Whats New
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new.md.
The substantive service-release content centers on Endpoint Privilege Management (EPM): elevation policies now support deployment to users on Azure Virtual Desktop single-session virtual machines. Intune also adds Windows 11, version 25H2, to two feature-update readiness reports, introduces new Windows Settings catalog controls, and adds a Lenovo Device Orchestration link plus four protected apps. Separately, Windows Autopilot guidance records a Hybrid Entra join timeout and the OS updates that resolve it. The Settings insight rewrite clarifies documented scope and interpretation; much of the remaining activity is editorial or procedural maintenance.
The service release 2601 entry states that EPM elevation policies support deployment to users on AVD single-session virtual machines. It also adds a direct Intune admin center link to Lenovo Device Orchestration for supported Lenovo devices and lists four protected apps as newly available: Clarity Express for Intune, Datadog, Qlik Analytics, and Tier1 for Intune (iOS).
The Windows Settings catalog adds Microsoft Edge policies through version 143.0.3650.23, including Allow sharing tenant-approved browsing history with Microsoft 365 Copilot Search, Enable RAM (memory) resource controls, and Specifies whether to opt out of Local Network access restrictions. Experience > Disable Share App Promotions prevents promotional apps from appearing in Windows Share Sheet when enabled. The profile path is Devices > Configuration profiles > Create profile > Windows 10 and later > Settingsカタログ.
The Windows feature update compatibility risks report and Windows feature update device readiness report now support Windows 11, version 25H2, as a selectable target OS under Select target OS. The reports provide readiness and compatibility-risk insights for that target.
The Windows Autopilot Known Issues page records deployment timeouts with error code 0x80004005 for Hybrid Entra join Autopilot deployments. The issue is resolved in KB5065789 or later for 25H2, KB5065426 or later for 24H2, and KB5070312 or later for 23H2.
The revised guidance says Settings insight is available for the Microsoft Edge Baseline and Microsoft 365 Apps for Enterprise Security Baseline, but not currently for the Security Baseline for Windows 10 and later or the Microsoft Defender for Endpoint baseline. Light-bulb icons indicate that similar organizations commonly use Microsoft's recommended default; the feature does not suggest alternative values. This is a documentation clarification, not evidence of changed baseline behavior.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new-archive.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/settings-insight.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/whats-new.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/in-development.md.
Updated Microsoft Intune documentation in intune/device-updates/apple/index.md.
Updated Microsoft Intune documentation in intune/device-updates/windows/feature-update-policy.md.
Updated Microsoft Intune documentation in intune/intune-service/remote-actions/device-restore-managed-home-screen.md.
Updated Microsoft Intune documentation in intune/intune-service/remote-actions/device-suspend-managed-home-screen.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/apps-win32-add.md.
Updated Microsoft Intune documentation in intune/intune-service/configuration/properties-catalog.md.
Updated Microsoft Intune documentation in autopilot/known-issues.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/manage/replication/sql-replication.md.