← Previous day

Keep up with Microsoft Intune

Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →

Day in brief

Windows Autopilot device association binds physical Windows 11 devices before enrollment

Windows Autopilot device preparation now supports TPM-backed device association: tenant affinity is written to UEFI before enrollment, allowing associated physical Windows 11 devices to receive device-targeted policies, naming, corporate marking, and additional OOBE customization. Related guidance covers prerequisites, the association workflow, removal, and automatic stale-record cleanup after 360 days. Elsewhere, Intune documents the Windows 365 for Agents 24H1 baseline, adds DDM controls to Apple VPP tokens, and covers enhanced log collection; Configuration Manager security guidance adds site-reset and secondary-site requirements.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

29 updates

3

Overview

Doc update

The security baselines overview now links to the Windows 365 for Agents security baseline, including its Version 24H1 settings reference.

Configure Baselines

Doc update

The Configure baselines documentation now links to the Windows 365 for Agents security baseline settings reference.

2

Manage Vpp Apple

New feature

The VPP token settings now include a Management type option: MDM (default) or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later, and supports only Required or Uninstall assignments.

Ref Protected Apps

Doc update

The reference now includes Ben for Intune, Calven, Heijmans, Notability, Notion, SDP - On Premises | Intune, and Superhuman Mail, with descriptions and app links.

1
1

Setup Personal Work Profile

Feature update

The documentation now lists Chrome, Edge, and Samsung browser as supported for web-based enrollment. The note about phone-call MFA potentially breaking enrollment and its workaround was removed.

1

Endpoints

Feature update

The Intune client and host service endpoint entry now includes 150.171.109.0/24 and 150.171.110.0/24.

1

What's new in Microsoft Intune

Doc update

The page now states that the listed eSIM features are rolling out and might not yet be available to all tenants. The page date and authoring metadata were also updated.

18

Overview of Windows Autopilot device association

New feature

The documentation describes TPM-backed association that writes tenant affinity to UEFI before enrollment, enabling device-targeted policies, device naming, OOBE customization, corporate marking, and stronger onboarding security.

Device association lifecycle management

Doc update

The new article documents device resets, local association removal, CSV updates, Autopilot registration, stale records, and decommissioning. It notes that associations persist through resets and that stale records are automatically deleted after 360 days.

Windows Autopilot device association FAQ

Doc update

A new FAQ explains DeviceLink CSV timestamp changes, exporting device information after OOBE, corporate identifier requirements, OEM and partner support, and virtual machine limitations.

What's new in Windows Autopilot

New feature

Windows Autopilot device preparation now supports associating physical Windows 11 devices with an organization before enrollment. Associated devices are automatically marked corporate-owned and can receive device-targeted policies and naming.

Overview of Windows Autopilot device preparation

New feature

The documentation explains that association state determines whether the Windows Autopilot profile or device association takes precedence. Associated physical Windows 11 devices are marked corporate-owned and can receive device-targeted policies and additional OOBE customizations.

2

Security update for the SMS Provider and administration service

Doc updateAction required

The new page documents security fixes for the SMS Provider and administration service, applicable to Configuration Manager versions 2603, 2509, and 2503 with required rollups. Installation requires a site reset and manual updating of existing secondary sites.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…