Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/upgrade.md.
Configuration Manager 2603 requires management-point internet access for Entra token validation
The consequential change is a new Configuration Manager 2603 management-point prerequisite: sites using Microsoft Entra authentication for Entra-joined users and devices, typically through a cloud management gateway, must provide internet access for MISE token validation. Supporting pages add the required proxy and endpoint details. The other notable updates change the published SQL Server 2025 support matrix and record a Microsoft Tunnel Gateway image release with package and security updates; they do not introduce a new Intune control-plane capability.
- Configuration Manager 2603 adds a management-point connectivity requirement
Configuration Manager · General
Starting in version 2603, the management point uses Microsoft Identity Service Essentials (MISE) for Microsoft Entra token validation. The server requires internet access when the site supports Microsoft Entra-joined users and devices and clients authenticate with Entra tokens, typically through a CMG. AD-only environments without Entra integration are excluded. Network failures can appear in CCM_STS_ManagedBase.log as a MISE12034 exception with a SocketException, HttpRequestException, or timeout.
- MISE validation requires a system-level WinHTTP proxy
Configuration Manager · General
The proxy configured in Configuration Manager site system properties does not apply to MISE token validation. Administrators must configure the proxy at the management-point server’s system level, for example with `netsh winhttp set proxy <proxyservername>:<portnumber>`; `netsh winhttp show proxy` verifies the setting and `netsh winhttp reset proxy` removes it.
- Azure authentication endpoints are added to management-point requirements
Configuration Manager · General
For Azure public cloud, the documented endpoints are `https://login.microsoftonline.com` and `https://sts.windows.net`. For Azure US Government cloud, they are `https://login.microsoftonline.us` and `https://sts.windows.net`. The access is required for MISE-based Microsoft Entra token validation starting in Configuration Manager 2603.
- SQL Server 2025 support matrix expands its listed versions
Configuration Manager · General
The SQL Server 2025 row now lists 170, 160, 150, 140, 130, 120, and 110, with 170 as the maximum, replacing the previous list of 160, 150, 140, and 130 with 160 as the maximum. This is a published support-matrix change rather than a described new Intune feature.
- Microsoft Tunnel Gateway records release 20260527.1
Intune · Device security
The Tunnel Gateway upgrade page adds version 20260527.1, agent and server image SHA-256 digests, and a release note stating: “Package and security updates.” The entry supplies release and image-identification data; it does not describe a new Tunnel capability or setting.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
6 updates
Microsoft Intune
1 updateMicrosoft Configuration Manager
5 updatesWhats New In Version 2603
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/core/plan-design/changes/whats-new-in-version-2603.md.
Proxy server support
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/proxy-server-support.md.
Internet access requirements
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/internet-endpoints.md.
37426535
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/hotfix/2603/37426535.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-sql-server-versions.md.