← Previous day

Next day →
Day in brief

Managed Home Screen remote-action guidance names Android Enterprise scopes and RBAC permissions

The 20 January period was documentation-led: two new Intune how-to pages cover suspending and restoring Managed Home Screen, while revisions add the most useful operational detail around those actions. Other notable changes clarify Windows quality-update enforcement, app-protection assignment scope, and least-privilege trial setup. Most of the remaining 23 changes are routine metadata, wording, title, navigation, or link updates; the Windows Autopilot entry only changes a linked section anchor.

  • This is a documentation clarification, not evidence of a new rollout. The revised restore page identifies Android Enterprise corporate-owned Fully Managed (COBO) and Dedicated (COSU) devices, names Remote tasks/Restore Managed Home Screen as the custom-role permission, and says restoration re-enforces Managed Home Screen policies. Administrators using the action should check both enrollment mode and delegated permissions.

  • The revised page replaces the generic Android platform reference with Android Enterprise corporate-owned Fully Managed (COBO) and Dedicated (COSU), and identifies Remote tasks/Temporarily Suspend Managed Home Screen for custom roles. It also states that suspension stops Managed Home Screen policy enforcement and returns the user to the standard home screen and apps.

  • The Enrollment Status Page guidance now states that OS enforcement for the Install Windows quality updates Intune setting is included in the 2026-01 B quality update. This replaces the previous wording that the setting was available but not yet enforced and that enforcement was only planned. Review ESP rollout expectations and testing for devices receiving that release.

  • The app-protection procedure now tells administrators to select a users group and explicitly states that app protection policies can be applied only to groups containing users, not groups containing devices. Assignment plans or runbooks that rely on device-only groups need to be corrected.

  • The free-trial walkthrough now identifies the EMS subscription contents—Microsoft Entra ID P1 or P2 and Intune—and adds an admin-team step. It identifies Intune Administrator for Intune setup and Domain Name Administrator only when configuring an optional custom domain, while noting that the subscription-creating account receives Global Administrator and has more access than most Intune tasks require.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

23 updates

7

Index

Updated

Updated Microsoft Intune documentation in intune/intune-service/remote-actions/index.md.

4

Try Intune Overview

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/try-intune-overview.md.

Enroll a Windows device

Updated

Updated Microsoft Intune documentation in intune/intune-service/enrollment/quickstart-enroll-windows-device.md.

4
3

Quickstart Create Custom Role

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/quickstart-create-custom-role.md.

2

Add and Assign an App

Updated

Updated Microsoft Intune documentation in intune/intune-service/apps/quickstart-add-assign-app.md.

1
1
1

Whats New

Updated

Updated Microsoft Intune documentation in autopilot/device-preparation/whats-new.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…