalog for profile type.
iOS/iPadOS
Restrictions:
Rating Apps Exempted Bundle IDs: This setting lets admins specify apps that can bypass the 17 and older restriction.For example, a device can have its content restricted to ages 9 and below. With this restriction, apps with an age-based rating of 17 and older are automatically blocked. Admins can use this setting to allow specific apps to bypass this restriction.
Apple rebranded Rapid Security Responses to Background Security Improvements. This change is updated in the settings catalog. For more information on Background Security Improvements, see Background Security Improvements on Apple devices (opens Apple's web site).
Device management
More options for assignment filters > Device Management Type property for managed apps on Android and iOS/iPadOS
For Android, the Device Management Type property for managed apps is:
Adding the following options:
To replace the following option:
For iOS/iPadOS, the Device Management Type property for managed apps is:
Adding the following options:
To replace the following option:
When you create policies for your managed apps, you can use assignment filters to assign policies based on rules you create. In these rules, you can use different device and app properties, including the Device Management Type property on Android and iOS/iPadOS.
What you need to know
com.microsoft.intune.mam.IntuneMAMOnly.RequireAADRegistration=Enabled key.
To learn more about filters, see:
Use assignment filters to assign your apps, policies, and profiles in Microsoft IntuneApp and device properties, operators, and rule editing when creating assignment filters in Microsoft Intune
[!div class="checklist"] Applies to:
AndroidiOS/iPadOS
Intune certificate inventory integration with Zimperium mobile threat defense
You can now configure the Zimperium Mobile Threat Defense (MTD) connector to synchronize certificate inventory from your managed iOS devices. This enhancement helps you identify when a device threat level is elevated due to approved but potentially malicious certificates on the device. The following settings are now available when configuring the connector:
Enable Certificate Sync for iOS/iPadOS devices- Allows this Mobile Threat Defense partner to request a list of installed certificates on iOS/iPadOS devices from Intune to use for threat analysis purposes.Send full certificate inventory data on personally owned iOS/iPadOS devices- This setting controls the certificate inventory data that Intune shares with this Mobile Threat Defense partner for personally owned devices. Data is shared when the partner syncs certificate data and requests the certificate inventory list.
When certificate sync is enabled, the following data is shared:
Account IDEntra ID Device IDDevice OwnerCertificate ListCommon NameDataIs Identity
For more information, see Mobile Threat Defense toggle options.
[!div class="checklist"] Applies to:
iOS/iPadOS
Device security
Update firewall configurations for new Intune network endpoints
As part of Microsoft's ongoing Secure Future Initiative (SFI), Microsoft Intune began using Azure Front Door (AFD) IP addresses in addition to the existing Intune service IPs in December 2025.
Customers that use IP-based allowlist, Azure service tags, or have strict outbound filtering in their firewall, VPN, proxy, or other network infrastructure may block this new traffic, causing degraded or failed device connectivity. This can affect core Intune functions including device and app management.
If your organization uses Fully Qualified Domain Name (FQDN)-based rules or does not restrict outbound traffic, no changes are typically required. However, you should verify that the appropriate wildcard rules are configured, specifically*.manage.microsoft.com, to ensure all Intune services remain reachable. Microsoft continues to recommend using FQDN-based wildcard rules whenever possible to reduce administrative overhead for organizations that require outbound filtering.If your organization uses IP-based allowlistsin your firewall, proxy, or VPN rules, you must add the Azure Front Door IP ranges below or use Azure service tagAzureFrontDoor.MicrosoftSecurityto avoid potential connectivity issues for managed devices.
Required IP addresses for commercial endpoints:
13.107.219.0/2413.107.227.0/2413.107.228.0/23150.171.97.0/242620:1ec:40::/482620:1ec:49::/482620:1ec:4a::/47
Required IP addresses for US government endpoints:
51.54.53.136/2951.54.114.160/2962.11.173.176/29
For the authoritative and up-to-date list of network endpoints required by Intune client and host services, see Intune core service in Network endpoints for Microsoft Intune, and Ports and IP addresses list in US government endpoints for Microsoft Intune.
For additional context on this change, see Support Tip: Upcoming Microsoft Intune Network Changes.
Monitor and troubleshoot
Windows feature update reports support Windows 11, version 25H2
The Windows feature update compatibility risks report and Windows feature update device readiness report support Windows 11, version 25H2 as a selectable target OS. When you choose this version under Select target OS, the reports provide updated insights to help you assess device readiness and identify potential compatibility risks before deploying the feature update.
[!div class="checklist"] Applies to:
Windows
Tenant administration
Admin tasks in Microsoft Intune are now generally available
Admin tasks in the Intune admin center are out of preview and now generally available. Admin tasks provide a centralized view where admins can discover, organize, and act on common tasks that are otherwise spread throughout the Intune admin center. Located under Tenant Administration, this unified experience supports search, filtering, and sorting to help you focus on what needs attention, without navigating across multiple nodes.
The following task types are supported:
Endpoint Privilege Management file elevation requestsMicrosoft Defender security tasksMulti Admin Approval requests
Intune only shows tasks you have permission to manage. When you select a task, Intune opens the same interface and workflow you'd use if managing the task from its original location. This ensures a consistent experience whether you're working from the admin tasks node or directly within the source capability.
To learn more, see:
For previous months, see the What's new archive.
@@ -1,7 +1,7 @@ --- title: What's new in Microsoft Intune description: Find out what's new in Microsoft Intune.-ms.date: 07/27/2026+ms.date: 08/24/2026 ms.topic: whats-new ai-usage: ai-assisted ms.collection:@@ -49,6 +49,271 @@ You can use RSS to be notified when this page is updated. For more information, --> +## Week of August 25, 2026 (Service release 2608)++### Advanced capabilities (formerly "Microsoft Intune Suite")++#### Unattended Remote Help sessions for Windows devices<!-- 9052232 -->++Microsoft Intune now supports unattended Remote Help sessions on physical Windows devices. Authorized helpdesk agents can sign in to a remote device with their own credentials without requiring the user to be present or take action. Helpers can view and control the device to troubleshoot issues and complete support tasks remotely.++For more information, see [Planning for Remote Help](../remote-help/plan.md).++> [!div class="checklist"]+> Applies to:+>+> - Windows++### App management++#### Newly available protected apps for Intune<!-- 37759185, 37775055, 38439465, 38470930, 38472151, 38542841, 38657260 -->++The following protected apps are now available for Microsoft Intune:++- Notion by Notion Labs+- Superhuman Mail by Superhuman Labs+- Calven by Calven Pty Limited+- Heijmans by Heijmans+- Notability by Ginger Labs, Inc. (iOS)+- Ben for Intune by Thanks Ben Ltd+- SDP - On Premises | Intune by Zoho Corporation++For more information about protected apps, see [Microsoft Intune protected apps](../app-management/ref-protected-apps.md).++#### Declarative Device Management for Apple volume purchase program apps<!-- 30457044 -->++Microsoft Intune now supports Apple Declarative Device Management (DDM) for required volume purchase program (VPP) apps on devices running iOS/iPadOS 17.2 and later and macOS 26 and later. By changing the management type to DDM when you upload a new VPP token, you can deploy and configure apps using Apple's policy-based model, which improves delivery efficiency, provides real-time app status, and adds new per-app settings such as automatic app updates.++> [!div class="checklist"]+> Applies to:+>+> - iOS/iPadOS+> - macOS++### Device configuration++#### Configure screen timeout for corporate Android devices<!-- 29677574 -->++Microsoft Intune now supports a **Screen timeout** setting in the Android Enterprise settings catalog, letting you specify how many seconds pass before the screen turns off. Configure it under **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy** > **Android Enterprise** > **Settings catalog**. The value must stay at or below **Time to lock screen** and applies to fully managed and dedicated devices on Android 9 and later, and corporate-owned work profile devices on Android 15 and later.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate owned fully managed (COBO)+> - Android Enterprise corporate owned dedicated devices (COSU)+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### Separate device and work profile passwords on Android Enterprise devices<!-- 31576322 -->++Microsoft Intune now supports the **Block one lock for device and work profile** setting in the Android Enterprise settings catalog, letting you require separate locks for the device and work profile instead of a shared one. Set it to **True** after configuring a work profile password requirement. The default, **False**, allows a common lock. The setting supports Android 9 and later.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### Limit how long an Android work profile can stay off<!-- 33982125 -->++Microsoft Intune now supports the **Number of days work profile is allowed to be switched off** setting in the Android Enterprise settings catalog, so you can limit how long a work profile stays turned off. Enter the maximum number of days, with a minimum of three, or enter **0** to disable the restriction. There's no documented upper limit, giving you flexibility for your organization's needs.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### Remove eSIMs during a device wipe with a settings catalog policy<!-- 37385796 -->++Microsoft Intune now supports the **Remove all eSIMs during a device wipe** setting in the Android Enterprise settings catalog. Set it to **True** to request removal of all eSIMs when a corporate-owned device is wiped while the policy applies. The default, **False**, doesn't request removal, although the operating system might still remove eSIMs when required. The setting supports Android 15 and later.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate owned fully managed (COBO)+> - Android Enterprise corporate owned dedicated devices (COSU)+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### New updates to the Apple settings catalog<!-- 38356110 -->++Microsoft Intune now supports new Settings Catalog options for testing on the OS 27 betas, covering Declarative Device Management areas such as **App Settings**, **Web Content Filter**, and **Siri Settings** for iOS/iPadOS and macOS. Configure them under **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy** > **iOS/iPadOS** or **macOS** > **Settings catalog**. This lets you test upcoming Apple management controls ahead of general availability.++For more information, see [Create a policy using settings catalog](../device-configuration/settings-catalog/index.md).++> [!div class="checklist"]+> Applies to:+>+> - iOS/iPadOS+> - macOS++#### Keep Android device screens on while charging<!-- 38815189 -->++Microsoft Intune now includes a settings catalog option for keeping fully managed and dedicated Android device screens on while charging. Select one or more modes - **AC**, **USB**, or **Wireless** - to control when the screen stays on. AC and USB support Android 6.0 and later; wireless charging requires Android 8.1 and later. No modes are selected by default.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate owned fully managed (COBO)+> - Android Enterprise corporate owned dedicated devices (COSU)++#### New policy settings for Windows<!-- 38928110 -->++Microsoft Intune now includes new Windows settings catalog options across several administrative template refreshes. Highlights include **Turn on Protected Mode** controls for Internet Explorer security zones, new Microsoft Edge policies from the Edge 150 template refresh, and a **Disconnect if a Remote Desktop Services session when no smart card is present** option for interactive logon. The Microsoft Office templates also gained new settings. Create a Windows settings catalog profile to configure them.++> [!div class="checklist"]+> Applies to:+>+> - Windows++### Device enrollment++#### Skip new Apple Setup Assistant panes during enrollment<!-- 38408206 -->++Microsoft Intune now includes Apple OS 27 Setup Assistant skip keys for Liquid Glass and Accessibility Appearance in Automated Device Enrollment profiles. You can hide these panes to reduce setup interactions and provide a more consistent enrollment experience on supported iPhone, iPad, and Mac devices.++> [!div class="checklist"]+> Applies to:+>+> - iOS/iPadOS+> - macOS++### Device management++#### New single device page in the Intune admin center<!-- 16532161 -->++The new single device page is turned on by default for all customers. You can use the **Preview new device view** toggle to turn it off and return to the original device page.++In the Intune admin center, when you go to **Devices** > **All devices** and select a device, you can see device-specific information, including device properties, device activity, tools, and reports.++**Where to find common device information and actions in the new single device view:**++- Change the management name, primary user, or device category: Go to **Devices** > **All devices** > select a device > **Properties** > **Edit**.+- View hardware and operating system information: Go to **Devices** > **All devices** > select a device > **Device details**. The **Device details** tab was previously called **Hardware**.+- Perform device actions: Go to **Devices** > **All devices** and select a device. Some actions are organized in the **Remote actions**, **Secure**, and **Remove data** menus on the device command bar. The available actions depend on the device platform, management type, ownership, permissions, and supported capabilities.+- View the status of device actions: Go to **Devices** > **All devices** > select a device > **Device action status**.+- View the status of Remediations: Go to **Devices** > **All devices** > select a device > **Tools** > **Remediations**.+- View scope tags: Go to **Devices** > **All devices** > select a device > **Properties**.++**Return to the original device page:**++If you prefer to use the original device page, you can turn off the new experience:++1. In the Intune admin center, go to **Devices** > **All devices**.+1. Move the **Preview new device view** toggle to **Off**.++> [!div class="checklist"]+> Applies to:+>+> - Android+> - iOS/iPadOS+> - macOS+> - Windows++#### Operating system version property in assignment filters is generally available<!-- 38448498 -->++The `operatingSystemVersion` property in assignment filters is now generally available for managed devices and managed apps. Use this property to create filter rules that scope your app and policy assignments to devices running a specific OS version or build range. For example, create an assignment filter that pilots a configuration on a newer build before rolling it out broadly or excludes devices that haven't yet updated.++You can build rules using the rule editor or the rule syntax text box, with the same operators available for other filter properties. Existing assignments continue to work without changes.++For more information, see:++- [Use assignment filters to assign apps, policies, and profiles](../fundamentals/filters/overview.md)+- [App and device properties, operators, and rule editing when creating assignment filters](../fundamentals/filters/ref-device-properties.md)++#### Collect enhanced diagnostic logs from supervised Apple devices<!-- 35859652 -->++Microsoft Intune now supports Apple's Enhanced Logging device action on supported supervised devices running a compatible OS release. Administrators can start an AppleCare diagnostic-log collection session using an AppleCare-provided token and monitor device-reported status through Declarative Device Management, reducing the need to coordinate manual log collection with the device user.++> [!div class="checklist"]+> Applies to:+>+> - iOS/iPadOS+> - macOS++#### View expanded SIM inventory for corporate-owned Android devices<!-- 36971225 -->++Microsoft Intune now surfaces expanded SIM inventory for corporate-owned Android Enterprise devices, including EIDs, multiple ICCIDs, and activation state. View these details under **Devices** > **All devices** > select a device > **Hardware**, and use the reported ICCID to identify the correct eSIM for a removal action. EID reporting requires Android 13 and later; full inventory requires Android 15 and later.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate owned fully managed (COBO)+> - Android Enterprise corporate owned dedicated devices (COSU)+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### Activate an eSIM on a corporate-owned Android device<!-- 36971755 -->++Microsoft Intune now supports single-device eSIM activation for corporate-owned Android Enterprise devices running Android 15 and later. Turn on **Preview new device view**, select the device, then select **Activate eSIM** and enter the carrier activation code. Intune sends the request without first blocking it based on reported eSIM slot capacity and surfaces errors returned by Google. Personally owned work profile devices aren't supported.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate owned fully managed (COBO)+> - Android Enterprise corporate owned dedicated devices (COSU)+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### Remove an individual eSIM from a corporate-owned Android device<!-- 36975091 -->++Microsoft Intune now lets you remove a single eSIM from a corporate-owned Android Enterprise device without wiping it. Turn on **Preview new device view**, select the device, copy the eSIM's ICCID from device inventory, then select **Remove eSIM** and enter the ICCID. The action supports fully managed and dedicated devices on Android 15 and later, and work profile devices on Android 17 and later.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate owned fully managed (COBO)+> - Android Enterprise corporate owned dedicated devices (COSU)+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### Choose whether to remove eSIMs when wiping one corporate-owned Android device<!-- 36975226 -->++Microsoft Intune now lets you choose whether to preserve or remove eSIMs when wiping one corporate-owned Android Enterprise device. Turn on **Preview new device view**, select the device, then select **Wipe**. By default, the wipe preserves eSIMs; select the eSIM removal option only when you want the wipe to remove them. Personally owned work profile devices aren't supported.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise corporate owned fully managed (COBO)+> - Android Enterprise corporate owned dedicated devices (COSU)+> - Android Enterprise corporate-owned devices with a work profile (COPE)++#### Device inventory for personally owned devices on Android Enterprise<!-- 37853885 -->++Microsoft Intune now supports device inventory for personally owned Android Enterprise devices with a work profile managed by Android Management API. View these devices from the device's **Inventory** page alongside corporate-owned devices in Resource Explorer, and query them with Multi-Device Query. Inventory data is a subset of corporate-owned data; properties such as IMEI, ICCID, and MAC address aren't available. This gives you more consistent analytics across mixed corporate and BYOD environments.++> [!div class="checklist"]+> Applies to:+>+> - Android Enterprise personally owned devices with a work profile using Android Management API++### Device security++#### Audit mode for the Microsoft Defender Antivirus template for Linux<!-- 37284585 -->++The Microsoft Defender Antivirus template for Linux, which is part of Intune's Endpoint Security Antivirus policy, now includes a new **Audit** value for the **Enforcement level** setting. When you set **Enforcement level** to **Audit**, the antivirus engine detects threats in real time but doesn't automatically remediate them. Malware detections are reported as alerts in the Microsoft Defender portal through real-time scanning, without quarantining the malicious files. Audit mode gives you visibility into the threat landscape before you turn on full protection.++The Microsoft Defender Antivirus template for Linux is supported for devices [managed by Intune](../device-configuration/endpoint-security/antivirus.md), and for devices managed only by Defender through the [Microsoft Defender for Endpoint security settings management](../device-security/microsoft-defender/security-settings-management.md) scenario (MDE attach).++> [!div class="checklist"]+> Applies to:+>+> - Linux++#### Windows 365 for Agents security baseline<!-- 37334751 -->++Microsoft Intune now includes a security baseline for Windows 365 for Agents Cloud PCs. Administrators can deploy and customize recommended, device-scoped settings for Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint to establish a consistent security posture for agentic workloads.++For more information, see [Manage security baseline profiles in Microsoft Intune](../device-security/security-baselines/configure-baselines.md) and [What is Windows 365 for Agents?](https://learn.microsoft.com/windows-365/agents/introduction-windows-365-for-agents).++> [!div class="checklist"]+> Applies to:+>+> - Windows 365 for Agents Cloud PCs running Windows 11 and later++#### Memory scan setting for Microsoft Defender Antivirus on Linux<!-- 37379877 -->++Microsoft Intune now supports a memory scan setting in the Microsoft Defender Antivirus template for Linux endpoint security antivirus policies. You can manage memory scan behavior on Linux devices managed through Microsoft Defender for Endpoint security settings management, giving you finer control over how Defender inspects memory on your Linux endpoints.++> [!div class="checklist"]+> Applies to:+>+> - Linux+ ## Week of July 27, 2026 (Service release 2607) ### Device configuration@@ -1954,266 +2219,6 @@ Device query for multiple devices now includes expanded operator support, cleare - **Clearer error messages**\ Some query error messages have been updated to provide clearer, more descriptive guidance when queries are invalid. -## Week of February 9, 2026 (Service release 2601)--### Advanced capabilities--#### Endpoint Privilege Management support on Azure Virtual Desktop<!-- 26079227 -->--Endpoint Privilege Management (EPM) elevation policies now support deployment to users on Azure Virtual Desktop (AVD) single-session virtual machines.--For information about using EPM, see [Plan and Prepare for Endpoint Privilege Management Deployment](../epm/deployment-planning.md).--### App management--#### Lenovo Device Orchestration (LDO) link in the Intune admin center<!-- 32634377 -->--Microsoft Intune now includes a direct link to **Lenovo Device Orchestration (LDO)** in the Intune admin center. This integration expands the **Partner portals** experience by giving IT admins a single, secure entry point to manage supported Lenovo devices.--From the Intune admin center, IT admins can open the Lenovo Device Orchestration portal directly to access Lenovo-specific device management capabilities.--> [!div class="checklist"]-> Applies to:->-> - Windows 11--#### Newly available protected apps for Intune<!-- 35601128, 36072132, 36072263, 36078662 -->--The following protected apps are now available for Microsoft Intune:--- Clarity Express for Intune by Rego Consulting Corporation-- Datadog by Datadog Inc.-- Qlik Analytics by Qlik-- Tier1 for Intune by SS&C Technologies, Inc. (iOS)--For more information about protected apps, see [Microsoft Intune protected apps](../app-management/ref-protected-apps.md).--### Device configuration--#### New settings in the Windows settings catalog<!-- 34625889 -->--There are new settings in the Windows settings catalog. To see and configure these settings in Intune, create a Windows settings catalog profile (**Devices > Configuration profiles > Create profile > Windows 10 and later > Settings catalog**).--The new policies include:--- Microsoft Edge - Includes the latest Microsoft Edge browser policies, up to version 143.0.3650.23, including:-- - **Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search**- - **Enable RAM (memory) resource controls**- - **Specifies whether to opt out of Local Network access restrictions**-- Due to differences in release cadences between Microsoft Edge and Intune, there can be a one-to-two-week delay in the settings catalog.--- Experience > **Disable Share App Promotions** - This policy setting allows IT admins to control if promotional apps are shown in the [Windows Share Sheet](/windows/apps/develop/windows-integration/integrate-sharesheet-overview). If you enable this policy, Windows doesn't show promotional apps in the Share Sheet.--- Licensing > **Enable ESU Subscription Check**: This policy is deprecated and only works on Windows 10. Setting this policy has no effect on other supported Windows versions. This policy enables or disables subscription check for Windows 10 Extended Security Updates. If enabled, the device check for the ESU subscription status of the signed-in Microsoft Entra ID user account.--- Windows AI - Includes the following new settings that are available to Windows Insiders:-- - **Disable Agent Workspaces** - Enables or disables Agent Workspaces.- - **Disable Agent Connectors** - Enables or disables Agent Connectors.- - **Disable Remote Agent Connectors** - Enables or disables remote Agent Connectors.- - **Agent Connector Minimum Policy** - Configures the minimum policy value that controls how agent connectors run on the machine.--- Google Chrome - Includes the Google Chrome ADMX browser policies, up to version 141.0.7390.108.-- Due to differences in release cadences between Chrome and Intune, Intune can be one to two versions behind the latest released Chrome version.--- Firewall > **Enable Audit Mode** - If enabled, the target machine goes into Firewall audit mode.--- Microsoft Visual Studio > Copilot settings > **Disable agent mode** - This existing Copilot setting is updated to include localization. This setting prevents users from using GitHub Copilot agent mode.--- Windows Components > Internet Explorer > Internet Control Panel > Security Page:-- - **Turn on automatic detection of intranet** - This policy setting enables intranet mapping rules to be applied automatically if the computer belongs to a domain. If you enable this policy setting, automatic detection of the intranet is turned on, and intranet mapping rules are applied automatically if the computer belongs to a domain.-- - **Intranet Sites: Include all sites that bypass the proxy server** - This policy setting controls whether sites which bypass the proxy server are mapped into the local Intranet security zone. If you enable this policy setting, sites which bypass the proxy server are mapped into the Intranet Zone.--> [!div class="checklist"]-> Applies to:->-> - Windows--To learn more about the settings catalog, see [Use the Intune settings catalog to configure settings](../device-configuration/settings-catalog/index.md).--#### New supported OEMConfig apps for Android Enterprise<!-- 35178386 -->--The following OEMConfig apps are available in Intune for Android Enterprise:--- FCNT - Senior Care | `com.fcnt.mobile_phone.seniorcareconfig`-- FCNT - Schema | `com.fcnt.mobile_phone.schematest`-- Sonim | `com.sonim.oemappconfig`--For more information about OEMConfig, see [Use and manage Android Enterprise devices with OEMConfig in Microsoft Intune](../device-configuration/templates/configure-oemconfig-android.md).--#### Filter by Android management mode in the settings catalog<!-- 31844205 -->--The [settings catalog](../device-configuration/settings-catalog/index.md) includes hundreds of settings that you can configure. There are built-in features that help filter the available settings.--When you create an Android settings catalog policy, there's a management mode filter option that filters the available settings by their enrollment type, including:--- Fully managed-- Corporate-owned work profile-- Dedicated--To learn more about the settings catalog, see:--- [Use the Intune settings catalog to configure settings](../device-configuration/settings-catalog/index.md)-- [Android Intune settings catalog settings list](../device-configuration/settings-catalog/ref-android-settings.md)--#### New updates to the Apple settings catalog<!-- 35787099 -->--The [Settings Catalog](../device-configuration/settings-catalog/index.md) lists all the settings you can configure in a device policy, and all in one place. For more information about configuring Settings Catalog profiles in Intune, see [Create a policy using settings catalog](../device-configuration/settings-catalog/index.md).--There is a new setting in the Settings Catalog. To see this setting, in the [Microsoft Intune admin center], go to **Devices** > **Manage devices** > **Configuration** > **Create** > **New policy** > **iOS/iPadOS** for platform > **Settings catalog** for profile type.--##### iOS/iPadOS--**Restrictions**:--- Rating Apps Exempted Bundle IDs: This setting lets admins specify apps that can bypass the 17 and older restriction.-- For example, a device can have its content restricted to ages 9 and below. With this restriction, apps with an age-based rating of 17 and older are automatically blocked. Admins can use this setting to allow specific apps to bypass this restriction.--Apple rebranded **Rapid Security Responses** to **Background Security Improvements**. This change is updated in the settings catalog. For more information on Background Security Improvements, see [Background Security Improvements on Apple devices](https://support.apple.com/guide/deployment/background-security-improvements-dep93ff7ea78/web) (opens Apple's web site).--### Device management--#### More options for assignment filters > Device Management Type property for managed apps on Android and iOS/iPadOS<!-- 25040926 -->--When you create policies for your managed apps, you can use [assignment filters](../fundamentals/filters/overview.md) to assign policies based on rules you create. In these rules, you can use different device and app properties, including the **Device Management Type** property on Android and iOS/iPadOS.--> [!NOTE]-> This feature is rolling out slowly and should be available for all customers by late March 2026.--For Android, the **Device Management Type** property for managed apps is:--- Adding the following options:-- - Corporate-owned with work profile- - Corporate-owned fully managed- - Corporate-owned dedicated devices with Entra ID Shared mode- - Corporate-owned dedicated devices without Entra ID Shared mode- - Personally owned work profile--- To replace the following option:-- - Android Enterprise--For iOS/iPadOS, the **Device Management Type** property for managed apps is:--- Adding the following options:-- - Automated Device Enrollment user-associated devices- - Automated Device Enrollment userless devices- - Account Driven User Enrollment- - Device Enrollment with Company Portal and Web Enrollment--- To replace the following option:-- - Managed--##### What you need to know--- If you're using the legacy values in your filters, the values are automatically mapped to the new available values for that platform.-- For the automatic mapping to work correctly, devices must be registered with Microsoft Entra and have a Microsoft Entra Device ID. If the devices don't meet these requirements, the app assignment filters won't match to the more granular management types. You can use an Intune [app configuration policy](../app-management/configuration/configure-managed-apps.md#add-an-app-configuration-policy-for-managed-apps-on-iosipados-and-android-devices) to force Microsoft Entra device registration with the `com.microsoft.intune.mam.IntuneMAMOnly.RequireAADRegistration=Enabled` key.-- If the device is MDM-managed by a third-party or partner service, the managed app assignment filters won't match to the more granular management types.--To learn more about filters, see:--- [Use assignment filters to assign your apps, policies, and profiles in Microsoft Intune](../fundamentals/filters/overview.md)-- [App and device properties, operators, and rule editing when creating assignment filters in Microsoft Intune](../fundamentals/filters/ref-device-properties.md)--> [!div class="checklist"]-> Applies to:->-> - Android-> - iOS/iPadOS--#### Intune certificate inventory integration with Zimperium mobile threat defense<!-- 35519603 -->--You can now configure the Zimperium Mobile Threat Defense (MTD) connector to synchronize certificate inventory from your managed iOS devices. This enhancement helps you identify when a device threat level is elevated due to approved but potentially malicious certificates on the device. The following settings are now available when configuring the connector:--- **Enable Certificate Sync for iOS/iPadOS devices** - Allows this Mobile Threat Defense partner to request a list of installed certificates on iOS/iPadOS devices from Intune to use for threat analysis purposes.-- **Send full certificate inventory data on personally owned iOS/iPadOS devices** - This setting controls the certificate inventory data that Intune shares with this Mobile Threat Defense partner for personally owned devices. Data is shared when the partner syncs certificate data and requests the certificate inventory list.--When certificate sync is enabled, the following data is shared:--- Account ID-- Entra ID Device ID-- Device Owner-- Certificate List- - Common Name- - Data- - Is Identity--For more information, see [Mobile Threat Defense toggle options](../device-security/mobile-threat-defense/enable-connector.md#mobile-threat-defense-toggle-options).--> [!div class="checklist"]-> Applies to:->-> - iOS/iPadOS--### Device security--#### Update firewall configurations for new Intune network endpoints<!-- 34445623 -->--As part of Microsoft's ongoing [Secure Future Initiative (SFI)](https://www.microsoft.com/trust-center/security/secure-future-initiative), Microsoft Intune began using Azure Front Door (AFD) IP addresses in addition to the existing Intune service IPs in December 2025.--Customers that use IP-based allowlist, Azure service tags, or have strict outbound filtering in their firewall, VPN, proxy, or other network infrastructure may block this new traffic, causing degraded or failed device connectivity. This can affect core Intune functions including device and app management.--- **If your organization uses Fully Qualified Domain Name (FQDN)-based rules or does not restrict outbound traffic**, no changes are typically required. However, you should verify that the appropriate wildcard rules are configured, specifically `*.manage.microsoft.com`, to ensure all Intune services remain reachable. Microsoft continues to recommend using FQDN-based wildcard rules whenever possible to reduce administrative overhead for organizations that require outbound filtering.-- **If your organization uses IP-based allowlists** in your firewall, proxy, or VPN rules, you must add the Azure Front Door IP ranges below or use Azure service tag `AzureFrontDoor.MicrosoftSecurity` to avoid potential connectivity issues for managed devices.--Required IP addresses for commercial endpoints:--- 13.107.219.0/24-- 13.107.227.0/24-- 13.107.228.0/23-- 150.171.97.0/24-- 2620:1ec:40::/48-- 2620:1ec:49::/48-- 2620:1ec:4a::/47--Required IP addresses for US government endpoints:--- 51.54.53.136/29-- 51.54.114.160/29-- 62.11.173.176/29--For the authoritative and up-to-date list of network endpoints required by Intune client and host services, see [Intune core service](../fundamentals/endpoints.md#intune-core-service) in *Network endpoints for Microsoft Intune*, and [Ports and IP addresses list](../fundamentals/endpoints-us-government.md#ports-and-ip-addresses-list) in *US government endpoints for Microsoft Intune*.--For additional context on this change, see [Support Tip: Upcoming Microsoft Intune Network Changes](https://techcommunity.microsoft.com/blog/intunecustomersuccess/support-tip-upcoming-microsoft-intune-network-changes/4452738).--### Monitor and troubleshoot--#### Windows feature update reports support Windows 11, version 25H2<!-- 36157178 -->- -The *Windows feature update compatibility risks report* and *Windows feature update device readiness report* support Windows 11, version 25H2 as a selectable target OS. When you choose this version under **Select target OS**, the reports provide updated insights to help you assess device readiness and identify potential compatibility risks before deploying the feature update.--> [!div class="checklist"]-> Applies to:->-> - Windows--### Tenant administration--#### Admin tasks in Microsoft Intune are now generally available<!-- 32978931 -->--**Admin tasks** in the Intune admin center are out of preview and now generally available. Admin tasks provide a centralized view where admins can discover, organize, and act on common tasks that are otherwise spread throughout the Intune admin center. Located under **Tenant Administration**, this unified experience supports search, filtering, and sorting to help you focus on what needs attention, without navigating across multiple nodes.--The following task types are supported:--- Endpoint Privilege Management file elevation requests-- Microsoft Defender security tasks-- Multi Admin Approval requests--Intune only shows tasks you have permission to manage. When you select a task, Intune opens the same interface and workflow you'd use if managing the task from its original location. This ensures a consistent experience whether you're working from the admin tasks node or directly within the source capability.--To learn more, see:--- [Admin tasks](../device-management/admin-tasks.md)- For previous months, see the [What's new archive](archive.md). <!-- Past announcements that are older than six months will be moved to the archive -->