Microsoft Intune
General

In development - Microsoft Intune

In brief

The page adds upcoming features including MHS authentication for protected app activities, declarative VPP downloads, deployment plans, Defender launch during Android setup, bulk eSIM actions, new Apple settings, and Quick Machine Recovery policies. It also documents future macOS and iOS/iPadOS support changes and the September 2609 single-device page default.

What Intune admins need to know

Administrators should review the upcoming platform support requirements and plan for changes to device administration, app rollout, enrollment, and the Intune admin center experience.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: In development - Microsoft Intune description: This article describes Microsoft Intune features that are in development. ms.date: 08/21/09/01/2026 ms.topic: whats-new ai-usage: ai-assisted ms.reviewer: intuner

App management

Require Managed Home Screen authentication for protected app activities

For Android Enterprise dedicated devices using Managed Home Screen (MHS) with Microsoft Entra shared device mode, Intune will allow admins to requiring users to complete MHS authentication state before allowing protected activities in MAM-integrated apps. When MHS requires sign-in or session PIN authentication, users will still be able to complete limited actions, such as accepting or declining incoming calls. If a user tries to open another protected activity, the app will return them to MHS to authenticate. After authentication, protected app activities will become available normally. This behavior will help prevent users from bypassing the MHS session PIN while preserving critical communication actions.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate-owned dedicated devices using Managed Home Screen with Microsoft Entra shared device mode

Declarative VPP app download in Company Portal

The iOS/iPadOS Company Portal will support Declarative Volume-Purchased Program (VPP) app downloads from the Apps tab. Declarative VPP apps provide an improved end-user experience by reducing app installation latency, allowing for automatic overnight app updates, and providing the end user with a live status of an app installation. If you choose not to use Declarative VPP apps, there will be no changes to the admin and user experience.

[!div class="checklist"] Applies to:

  • iOS/iPadOS

Device configuration

New Apple settings in the Settings Catalog for iOS/iPadOS and macOS

Microsoft Intune will add new Apple settings for supported iOS/iPadOS and macOS devices. You'll be able to configure the new options by using Settings Catalog profiles in the Microsoft Intune admin center. These settings will expand the device management controls available through Intune and help you manage Apple devices with a consistent policy workflow. To see these settings, go to Devices > Manage devices > Configuration > Create > New policy > iOS/iPadOS or macOS for platform > Settings catalog for profile type.

[!div class="checklist"] Applies to:

  • iOS/iPadOS
  • macOS

Enforce Routes capability in iOS/iPadOS and macOS VPN profiles

Microsoft Intune will support Apple's Enforce Routes feature in iOS/iPadOS and macOS VPN profiles.

Device enrollment

Automatically launch Microsoft Defender for Endpoint during Android Enterprise device setup

You'll be able to configure Microsoft Defender for Endpoint to open automatically during out-of-box setup for supported corporate-owned Android Enterprise devices. After you configure the Defender for Endpoint connector, turn on Grant MTD role permissions, and assign the Defender app as required, you'll enable this experience from Endpoint security > Defender for Endpoint. Intune will open Defender during enrollment so users can complete its initial configuration as part of device setup. If configuration isn't completed, the Intune setup step will remain available so users can open Defender again. This experience will help ensure that Defender is configured before enrollment finishes.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate-owned fully managed devices (COBO)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

Device management

Updated minimum supported version for macOS

Microsoft Intune will update its minimum supported macOS version after Apple releases macOS 27. Intune, the Company Portal, and the Intune management agent will support macOS 15 and later. Devices running macOS 14 or earlier that are already enrolled will remain enrolled, but new devices on those versions won't be able to enroll. You'll be able to use Intune reporting to identify affected devices and plan upgrades. Devices enrolled without user affinity have a separate support statement.

[!div class="checklist"] Applies to:

  • macOS

Updated minimum supported version for iOS and iPadOS

Microsoft Intune will update its minimum supported operating-system version after Apple releases iOS and iPadOS 27. Intune device management, the Company Portal, and app protection policies will require iOS/iPadOS 18 or later for standard supported scenarios. You'll be able to use Intune reports to identify affected devices and users and plan operating-system upgrades before the change. Userless devices enrolled through Automated Device Enrollment have a separate support statement and should be evaluated using the applicable guidance.

[!div class="checklist"] Applies to:

  • iOS/iPadOS

New single device page becomes the default experience in the Intune admin center

Starting with Intune's September (2609) release, the new single device page in the Intune admin center will become the default experience for all admins, and the previous device page will no longer be available. When you go to Devices > All devices and select a device, you'll use a consolidated view to find device details and properties, monitor activity, access tools and reports, and perform device actions. A consistent layout across platforms will group actions by purpose and show only supported and permitted actions, helping you find information and complete common device-management tasks more efficiently. Existing device-management capabilities will remain available in the redesigned experience.

[!div class="checklist"] Applies to:

  • All platforms

Stage app and policy rollout with deployment plans

Deployments and Deployments plans will give you a new way to roll out apps and configuration policies in Intune. Instead of assigning to all targeted groups at once, you'll be able to stage a rollout across multiple rings, control the timing of each ring, and monitor progress from a new Deployments experience in the Intune admin center. Plans provide reusable templates that define standardized rollout patterns for delivering a payload across devices in controlled stages, or rings. Deployments integrate with Multiple Admin Approval for change control. This helps you reduce risk when introducing changes to large device fleets.

[!div class="checklist"] Applies to:

  • Windows
  • Win32 and Enterprise app catalog apps
  • Settings catalog and Endpoint security policies

Bulk eSIM activation and wipe options for corporate-owned Android Enterprise devices

You'll be able to use Microsoft Intune bulk device actions to activate eSIMs on up to 100 supported corporate-owned Android Enterprise devices running Android 15 or later by using a carrier activation server URL. When you bulk wipe supported devices, Intune will preserve eSIM data plans by default, and you'll be able to choose to remove them when needed. These bulk actions will help you deploy or retire devices more efficiently without configuring each device individually. Personally owned Android Enterprise work profile devices won't be supported.

[!div class="checklist"] Applies to:

  • Android Enterprise corporate-owned fully managed devices (COBO)
  • Android Enterprise corporate-owned dedicated devices (COSU)
  • Android Enterprise corporate-owned devices with a work profile (COPE)

Device query for multiple devices for app inventory on Windows

Advanced Analytics will extend device query for multiple devices to cover app inventory data on Windows. Building on the existing multi-device query for hardware inventory, you'll be able to use Kusto Query Language (KQL) to investigate installed applications across your entire Windows fleet—identifying versions, surfacing outdated or unwanted software, and producing detailed reports without targeting devices one at a time. Multi-device app inventory queries will run against collected inventory data, so you get fleet-wide answers for compliance reviews, vulnerability triage, and license-tracking scenarios.

Device security

Configure Quality Update approvals and policies for Quick Machine Recovery (QMR)

Windows Autopatch currently offers limited control over the deployment of quality updates. Today, the expedite mechanism focuses on deploying the latest security update and doesn't let admins select specific quality update releases or apply different deployment schedules, which can limit compliance, validation, and operational planning scenarios.

Soon, Windows Autopatch will let you explicitly approve, auto-approve, reject, and schedule quality updates by update type, using the same approval infrastructure used for driver updates. This unified model helps you control what content is deployed and when, so you can align rollout timing with testing, compliance, and business readiness requirements. You'll be able to independently manage:

  • Monthly security updates
  • Monthly non-security updates
  • Out-of-band security updates
  • Out-of-band non-security updates

[!div class="checklist"] Applies to:

  • Windows

Associate devices to your organization with Windows Autopilot device preparation

A new capability for Windows Autopilot device preparation will be available soon: device association. Device association binds a Windows device to your organization and enables advanced functionality such as streamlined out-of-box experience (OOBE) pages, device naming before enrollment, and device-based targeting. It also improves onboarding security by verifying device identity before enrollment through hardware-based attestation and TPM-backed cryptographic validation, helping ensure that only trusted devices can access organizational resources.

Monitor and troubleshoot

Remote Help support in GCCH

You'll be able to use Remote Help in US Government Community Cloud High (GCCH) environments. This expansion extends the same secure, cloud-based remote assistance capabilities currently available in GCC to GCCH tenants. IT support staff will be able to establish Remote Help sessions with end users on GCCH-enrolled devices, providing real-time troubleshooting with role-based access controls through Intune. Both helpers and sharers must sign in with their organization's Microsoft Entra ID accounts.

[!div class="checklist"] Applies to:

  • Android
  • macOS
  • Windows

Certificate connector health monitoring in the Microsoft Intune admin center

The Certificate Connector for Microsoft Intune will surface new health and status signals in the admin center, so you can spot certificate-issuance problems early. You'll get clear indicators for common failure conditions — such as the connector being unable to reach the certification authority (CA), the connector's service account lacking permission to issue or revoke certificates, or certificate requests being rejected because of a template mismatch with your SCEP or PKCS profile. Each signal includes guidance to help you investigate and remediate before devices relying on certificate-based authentication hit access, sign-in, or compliance issues.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…