← Previous day

Next day →
Day in brief

Recovery Lock guidance details macOS prerequisites, roles, and passcode procedures

The strongest Intune material is a Recovery Lock documentation cluster: the rotate-action guidance now records a specific supported Mac configuration, while Settings Catalog guidance clarifies who can run the related device actions. Other changes with direct operational value clarify that ASR Application control still uses a legacy template and that AppLocker CSP deployment can prompt a reboot, while Managed Home Screen exit passwords cannot be viewed after setup. Most remaining edits are terminology, punctuation, metadata, or navigation cleanup. A View macOS Recovery Lock Password page appears as both added and removed in the supplied records, so the evidence does not establish a stable launch or retirement.

  • The revised Intune guidance documents the action for macOS in Supervised Mode running macOS 11.5 or later on Apple silicon; Intel-based Macs are not supported. It also requires a device policy that enables Recovery Lock and directs administrators to **Passwords and keys** > **View Recovery Lock Passcode** after rotation. This is a documentation clarification, not a stated availability announcement.

  • Settings Catalog guidance changes the prerequisite from a custom role alone to either the Intune administrator Microsoft Entra role or a custom role with **Remote tasks/Rotate macOS recovery lock password** and **Remote tasks/View macOS recovery lock password** permissions. The page also links to the dedicated rotate-action procedure.

  • The Endpoint Security ASR page now states that the Application control profile has not been updated to the Settings Catalog format and remains an older template-based profile in the admin center. Existing policies remain functional, while AppLocker CSP deployment currently prompts the end user to reboot. This replaces the former profile-migration note and should be treated as documentation clarification rather than evidence of changed policy behavior.

  • For the **Exit lock task mode password** setting, the documentation now says the 4–6-digit value is obfuscated and cannot be viewed again once set. To rotate or change it, administrators must configure a new value in the device configuration profile.

  • New lifecycle guidance says Configuration Manager LTSB continues to be supported through its defined end of support even when a dependent component reaches end of support earlier, provided the reported issue is not caused by that out-of-support component. This is a Configuration Manager support clarification, not an Intune service change.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

22 updates

7

Device Macos

Removed

Removed Microsoft Intune documentation in intune/intune-service/remote-actions/-device-macos-.md.

4

Rotate Recovery Lock Passcode

Updated

Updated Microsoft Intune documentation in intune/intune-service/remote-actions/rotate-recovery-lock-passcode.md.

2
2
2
2
2

Introduction To The Ltsb

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/understand/introduction-to-the-ltsb.md.

1

In Development

Updated

Updated Microsoft Intune documentation in intune/intune-service/fundamentals/in-development.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…