← Previous day

Next day →
Day in brief

Driver controls, update reporting, and AVD elevation support come into focus

The day adds practical boundaries for Windows driver update management, clarifies the diagnostic-data dependency for feature-update reporting, and updates EPM support information for Azure Virtual Desktop. A Message Center post also previews new Managed Home Screen permissions in built-in roles.

  • The new FAQ confirms that driver policies do not support assignment filters or Windows Autopilot, do not provide rollback, and are clearer when a device receives one policy. It recommends staged rings, monitoring, and pausing updates where early-ring issues appear.

  • The reporting documentation now explicitly requires sharing Windows diagnostic data with Intune at Required level or higher to show full device status and event reporting for feature updates.

  • Endpoint Privilege Management · Device security
    EPM supports Azure Virtual Desktop single-session VMs

    Endpoint Privilege Management support information now includes Azure Virtual Desktop single-session virtual machines, enabling EPM onboarding and elevation-policy planning for that supported VDI configuration.

  • School Administrator and Help Desk Operator will receive permissions to temporarily suspend and restore Managed Home Screen in the February release. The announcement recommends reviewing role assignments and documentation, though no immediate action is required.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

26 updates

12

Driver Updates

Updated

The driver updates overview removed its Frequently Asked Questions section, including assignment filters, Autopilot, rollback, policy conflict, pauses, deadlines, deferrals, and co-management guidance, following publication of a separate FAQ article.

Expedite Updates

Updated

The expedited quality update reporting steps were renumbered using Markdown auto-numbering without changing the report navigation or actions.

Feature Updates

Updated

The article states feature update policies are public-cloud only and not supported in GCC High or DoD, distinguishes Intune Plan 1 from Autopatch-entitled licensing for gradual rollout and optional updates, and clarifies LTSC is unsupported.

Index

Updated

The overview renames the Workplace Joined limitation section for Microsoft Entra registered devices and states that feature, quality, driver, and Hotpatch policies relying on WUfB DS cannot be used on those devices.

Index

Updated

The Windows updates overview moves Microsoft Entra registered-device restrictions into its general prerequisites: WUfB DS-backed feature, quality, driver, and Hotpatch policies are unsupported, while update rings remain available.

Update Rings

Updated

The update rings article clarifies that Intune Plan 1 is required for core policy creation and assignment and updates platform and edition wording.

Index

Updated

The registered-device limitation sentence received a formatting-only correction.

Update Rings

Updated

The update rings article made a minor wording change to the statement that Windows Holographic for Business supports a subset of Windows update settings.

Feature Updates

Updated

The article replaced a hard-coded list of qualifying Windows licenses with a link to the Autopatch entitlement licensing documentation for gradual rollout and optional feature updates.

Update Rings

Updated

The article heading changed from Manage your Windows Update rings to Manage update rings.

Feature Updates

Updated

The feature update policy prerequisites removed the instruction to enable data collection for reporting.

4

Feature Updates Reports

Updated

The feature update reports article reorganized diagnostic-data requirements into tenant and device sections, explains that Windows update reports require sharing diagnostic data with Intune, and removes older duplicate collection text.

Driver Updates Reports

Updated

The driver reports article reorganized prerequisites into shared device and tenant requirement sections and states Windows diagnostic data must be collected at Required or higher for complete status and event reporting.

Driver Updates Reports

Updated

The report requirements now separate tenant configuration from device configuration and direct admins to enable Windows diagnostic data at Required or higher for driver-update reporting.

2

Manually Add the Windows Company Portal App

Updated

The manual Company Portal article now uses `winget download "Company Portal" --source msstore` rather than the install command, and identifies the default Downloads folder.

Store Apps Company Portal App

Updated

The Company Portal download command was indented as a PowerShell block and the Downloads-folder guidance was converted from a note to regular text.

2

Epm Plan

Updated

The EPM plan replaced a support note with a dedicated statement that Endpoint Privilege Management supports specified virtual platforms.

Privacy Data Store Process

Updated

The privacy data-storage article changed the documented Intune audit-log retention period from up to one year to up to two years; personal data deletion remains described as within 30 days after deletion.

1

In Development

Updated

The in-development page says Apple’s Rapid Security Responses rebrand to Background Security Improvements will be reflected in iOS/iPadOS Settings Catalog restrictions, and changes Android management-mode filtering to future tense.

1

Plan for Change: New Managed Home Screen RBAC permissions added to School Admin and Help Desk Operator built-in roles

New

Intune's February release adds two new Managed Home Screen RBAC permissions—TemporarilySuspendManagedHomeScreen and RestoreManagedHomeScreen—to the School Administrator and Help Desk Operator roles, enhancing Android device management. No admin action is needed, but reviewing role assignments and updating documentation is recommended.

Message CenterMC1213781 on mc.merill.net ↗Plan for change
1

Release Notes

Updated

The release notes now state that Microsoft Deployment Toolkit and its Configuration Manager integration are retired and unsupported, warn that retained MDT task-sequence steps can cause corruption or modification failures, and point to Autopilot or supported OSD.

1

Release Notes

Updated

The MDT retirement warning changed the instruction to say customers should remove MDT task-sequence steps and MDT integration to avoid corruption and modification failures.

2

Epm Frequently Asked Questions

Updated

The EPM FAQ replaces the statement that Azure Virtual Desktop is unsupported with a supported-virtual-devices section and clarifies that administrator launches matching elevation rules are reported as unmanaged elevations.

Epm Plan

Updated

The EPM planning article now states that EPM policies support Azure Virtual Desktop single-session VMs instead of listing Azure Virtual Desktop as unsupported.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.