Day in brief

Planned Windows Sync expansion spans compliance, configuration policies, apps, and scripts

The Intune changes on 4 May are mostly documentation clarification: enrollment and RBAC requirements were reorganized into standard sections rather than changed service behavior. The consequential signals are a planned broader Windows Sync, planned macOS, iOS/iPadOS, and Android Enterprise controls, and a Direct Android LOB rollout expected to reach full availability by mid-May 2026. A previously listed Managed Home Screen suspend/restore roadmap item was removed, but the evidence does not establish a retirement or cancellation. Separately, Configuration Manager gained a new checklist for installing update 2603.

  • The In development entry says the Windows device Sync action will initiate a more comprehensive synchronization across compliance, configuration policies, apps, and scripts instead of waiting for scheduled check-ins. The planned enhancement is aimed at troubleshooting, incident response, and high-priority rollouts; it is not presented as currently available.

  • The roadmap lists Disable MAC address randomization for macOS 15 and later Wi-Fi profiles; a new 802.1x Wired Networks profile for iOS/iPadOS 17 and later with EAP protocols including TLS, PEAP, and TTLS; and an Android Enterprise Settings catalog Block Bluetooth sharing setting, where True prevents content sharing over Bluetooth. These remain In development items, not general-availability announcements.

  • The Intune What's New index says Direct Android LOB is gradually rolling out and may not yet be available in a tenant. Full availability is expected by mid-May 2026, so administrators should wait for rollout completion rather than treat its absence as a configuration error.

  • The Android Enterprise In development article no longer lists remote actions to temporarily suspend and restore Managed Home Screen for corporate-owned fully managed and dedicated devices. The diff shows removal from the article only; it does not establish a retirement, launch, or replacement. Do not plan around the old notice and verify currently supported remote actions.

  • The Migrate To Application Management guide groups the required Managed apps permissions—Assign, Create, Delete, Read, Update, and Wipe—and identifies the built-in Application Manager role as sufficient. It also says scope tags can limit administrator visibility and emphasizes that Company Portal must be installed for users to receive app protection policies. This is a documentation clarification, not evidence that permission semantics changed.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

53 updates

34

Migrate To Application Management

Doc update

The guide preserves the required Managed apps permissions and explains that Application Manager has sufficient permissions and scope tags control administrator visibility.

Delete

Doc update

The Delete device action article replaces iOS/iPadOS with Apple mobile while preserving the behavior: Delete triggers Retire for Apple mobile, macOS, and Windows; Android behavior continues to depend on enrollment type.

Configure Multifactor Authentication

Doc update

The MFA article now explicitly lists Android, iOS/iPadOS, macOS, and Windows support and states that users need Microsoft Entra ID P1 or later.

Set up enrollment time grouping

Doc update

The article restructures requirements for Windows Autopilot device preparation, Android Enterprise, and tvOS/visionOS ADE, including the relevant enrollment-time device membership assignment permissions.

Enable Backup Restore

Doc update

The backup and restore guide structures requirements for Entra-joined or hybrid-joined devices and supported Windows builds.

Create Bulk Package

Doc update

The bulk package guide moves Windows support and Microsoft Entra role requirements into a formal Requirements section.

Setup Fully Managed

Doc update

The guide restructures prerequisites while retaining Android 10+, Google Mobile Services connectivity, regional and device support checks, and the existing tenant setup guidance.

Setup Corporate Work Profile

Doc update

The guide reformats its requirements while retaining Android 8.0+, Google Mobile Services connectivity, regional Android Enterprise availability, and device-support checks.

Setup Dedicated

Doc update

The dedicated-device guide restructures requirements while retaining Android 8.0+, Google Mobile Services connectivity, regional availability, and device support checks.

Setup Just In Time Registration

Doc update

The JIT registration article restructures supported iOS/iPadOS enrollment scenarios and the compliance-policy requirement for JIT remediation.

Setup Personal Work Profile

Doc update

The guide restructures Android Enterprise availability, tenant connection, and platform support prerequisites into dedicated requirement sections.

Add Corporate Identifiers

Doc update

The article reformats requirements and explicitly lists Android, iOS/iPadOS, and Windows support plus Policy and Profile Manager or Intune Administrator role requirements.

Connect Managed Google Play

Doc update

The connection guide now groups country availability, Microsoft Entra account/mailbox, and Intune Administrator or custom organization read/update permissions as requirements.

Setup Aosp Corporate User Associated

Doc update

The AOSP setup guide separates platform, licensing, and tenant requirements and states that specialized-device users need valid licenses.

Setup Aosp Corporate Userless

Doc update

The userless AOSP guide now separates platform, licensing, and tenant requirements and calls out valid licenses for specialized-device users.

Setup Automated Vision Os

Doc update

The Vision Pro ADE guide separates device eligibility from Apple Business/School Manager portal, token, and Intune push-certificate requirements.

Setup Direct Macos

Doc update

The direct macOS enrollment guide explicitly identifies macOS support and retains the requirement to unenroll a Mac from another MDM provider first.

School Manager

Doc update

The guide restructures Apple School Manager enrollment prerequisites, including supported Apple mobile platforms and portal-based setup.

Device Staging

Doc update

The device-staging article separates the Android 8+ requirement and supported corporate-owned fully managed and work-profile enrollment methods from its overview.

Setup Automated Ios

Doc update

The ADE guide now separately identifies new or wiped Apple Business Manager or School Manager devices and the required Apple portal access, token, and MDM push certificate.

Setup Automated Tv Os

Doc update

The tvOS ADE guide separates eligible new or wiped Apple TV hardware from portal access, active Apple token, and Intune MDM push-certificate requirements.

Setup Corporate Userless

Doc update

The userless corporate Apple enrollment guide now presents platform support and setup prerequisites in requirement sections.

Setup Account Driven User

Doc update

The guide explicitly identifies iOS/iPadOS 15+ support; devices on 14.9 and earlier use Company Portal user enrollment.

Setup Automated Macos

Doc update

The macOS ADE guide now separates device eligibility from tenant requirements, including Apple portal access, a macOS ADE token, and an Intune MDM push certificate.

Setup Configurator Ios

Doc update

The iOS/iPadOS Configurator guide adds explicit platform and tenant-configuration requirement sections for MDM authority and Apple MDM push certificate.

Setup User Company Portal

Doc update

The guide identifies support for iOS 13+ and iPadOS 13.1+ and restructures setup requirements.

Attestation

Doc update

The attestation guide explicitly lists supported Windows 10 and Windows 11 build levels, TPM 2.0+, and physical-device-only support.

Create Device Limit Restrictions

Doc update

The guide lists Android, iOS/iPadOS, macOS, and Windows support and confirms Intune Service Administrator can create, edit, delete, and reprioritize restrictions; custom and other built-in roles are read-only.

Create Platform Restrictions

Doc update

The guide lists Android, iOS/iPadOS, macOS, and Windows support and confirms Intune Administrator can create, edit, delete, and reprioritize platform restrictions while other built-in roles are read-only.

Setup Notifications

Doc update

The guide now requires Intune Administrator to create enrollment notifications and calls out Intune branding and customization setup under Tenant administration > Customization.

Setup Web Based Ios

Doc update

The guide explicitly states iOS/iPadOS 15+ support, with earlier versions automatically using app-based enrollment, and identifies MDM authority and push-certificate prerequisites.

Setup Enrollment Manager

Doc update

The guide now structures the Intune Administrator requirement separately and documents Update permission for creating or deleting DEM accounts and Read permission for viewing them.

Configure Chrome Enterprise Connector

Doc update

The connector guide now groups Google Admin console and ChromeOS-device-management access with the Intune Service Administrator or equivalent custom-role requirement.

Enroll Package

Doc update

The education tutorial changes its bulk enrollment token reference from Roles and permissions to the renamed Requirements section.

6

In Development

Doc update

The planned Android Managed Home Screen actions to temporarily suspend and restore the launcher were removed from the in-development article.

In development - Microsoft Intune

Public preview

The in-development article adds planned macOS Wi-Fi MAC-randomization control, iOS/iPadOS 802.1X wired-network profiles, Android Enterprise Bluetooth-sharing control, Apple ADE enrollment-time grouping, and in-place renewal for eligible Cloud PKI issuing CAs.

In Development

Public preview

A planned enhancement will make the Windows Sync device action perform a more comprehensive immediate synchronization across compliance, configuration policies, apps, and scripts instead of waiting for scheduled check-ins.

In Development

Public preview

Intune plans custom macOS compliance checks using scripts and JSON rules, with results displayed alongside standard compliance reporting.

In Development

Doc update

The planned iOS/iPadOS wired-network profile entry now links to the current wired-networks configuration article instead of a broken path.

Index

Feature update

The What's New entry adds that the Direct Android LOB feature is gradually rolling out, with full availability expected by mid-May 2026.

1

In Development

Doc update

The In development entry for Android Enterprise Bluetooth sharing updates its Settings catalog and Android settings-list links to their current device-configuration locations.

1

Upgrade

Feature update

The Microsoft Tunnel upgrade article adds a May 1, 2026 release-notes section for version 20260407.1 and its image hashes.

1

Encrypt Bitlocker Windows

Doc update

The BitLocker documentation now identifies pre-boot PIN modification events in Event Viewer: Microsoft-Windows-Bitlocker-API/Management, Bitlocker PIN Modification Task category, Event ID 789.

8

Checklist for 2603

Doc update

A new checklist documents installing Configuration Manager current-branch update 2603, including early-ring opt-in, hierarchy and site-system behavior, prerequisites, backup, replication, ADK, and update-installation checks. The update applies to sites on version 2409 or later.

37426535

Doc update

Uses “Azure Virtual Machine Scale Set,” “Arm64,” and “nonfunctional” terminology in release notes while retaining the documented 2603 fixes.

Whats New In Version 2603

Doc update

The 2603 What's New article corrects all installation and post-update checklist links from the 2509 checklist to the new 2603 checklist.

Updates

Feature update

The supported-versions table now lists Configuration Manager 2603 (5.00.9146.1000), with an early-ring availability date of May 5, 2026 and support through November 5, 2027. Its availability-date note now points to the 2603 checklist.

Release Notes

Doc update

The release-notes index adds a link to the Configuration Manager 2603 What's New article.

Release Notes

Doc update

The release-notes page updates its troubleshooting link to the Configuration Manager welcome page.

Updates

Doc update

The supported-versions page retains its explanation that availability dates refer to early-ring release but removes the hyperlink to the 2603 early-ring checklist section.

Whats New In Version 2603

Doc update

The 2603 What's New article now says Microsoft SQL Server Management Objects and System CLR Types move from SQL Server 2014 versions to SQL Server 2025 versions (SMO 17), replacing the prior SQL Server 2016 wording.

1

Whats New In Version 2603

Doc update

The 2603 What's New article corrects an ARM64 version reference and a troubleshooting URL.

1

Checklist For Installing Update 2603

Doc update

The Configuration Manager 2603 installation checklist removes the SQL Server 2012 Native Client prerequisite section while retaining the SQL ODBC driver requirement.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…