Endpoints China
Doc updateThe China endpoints documentation now lists `https://graph.chinacloudapi.cn` instead of `https://graph.chinacloudapi.us`.
Daily highlights from Microsoft Learn and Message Center. Browse the archive from 1 January 2026 → About this project →
The period’s main development is a rewritten Configuration Manager article covering co-management scenarios, scan-source policies, troubleshooting, and the effects of receiving Windows updates directly from Windows Update. The former Windows Update for Business article was deleted, while Advanced Analytics Device Query guidance tightens documented role requirements and Intune corrects the Microsoft Graph hostname for China environments.
The new Configuration Manager article covers co-management scenarios, scan-source policies, common pitfalls, troubleshooting, and the effects of receiving Windows updates directly from Windows Update. It notes potential Unknown status for affected updates and limitations involving compliance reporting, Microsoft app updates, third-party updates, and software-update-based client deployment.
The article covering Windows Update client policies, co-management considerations, limitations, prerequisites, and client-identification procedures was removed. Administrators relying on it should locate the current guidance and update saved references.
Advanced Analytics guidance now describes custom roles as needing permissions to view and access managed devices, giving Organization/Read and Managed devices/Read as examples. The separate Managed Devices/Query permission is no longer listed.
The Device Query article now specifies that users must be assigned a custom role and no longer lists Help Desk Operator as a role option. Review assignments for administrators who need to use Device Query.
The China endpoints page now lists https://graph.chinacloudapi.cn instead of https://graph.chinacloudapi.us. Update configurations or connection references that still use the previous hostname.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The China endpoints documentation now lists `https://graph.chinacloudapi.cn` instead of `https://graph.chinacloudapi.us`.
The planning guide now links to `integrate-windows-update-client-policies.md` instead of the previous `integrate-windows-update-for-business-windows-10.md` article.
The article was rewritten to explain co-management scenarios, scan source policies, common pitfalls, troubleshooting, and the effects of receiving Windows updates directly from Windows Update. It documents impacts to compliance reporting, Microsoft app updates, third-party updates, and software-update-based client deployment.
The article now links to `integrate-windows-update-client-policies.md` instead of `integrate-windows-update-for-business-windows-10.md`.
The version 1706 documentation now links to the Windows Update client policies article at a new path, retaining the same configuration section anchor.
The Configuration Manager article covering Windows Update client policies, co-management considerations, limitations, prerequisites, and client identification procedures was deleted.
The Configuration Manager documentation now links to `integrate-windows-update-client-policies.md` instead of `integrate-windows-update-for-business-windows-10.md`.
The article’s guidance on integrating Windows Update client policies was revised. It continues to state that computers using Windows Update client policies or Windows Insiders aren’t evaluated in Windows servicing plans and must use Configuration Manager software updates with WSUS.
The article now revises its explanation of how Configuration Manager distinguishes Windows Update client policies from WSUS, including the UseWUServer attribute.
The documentation now describes custom roles as needing permissions to view and access managed devices, with Organization/Read and Managed devices/Read as examples. The separate Managed Devices/Query permission is no longer listed.
The documentation now specifies that Device Query users must be assigned a custom role; the Help Desk Operator role option was removed.