Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/multi-admin-approval.md.
Multi Admin Approval’s app-auth Graph API article is removed from Learn
The main story is a documentation change around Multi Admin Approval (MAA): the standalone app-authenticated Microsoft Graph API article was removed, while the core MAA article also drops explicit app-auth enforcement wording and revises approver requirements. Elsewhere, Configuration Manager guidance records a version 2509 planning endpoint for diagnostic-data changes, and Device Query documents a new Local AI Agent entity with no NL2KQL assistance yet.
- Standalone MAA app-auth Graph API article removed
Intune · Fundamentals
The page “Use Multi Admin Approval with the Microsoft Graph API” was removed. Its deleted content covered MAA enforcement for app-only Graph calls to protected resources, HTTP 403 responses when approval headers were absent, affected resource types including policies, device actions, RBAC, scripts, and tenant configuration, plus the required app permissions, access policies, and interactive approver. The removal is a documentation change and does not by itself establish a change in enforcement.
- Core MAA article removes explicit app-auth enforcement wording
Intune · Fundamentals
The main article no longer states that MAA intercepts app-authenticated Graph API calls or includes the tip that automation enforcement applies only in tenants with MAA access policies configured. It also presents the approver requirements as items 2 and 3 and says the approver group must be directly assigned to an Intune role as a member group. No product-behavior change is announced in the diff.
- Configuration Manager 2509 guidance says diagnostic-collection changes will stop
Configuration Manager · Troubleshooting
The diagnostics guidance now says that, with version 2509, no further changes or updates are planned for diagnostic and usage data collection. This is a forward-looking documentation note; it does not say that current collection is disabled.
- Device Query adds Local AI Agent with an NL2KQL limitation
Advanced Analytics · Endpoint analytics
Device Query Multiple Devices now lists Local AI Agent as an entity, but explicitly states that NL2KQL assistance for that entity is currently unsupported. Administrators using natural-language query assistance should not expect it to work for Local AI Agent.
- Virtualization validation guidance gets a new destination URL
Configuration Manager · General
The Configuration Manager virtualization-environment article changes the Server Virtualization Validation Program link from windowsservercatalog.com/svvp.aspx to windowsservercatalog.com/svvp/program-home. The diff changes only the link destination and does not announce a change to virtualization support.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
6 updates
Microsoft Intune
2 updatesRemoved Microsoft Intune documentation in intune/fundamentals/role-based-access-control/multi-admin-approval-graph-api.md.
Microsoft Configuration Manager
3 updatesLevels Overview
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/core/plan-design/diagnostics/levels-overview.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-virtualization-environments.md.
Diagnostics And Usage Data
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/core/plan-design/diagnostics/diagnostics-and-usage-data.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.