Create Policy
UpdatedUpdated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
The 8 May feed was documentation-only: all 41 supplied changes updated existing Intune pages, with no new or removed items and no Message Center notices. The consequential edits add explicit guidance for Android threat-defense permissions and Microsoft Tunnel enforcement, while compliance pages sharpen scheduling and platform-version boundaries. The evidence does not classify these updates as previews, general-availability releases, retirements, or confirmed service-behavior changes; much of the remaining work is heading, link, wording, and procedure cleanup.
The updated Intune Mobile Threat Defense connector page documents an optional **Mobile Threat Defense role** toggle for Android Enterprise corporate-owned fully managed and corporate-owned work profile devices. It grants the selected partner enhanced permissions: preventing app suspension and hibernation, exempting the app from power restrictions, and disabling user controls such as clearing app data or force-stopping the app. Only one partner can hold the role per tenant; the connector must be configured, the MTD
The Microsoft Tunnel VPN profile guidance says Android Strict Tunnel Mode is available when the connection type is Microsoft Tunnel and Always-on VPN is enabled. It forces all traffic through the tunnel and blocks traffic if the VPN drops until reconnection; an app exclusion list can bypass the tunnel. The listed scope includes Android Enterprise corporate-owned fully managed, corporate-owned work profile, and personally-owned work profile devices, with Android Management API enrollment required; legacy EMM APIxE3
For unenrolled MAM Tunnel devices, the `StrictTunnelMode` Microsoft Edge app-configuration key blocks Edge internet traffic when the MAM Tunnel connection is unavailable. For enrolled devices, Strict Tunnel Mode is configured at the device level in the Microsoft Tunnel VPN profile and applies to all network traffic, not just Edge. Administrators should choose the configuration path based on enrollment state; this is a clarified security procedure, not a stated rollout.
The revised Intune compliance-action guidance says **Schedule (days after noncompliance)** accepts whole numbers and decimal values in 0.25 increments in the admin center: `0.25` equals 6 hours and `0.5` equals 12 hours. Other decimal values, such as `0.33` for 8 hours, must be configured through Microsoft Graph. This clarifies the UI/API procedure rather than announcing a new action.
The iOS/iPadOS compliance settings reference changes repeated labels from **iOS 8.0 and later** to **iOS 17.0 and later**. The supplied diff does not establish whether enforcement or underlying service support changed, so administrators should validate the impact on older devices before treating the wording as a retirement or changing policy scope.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/enable-connector.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-wsl.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-wsl.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-ios-ipados-settings.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/app-based-policies.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Clarifies that the Company Portal retries check-in before issuing retire after 30 days or Lost contact; other edits are wording-only.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-windows-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-administrator-settings.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/install.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-aosp-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/overview.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/overview.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-linux-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-macos-settings.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-integration.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-enterprise-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/third-party-partners.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/overview.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/overview.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/block-no-modern-auth.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/install.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/overview.md.
Corrects reporting prose and renumbers the compliance-reporting option step; the Noncompliant devices report remains under Devices > Monitor.
Changes Android support wording to “later,” corrects “device is reported,” and clarifies Google Mobile Services unavailable regions fail Play Protect evaluation.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/mam-android.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/create-app-based-policy.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/mam-android.md.
Updated Microsoft Intune documentation in intune/user-help/vpn/microsoft-tunnel-android.md.
Updated Microsoft Intune documentation in intune/user-help/vpn/microsoft-tunnel-android.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/scenarios.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment.md.