Updated Microsoft Intune documentation in intune/whats-new/index.md.
Available macOS PKG apps now auto-update with management agent 2606.013
The service release 2606 material documents a concrete macOS app-management behavior change: available PKG apps can update automatically after an administrator uploads a newer version. It also records Enterprise App Management auto-updates, GCC High and DoD support, and ChatGPT as a protected app. Separate updates add Vulnerability Remediation Agent RBAC timing guidance and remove legacy Azure CDN aliases from selected endpoint tables; those are operational or documentation clarifications rather than evidence of new tenant capabilities.
For an available macOS PKG app, Intune now deploys an uploaded newer version automatically when it is added to the existing app policy with the same bundle ID, provided the user already installed the app. Users no longer need to select Install or Reinstall in Company Portal. The behavior requires the macOS Intune management agent version 2606.013 or later.
Intune now supports automatic updates for EAM applications when auto-update is enabled on an app with a required assignment; newer catalog versions are automatically deployed to targeted devices. The release notes also say EAM now extends to GCC High and DoD, allowing government organizations to discover, deploy, and keep prepackaged Microsoft and third-party apps up to date without manual repackaging.
- ChatGPT is newly available as an Intune protected app
Intune · General
The service-release notes list ChatGPT as a newly available protected app for Microsoft Intune. The supplied change does not specify additional platform scope or policy settings, so it supports the protected-app availability claim but not broader configuration conclusions.
- Vulnerability Remediation Agent guidance adds RBAC propagation timing
Security Copilot · Troubleshooting
The Security Copilot Vulnerability Remediation Agent page now adds an Important note that permissions assigned through an Intune RBAC role may take several minutes to take effect after the agentic user is added to the group. This is troubleshooting guidance about permission propagation, not evidence that RBAC behavior or the agent capability itself changed.
- Selected endpoint tables remove legacy azureedge.net aliases
Intune · Fundamentals
The Endpoints page now lists intunecdnpeasd.manage.microsoft.com alone for the Android AOSP dependency, instead of also listing intunecdnpeasd.azureedge.net. The North America, Europe, and Asia Pacific macOS sidecar rows likewise retain only their manage.microsoft.com hostnames and remove the macsidecarprod*.azureedge.net aliases and migration notes. This is an allowlist-documentation cleanup; the supplied diff does not establish a separate endpoint retirement deadline.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
7 updates
Microsoft Intune
6 updatesUpdated Microsoft Intune documentation in intune/whats-new/in-development.md.
Index
UpdatedUpdated Microsoft Intune documentation in intune/whats-new/index.md.
Management Extension Windows
UpdatedUpdated Microsoft Intune documentation in intune/device-management/tools/management-extension-windows.md.
Ref Settings Ios
UpdatedUpdated Microsoft Intune documentation in intune/app-management/protection/ref-settings-ios.md.
Endpoints
UpdatedUpdated Microsoft Intune documentation in intune/fundamentals/endpoints.md.
Updated Microsoft Intune documentation in intune/copilot/agents/vulnerability-remediation-agent.md.