The documentation updates the COPE device table and explains that a Settings reset doesn’t enforce factory reset protection when Factory reset protection emails is Not configured.
Keep up with Microsoft Intune
Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →
EPM system-settings policy covers controlled IPv4, IPv6, and DNS changes
The period’s most consequential update centers on Endpoint Privilege Management’s Elevation system settings policy, which documents how standard Windows users can make selected network changes under administrator-defined controls. Intune guidance also tightens Android reset and factory reset protection expectations, while Advanced Analytics documents unavailable device identifiers.
- EPM documents controlled network-setting delegation
Endpoint Privilege Management · Device security
A new Endpoint Privilege Management page describes policies that let standard Windows users change IPv4, IPv6, and DNS settings. Administrators can require confirmation, business justification, Windows authentication, or both, and devices need an EPM elevation settings policy enabled.
- Android reset guidance links FRP enforcement to email configuration
Intune · Device enrollment
The Corporate Methods guidance states that Settings resets don’t enforce factory reset protection when Factory reset protection emails is Not configured. For Android 15 devices with a configured Google account email, the account must be re-entered after the reset.
- Advanced Analytics records ICCID and SimInfo data limitations
Advanced Analytics · Endpoint analytics
The schema reference now states that ICCID isn’t supported on Windows. It also continues to specify that SimInfo isn’t supported for Android Enterprise personally owned devices with a work profile.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
5 updates
Microsoft Intune
2 updatesRef Corporate Methods
Doc updateThe page now explains that Settings resets don't enforce FRP when Factory reset protection emails is Not configured. For Android 15 devices with a configured Google account email, the account must be re-entered after the reset.
Endpoint Privilege Management
2 updatesManage system settings with Endpoint Privilege Management - Microsoft Intune | Microsoft Learn
New featureThe documentation describes policies that let standard Windows users change IPv4, IPv6, and DNS settings. Administrators can require confirmation, business justification, Windows authentication, or both.
Overview
New featureThe EPM overview now lists three policy types and adds an Elevation system settings policy for allowing standard users to change selected Windows settings, including IPv4, IPv6, and DNS configuration.
Ref Data Platform Schema
Feature updateThe schema documentation now states that ICCID isn’t supported on Windows. It continues to note that SimInfo isn’t supported for Android Enterprise personally owned devices with a work profile.