← Previous day

Next day →
Day in brief

Autopatch entitlement and driver-blocking settings anchor revised Intune update guidance

The period was dominated by documentation consolidation rather than a demonstrated product release. Intune’s feature, quality, and driver update material now points to shared Autopatch-backed prerequisites, while driver policy guidance spells out settings that can block driver installation. Separate guidance emphasizes Platform Single Sign-On for macOS registration, and Endpoint Privilege Management support for Azure Virtual Desktop single-session VMs remains listed as in development.

  • The Intune index describes feature update, quality update, and driver update policies as using the same cloud orchestration layer and sharing prerequisites. Licensing wording changed from Windows Enterprise E3/E5 or equivalent to a Windows license that includes the Autopatch entitlement; the Microsoft Account Sign-In Assistant remains listed as a service requirement. This is documentation consolidation and terminology clarification, not evidence of changed backend behavior.

  • The Driver Updates Policy article warns that update rings and Settings Catalog policies can block Windows driver updates. It specifies Windows driver = Allow in update ring policy and Exclude WU Drivers in Quality Update = Allow Windows Update drivers in Settings Catalog; the guidance says both settings default to configurations that allow drivers. Review applicable policies before deployment.

  • The Windows updates index clarifies that Microsoft Entra registered devices aren't supported for Feature updates, Quality updates, or Driver updates policy types using the Autopatch backend. For those devices, update management remains limited to Windows Update client policies and update rings. The edit moves an existing limitation into a callout rather than announcing a new restriction.

  • The macOS endpoints guide calls Platform Single Sign-On the most secure approach for device attestation and registration, and describes enforcing the SSO extension during registration as a Zero Trust best practice that replaces traditional Company Portal registration. This is security guidance, not evidence of a new enrollment capability.

  • Endpoint Privilege Management · Device enrollment
    Endpoint Privilege Management support for AVD is listed as in development

    The Endpoint Privilege Management roadmap page restores an entry for deploying EPM policies to users on Azure Virtual Desktop single-session virtual machines. The entry says EPM elevation policies will work in that environment when support is added, but provides no general-availability indication or date.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

30 updates

22

Driver Updates

Doc update

The driver updates article adds a shared network-prerequisites include.

Index

Doc update

The index advises tenants blocked from creating Autopatch-required policies under EA licensing to contact their account team or licensing partner.

Feature Updates

Doc update

The feature update article removes a shared cloud-requirements block.

Driver Updates Policy

Doc update

The driver policy article removes its former Create Windows driver update policies heading and introductory procedure text.

Windows driver update management

Doc update

The article is retitled Windows driver update management and updates its introductory wording and applicable-platform presentation.

Driver Updates

Doc update

The driver updates article removes shared platform and other prerequisite blocks as content is consolidated into reusable requirement sections.

Driver Updates Policy

Feature update

The article warns that update rings and Settings Catalog can block drivers, and specifies Windows driver = Allow and Exclude WU Drivers in Quality Update = Allow Windows Update drivers.

Driver Updates Policy

Feature update

The article removes the earlier detailed callout about update-ring and Settings Catalog settings that block drivers.

Index

Doc update

The Windows updates index removes the table comparing manual and Autopatch update coordination.

Driver Updates Policy

Doc update

The Windows driver and Exclude WU Drivers setting guidance received indentation fixes.

Index

Doc update

The overview says feature, quality, and driver update policies share the Autopatch orchestration layer and have the same prerequisites across those three types.

Driver Updates

Doc update

The driver updates article replaces the inline RBAC-permissions list with shared tenant and RBAC prerequisite content.

Index

Doc update

The Windows updates index adds that updates fail when the Microsoft Account Sign-In Assistant service is blocked or disabled, and notes its default Manual (Trigger Start) setting.

Quality Updates

Doc update

The quality updates article now includes a reusable licensing-prerequisites section.

Expedite Updates

Doc update

The expedited updates article removed its explicit unsupported-cloud notice for GCC and GCC High/DoD environments.

Index

Doc update

The index changes feature, quality, and driver update references to explicitly say policy.

Index

Doc update

The note about the Microsoft Account Sign-In Assistant service was formatted as a nested callout.

Index

Doc update

The index corrects plural wording for feature, quality, and driver update policies.

Index

Doc update

The prerequisites emphasize Microsoft Entra joined or hybrid joined devices; Microsoft Entra registered devices remain limited to Windows Update client policies and update rings.

Driver Updates

Doc update

A blank line was removed from the driver updates article.

Driver Updates Overview

Doc update

The Markdown driver-updates-overview article was removed in a table-of-contents update.

Rollout Options

Doc update

The rollout options article removes the warning that gradual rollout would be unavailable after October 14, 2025.

2

Driver Updates Reports

Doc update

The reports article removes the detailed prerequisites section in favor of consolidated requirements content.

Feature Updates Reports

Doc update

The report article removes its standalone prerequisites content during requirements consolidation.

1

Lob Apps Ios

Doc update

The iOS LOB app size and bundle-identifier guidance was reformatted; its app-targeting caution remains intact.

1

Macos Endpoints Get Started

Doc update

The macOS endpoints guide says Platform Single Sign-On is the most secure approach for device attestation and registration and recommends enforcing the SSO extension for Zero Trust device identity.

1

Index

Doc update

The limitation on Entra registered devices using Autopatch-backed policy types is moved into a callout.

2

Removed And Deprecated Cmfeatures

Retirement

The MDT Integration retirement row now links to Microsoft’s MDT retirement information while retaining the direction to remove MDT task-sequence steps and integration.

1

In Development

Public preview

The in-development page restores an Endpoint Privilege Management support on Azure Virtual Desktop entry.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…