Intune now documents the Windows 365 for Agents security baseline version 24H1, including default settings for Cloud PCs running agentic workloads across Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint.
Keep up with Microsoft Intune
Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →
Windows 365 for Agents baseline and Apple log collection gain detailed Intune guidance
Two new reference articles are the period's clearest additions: a version 24H1 Windows 365 for Agents security-baseline settings list and an Apple enhanced-log-collection procedure. Other updates document DDM constraints for VPP tokens, add Samsung browser to web-based Personal Work Profile enrollment guidance, expand the protected-apps reference, and mark listed eSIM features as rolling out across tenants.
- Windows 365 for Agents gets a documented version 24H1 baseline settings list
Intune · Device security
The new settings reference covers default security-baseline settings for Cloud PCs running agentic workloads across Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint, with linked CSP details for review before deploying or customizing the baseline.
A new procedure explains how to trigger or cancel remote enhanced log collection from a device overview page for supervised macOS 27+, iOS 27+, and iPadOS 27+ devices. Triggering requires remote-task permissions and an AppleCare token, and sends logs directly to Apple for support analysis.
- VPP token guidance defines DDM mode and its assignment limits
Intune · App management
The Management type option is now documented as MDM, the default, or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later and supports only Required or Uninstall assignments; Available assignments aren't supported in DDM mode.
- Personal Work Profile enrollment guidance adds Samsung browser support
Intune · Device enrollment
The web-based enrollment guidance now lists Chrome, Edge, and Samsung browser as supported options. It also removes the note that phone-call MFA could break enrollment and the associated workaround.
- Intune’s eSIM guidance now flags phased tenant availability
Intune · General
The What's new page now states that its listed eSIM features are rolling out and might not yet be available to all tenants, giving administrators a clearer availability caveat when evaluating the features.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
8 updates
Microsoft Intune
8 updatesOverview
Doc updateThe security baselines overview now links to the Windows 365 for Agents security baseline, including its Version 24H1 settings reference.
Configure Baselines
Doc updateThe Configure baselines documentation now links to the Windows 365 for Agents security baseline settings reference.
Manage Vpp Apple
New featureThe VPP token settings now include a Management type option: MDM (default) or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later, and supports only Required or Uninstall assignments.
Ref Protected Apps
Doc updateThe reference now includes Ben for Intune, Calven, Heijmans, Notability, Notion, SDP - On Premises | Intune, and Superhuman Mail, with descriptions and app links.
A new article explains how to trigger and cancel remote enhanced log collection on supervised macOS 27+, iOS 27+, and iPadOS 27+ devices. Logs are sent directly to Apple for support analysis.
Setup Personal Work Profile
Feature updateThe documentation now lists Chrome, Edge, and Samsung browser as supported for web-based enrollment. The note about phone-call MFA potentially breaking enrollment and its workaround was removed.
What's new in Microsoft Intune
Doc updateThe page now states that the listed eSIM features are rolling out and might not yet be available to all tenants. The page date and authoring metadata were also updated.