Updated Microsoft Intune documentation in intune/intune-service/protect/security-baseline-settings-mdm-all.md.
Configuration Manager hotfix addresses co-managed devices redirected from Intune updates
6 March is dominated by documentation maintenance, but one item has direct operational weight: a new Configuration Manager hotfix reference says KB36495448 fixes partial Windows Update scan-source policies on co-managed devices with third-party updates, which can send Intune or Windows Update for Business Feature and Quality Updates to WSUS or Configuration Manager. Intune changes refine Security Baselines, iOS app wrapping, and Windows automatic-enrollment guidance; the supplied diffs do not establish a new Intune feature, preview, GA announcement, or product retirement. A same-day removed record contains the same KB36495448 material as the new entry, with no evidence that the hotfix itself was retired.
- KB36495448 targets co-managed Intune update-source redirection
Configuration Manager · General
The new reference says Configuration Manager versions 2503, with Update rollup 32851084 installed, and 2509 can set UseUpdateClassPolicySource and SetPolicyDrivenUpdateSourceForOtherUpdates while leaving related Feature, Quality, and Driver policy values unset or removed when third-party updates are enabled on co-managed devices. Windows Update can then redirect Feature Updates and Quality Updates intended for Intune or Windows Update for Business to WSUS or Configuration Manager. After the hotfix, Configuration
- Security Baselines page adds a Version 25H2 settings link
Intune · Device security
The Security Baselines index now includes a Version 25H2 link to security-baseline-settings-mdm-all.md?pivots=mdm-25h2. Its ms.date also changes from 02/12/2025 to 03/23/2026. This evidence shows a reference and navigation update, not a GA rollout or automatic assignment of a baseline.
- Baseline reference revises RPC, auditing, and default-setting descriptions
Intune · Device security
The settings reference changes “Protocol to allow for incoming RPC connections” to “Protocol to use for outgoing RPC connections,” corrects RPC/TCP labels, adds “Include command line in process creation events” with a baseline default of Enabled, and adds “Block process creations originating from PSExec and WMI commands” with a default of Audit. It no longer lists “Scan packed executables”; other edits include Min Smb2 Dialect defaulting to “SMB 3.0.0” and describing preconfigured SIDs as present but unselected by
- Automatic-enrollment guidance replaces Intune Administrator with Global Administrator
Intune · Device enrollment
The Windows MDM automatic-enrollment page now lists the built-in Global Administrator Microsoft Entra role instead of the built-in Intune Administrator role. The diff establishes a change in the published prerequisite, but does not establish that Intune’s authorization enforcement changed.
The App Wrapping Tool guidance now explicitly identifies MultiIdentity, MAMPolicyRequired, AutoEnrollOnLaunch, and ContainingAppBundleId as unsupported through the -mp custom plist parameter. These settings are automatically configured by the wrapping process, while supported custom settings are merged into the app’s IntuneMAMSettings dictionary.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
9 updates
Microsoft Intune
6 updatesSecurity Baselines
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/protect/security-baselines.md.
Updated Microsoft Intune documentation in intune/intune-service/protect/security-baseline-settings-mdm-all.md.
App Wrapper Prepare Ios
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/developer/app-wrapper-prepare-ios.md.
App Wrapper Prepare Ios
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/developer/app-wrapper-prepare-ios.md.
Updated Microsoft Intune documentation in intune/intune-service/enrollment/windows-enroll.md.
Microsoft Configuration Manager
3 updatesAdded Microsoft Intune documentation in intune/configmgr/hotfix/2503/36495448.md.
Added Microsoft Intune documentation in intune/configmgr/hotfix/2509/36419222.md.
36495448
RemovedRemoved Microsoft Intune documentation in intune/configmgr/hotfix/2503/36495448.md.