← Previous day

Keep up with Microsoft Intune

Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →

Day in brief

Configuration Manager guidance details co-management limits and reporting gaps for Windows Update policies

The period’s main development is a rewritten Configuration Manager article covering co-management scenarios, scan-source policies, troubleshooting, and the effects of receiving Windows updates directly from Windows Update. The former Windows Update for Business article was deleted, while Advanced Analytics Device Query guidance tightens documented role requirements and Intune corrects the Microsoft Graph hostname for China environments.

  • The new Configuration Manager article covers co-management scenarios, scan-source policies, common pitfalls, troubleshooting, and the effects of receiving Windows updates directly from Windows Update. It notes potential Unknown status for affected updates and limitations involving compliance reporting, Microsoft app updates, third-party updates, and software-update-based client deployment.

  • Configuration Manager · Device updates
    Former Windows Update for Business guidance was deleted

    The article covering Windows Update client policies, co-management considerations, limitations, prerequisites, and client-identification procedures was removed. Administrators relying on it should locate the current guidance and update saved references.

  • Advanced Analytics guidance now describes custom roles as needing permissions to view and access managed devices, giving Organization/Read and Managed devices/Read as examples. The separate Managed Devices/Query permission is no longer listed.

  • Advanced Analytics · Endpoint analytics
    Device Query guidance now requires a custom role

    The Device Query article now specifies that users must be assigned a custom role and no longer lists Help Desk Operator as a role option. Review assignments for administrators who need to use Device Query.

  • The China endpoints page now lists https://graph.chinacloudapi.cn instead of https://graph.chinacloudapi.us. Update configurations or connection references that still use the previous hostname.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

11 updates

1

Endpoints China

Doc update

The China endpoints documentation now lists `https://graph.chinacloudapi.cn` instead of `https://graph.chinacloudapi.us`.

1

Planning Guide

Doc update

The planning guide now links to `integrate-windows-update-client-policies.md` instead of the previous `integrate-windows-update-for-business-windows-10.md` article.

4

Integrate Windows Update client policies

Doc update

The article was rewritten to explain co-management scenarios, scan source policies, common pitfalls, troubleshooting, and the effects of receiving Windows updates directly from Windows Update. It documents impacts to compliance reporting, Microsoft app updates, third-party updates, and software-update-based client deployment.

Plan For Software Updates

Doc update

The article now links to `integrate-windows-update-client-policies.md` instead of `integrate-windows-update-for-business-windows-10.md`.

Whats New In Version 1706

Doc update

The version 1706 documentation now links to the Windows Update client policies article at a new path, retaining the same configuration section anchor.

Integrate Windows Update For Business Windows 10

Doc update

The Configuration Manager article covering Windows Update client policies, co-management considerations, limitations, prerequisites, and client identification procedures was deleted.

2

Manage Windows As A Service

Doc update

The article’s guidance on integrating Windows Update client policies was revised. It continues to state that computers using Windows Update client policies or Windows Insiders aren’t evaluated in Windows servicing plans and must use Configuration Manager software updates with WSUS.

1
2

Device Query for Multiple Devices

Feature update

The documentation now describes custom roles as needing permissions to view and access managed devices, with Organization/Read and Managed devices/Read as examples. The separate Managed Devices/Query permission is no longer listed.

Device Query

Feature updateAction required

The documentation now specifies that Device Query users must be assigned a custom role; the Help Desk Operator role option was removed.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…