Microsoft Intune
General

What's new in Microsoft Intune

In brief

The documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.

What Intune admins need to know

Administrators can use these options to support remote troubleshooting, app deployment, device security, and platform configuration. No mandatory action is stated.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: What's new in Microsoft Intune description: Find out what's new in Microsoft Intune. ms.date: 07/27/08/24/2026 ms.topic: whats-new ai-usage: ai-assisted ms.collection:

-->

Week of August 25, 2026 (Service release 2608)

Advanced capabilities (formerly "Microsoft Intune Suite")

Unattended Remote Help sessions for Windows devices

Microsoft Intune now supports unattended Remote Help sessions on physical Windows devices. Authorized helpdesk agents can sign in to a remote device with their own credentials without requiring the user to be present or take action. Helpers can view and control the device to troubleshoot issues and complete support tasks remotely.

For more information, see Planning for Remote Help.

[!div class="checklist"] Applies to:

  • Windows

App management

Newly available protected apps for Intune

The following protected apps are now available for Microsoft Intune:

  • Notion by Notion Labs
  • Superhuman Mail by Superhuman Labs
  • Calven by Calven Pty Limited
  • Heijmans by Heijmans
  • Notability by Ginger Labs, Inc. (iOS)
  • Ben for Intune by Thanks Ben Ltd
  • SDP - On Premises | Intune by Zoho Corporation

For more information about protected apps, see Microsoft Intune protected apps.

Declarative Device Management for Apple volume purchase program apps

Microsoft Intune now supports Apple Declarative Device Management (DDM) for required volume purchase program (VPP) apps on devices running iOS/iPadOS 17.2 and later and macOS 26 and later. By changing the management type to DDM when you upload a new VPP token, you can deploy and configure apps using Apple's policy-based model, which improves delivery efficiency, provides real-time app status, and adds new per-app settings such as automatic app updates.

[!div class="checklist"] Applies to:

  • iOS/iPadOS
  • macOS

Device configuration

Configure screen timeout for corporate Android devices

Microsoft Intune now supports a Screen timeout setting in the Android Enterprise settings catalog, letting you specify how many seconds pass before the screen turns off. Configure it under Devices > Manage devices > Configuration > Create > New policy > Android Enterprise > Settings catalog. The value must stay at or below Time to lock screen and applies to fully managed and dedicated devices on Android 9 and later, and corporate-owned work profile devices on Android 15 and later.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned dedicated devices (COSU)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

Separate device and work profile passwords on Android Enterprise devices

Microsoft Intune now supports the Block one lock for device and work profile setting in the Android Enterprise settings catalog, letting you require separate locks for the device and work profile instead of a shared one. Set it to True after configuring a work profile password requirement. The default, False, allows a common lock. The setting supports Android 9 and later.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate-owned devices with a work profile (COPE)

Limit how long an Android work profile can stay off

Microsoft Intune now supports the Number of days work profile is allowed to be switched off setting in the Android Enterprise settings catalog, so you can limit how long a work profile stays turned off. Enter the maximum number of days, with a minimum of three, or enter 0 to disable the restriction. There's no documented upper limit, giving you flexibility for your organization's needs.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate-owned devices with a work profile (COPE)

Remove eSIMs during a device wipe with a settings catalog policy

Microsoft Intune now supports the Remove all eSIMs during a device wipe setting in the Android Enterprise settings catalog. Set it to True to request removal of all eSIMs when a corporate-owned device is wiped while the policy applies. The default, False, doesn't request removal, although the operating system might still remove eSIMs when required. The setting supports Android 15 and later.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned dedicated devices (COSU)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

New updates to the Apple settings catalog

Microsoft Intune now supports new Settings Catalog options for testing on the OS 27 betas, covering Declarative Device Management areas such as App Settings, Web Content Filter, and Siri Settings for iOS/iPadOS and macOS. Configure them under Devices > Manage devices > Configuration > Create > New policy > iOS/iPadOS or macOS > Settings catalog. This lets you test upcoming Apple management controls ahead of general availability.

For more information, see Create a policy using settings catalog.

[!div class="checklist"] Applies to:

  • iOS/iPadOS
  • macOS

Keep Android device screens on while charging

Microsoft Intune now includes a settings catalog option for keeping fully managed and dedicated Android device screens on while charging. Select one or more modes - AC, USB, or Wireless - to control when the screen stays on. AC and USB support Android 6.0 and later; wireless charging requires Android 8.1 and later. No modes are selected by default.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned dedicated devices (COSU)

New policy settings for Windows

Microsoft Intune now includes new Windows settings catalog options across several administrative template refreshes. Highlights include Turn on Protected Mode controls for Internet Explorer security zones, new Microsoft Edge policies from the Edge 150 template refresh, and a Disconnect if a Remote Desktop Services session when no smart card is present option for interactive logon. The Microsoft Office templates also gained new settings. Create a Windows settings catalog profile to configure them.

[!div class="checklist"] Applies to:

  • Windows

Device enrollment

Skip new Apple Setup Assistant panes during enrollment

Microsoft Intune now includes Apple OS 27 Setup Assistant skip keys for Liquid Glass and Accessibility Appearance in Automated Device Enrollment profiles. You can hide these panes to reduce setup interactions and provide a more consistent enrollment experience on supported iPhone, iPad, and Mac devices.

[!div class="checklist"] Applies to:

  • iOS/iPadOS
  • macOS

Device management

New single device page in the Intune admin center

The new single device page is turned on by default for all customers. You can use the Preview new device view toggle to turn it off and return to the original device page.

In the Intune admin center, when you go to Devices > All devices and select a device, you can see device-specific information, including device properties, device activity, tools, and reports.

Where to find common device information and actions in the new single device view:

  • Change the management name, primary user, or device category: Go to Devices > All devices > select a device > Properties > Edit.
  • View hardware and operating system information: Go to Devices > All devices > select a device > Device details. The Device details tab was previously called Hardware.
  • Perform device actions: Go to Devices > All devices and select a device. Some actions are organized in the Remote actions, Secure, and Remove data menus on the device command bar. The available actions depend on the device platform, management type, ownership, permissions, and supported capabilities.
  • View the status of device actions: Go to Devices > All devices > select a device > Device action status.
  • View the status of Remediations: Go to Devices > All devices > select a device > Tools > Remediations.
  • View scope tags: Go to Devices > All devices > select a device > Properties.

Return to the original device page:

If you prefer to use the original device page, you can turn off the new experience:

  1. In the Intune admin center, go to Devices > All devices.
  2. Move the Preview new device view toggle to Off.

[!div class="checklist"] Applies to:

  • Android
  • iOS/iPadOS
  • macOS
  • Windows

Operating system version property in assignment filters is generally available

The operatingSystemVersion property in assignment filters is now generally available for managed devices and managed apps. Use this property to create filter rules that scope your app and policy assignments to devices running a specific OS version or build range. For example, create an assignment filter that pilots a configuration on a newer build before rolling it out broadly or excludes devices that haven't yet updated.

You can build rules using the rule editor or the rule syntax text box, with the same operators available for other filter properties. Existing assignments continue to work without changes.

For more information, see:

Collect enhanced diagnostic logs from supervised Apple devices

Microsoft Intune now supports Apple's Enhanced Logging device action on supported supervised devices running a compatible OS release. Administrators can start an AppleCare diagnostic-log collection session using an AppleCare-provided token and monitor device-reported status through Declarative Device Management, reducing the need to coordinate manual log collection with the device user.

[!div class="checklist"] Applies to:

  • iOS/iPadOS
  • macOS

View expanded SIM inventory for corporate-owned Android devices

Microsoft Intune now surfaces expanded SIM inventory for corporate-owned Android Enterprise devices, including EIDs, multiple ICCIDs, and activation state. View these details under Devices > All devices > select a device > Hardware, and use the reported ICCID to identify the correct eSIM for a removal action. EID reporting requires Android 13 and later; full inventory requires Android 15 and later.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned dedicated devices (COSU)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

Activate an eSIM on a corporate-owned Android device

Microsoft Intune now supports single-device eSIM activation for corporate-owned Android Enterprise devices running Android 15 and later. Turn on Preview new device view, select the device, then select Activate eSIM and enter the carrier activation code. Intune sends the request without first blocking it based on reported eSIM slot capacity and surfaces errors returned by Google. Personally owned work profile devices aren't supported.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned dedicated devices (COSU)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

Remove an individual eSIM from a corporate-owned Android device

Microsoft Intune now lets you remove a single eSIM from a corporate-owned Android Enterprise device without wiping it. Turn on Preview new device view, select the device, copy the eSIM's ICCID from device inventory, then select Remove eSIM and enter the ICCID. The action supports fully managed and dedicated devices on Android 15 and later, and work profile devices on Android 17 and later.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned dedicated devices (COSU)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

Choose whether to remove eSIMs when wiping one corporate-owned Android device

Microsoft Intune now lets you choose whether to preserve or remove eSIMs when wiping one corporate-owned Android Enterprise device. Turn on Preview new device view, select the device, then select Wipe. By default, the wipe preserves eSIMs; select the eSIM removal option only when you want the wipe to remove them. Personally owned work profile devices aren't supported.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned dedicated devices (COSU)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

Device inventory for personally owned devices on Android Enterprise

Microsoft Intune now supports device inventory for personally owned Android Enterprise devices with a work profile managed by Android Management API. View these devices from the device's Inventory page alongside corporate-owned devices in Resource Explorer, and query them with Multi-Device Query. Inventory data is a subset of corporate-owned data; properties such as IMEI, ICCID, and MAC address aren't available. This gives you more consistent analytics across mixed corporate and BYOD environments.

[!div class="checklist"] Applies to:

  • Android Enterprise personally owned devices with a work profile using Android Management API

Device security

Audit mode for the Microsoft Defender Antivirus template for Linux

The Microsoft Defender Antivirus template for Linux, which is part of Intune's Endpoint Security Antivirus policy, now includes a new Audit value for the Enforcement level setting. When you set Enforcement level to Audit, the antivirus engine detects threats in real time but doesn't automatically remediate them. Malware detections are reported as alerts in the Microsoft Defender portal through real-time scanning, without quarantining the malicious files. Audit mode gives you visibility into the threat landscape before you turn on full protection.

The Microsoft Defender Antivirus template for Linux is supported for devices managed by Intune, and for devices managed only by Defender through the Microsoft Defender for Endpoint security settings management scenario (MDE attach).

[!div class="checklist"] Applies to:

  • Linux

Windows 365 for Agents security baseline

Microsoft Intune now includes a security baseline for Windows 365 for Agents Cloud PCs. Administrators can deploy and customize recommended, device-scoped settings for Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint to establish a consistent security posture for agentic workloads.

For more information, see Manage security baseline profiles in Microsoft Intune and What is Windows 365 for Agents?.

[!div class="checklist"] Applies to:

  • Windows 365 for Agents Cloud PCs running Windows 11 and later

Memory scan setting for Microsoft Defender Antivirus on Linux

Microsoft Intune now supports a memory scan setting in the Microsoft Defender Antivirus template for Linux endpoint security antivirus policies. You can manage memory scan behavior on Linux devices managed through Microsoft Defender for Endpoint security settings management, giving you finer control over how Defender inspects memory on your Linux endpoints.

[!div class="checklist"] Applies to:

  • Linux

Week of July 27, 2026 (Service release 2607)

Device configuration

  • Clearer error messages
    Some query error messages have been updated to provide clearer, more descriptive guidance when queries are invalid.

Week of February 9, 2026 (Service release 2601)

Advanced capabilities

Endpoint Privilege Management support on Azure Virtual Desktop

Endpoint Privilege Management (EPM) elevation policies now support deployment to users on Azure Virtual Desktop (AVD) single-session virtual machines.

For information about using EPM, see Plan and Prepare for Endpoint Privilege Management Deployment.

App management

Lenovo Device Orchestration (LDO) link in the Intune admin center

Microsoft Intune now includes a direct link to Lenovo Device Orchestration (LDO) in the Intune admin center. This integration expands the Partner portals experience by giving IT admins a single, secure entry point to manage supported Lenovo devices.

From the Intune admin center, IT admins can open the Lenovo Device Orchestration portal directly to access Lenovo-specific device management capabilities.

[!div class="checklist"] Applies to:

  • Windows 11

Newly available protected apps for Intune

The following protected apps are now available for Microsoft Intune:

  • Clarity Express for Intune by Rego Consulting Corporation
  • Datadog by Datadog Inc.
  • Qlik Analytics by Qlik
  • Tier1 for Intune by SS&C Technologies, Inc. (iOS)

For more information about protected apps, see Microsoft Intune protected apps.

Device configuration

New settings in the Windows settings catalog

There are new settings in the Windows settings catalog. To see and configure these settings in Intune, create a Windows settings catalog profile (Devices > Configuration profiles > Create profile > Windows 10 and later > Settings catalog).

The new policies include:

  • Microsoft Edge - Includes the latest Microsoft Edge browser policies, up to version 143.0.3650.23, including:

    • Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search
    • Enable RAM (memory) resource controls
    • Specifies whether to opt out of Local Network access restrictions

    Due to differences in release cadences between Microsoft Edge and Intune, there can be a one-to-two-week delay in the settings catalog.

  • Experience > Disable Share App Promotions - This policy setting allows IT admins to control if promotional apps are shown in the Windows Share Sheet. If you enable this policy, Windows doesn't show promotional apps in the Share Sheet.

  • Licensing > Enable ESU Subscription Check: This policy is deprecated and only works on Windows 10. Setting this policy has no effect on other supported Windows versions. This policy enables or disables subscription check for Windows 10 Extended Security Updates. If enabled, the device check for the ESU subscription status of the signed-in Microsoft Entra ID user account.

  • Windows AI - Includes the following new settings that are available to Windows Insiders:

    • Disable Agent Workspaces - Enables or disables Agent Workspaces.
    • Disable Agent Connectors - Enables or disables Agent Connectors.
    • Disable Remote Agent Connectors - Enables or disables remote Agent Connectors.
    • Agent Connector Minimum Policy - Configures the minimum policy value that controls how agent connectors run on the machine.
  • Google Chrome - Includes the Google Chrome ADMX browser policies, up to version 141.0.7390.108.

    Due to differences in release cadences between Chrome and Intune, Intune can be one to two versions behind the latest released Chrome version.

  • Firewall > Enable Audit Mode - If enabled, the target machine goes into Firewall audit mode.

  • Microsoft Visual Studio > Copilot settings > Disable agent mode - This existing Copilot setting is updated to include localization. This setting prevents users from using GitHub Copilot agent mode.

  • Windows Components > Internet Explorer > Internet Control Panel > Security Page:

    • Turn on automatic detection of intranet - This policy setting enables intranet mapping rules to be applied automatically if the computer belongs to a domain. If you enable this policy setting, automatic detection of the intranet is turned on, and intranet mapping rules are applied automatically if the computer belongs to a domain.

    • Intranet Sites: Include all sites that bypass the proxy server - This policy setting controls whether sites which bypass the proxy server are mapped into the local Intranet security zone. If you enable this policy setting, sites which bypass the proxy server are mapped into the Intranet Zone.

[!div class="checklist"] Applies to:

  • Windows

To learn more about the settings catalog, see Use the Intune settings catalog to configure settings.

New supported OEMConfig apps for Android Enterprise

The following OEMConfig apps are available in Intune for Android Enterprise:

  • FCNT - Senior Care | com.fcnt.mobile_phone.seniorcareconfig
  • FCNT - Schema | com.fcnt.mobile_phone.schematest
  • Sonim | com.sonim.oemappconfig

For more information about OEMConfig, see Use and manage Android Enterprise devices with OEMConfig in Microsoft Intune.

Filter by Android management mode in the settings catalog

The settings catalog includes hundreds of settings that you can configure. There are built-in features that help filter the available settings.

When you create an Android settings catalog policy, there's a management mode filter option that filters the available settings by their enrollment type, including:

  • Fully managed
  • Corporate-owned work profile
  • Dedicated

To learn more about the settings catalog, see:

New updates to the Apple settings catalog

The Settings Catalog lists all the settings you can configure in a device policy, and all in one place. For more information about configuring Settings Catalog profiles in Intune, see Create a policy using settings catalog.

There is a new setting in the Settings Catalog. To see this setting, in the [Microsoft Intune admin center], go to Devices > Manage devices > Configuration > Create > New policy > iOS/iPadOS for platform > Settings catalog for profile type.

iOS/iPadOS

Restrictions:

  • Rating Apps Exempted Bundle IDs: This setting lets admins specify apps that can bypass the 17 and older restriction.

    For example, a device can have its content restricted to ages 9 and below. With this restriction, apps with an age-based rating of 17 and older are automatically blocked. Admins can use this setting to allow specific apps to bypass this restriction.

Apple rebranded Rapid Security Responses to Background Security Improvements. This change is updated in the settings catalog. For more information on Background Security Improvements, see Background Security Improvements on Apple devices (opens Apple's web site).

Device management

More options for assignment filters > Device Management Type property for managed apps on Android and iOS/iPadOS

When you create policies for your managed apps, you can use assignment filters to assign policies based on rules you create. In these rules, you can use different device and app properties, including the Device Management Type property on Android and iOS/iPadOS.

For Android, the Device Management Type property for managed apps is:

  • Adding the following options:

    • Corporate-owned with work profile
    • Corporate-owned fully managed
    • Corporate-owned dedicated devices with Entra ID Shared mode
    • Corporate-owned dedicated devices without Entra ID Shared mode
    • Personally owned work profile
  • To replace the following option:

    • Android Enterprise

For iOS/iPadOS, the Device Management Type property for managed apps is:

  • Adding the following options:

    • Automated Device Enrollment user-associated devices
    • Automated Device Enrollment userless devices
    • Account Driven User Enrollment
    • Device Enrollment with Company Portal and Web Enrollment
  • To replace the following option:

    • Managed
What you need to know
  • If you're using the legacy values in your filters, the values are automatically mapped to the new available values for that platform.
  • For the automatic mapping to work correctly, devices must be registered with Microsoft Entra and have a Microsoft Entra Device ID. If the devices don't meet these requirements, the app assignment filters won't match to the more granular management types. You can use an Intune app configuration policy to force Microsoft Entra device registration with the com.microsoft.intune.mam.IntuneMAMOnly.RequireAADRegistration=Enabled key.
  • If the device is MDM-managed by a third-party or partner service, the managed app assignment filters won't match to the more granular management types.

To learn more about filters, see:

[!div class="checklist"] Applies to:

  • Android
  • iOS/iPadOS

Intune certificate inventory integration with Zimperium mobile threat defense

You can now configure the Zimperium Mobile Threat Defense (MTD) connector to synchronize certificate inventory from your managed iOS devices. This enhancement helps you identify when a device threat level is elevated due to approved but potentially malicious certificates on the device. The following settings are now available when configuring the connector:

  • Enable Certificate Sync for iOS/iPadOS devices - Allows this Mobile Threat Defense partner to request a list of installed certificates on iOS/iPadOS devices from Intune to use for threat analysis purposes.
  • Send full certificate inventory data on personally owned iOS/iPadOS devices - This setting controls the certificate inventory data that Intune shares with this Mobile Threat Defense partner for personally owned devices. Data is shared when the partner syncs certificate data and requests the certificate inventory list.

When certificate sync is enabled, the following data is shared:

  • Account ID
  • Entra ID Device ID
  • Device Owner
  • Certificate List
    • Common Name
    • Data
    • Is Identity

For more information, see Mobile Threat Defense toggle options.

[!div class="checklist"] Applies to:

  • iOS/iPadOS

Device security

Update firewall configurations for new Intune network endpoints

As part of Microsoft's ongoing Secure Future Initiative (SFI), Microsoft Intune began using Azure Front Door (AFD) IP addresses in addition to the existing Intune service IPs in December 2025.

Customers that use IP-based allowlist, Azure service tags, or have strict outbound filtering in their firewall, VPN, proxy, or other network infrastructure may block this new traffic, causing degraded or failed device connectivity. This can affect core Intune functions including device and app management.

  • If your organization uses Fully Qualified Domain Name (FQDN)-based rules or does not restrict outbound traffic, no changes are typically required. However, you should verify that the appropriate wildcard rules are configured, specifically *.manage.microsoft.com, to ensure all Intune services remain reachable. Microsoft continues to recommend using FQDN-based wildcard rules whenever possible to reduce administrative overhead for organizations that require outbound filtering.
  • If your organization uses IP-based allowlists in your firewall, proxy, or VPN rules, you must add the Azure Front Door IP ranges below or use Azure service tag AzureFrontDoor.MicrosoftSecurity to avoid potential connectivity issues for managed devices.

Required IP addresses for commercial endpoints:

  • 13.107.219.0/24
  • 13.107.227.0/24
  • 13.107.228.0/23
  • 150.171.97.0/24
  • 2620:1ec:40::/48
  • 2620:1ec:49::/48
  • 2620:1ec:4a::/47

Required IP addresses for US government endpoints:

  • 51.54.53.136/29
  • 51.54.114.160/29
  • 62.11.173.176/29

For the authoritative and up-to-date list of network endpoints required by Intune client and host services, see Intune core service in Network endpoints for Microsoft Intune, and Ports and IP addresses list in US government endpoints for Microsoft Intune.

For additional context on this change, see Support Tip: Upcoming Microsoft Intune Network Changes.

Monitor and troubleshoot

Windows feature update reports support Windows 11, version 25H2

The Windows feature update compatibility risks report and Windows feature update device readiness report support Windows 11, version 25H2 as a selectable target OS. When you choose this version under Select target OS, the reports provide updated insights to help you assess device readiness and identify potential compatibility risks before deploying the feature update.

[!div class="checklist"] Applies to:

  • Windows

Tenant administration

Admin tasks in Microsoft Intune are now generally available

Admin tasks in the Intune admin center are out of preview and now generally available. Admin tasks provide a centralized view where admins can discover, organize, and act on common tasks that are otherwise spread throughout the Intune admin center. Located under Tenant Administration, this unified experience supports search, filtering, and sorting to help you focus on what needs attention, without navigating across multiple nodes.

The following task types are supported:

  • Endpoint Privilege Management file elevation requests
  • Microsoft Defender security tasks
  • Multi Admin Approval requests

Intune only shows tasks you have permission to manage. When you select a task, Intune opens the same interface and workflow you'd use if managing the task from its original location. This ensures a consistent experience whether you're working from the admin tasks node or directly within the source capability.

To learn more, see:

For previous months, see the What's new archive.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…