Updated Microsoft Intune documentation in intune/device-security/security-baselines/ref-v2-office-settings.md.
Trustd Mobile integration, required-app auto-updates, and baseline changes headline Intune guidance
The substantive updates center on newly documented Trustd Mobile Mobile Threat Defense integration, Enterprise App Catalog auto-update rules, and security-baseline revisions. Trustd Mobile guidance covers risk-driven compliance and Conditional Access for Android 9.0 and later and iOS/iPadOS 15.0 and later; Enterprise App Catalog auto-update is scoped to Windows 10 and Windows 11 apps with Required assignments. The Microsoft 365 Apps security baseline 2512 replaces version 2306, while older Windows 25H2 profiles need an edit-and-save to receive the newly added IE11 COM-automation control. Intune also documented self-service compliance-partner onboarding; other notable clarification includes Remote Help's different control scope for AVD desktop and RemoteApp sessions.
- Trustd Mobile integration is newly documented for Intune MTD
Intune · Device security
New guidance describes Trustd Mobile sending a risk score through the Intune Mobile Threat Defense connector; the score updates device compliance and can drive Conditional Access blocking. The documented scope is Android 9.0 and later and iOS/iPadOS 15.0 and later, with Microsoft Entra ID P1, Intune Plan 1, a Trustd Mobile subscription, and the Trustd Mobile app required. This is newly added integration guidance, not a supplied GA announcement.
- Enterprise App Catalog auto-update is documented for Required assignments
Enterprise App Management · App management
The updated Enterprise App Management guidance says Intune can automatically update Enterprise App Catalog apps when a newer catalog version is available, without creating a new app or configuring supersedence for each update. The scope is Windows 10 and Windows 11 devices and apps with a Required assignment; Available for enrolled devices assignments retain the existing update workflow. Guided update supersedence remains an option for administrators who want to review updates before applying them.
- Microsoft 365 Apps security baseline 2512 replaces version 2306
Intune · Device security
The settings reference identifies Version 2512 as first made available in June 2026 and states that it replaces Version 2306. Listed defaults include Block Flash activation in Office documents set to Enabled and Restrict legacy JScript execution for Office set to Enabled. Microsoft directs administrators to the Security Compliance Toolkit's Microsoft 365 Apps for Enterprise 2512.zip for the complete settings list.
- Older Windows 25H2 profiles need saving for the new IE11 control
Intune · Device security
The Windows security baseline guidance says Disable Internet Explorer 11 Launch Via COM Automation was added in the June 2026 service update with an Enabled baseline default. Profiles created before the update do not apply it automatically: edit and save the profile, after which Intune deploys the setting at the next device check-in. Newly created or updated-to-25H2 profiles include the setting by default.
- Self-service compliance partners gain a custom connector path
Intune · Device security
Intune guidance now describes compliance partners onboarding and publishing their own connectors. Once a partner connector is available, administrators select Custom MDM Compliance Partner and enter the partner-provided Custom MDM Compliance Partner Entra Application ID. Configuration cannot be completed unless the ID belongs to a valid onboarded partner, and partner availability depends on completed onboarding and connector publication.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
29 updates
Microsoft Intune
25 updatesAdded Microsoft Intune documentation in intune/device-security/mobile-threat-defense/trustd-mobile.md.
Added Microsoft Intune documentation in intune/device-security/mobile-threat-defense/setup-trustd-mobile.md.
Assign Apps
UpdatedUpdated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/assign-apps.md.
Updated Microsoft Intune documentation in intune/device-security/security-baselines/ref-windows-mdm-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/third-party-partners.md.
Overview
UpdatedUpdated Microsoft Intune documentation in intune/device-security/security-baselines/overview.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/prerequisites.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-web-protection-android.md.
Overview
UpdatedUpdated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/overview.md.
Configure Integration
UpdatedUpdated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-integration.md.
Deploy Android
UpdatedUpdated Microsoft Intune documentation in intune/device-security/microsoft-defender/deploy-android.md.
Monitor
UpdatedUpdated Microsoft Intune documentation in intune/device-security/microsoft-defender/monitor.md.
Overview
UpdatedUpdated Microsoft Intune documentation in intune/device-security/microsoft-defender/overview.md.
Remediate Vulnerabilities
UpdatedUpdated Microsoft Intune documentation in intune/device-security/microsoft-defender/remediate-vulnerabilities.md.
Ref Android Settings
UpdatedUpdated Microsoft Intune documentation in intune/device-configuration/settings-catalog/ref-android-settings.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/configure-oemconfig-android.md.
Microsoft Intune will require iOS/iPadOS 18 or higher after Apple's iOS/iPadOS 27 release later this year. Organizations should check device compatibility and Intune reports to identify affected devices. Userless devices via ADE have different OS version requirements. Use Intune controls to manage supported OS versions.
Ref Protected Apps
UpdatedUpdated Microsoft Intune documentation in intune/app-management/ref-protected-apps.md.
Intune will support macOS 15 and later after Apple's macOS Golden Gate 27 release this year. Existing devices on macOS 14.x or below remain enrolled but new enrollments on these versions won't be allowed. Organizations should identify and upgrade affected macOS devices in Intune before the change.
Updated Microsoft Intune documentation in intune/device-enrollment/setup-time-grouping.md.
Endpoints
UpdatedUpdated Microsoft Intune documentation in intune/fundamentals/endpoints.md.
Updated Microsoft Intune documentation in intune/fundamentals/government-service.md.
Ref Wifi Settings Apple
UpdatedUpdated Microsoft Intune documentation in intune/device-configuration/templates/ref-wifi-settings-apple.md.
Index
UpdatedUpdated Microsoft Intune documentation in intune/whats-new/index.md.
Microsoft Intune Remote Help
2 updatesUpdated Microsoft Intune documentation in intune/remote-help/plan.md.
Updated Microsoft Intune documentation in intune/remote-help/start-session.md.
Enterprise App Management
2 updatesUpdated Microsoft Intune documentation in intune/app-management/deployment/enterprise-app-management.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-enterprise-catalog-app.md.