Updated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless guidance adds platform gates, recovery planning, and clearer Intune boundaries
25 March was primarily a documentation-refinement day centered on a substantial rewrite of Intune passwordless guidance. The revised material adds licensing and OS prerequisites, phishing-resistance and Conditional Access context, hybrid-Windows caveats, and recovery planning; a separate iOS App SDK page adds a security-critical integration warning. The supplied evidence shows guidance and terminology changes—not a new Intune feature, preview, GA announcement, or product-behavior rollout. One removed item is an Outline page; nothing supplied describes a capability retirement.
- Entra-versus-Intune ownership is stated more explicitly
Intune · General
The updated Passwordless article says Intune does not issue passwordless credentials: it prepares devices, apps, and user experiences, while Microsoft Entra ID provides the identity controls and authentication methods. Intune configures device settings and compliance that those methods depend on. This is an administrator-facing scope clarification, not evidence of a changed service boundary.
The revised table lists Microsoft Entra ID P1 for Windows Hello for Business, FIDO2, passkeys, Authenticator phone sign-in, Temporary Access Pass, and authentication-strength policies; P2 for risk-based Conditional Access; Intune Plan 1 for device compliance and configuration; and an Intune Suite or standalone Cloud PKI add-on for Microsoft Cloud PKI. Its minimum-version table lists passkeys on Windows 11, all supported macOS and iOS/iPadOS versions, and Android 14 or later. This is documentation guidance, so use
New dependency text says authentication-strength policies can require phishing-resistant MFA and block weaker methods such as passwords or SMS. It also directs administrators to maintain at least two break-glass accounts excluded from Conditional Access and passwordless enforcement, and to use Temporary Access Pass to register a replacement credential after device loss. These are planning recommendations in the article, not a report that Microsoft changed default policies.
- Hybrid Windows caveats are made more visible
Intune · General
The Windows section now says its passwordless examples assume a cloud-first direction with Microsoft Entra-joined devices. For hybrid Entra-joined deployments, additional infrastructure may be needed depending on the trust model; on-premises resource access requires Cloud Kerberos Trust or certificate-based trust, and applications requiring NTLM or direct LDAP bind may need additional planning. The article identifies Cloud Kerberos Trust as the recommended model because it avoids deploying certificates for Kerberos
The Intune App SDK for iOS Phase 5 page now highlights that the SDK cannot independently detect identity changes and relies entirely on the app to report them. If the app fails to notify the SDK when the active identity changes, policies may not be enforced for that user, managed data may be accessible without app protection restrictions, or unmanaged data may be incorrectly restricted.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
34 updates
Microsoft Intune
33 updatesPasswordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Outline
UpdatedUpdated Microsoft Intune documentation in intune/solutions/outline.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Outline
UpdatedUpdated Microsoft Intune documentation in intune/solutions/outline.md.
Outline
UpdatedUpdated Microsoft Intune documentation in intune/solutions/outline.md.
Outline
RemovedRemoved Microsoft Intune documentation in intune/solutions/outline.md.
Updated Microsoft Intune documentation in intune/solutions/passwordless.md.
Updated Microsoft Intune documentation in intune/solutions/passwordless.md.
Outline
UpdatedUpdated Microsoft Intune documentation in intune/solutions/outline.md.
App Sdk Ios Phase5
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/developer/app-sdk-ios-phase5.md.
Outline
UpdatedUpdated Microsoft Intune documentation in intune/solutions/outline.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
Passwordless
UpdatedUpdated Microsoft Intune documentation in intune/solutions/passwordless.md.
The Intune Data Warehouse update, now expected mid-June 2026, will reset historical data to about 30 days, refresh surrogate keys, and revise licensing definitions. The beta Power BI connector will be discontinued; users must switch to the OData feed from the Intune admin center and back up data beforehand.
Security Copilot will be included with Microsoft 365 E5 via a phased rollout from April 20 to June 30, 2026, providing 400 Security Compute Units per 1,000 users and core agentic features across Microsoft security products. Additional advanced capabilities may incur extra costs.