Microsoft Intune
General

In Development

In brief

The page now lists Apple OS 27 DDM inventory data, MEFERI OEMConfig support for Android Enterprise, removal of legacy Apple MDM software-update workloads, and two Administrator protection settings for Windows 11 24H2 and 25H2.

What Intune admins need to know

Administrators should track these planned changes for device inventory, OEMConfig deployments, Apple update management, and Windows Account Protection policies. No action or deadline is stated.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Device configuration

Apple OS 27 DDM status data in device inventory

Microsoft Intune will add Apple OS 27 declarative device management (DDM) status data to device inventory. You'll be able to review system health information for supported hardware components, content cache details, and MDM state such as enrollment type, awaiting configuration, Return to Service, Shared iPad, and Lockdown Mode. Reported values will depend on the device's supported operating system, hardware, enrollment type, and available DDM capabilities.

Applies to:

  • Apple devices running OS 27

Add support for the MEFERI OEMConfig app on Android Enterprise

Intune will add support for the MEFERI OEMConfig app (com.meferi.oemconfig) for Android Enterprise devices. Once onboarded, admins will be able to use Intune's OEMConfig workflow to deploy and manage the device settings that MEFERI exposes through its OEM-provided schema. This update will expand the catalog of supported OEMConfig apps and reduce the need for custom management workarounds when organizations use MEFERI hardware. Admins will continue using the same OEMConfig pattern in Intune by adding the app from Managed Google Play, assigning it to devices, and creating OEMConfig profiles against the supported bundle.

Applies to:

  • Android Enterprise

Enforce Routes capability in iOS/iPadOS and macOS VPN profiles

Microsoft Intune will support Apple's Enforce Routes feature in iOS/iPadOS and macOS VPN profiles.

Device management

Remove legacy Apple MDM software update workloads from Intune

Intune will remove legacy Apple MDM software update workloads after Apple retires the underlying MDM update commands and payloads. This change will help keep the Intune admin experience, Graph surface, and documentation aligned to what Apple still supports, instead of leaving behind settings that no longer have a valid backend. Organizations that still depend on the older workflows will need to finish moving remaining Apple software update scenarios to declarative device management (DDM). By cleaning up the outdated path, Intune will reduce confusion and make the supported Apple update model clearer for administrators planning future update deployments.

Applies to:

  • Apple software updates in Microsoft Intune

New settings for Administrator protection in endpoint security Account Protection policy

We’re adding two settings to Intune's Endpoint security Account Protection profile. These settings enhance device security by requiring user authentication for administrator level actions. This authentication request helps to safeguard devices from unauthorized changes and malware.

The two new settings are already available in the Intune settings catalog. Selecting the setting name link opens its entry in the LocalPoliciesSecurityOptions CSP documentation:

To learn more about the Administrator protection scenario, see Administrator protection on Windows 11 on the Windows IT Pro Blog.

Applies to:

  • Windows 11 (24H2 and 25H2)

Updated minimum supported version for macOS

Microsoft Intune will update its minimum supported macOS version after Apple releases macOS 27. Intune, the Company Portal, and the Intune management agent will support macOS 15 and later. Devices running macOS 14 or earlier that are already enrolled will remain enrolled, but new devices on those versions won't be able to enroll. You'll be able to use Intune reporting to identify affected devices and plan upgrades. Devices enrolled without user affinity have a separate support statement.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…