← Previous day

Next day →
Day in brief

OpenClaw preview baseline details Node.js blocking and collateral-impact warnings

29 May was primarily a documentation day, but several changes have concrete administrative relevance. Intune’s security-baseline overview now lists Local AI Agent Baseline - OpenClaw as Preview, Version 1, for May 2026, while its new settings reference describes controls intended to disrupt unauthorized local AI-agent execution paths. A new account-moves article explains regional relocation of Intune data at rest. Other notable edits clarify Platform SSO setup, change Configuration Manager’s evaluation guidance from 180 to 360 days, and remove the older Windows in cloud configuration overview and setup pages as related links move to cloud-native Windows endpoint guidance. The supplied evidence does not establish OpenClaw general availability or retirement of the cloud-native endpoint capability.

  • The Intune security-baselines overview adds Local AI Agent Baseline - OpenClaw (Preview), Version 1, with a May 2026 listing. This establishes preview documentation, not general availability or a tenant-wide rollout.

  • The new settings reference says the baseline limits unauthorized local AI agents such as OpenClaw by disrupting common execution paths, including outbound firewall controls for Node.js and controls affecting environments such as Windows Subsystem for Linux. It warns that other processes may also be blocked, so each setting should be reviewed and tested before deployment. The reference also recommends collecting Local AI Agent inventory through Properties catalog first.

  • The new overview defines an Intune account move as a managed migration of customer data at rest between geographic datacenter regions, while preserving policies, profiles, device enrollments, app management state, and service configuration. It explicitly distinguishes the process from a tenant-to-tenant migration, and describes support coordination for customer-requested moves and advance notice for Microsoft-initiated moves.

  • The Enable Create First User During Setup guidance now says to configure the setting when using the Password authentication method; with other authentication methods, it isn’t required. The previous note that the setting was rolling out slowly and should be available by the end of May 2026 was removed. This is a documentation clarification, not evidence of changed product behavior.

  • The evaluation-install procedure now says the Configuration Manager console becomes read-only after 360 days, replacing the previous 180-day statement. The guidance still directs administrators to activate from Site Maintenance in Setup and says a full installation can be obtained before or after that period.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

13 updates

3

Ref Openclaw Settings

Updated

Updated Microsoft Intune documentation in intune/device-security/security-baselines/ref-openclaw-settings.md.

Overview

Updated

Updated Microsoft Intune documentation in intune/device-security/security-baselines/overview.md.

3

Index

Updated

Updated Microsoft Intune documentation in intune/solutions/frontline-worker/index.md.

Cloud Configuration

Removed

Removed Microsoft Intune documentation in intune/solutions/cloud-native-endpoints/cloud-configuration.md.

Setup Cloud Configuration

Removed

Removed Microsoft Intune documentation in intune/solutions/cloud-native-endpoints/setup-cloud-configuration.md.

2

Planning Guide

Updated

Updated Microsoft Intune documentation in intune/fundamentals/planning-guide.md.

1
1

Collect Device Properties

Updated

Updated Microsoft Intune documentation in intune/device-configuration/collect-device-properties.md.

1
1
1
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…