← Previous day

Next day →
Day in brief

Autopilot device preparation reaches 25 apps amid Cloud PKI’s CA-guide overhaul

The period is mostly a Cloud PKI documentation move: path and image-link fixes accompany eight legacy `/intune/intune-service/protect` pages being replaced by `/intune/cloud-pki` pages for deployment, CA configuration, monitoring, deletion, audit logs, and fundamentals. That is documentation reorganization—not evidence of a Cloud PKI launch or product retirement. The significant operational items are a documented 25-app Windows Autopilot device-preparation limit and a status update saying the previously delayed Enrollment Status Page security-update capability is included in Windows `2026-01 B`. An Intune Mobile Threat Defense/App Protection example also changes its block thresholds, but the evidence supports a documentation example change only.

  • The updated guidance changes the managed-application example from 10 to 25. It says up to 25 apps can be configured in a Windows Autopilot device-preparation policy for both user-driven and automatic modes, including all Cloud PC offerings. It warns that deployments with more apps may need longer deployment timeouts. The evidence does not label this change preview or generally available.

  • The page replaces a September 2025 delay notice with: “As of January 13, 2026, this capability is included in the Windows `2026-01 B` quality update.” The earlier note specifically said automatic installation of monthly security update releases and the new user interface were unavailable. This is an availability/status update in the What’s New guidance, not a supplied general-availability announcement.

  • The new deployment-model guidance lists two options: create Microsoft Cloud PKI root and issuing CAs in the cloud, producing a two-tier hierarchy with multiple issuing CAs; or create a private cloud issuing CA anchored to an on-premises or private CA, including external private CA N+1 hierarchies. This is newly organized guidance, not evidence of a new service launch.

  • The new procedure distinguishes Pause, Resume, Revoke, and Delete. Pausing stops leaf issuance while the CA continues responding to CRL and AIA requests. A root CA cannot be deleted until all anchored issuing CAs are deleted, active leaf certificates must already be revoked before an issuing CA can be revoked, and revocation or deletion cannot be undone. The page also names the Intune Administrator or a custom Intune role with Read CAs, Disable and reenable CAs, and Revoke issued leaf certificates permissions.

  • In Step 3, one Max allowed device threat level example changes from Low to High, with Block access in both versions; another changes from Medium to Low, also with Block access. This is a Mobile Threat Defense/App Protection documentation example change. The supplied diff does not say that existing policies, defaults, or enforcement behavior changed.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

41 updates

3

Intune Endpoints

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/intune-endpoints.md.

Whats New Archive

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new-archive.md.

Intune Endpoints

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/intune-endpoints.md.

1
5

Whats New

Updated

Updated Microsoft Intune documentation in autopilot/device-preparation/whats-new.md.

11

Configure Byoca

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/configure-byoca.md.

Configure Ca

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/configure-ca.md.

Configure Ca

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/configure-ca.md.

Configure Byoca

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/configure-byoca.md.

Deploy

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/deploy.md.

Fundamentals

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/fundamentals.md.

Fundamentals

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/fundamentals.md.

Index

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/index.md.

Intune Add Ons

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/intune-add-ons.md.

8

Microsoft Cloud Pki Delete

Removed

Removed Microsoft Intune documentation in intune/intune-service/protect/microsoft-cloud-pki-delete.md.

Microsoft Cloud Pki Monitor

Removed

Removed Microsoft Intune documentation in intune/intune-service/protect/microsoft-cloud-pki-monitor.md.

7

Delete

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/delete.md.

Deploy

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/deploy.md.

Configure Byoca

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/configure-byoca.md.

3

Monitor

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/monitor.md.

Monitor

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/monitor.md.

2

Index

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/index.md.

Index

Updated

Updated Microsoft Intune documentation in intune/cloud-pki/index.md.

1
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…