Intune now documents the Windows 365 for Agents security baseline version 24H1, including default settings for Cloud PCs running agentic workloads across Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint.
Keep up with Microsoft Intune
Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →
Windows Autopilot device association binds physical Windows 11 devices before enrollment
Windows Autopilot device preparation now supports TPM-backed device association: tenant affinity is written to UEFI before enrollment, allowing associated physical Windows 11 devices to receive device-targeted policies, naming, corporate marking, and additional OOBE customization. Related guidance covers prerequisites, the association workflow, removal, and automatic stale-record cleanup after 360 days. Elsewhere, Intune documents the Windows 365 for Agents 24H1 baseline, adds DDM controls to Apple VPP tokens, and covers enhanced log collection; Configuration Manager security guidance adds site-reset and secondary-site requirements.
- TPM-backed association establishes Autopilot tenant affinity before enrollment
Windows Autopilot · Device enrollment
Windows Autopilot device preparation now documents TPM-backed association that writes tenant affinity to UEFI before enrollment. The association enables device-targeted policies, device naming, OOBE customization, corporate marking, and stronger onboarding security.
- Windows 365 for Agents gets a documented 24H1 security-baseline reference
Intune · Device security
Intune now documents version 24H1 default settings for Cloud PCs running agentic workloads across Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint, with linked CSP details for review.
- Apple VPP tokens add DDM management for iOS and iPadOS 18+
Intune · App management
VPP token settings now offer a Management type of MDM, the default, or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later and supports only Required or Uninstall assignments.
A new Device Action article explains how to trigger and cancel remote enhanced log collection on supervised macOS 27+, iOS 27+, and iPadOS 27+ devices. Collected logs are sent directly to Apple for support analysis.
- Configuration Manager security update carries site-reset and secondary-site requirements
Configuration Manager · General
The update applies to Configuration Manager versions 2603, 2509, and 2503 with required rollups. Installation through Updates and Servicing requires a site reset, while existing secondary sites must be updated manually through Recover Secondary Site.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
29 updates
Microsoft Intune
9 updatesOverview
Doc updateThe security baselines overview now links to the Windows 365 for Agents security baseline, including its Version 24H1 settings reference.
Configure Baselines
Doc updateThe Configure baselines documentation now links to the Windows 365 for Agents security baseline settings reference.
Manage Vpp Apple
New featureThe VPP token settings now include a Management type option: MDM (default) or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later, and supports only Required or Uninstall assignments.
Ref Protected Apps
Doc updateThe reference now includes Ben for Intune, Calven, Heijmans, Notability, Notion, SDP - On Premises | Intune, and Superhuman Mail, with descriptions and app links.
A new article explains how to trigger and cancel remote enhanced log collection on supervised macOS 27+, iOS 27+, and iPadOS 27+ devices. Logs are sent directly to Apple for support analysis.
Setup Personal Work Profile
Feature updateThe documentation now lists Chrome, Edge, and Samsung browser as supported for web-based enrollment. The note about phone-call MFA potentially breaking enrollment and its workaround was removed.
Endpoints
Feature updateThe Intune client and host service endpoint entry now includes 150.171.109.0/24 and 150.171.110.0/24.
What's new in Microsoft Intune
Doc updateThe page now states that the listed eSIM features are rolling out and might not yet be available to all tenants. The page date and authoring metadata were also updated.
Windows Autopilot
18 updatesThe documentation describes TPM-backed association that writes tenant affinity to UEFI before enrollment, enabling device-targeted policies, device naming, OOBE customization, corporate marking, and stronger onboarding security.
The new article explains how to remove pre-associated devices from Intune and how to clear Device Link UEFI variables before deleting associated devices from Intune.
The page specifies Windows 11, physical-device, TPM 2.0, networking, licensing, and Intune RBAC requirements, including custom-role setup steps.
Windows Autopilot device preparation user-driven Microsoft Entra join - Step 7 - Associate devices
New featureAction requiredA new Step 7 guide explains associating devices for user-driven Microsoft Entra join, including exporting device information, importing it into Intune, and reviewing associations. Association is an optional alternative to corporate identifiers.
Device association lifecycle management
Doc updateThe new article documents device resets, local association removal, CSV updates, Autopilot registration, stale records, and decommissioning. It notes that associations persist through resets and that stale records are automatically deleted after 360 days.
Step 7 now includes device association as an alternative to corporate identifiers. The documentation explains associated-device OOBE settings, deployment precedence, and device- versus user-based policy assignment.
Windows Autopilot device association FAQ
Doc updateA new FAQ explains DeviceLink CSV timestamp changes, exporting device information after OOBE, corporate identifier requirements, OEM and partner support, and virtual machine limitations.
Overview for Windows Autopilot device preparation user-driven Microsoft Entra join in Intune
Feature updateAction requiredThe tutorial now documents support for up to 25 essential applications, up from 10, and adds device association as an alternative to corporate identifiers. Associated devices can use settings such as OOBE customization and device naming.
Step 7 now identifies corporate identifiers as one option and links to optional device association as another. Associated devices are automatically treated as corporate-owned, and enrollment links were updated.
What's new in Windows Autopilot
New featureWindows Autopilot device preparation now supports associating physical Windows 11 devices with an organization before enrollment. Associated devices are automatically marked corporate-owned and can receive device-targeted policies and naming.
The tutorial now lists device association as an alternative to adding a Windows corporate identifier and clarifies the steps for deploying apps and PowerShell scripts.
The documentation explains that association state determines whether the Windows Autopilot profile or device association takes precedence. Associated physical Windows 11 devices are marked corporate-owned and can receive device-targeted policies and additional OOBE customizations.
The comparison now documents that device preparation devices can be associated with a tenant before enrollment, while Windows Autopilot devices can be registered. It also updates the explanation of deployment selection for Autopilot-registered devices.
Step 7 now offers two options: add a Windows corporate identifier or associate devices. The document date was also updated.
Step 7 now offers two paths: add a Windows corporate identifier or associate devices. The page’s update date was also refreshed.
Step 7 now presents two options: adding a Windows corporate identifier or associating devices. The documentation date was also updated.
Step 7 now documents two options: adding a Windows corporate identifier or using Associate devices. The page date was also updated.
What's new in Windows Autopilot
Doc updateThe documentation date and “Date added” value changed from August 20, 2026, to August 27, 2026.
Microsoft Configuration Manager
2 updatesSecurity update for the SMS Provider and administration service
Doc updateAction requiredThe new page documents security fixes for the SMS Provider and administration service, applicable to Configuration Manager versions 2603, 2509, and 2503 with required rollups. Installation requires a site reset and manual updating of existing secondary sites.
The documentation now states that KB 37447175 is superseded by KB 38982839 for version 2503, while remaining applicable to version 2409.