Updated Microsoft Intune documentation in intune/intune-service/remote-actions/device-restore-managed-home-screen.md.
Approved-client Conditional Access control retires in June; guided scenarios exit in March
The main operational signals are two planned retirements: the Microsoft Entra Conditional Access “Require approved client app” control is scheduled to retire in June 2026, while Intune guided scenarios will be removed in March except for Windows 365 Boot. The remaining updates are documentation and security-guidance clarifications rather than new feature launches or general-availability announcements.
- Microsoft Entra retires the approved-client Conditional Access control in June 2026
Intune · Compliance
The “Require approved client app” control will no longer be enforceable after retirement. Microsoft directs organizations to use “Require application protection policy” for equivalent and enhanced protection, making affected Conditional Access policies the clearest deadline-driven administrator task in this period.
- Intune guided scenarios will be removed from the admin center in March
Configuration Manager · Android
All Intune guided scenarios except Windows 365 Boot are scheduled for removal beginning in March 2026. Existing configurations are unaffected and Microsoft says no administrator action is needed; replacement guidance is available through the resources in the message.
- Windows .msu Win32 deployment guidance now favors Windows Update policies
Intune · App management
The deployment guide now explicitly says that deploying updates as Win32 apps is not the recommended approach. It points administrators to Update rings, Feature updates, and Quality updates, while retaining the Win32 method for cases that need more granular control. This changes the documented recommendation, not the deployment capability itself.
- The Basic Mobility and Security migration guide clarifies license-driven transition steps
Intune · Fundamentals
The renamed guide now includes policy mapping and license-assignment steps. Its procedure states that assigning Intune licenses to users or groups automatically switches them to Intune device management and leaves users and devices ready to receive newly created Intune policies; the earlier reference to switching at the next refresh cycle was removed. This is a procedural documentation clarification, not evidence of a newly launched migration capability.
- Microsoft strengthens the Platform SSO recommendation for macOS registration
Intune · Device enrollment
The macOS endpoint guidance now recommends enforcing Platform SSO during device registration, describing it as a Zero Trust best practice that supports strong device identity and replaces traditional registration typically performed through the Company Portal. The update provides security guidance rather than announcing a new Platform SSO feature or availability change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
8 updates
Microsoft Intune
8 updatesUpdated Microsoft Intune documentation in intune/intune-service/remote-actions/device-suspend-managed-home-screen.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/migrate-to-intune.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/migrate-to-intune.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/apps-win32-deploy-update-package.md.
Macos Endpoints Get Started
UpdatedUpdated Microsoft Intune documentation in intune/solutions/end-to-end-guides/macos-endpoints-get-started.md.
The "Require approved client app" control in Microsoft Entra Conditional Access will retire in June 2026. Organizations should update policies to use the "Require application protection policy" control for equivalent and enhanced protection. After retirement, the old control will no longer be enforceable.
Updated Microsoft Intune documentation in intune/solutions/end-to-end-guides/macos-endpoints-get-started.md.