← Previous day

Next day →
Day in brief

Endpoint Privilege Management guidance specifies add-on licensing and Windows-only scope

This was a documentation-only day: ten updates, with no new, removed, or Message Center items. The consequential change is an Intune endpoint-security clarification that explicitly documents Endpoint Privilege Management (EPM) as a least-privilege control, requires an additional Intune add-on license—standalone or through the Intune Suite—and limits EPM policies to Windows. Separate enrollment guidance adds a precise macOS failure message and documents that bring-your-own VPN configurations aren't supported during Windows Autopilot pre-provisioning; the Configuration Manager work is chiefly version labeling and sample cleanup.

  • This is a documentation clarification, not a launch announcement. The revised endpoint-security guidance places Endpoint Privilege Management in the Zero Trust and least-privilege model, describing temporary elevation through application elevation rules. It explicitly says EPM requires an additional Intune add-on license, available standalone or through the Microsoft Intune Suite, and that EPM policies are available only for Windows devices.

  • The existing limitation remains: this enrollment method doesn't support device enrollment restrictions, and Apple-targeted device platform restrictions can cause the enrollment profile download to fail. The revised warning adds the diagnostic text: `File download error. Failed to dynamically fetch target download uri.` It also retains the failure condition for profiles downloaded before a restriction is enabled and then used afterward.

  • The Windows Autopilot Hybrid article now states that bring-your-own (BYO) VPN configurations aren't supported during Windows Autopilot in pre-provisioning mode. Administrators planning that phase should not rely on a BYO VPN configuration.

  • The Configuration Manager article title and description now identify Microsoft Connected Cache updates for versions 2409, 2503, and 2509 rather than only 2509. Other changes are ordinary reference maintenance: PowerShell examples are placed in fenced code blocks, the RFC link points specifically to section 5.1.2, and punctuation is corrected in the Enhanced HTTP warning and `resetdps.trn` instruction. The supplied diff indicates no new Connected Cache capability or behavior change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

10 updates

3

Endpoint Security

Updated

Updated Microsoft Intune documentation in intune/intune-service/protect/endpoint-security.md.

Endpoint Security

Updated

Updated Microsoft Intune documentation in intune/intune-service/protect/endpoint-security.md.

2
1

Reports

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/reports.md.

1
3

33247081

Updated

Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/33247081.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…