Upgrade
Doc updateChanges the Microsoft Tunnel release entry from May 1 version 20260407.1 to May 7 version 20260507.2.
The period’s main rollout is general availability for Windows Autopilot device preparation in automatic mode for Windows 365 Enterprise, Windows 365 Frontline dedicated and shared, and Windows 365 Cloud Apps. Policies can provision apps, scripts, and configurations when a Cloud PC is created; Windows 365 Reserve remains in public preview. Other notable updates document deployment-log retention, a Configuration Manager rollup caveat, and Intune compliance and Android app-reporting guidance.
Windows Autopilot device preparation policies can now be included in Cloud PC provisioning policies for Windows 365 Enterprise, Windows 365 Frontline dedicated and shared, and Windows 365 Cloud Apps. Policies apply when a Cloud PC is created and deliver apps, scripts, and configurations before user sign-in. Windows 365 Reserve remains in public preview.
The reporting guidance specifies that deployment records created after automatic cleanup was introduced are removed every 28 days. Older Windows 365 records are not covered by automatic cleanup and require one-time manual removal; administrators should preserve any history they still need before cleanup.
The rollup’s known-issues section says KB 36419072, the offline feedback update, and KB 36495448, the co-management and third-party update scan source fix, are not included. Installing the rollup overwrites changes from either fix if it was previously installed individually; both are planned for a future rollup.
The Intune compliance-policy guidance now labels the most secure MTD threat level as Clear rather than Secured. Clear means the device cannot have any threats present; any detected threat makes the device noncompliant. This is a terminology correction in the guidance, not evidence of changed enforcement behavior.
Directly deployed Android Enterprise line-of-business apps still install correctly, but the Intune admin center can show a lower app version as Installed instead of In-Conflict, show a matching Managed Google Play app as Waiting for install or omit it, and report mixed Install and Uninstall intents inconsistently. Verify the app on the device rather than treating these status displays as installation failures.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Changes the Microsoft Tunnel release entry from May 1 version 20260407.1 to May 7 version 20260507.2.
Corrects the most secure MTD compliance threat level from Secured to Clear; devices with any threats remain noncompliant.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/ref-android-settings.md.
Adds Known issues explaining direct Android Enterprise LOB apps install correctly while only Intune admin-center install-status reporting is affected.
Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/multi-admin-approval.md.
Adds GA for automatic-mode device-preparation policies that provision Cloud PCs at creation; Windows 365 Reserve remains preview.
Adds GA for automatic-mode device-preparation policies that provision Cloud PCs at creation; Windows 365 Reserve remains preview.
Adds that device-preparation deployment records created after feature introduction are automatically removed after 28 days; older Windows 365 records need one-time manual removal.
Updated Microsoft Intune documentation in autopilot/device-preparation/whats-new.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/36949461.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2603/37426535.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/36949461.md.