Updated Microsoft Intune documentation in intune/intune-service/apps/app-protection-policy-settings-android.md.
EPM support-approved elevation guidance now covers all users of a device
This was a documentation-led period, not a release announcement: all supplied items were Microsoft Learn updates, with no Message Center evidence of a preview, general availability release, retirement, or tenant-wide rollout. The most consequential edits clarify EPM support-approved elevations, a 1,000-entry limit for Edge URL lists, Settings catalog (DDM) filter support, Android maximum-OS triggers, and Microsoft Tunnel DNS guidance. A separate Apple update-policy page removes an old DDM filter limitation warning but does not state that a replacement capability was added.
- EPM support-approved requests are no longer described as primary-user-only
Endpoint Privilege Management · Device security
The support-approved elevation page now states that requests can be submitted by all users of a device and aren't limited to its primary user. Administrators should revisit approval workflows for shared or multi-user devices, while recognizing that the supplied evidence is a documentation update rather than a separate rollout notice.
- Edge allow/block URL policies now document a 1,000-entry ceiling
Intune · App management
For com.microsoft.intune.mam.managedbrowser.AllowListURLs and BlockListURLs, corresponding to the Allowed URLs and Blocked URLs UI settings, the guidance now says each policy is limited to 1,000 entries and subsequent entries are ignored. Audit lists at or near that limit.
- Settings catalog (DDM) is marked supported in the assignment-filter matrix
Intune · Compliance
The Filters Supported Workloads table changes Settings catalog (DDM) from unsupported to supported in two entries. This is a support-matrix update; the supplied diff does not identify the affected workload rows or announce a separate feature rollout.
- Android app protection corrects the Max OS version trigger direction
Intune · App management
The App Protection Policy Settings Android page now says OS versions above the configured Max OS version trigger Warn or Block access. The Min OS version condition remains for versions below the minimum. The change corrects the documented condition rather than introducing a new setting.
- Microsoft Tunnel guidance adds corporate DNS to split-tunnel include rules
Intune · Device security
When corporate DNS is used in the server configuration, the updated guidance says those addresses should be added to the include rules for split tunneling. The page also retains the warning that 0.0.0.0 must not be used in include or exclude ranges because Tunnel Gateway can't route traffic with that range.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
8 updates
Microsoft Intune
6 updatesUpdated Microsoft Intune documentation in intune/intune-service/apps/app-protection-policy-settings-android.md.
Manage Microsoft Edge
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/apps/manage-microsoft-edge.md.
Filters Supported Workloads
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/filters-supported-workloads.md.
Updated Microsoft Intune documentation in intune/device-updates/apple/index.md.
Microsoft Tunnel Configure
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/microsoft-tunnel-configure.md.
Endpoint Privilege Management
2 updatesEpm Support Approved
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/epm-support-approved.md.
Epm Known Issues
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/epm-known-issues.md.