Updated Microsoft Intune documentation in intune/intune-service/apps/lob-apps-ios.md.
Planned GCC High STIG auditing baseline leads Intune’s March capability guidance
The period’s most consequential item is an upcoming Windows security baseline for GCC High tenants. Unlike a configuration baseline, it will audit devices against recommended STIG settings and produce detailed compliance reports. The iOS/iPadOS line-of-business app procedure also now documents a choice between default MDM and DDM management for iOS/iPadOS 18 and later. A removed Configuration Manager article covered a co-management update-source issue; its removal does not establish that the hotfix or product behavior was retired.
- Upcoming GCC High baseline will audit Windows devices against STIG recommendations
Intune · Fundamentals
The Intune In Development page says Microsoft is adding a security baseline available for GCC High tenants. It will focus on audits rather than configuration, apply to Windows devices, and generate detailed reports showing which devices meet recommended STIG settings. This is an upcoming capability, with no release date supplied.
- iOS/iPadOS line-of-business app procedure now documents MDM and DDM choices
Intune · App management
The app procedure now documents a Management type selector: MDM, which is the default, or DDM. It describes DDM as Apple’s policy-based management model for iOS/iPadOS 18 and later, with efficient app delivery, real-time app status reporting, and expanded app attribute options for per-app associated domains. This is a documentation clarification, not evidence of a new rollout.
- Removed Configuration Manager article covered co-managed update-source misrouting
Configuration Manager · General
The removed KB36495448 article described Configuration Manager versions 2503, with update rollup 32851084 installed, and 2509 when third-party updates were enabled. A partial scan-source policy could redirect Feature Updates and Quality Updates intended for Intune or Windows Update for Business to WSUS/Configuration Manager. The article documented post-hotfix cleanup and removal of UseUpdateClassPolicySource and SetPolicyDrivenUpdateSourceFor* values on co-managed devices. The evidence records article removal only,
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
4 updates
Microsoft Intune
3 updatesStarting May 2026, Windows Autopatch will enable hotpatch security updates by default for eligible Intune devices, speeding up security without restarts. An opt-out setting will be available from April 2026. Devices must meet prerequisites like enabling Virtualization-based Security to receive hotpatches.
In Development
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/in-development.md.
Microsoft Configuration Manager
1 update36495448
RemovedRemoved Microsoft Intune documentation in intune/configmgr/hotfix/2509/36495448.md.