← Previous day

Next day →
Day in brief

macOS ADE Platform SSO registration gets concrete prerequisites for desktop-ready access

28 April was chiefly a documentation-maintenance day, not evidence of a broad Intune release. The material exceptions are a week-of-4-May entry documenting Platform SSO registration during macOS Automated Device Enrollment, more precise Enhanced App Inventory lifecycle and identifier guidance, and a new Zero Trust Assessment pointer; an Apple VPP note also clarifies an expected app limitation. Configuration Manager changes were mainly title, link, formatting, and page-removal edits, so the removed 2603 summary should not be read as a product retirement.

  • The What's New entry for the week of 4 May documents Platform SSO during macOS Automated Device Enrollment. Before enrollment, administrators must create a settings catalog policy with `Enable Registration During Setup`, deploy Company Portal version 5.2604.0 or newer as a line-of-business app, and use Setup Assistant with modern authentication plus `Await final configuration` in the ADE profile. It applies to macOS 26 and newer and says users have Microsoft Entra ID access immediately at desktop. The evidence adds

  • The procedure now directs administrators to Configuration settings > `+ Add Properties` > `ApplicationProperties`. `Platform Specific App Id` maps to Package Name for Store apps and product code for MSI apps, falling back to Uninstall Registry Key Name when neither applies. The documented sequence is a full upload on the first sync and delta-based uploads thereafter; removing the policy allows collection to continue for approximately three days before collection stops and service data is removed. This is a changed,

  • The Configure Microsoft Intune for increased security page adds an Automated assessment section linking to What is the Zero Trust Assessment and describing automation that tests the listed security configuration items and more. This is a security-guidance addition; it does not state that Intune requires the assessment or that a tenant setting changed.

  • The ADE Platform SSO procedure now says assignment filters can be used on Assigned (static) user groups. It retains the constraint that all policies for the feature must target the same static user groups; assigning them to different groups causes Platform SSO during enrollment to fail. This is a documentation clarification of assignment scope, not an announced enrollment behavior change.

  • Apple device restrictions guidance adds a note that `In-App Purchase Disabled` is expected on VPP apps because in-app purchases and subscriptions aren't compatible with VPP, Managed Apps, or Managed Apple Accounts. It points education and enterprise customers needing deployment at scale toward a separate full-featured version, sometimes as a Custom App. This clarifies app capability expectations rather than announcing a new Intune control.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

18 updates

3

Index

Updated

Updated Microsoft Intune documentation in intune/whats-new/index.md.

3

Ref Zero Trust Security

Updated

Updated Microsoft Intune documentation in intune/device-security/ref-zero-trust-security.md.

2

Enhanced App Inventory

Updated

Updated Microsoft Intune documentation in intune/app-management/deployment/enhanced-app-inventory.md.

2
1

Ref Device Restrictions Apple

Updated

Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-device-restrictions-apple.md.

7

37172183

Updated

Updated Microsoft Intune documentation in intune/configmgr/hotfix/2503/37172183.md.

36949461

Updated

Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/36949461.md.

37426535

Removed

Removed Microsoft Intune documentation in intune/configmgr/hotfix/2603/37426535.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…