Updated Microsoft Intune documentation in intune/solutions/edge-data-security/protection-policies-step-2.md.
Guidance now highlights version-targeted policies for Android direct LOB updates
This was primarily a documentation-clarification period. The most actionable updates cover Android Enterprise direct line-of-business app versioning, macOS Platform SSO enrollment prerequisites, the Microsoft Edge for Business threat-level value, and Microsoft 365 Apps assignment behavior. A new device-security overview and related link cleanup are organizational changes; the supplied evidence does not establish a feature launch, preview, general-availability change, or product retirement.
- Updated Android LOB versions need newly targeted app-configuration policies
Intune · App management
The revised Android app-configuration guidance now covers directly deployed LOB apps and says policies associated with a previous app version are not automatically applied after an update. Administrators must create and assign a policy targeting the new version. Direct-LOB app configuration is supported on Android Enterprise fully managed (COBO) and dedicated (COSU) devices, not personally owned work profile or corporate-owned work profile (COPE) devices. This is explicit documentation guidance, not evidence of a 
- Direct APK deployment takes precedence over Managed Google Play
Intune · App management
The Android LOB deployment article clarifies that when the same app is deployed through Managed Google Play and as an APK uploaded directly to Intune, the directly uploaded app is installed regardless of the Managed Google Play version. If multiple directly uploaded versions are assigned, the higher version is installed. This documents deployment-selection behavior rather than announcing a new rollout.
- macOS Platform SSO enrollment now lists all required setup components
Intune · Device enrollment
The enrollment procedure now states that all of these are required: a Settings Catalog Platform SSO policy, Company Portal deployed as a line-of-business app, and an Automated Device Enrollment profile using Setup Assistant with Modern Authentication and await final configuration enabled. If any step is missing or misconfigured, the configuration fails; the documented recovery procedure removes the existing Platform SSO configuration and reenrolls the device.
- Edge app protection now specifies “Secured” for the blocked threat level
Intune · App management
In the Microsoft Edge for Business app protection policy procedure, the documented Max allowed device threat level paired with Block access changed from Medium to Secured. The evidence shows a documentation value update only, so administrators should verify the intended policy configuration rather than infer that the service behavior changed.
- Microsoft 365 Apps guidance adds a Word-uninstall assignment example
Intune · App management
The deployment page now gives a concrete example of the existing overwrite rule for multiple required or available assignments: if an earlier Microsoft 365 Apps assignment includes Word and a later assignment omits it, Word is uninstalled. The page explicitly says this condition does not apply to Visio or Project. This is a clarification and example, not evidence of a changed assignment engine.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
20 updates
Microsoft Intune
18 updatesUpdated Microsoft Intune documentation in intune/app-management/deployment/add-lob-android.md.
Updated Microsoft Intune documentation in intune/app-management/configuration/configure-managed-android.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-managed-google-play.md.
Add Apps to Microsoft Intune
UpdatedUpdated Microsoft Intune documentation in intune/app-management/deployment/index.md.
Updated Microsoft Intune documentation in intune/app-management/configuration/overview.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-microsoft-365-windows.md.
Configure Managed Android
UpdatedUpdated Microsoft Intune documentation in intune/app-management/configuration/configure-managed-android.md.
Overview
UpdatedUpdated Microsoft Intune documentation in intune/app-management/configuration/overview.md.
Added Microsoft Intune documentation in intune/device-security/overview.md.
Manage Policies
UpdatedUpdated Microsoft Intune documentation in intune/device-configuration/endpoint-security/manage-policies.md.
Ref Zero Trust Data
UpdatedUpdated Microsoft Intune documentation in intune/device-security/ref-zero-trust-data.md.
Ref Zero Trust Devices
UpdatedUpdated Microsoft Intune documentation in intune/device-security/ref-zero-trust-devices.md.
Ref Zero Trust Security
UpdatedUpdated Microsoft Intune documentation in intune/device-security/ref-zero-trust-security.md.
Ref Zero Trust Tenant
UpdatedUpdated Microsoft Intune documentation in intune/device-security/ref-zero-trust-tenant.md.
Index
RemovedRemoved Microsoft Intune documentation in intune/device-security/index.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment.md.
What Is Intune
UpdatedUpdated Microsoft Intune documentation in intune/fundamentals/what-is-intune.md.
Microsoft Configuration Manager
1 updateUpdated Microsoft Intune documentation in intune/configmgr/protect/understand/protect-data-and-site-infrastructure.md.
Endpoint Privilege Management
1 updateEndpoint Security Policies
UpdatedUpdated Microsoft Intune documentation in intune/device-security/endpoint-security-policies.md.