← Previous day

Next day →
Day in brief

Available macOS PKG apps now auto-update with management agent 2606.013

The service release 2606 material documents a concrete macOS app-management behavior change: available PKG apps can update automatically after an administrator uploads a newer version. It also records Enterprise App Management auto-updates, GCC High and DoD support, and ChatGPT as a protected app. Separate updates add Vulnerability Remediation Agent RBAC timing guidance and remove legacy Azure CDN aliases from selected endpoint tables; those are operational or documentation clarifications rather than evidence of new tenant capabilities.

  • For an available macOS PKG app, Intune now deploys an uploaded newer version automatically when it is added to the existing app policy with the same bundle ID, provided the user already installed the app. Users no longer need to select Install or Reinstall in Company Portal. The behavior requires the macOS Intune management agent version 2606.013 or later.

  • Intune now supports automatic updates for EAM applications when auto-update is enabled on an app with a required assignment; newer catalog versions are automatically deployed to targeted devices. The release notes also say EAM now extends to GCC High and DoD, allowing government organizations to discover, deploy, and keep prepackaged Microsoft and third-party apps up to date without manual repackaging.

  • The service-release notes list ChatGPT as a newly available protected app for Microsoft Intune. The supplied change does not specify additional platform scope or policy settings, so it supports the protected-app availability claim but not broader configuration conclusions.

  • The Security Copilot Vulnerability Remediation Agent page now adds an Important note that permissions assigned through an Intune RBAC role may take several minutes to take effect after the agentic user is added to the group. This is troubleshooting guidance about permission propagation, not evidence that RBAC behavior or the agent capability itself changed.

  • The Endpoints page now lists intunecdnpeasd.manage.microsoft.com alone for the Android AOSP dependency, instead of also listing intunecdnpeasd.azureedge.net. The North America, Europe, and Asia Pacific macOS sidecar rows likewise retain only their manage.microsoft.com hostnames and remove the macsidecarprod*.azureedge.net aliases and migration notes. This is an allowlist-documentation cleanup; the supplied diff does not establish a separate endpoint retirement deadline.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

7 updates

3

Index

Updated

Updated Microsoft Intune documentation in intune/whats-new/index.md.

2

Management Extension Windows

Updated

Updated Microsoft Intune documentation in intune/device-management/tools/management-extension-windows.md.

Ref Settings Ios

Updated

Updated Microsoft Intune documentation in intune/app-management/protection/ref-settings-ios.md.

1

Endpoints

Updated

Updated Microsoft Intune documentation in intune/fundamentals/endpoints.md.

1
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…