Setup Macos Token
UpdatedUpdated Microsoft Intune documentation in intune/device-enrollment/apple/setup-macos-token.md.
The period was largely maintenance, but the substantive Intune changes center on Android Enterprise personally owned work-profile enrollment and forthcoming device-management capabilities. Updated guidance centers a single enrollment profile for web and Company Portal flows, while clarifying that web enrollment is tenant-level and irreversible and may conflict with device-bound phone-call MFA. Intune’s in-development page also adds Samsung Knox E-FOTA integration and Windows registry and app-inventory work. The macOS token procedure was broadened to cover both Apple Business Manager and Apple School Manager; this is a procedural clarification, not a feature launch.
The setup article now says admins first create an enrollment profile that supports both web-based and Company Portal app-based enrollment. Web enrollment is enabled as an additional step by selecting Use web enrollment for all users enrolling into Android personally owned work profile management; when passkeys are the only authentication method, the guidance says to leave it unselected and use Company Portal enrollment instead.
The revised setup guidance explicitly states that enabling web-based enrollment applies at the tenant level and cannot be reversed. This clarifies the scope and consequence of the setting rather than announcing a product-behavior change.
The updated guidance records a limitation: if MFA requires a phone call that the user must answer on the device being enrolled, web enrollment might break. It lists authenticating on a secondary device or using SMS as workarounds and says the limitation will be resolved in a future update, without providing a date.
The In development page adds an upcoming Knox E-FOTA integration that would surface remote firmware deployment in the Intune admin center for eligible corporate-owned Samsung Android Enterprise devices: dedicated (COSU), fully managed (COBO), and corporate-owned with a work profile (COPE). It also lists Windows properties-catalog collection of HKLM registry data through Single Value, All Values Under Key (Non-Recursive), or Same Value Across Subkeys, plus Advanced Analytics multi-device Windows app-inventory querys
The enrollment program token procedure now explicitly covers Apple Business Manager and Apple School Manager with portal-specific steps. It changes the Intune action label from Add to Create and explains that Apple Business Manager creates a device management service while Apple School Manager creates an MDM server; both processes produce a server token uploaded to Intune. This is a procedure clarification, not evidence of a new token capability.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-macos-token.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/android-management-api-overview.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/android-management-api-overview.md.
Updated Microsoft Intune documentation in intune/device-enrollment/android/setup-personal-work-profile.md.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
Added Microsoft Intune documentation in intune/whats-new/archive.md.
Updated Microsoft Intune documentation in intune/whats-new/index.md.
Updated Microsoft Intune documentation in intune/whats-new/index.md.
Removed Microsoft Intune documentation in intune/whats-new/archive/index.md.
Updated Microsoft Intune documentation in intune/governance/monitor-audit-logs.md.
Updated Microsoft Intune documentation in intune/configmgr/core/clients/manage/cmg/configure-authentication.md.