Updated Microsoft Intune documentation in intune/intune-service/protect/endpoint-security.md.
Endpoint Privilege Management guidance specifies add-on licensing and Windows-only scope
This was a documentation-only day: ten updates, with no new, removed, or Message Center items. The consequential change is an Intune endpoint-security clarification that explicitly documents Endpoint Privilege Management (EPM) as a least-privilege control, requires an additional Intune add-on license—standalone or through the Intune Suite—and limits EPM policies to Windows. Separate enrollment guidance adds a precise macOS failure message and documents that bring-your-own VPN configurations aren't supported during Windows Autopilot pre-provisioning; the Configuration Manager work is chiefly version labeling and sample cleanup.
- EPM guidance adds explicit licensing and platform boundaries
Intune · Device security
This is a documentation clarification, not a launch announcement. The revised endpoint-security guidance places Endpoint Privilege Management in the Zero Trust and least-privilege model, describing temporary elevation through application elevation rules. It explicitly says EPM requires an additional Intune add-on license, available standalone or through the Microsoft Intune Suite, and that EPM policies are available only for Windows devices.
- Direct-enroll macOS guidance adds the precise profile-download error
Intune · Device enrollment
The existing limitation remains: this enrollment method doesn't support device enrollment restrictions, and Apple-targeted device platform restrictions can cause the enrollment profile download to fail. The revised warning adds the diagnostic text: `File download error. Failed to dynamically fetch target download uri.` It also retains the failure condition for profiles downloaded before a restriction is enabled and then used afterward.
- Windows Autopilot pre-provisioning guidance excludes bring-your-own VPN
Windows Autopilot · Device enrollment
The Windows Autopilot Hybrid article now states that bring-your-own (BYO) VPN configurations aren't supported during Windows Autopilot in pre-provisioning mode. Administrators planning that phase should not rely on a BYO VPN configuration.
- Connected Cache guidance is labeled for ConfigMgr 2409, 2503, and 2509
Configuration Manager · General
The Configuration Manager article title and description now identify Microsoft Connected Cache updates for versions 2409, 2503, and 2509 rather than only 2509. Other changes are ordinary reference maintenance: PowerShell examples are placed in fenced code blocks, the RFC link points specifically to section 5.1.2, and punctuation is corrected in the Enhanced HTTP warning and `resetdps.trn` instruction. The supplied diff indicates no new Connected Cache capability or behavior change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
10 updates
Microsoft Intune
6 updatesEndpoint Security
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/endpoint-security.md.
Endpoint Security
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/endpoint-security.md.
Updated Microsoft Intune documentation in intune/intune-service/enrollment/device-enrollment-direct-enroll-macos.md.
Updated Microsoft Intune documentation in intune/intune-service/enrollment/device-enrollment-direct-enroll-macos.md.
Reports
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/reports.md.
Windows Autopilot
1 updateWindows Autopilot Hybrid
UpdatedUpdated Microsoft Intune documentation in autopilot/windows-autopilot-hybrid.md.
Microsoft Configuration Manager
3 updatesUpdated Microsoft Intune documentation in intune/configmgr/hotfix/2509/33247081.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/33247081.md.
33247081
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/hotfix/2509/33247081.md.