Migrate To Application Management
Doc updateThe guide preserves the required Managed apps permissions and explains that Application Manager has sufficient permissions and scope tags control administrator visibility.
The Intune changes on 4 May are mostly documentation clarification: enrollment and RBAC requirements were reorganized into standard sections rather than changed service behavior. The consequential signals are a planned broader Windows Sync, planned macOS, iOS/iPadOS, and Android Enterprise controls, and a Direct Android LOB rollout expected to reach full availability by mid-May 2026. A previously listed Managed Home Screen suspend/restore roadmap item was removed, but the evidence does not establish a retirement or cancellation. Separately, Configuration Manager gained a new checklist for installing update 2603.
The In development entry says the Windows device Sync action will initiate a more comprehensive synchronization across compliance, configuration policies, apps, and scripts instead of waiting for scheduled check-ins. The planned enhancement is aimed at troubleshooting, incident response, and high-priority rollouts; it is not presented as currently available.
The roadmap lists Disable MAC address randomization for macOS 15 and later Wi-Fi profiles; a new 802.1x Wired Networks profile for iOS/iPadOS 17 and later with EAP protocols including TLS, PEAP, and TTLS; and an Android Enterprise Settings catalog Block Bluetooth sharing setting, where True prevents content sharing over Bluetooth. These remain In development items, not general-availability announcements.
The Intune What's New index says Direct Android LOB is gradually rolling out and may not yet be available in a tenant. Full availability is expected by mid-May 2026, so administrators should wait for rollout completion rather than treat its absence as a configuration error.
The Android Enterprise In development article no longer lists remote actions to temporarily suspend and restore Managed Home Screen for corporate-owned fully managed and dedicated devices. The diff shows removal from the article only; it does not establish a retirement, launch, or replacement. Do not plan around the old notice and verify currently supported remote actions.
The Migrate To Application Management guide groups the required Managed apps permissions—Assign, Create, Delete, Read, Update, and Wipe—and identifies the built-in Application Manager role as sufficient. It also says scope tags can limit administrator visibility and emphasizes that Company Portal must be installed for users to receive app protection policies. This is a documentation clarification, not evidence that permission semantics changed.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The guide preserves the required Managed apps permissions and explains that Application Manager has sufficient permissions and scope tags control administrator visibility.
The Delete device action article replaces iOS/iPadOS with Apple mobile while preserving the behavior: Delete triggers Retire for Apple mobile, macOS, and Windows; Android behavior continues to depend on enrollment type.
The MFA article now explicitly lists Android, iOS/iPadOS, macOS, and Windows support and states that users need Microsoft Entra ID P1 or later.
The article restructures requirements for Windows Autopilot device preparation, Android Enterprise, and tvOS/visionOS ADE, including the relevant enrollment-time device membership assignment permissions.
The backup and restore guide structures requirements for Entra-joined or hybrid-joined devices and supported Windows builds.
The bulk package guide moves Windows support and Microsoft Entra role requirements into a formal Requirements section.
The guide restructures prerequisites while retaining Android 10+, Google Mobile Services connectivity, regional and device support checks, and the existing tenant setup guidance.
The guide reformats its requirements while retaining Android 8.0+, Google Mobile Services connectivity, regional Android Enterprise availability, and device-support checks.
The dedicated-device guide restructures requirements while retaining Android 8.0+, Google Mobile Services connectivity, regional availability, and device support checks.
The JIT registration article restructures supported iOS/iPadOS enrollment scenarios and the compliance-policy requirement for JIT remediation.
The guide restructures Android Enterprise availability, tenant connection, and platform support prerequisites into dedicated requirement sections.
The article reformats requirements and explicitly lists Android, iOS/iPadOS, and Windows support plus Policy and Profile Manager or Intune Administrator role requirements.
The connection guide now groups country availability, Microsoft Entra account/mailbox, and Intune Administrator or custom organization read/update permissions as requirements.
The AOSP setup guide separates platform, licensing, and tenant requirements and states that specialized-device users need valid licenses.
The userless AOSP guide now separates platform, licensing, and tenant requirements and calls out valid licenses for specialized-device users.
The Vision Pro ADE guide separates device eligibility from Apple Business/School Manager portal, token, and Intune push-certificate requirements.
The direct macOS enrollment guide explicitly identifies macOS support and retains the requirement to unenroll a Mac from another MDM provider first.
The guide restructures Apple School Manager enrollment prerequisites, including supported Apple mobile platforms and portal-based setup.
The device-staging article separates the Android 8+ requirement and supported corporate-owned fully managed and work-profile enrollment methods from its overview.
The ADE guide now separately identifies new or wiped Apple Business Manager or School Manager devices and the required Apple portal access, token, and MDM push certificate.
The tvOS ADE guide separates eligible new or wiped Apple TV hardware from portal access, active Apple token, and Intune MDM push-certificate requirements.
The userless corporate Apple enrollment guide now presents platform support and setup prerequisites in requirement sections.
The guide explicitly identifies iOS/iPadOS 15+ support; devices on 14.9 and earlier use Company Portal user enrollment.
The macOS ADE guide now separates device eligibility from tenant requirements, including Apple portal access, a macOS ADE token, and an Intune MDM push certificate.
The iOS/iPadOS Configurator guide adds explicit platform and tenant-configuration requirement sections for MDM authority and Apple MDM push certificate.
The guide identifies support for iOS 13+ and iPadOS 13.1+ and restructures setup requirements.
The attestation guide explicitly lists supported Windows 10 and Windows 11 build levels, TPM 2.0+, and physical-device-only support.
The guide lists Android, iOS/iPadOS, macOS, and Windows support and confirms Intune Service Administrator can create, edit, delete, and reprioritize restrictions; custom and other built-in roles are read-only.
The guide lists Android, iOS/iPadOS, macOS, and Windows support and confirms Intune Administrator can create, edit, delete, and reprioritize platform restrictions while other built-in roles are read-only.
The guide now requires Intune Administrator to create enrollment notifications and calls out Intune branding and customization setup under Tenant administration > Customization.
The guide explicitly states iOS/iPadOS 15+ support, with earlier versions automatically using app-based enrollment, and identifies MDM authority and push-certificate prerequisites.
The guide now structures the Intune Administrator requirement separately and documents Update permission for creating or deleting DEM accounts and Read permission for viewing them.
The connector guide now groups Google Admin console and ChromeOS-device-management access with the Intune Service Administrator or equivalent custom-role requirement.
The education tutorial changes its bulk enrollment token reference from Roles and permissions to the renamed Requirements section.
The planned Android Managed Home Screen actions to temporarily suspend and restore the launcher were removed from the in-development article.
The in-development article adds planned macOS Wi-Fi MAC-randomization control, iOS/iPadOS 802.1X wired-network profiles, Android Enterprise Bluetooth-sharing control, Apple ADE enrollment-time grouping, and in-place renewal for eligible Cloud PKI issuing CAs.
A planned enhancement will make the Windows Sync device action perform a more comprehensive immediate synchronization across compliance, configuration policies, apps, and scripts instead of waiting for scheduled check-ins.
Intune plans custom macOS compliance checks using scripts and JSON rules, with results displayed alongside standard compliance reporting.
The planned iOS/iPadOS wired-network profile entry now links to the current wired-networks configuration article instead of a broken path.
The What's New entry adds that the Direct Android LOB feature is gradually rolling out, with full availability expected by mid-May 2026.
The In development entry for Android Enterprise Bluetooth sharing updates its Settings catalog and Android settings-list links to their current device-configuration locations.
The Microsoft Tunnel upgrade article adds a May 1, 2026 release-notes section for version 20260407.1 and its image hashes.
The BitLocker documentation now identifies pre-boot PIN modification events in Event Viewer: Microsoft-Windows-Bitlocker-API/Management, Bitlocker PIN Modification Task category, Event ID 789.
A new checklist documents installing Configuration Manager current-branch update 2603, including early-ring opt-in, hierarchy and site-system behavior, prerequisites, backup, replication, ADK, and update-installation checks. The update applies to sites on version 2409 or later.
Uses “Azure Virtual Machine Scale Set,” “Arm64,” and “nonfunctional” terminology in release notes while retaining the documented 2603 fixes.
The 2603 What's New article corrects all installation and post-update checklist links from the 2509 checklist to the new 2603 checklist.
The supported-versions table now lists Configuration Manager 2603 (5.00.9146.1000), with an early-ring availability date of May 5, 2026 and support through November 5, 2027. Its availability-date note now points to the 2603 checklist.
The release-notes index adds a link to the Configuration Manager 2603 What's New article.
The release-notes page updates its troubleshooting link to the Configuration Manager welcome page.
The supported-versions page retains its explanation that availability dates refer to early-ring release but removes the hyperlink to the 2603 early-ring checklist section.
The 2603 What's New article now says Microsoft SQL Server Management Objects and System CLR Types move from SQL Server 2014 versions to SQL Server 2025 versions (SMO 17), replacing the prior SQL Server 2016 wording.
The 2603 What's New article corrects an ARM64 version reference and a troubleshooting URL.
The Configuration Manager 2603 installation checklist removes the SQL Server 2012 Native Client prerequisite section while retaining the SQL ODBC driver requirement.