← Previous day

Next day →
Day in brief

Agentic identity and device-based Conditional Access guidance sharpen Intune setup requirements

This was primarily a documentation-maintenance day, with one substantive new how-to and one retired page. The strongest administrator-facing changes are the new device-based Conditional Access procedure, revised Vulnerability Remediation Agent identity guidance, and explicit custom-compliance script prerequisites. The agent remains documented as limited public preview for selected customers and public-cloud-only; the update is not a general-availability announcement. Most other edits are terminology, formatting, screenshot, or metadata corrections.

  • A new Intune how-to documents a two-phase process: configure compliance policies in Intune, report compliance to Microsoft Entra ID, and then create the Conditional Access policy in Entra through the Intune admin center. It specifies a Microsoft Entra ID P1 or P2 license, a Security Administrator or Conditional Access Administrator role, and compliance policies as prerequisites. This is a new guidance page, not evidence of a new Conditional Access capability launch.

  • The revised operations guidance says the agent runs under an agentic identity rather than the Intune administrator account used for setup. It adds identity management, including creating a new agent identity, and a Test run to verify delegated permissions before execution. It also states that authentication expires after 90 consecutive days without a run until the identity is renewed.

  • The Create Custom Script guidance now shows `return $hash | ConvertTo-Json -Compress` as the script’s last line so output is compressed into one line. It explicitly says the upload workflow does not support scope tags and that authors must have the default scope tag to create, edit, or view custom compliance discovery scripts. This is a documentation clarification with direct authoring and delegation impact, not evidence of a script-engine change.

  • The Create Policy example now states that when assigned policies have Unknown severity 1, Compliant severity 3, and InGracePeriod severity 4, the device receives the InGracePeriod status. The change clarifies how to interpret the example’s device-level result; it does not indicate that the compliance evaluation behavior changed.

  • The page identified as Create App Based Policy was removed, including its step-by-step procedure for configuring app-based Conditional Access. This is a documentation-page retirement only; the supplied evidence does not show that app-based Conditional Access itself was retired.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

47 updates

33

Custom Settings

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.

Create Custom Script

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.

Create Policy

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.

Overview

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/overview.md.

Custom Settings

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.

Manage Exchange Access

Updated

Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/manage-exchange-access.md.

App Based Policies

Updated

Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/app-based-policies.md.

Configure Wsl

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/configure-wsl.md.

Create Custom Json

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.

Custom Settings

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.

Overview

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/overview.md.

Ref Android Aosp Settings

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-aosp-settings.md.

Ref Linux Settings

Updated

Updated Microsoft Intune documentation in intune/device-security/compliance/ref-linux-settings.md.

Create App Based Policy

Removed

Removed Microsoft Intune documentation in intune/device-security/conditional-access-integration/create-app-based-policy.md.

Device Based Policies

Updated

Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/device-based-policies.md.

Ref Android Administrator Settings

Doc update

Changes Android support wording to “later,” corrects “device is reported,” and clarifies Google Mobile Services unavailable regions fail Play Protect evaluation.

1
1

Monitor Policy

Doc update

Corrects reporting prose and renumbers the compliance-reporting option step; the Noncompliant devices report remains under Devices > Monitor.

1

Zero Trust

Updated

Updated Microsoft Intune documentation in intune/fundamentals/zero-trust.md.

1

Troubleshoot Endpoint Client

Updated

Updated Microsoft Intune documentation in intune/configmgr/protect/deploy-use/troubleshoot-endpoint-client.md.

1

Pre Release Construction

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/misc/pre-release-construction.md.

1

Cmpivot Tsg

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/servers/manage/cmpivot-tsg.md.

5
3

Suggestions

Doc update

Flags images in the manage-vulnerability-remediation-agent guidance for product-manager review or update.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…