← Previous day

Next day →
Day in brief

Approved-client Conditional Access control retires in June; guided scenarios exit in March

The main operational signals are two planned retirements: the Microsoft Entra Conditional Access “Require approved client app” control is scheduled to retire in June 2026, while Intune guided scenarios will be removed in March except for Windows 365 Boot. The remaining updates are documentation and security-guidance clarifications rather than new feature launches or general-availability announcements.

  • The “Require approved client app” control will no longer be enforceable after retirement. Microsoft directs organizations to use “Require application protection policy” for equivalent and enhanced protection, making affected Conditional Access policies the clearest deadline-driven administrator task in this period.

  • All Intune guided scenarios except Windows 365 Boot are scheduled for removal beginning in March 2026. Existing configurations are unaffected and Microsoft says no administrator action is needed; replacement guidance is available through the resources in the message.

  • The deployment guide now explicitly says that deploying updates as Win32 apps is not the recommended approach. It points administrators to Update rings, Feature updates, and Quality updates, while retaining the Win32 method for cases that need more granular control. This changes the documented recommendation, not the deployment capability itself.

  • The renamed guide now includes policy mapping and license-assignment steps. Its procedure states that assigning Intune licenses to users or groups automatically switches them to Intune device management and leaves users and devices ready to receive newly created Intune policies; the earlier reference to switching at the next refresh cycle was removed. This is a procedural documentation clarification, not evidence of a newly launched migration capability.

  • The macOS endpoint guidance now recommends enforcing Platform SSO during device registration, describing it as a Zero Trust best practice that supports strong device identity and replaces traditional registration typically performed through the Company Portal. The update provides security guidance rather than announcing a new Platform SSO feature or availability change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

8 updates

2
2
1
1

Macos Endpoints Get Started

Updated

Updated Microsoft Intune documentation in intune/solutions/end-to-end-guides/macos-endpoints-get-started.md.

1
1
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…