Updated Microsoft Intune documentation in intune/fundamentals/filters/performance-recommendations.md.
Samsung Knox E-FOTA guidance highlights firmware campaigns, targeting performance, and EPM scope tags
This was a documentation-led period with two new Intune articles and 18 updates, but no Message Center notices or retirements. The most substantive additions document Samsung Knox E-FOTA integration prerequisites and capabilities, introduce a broader targeting-method framework, warn against inefficient dynamic-group rules, and record an Endpoint Privilege Management scope-tag limitation. Other changes mainly clarify navigation, external links, dates, and related content; the new Samsung article does not by itself establish a separate preview or general-availability announcement.
- Samsung Knox E-FOTA integration gets a new Intune setup article
Intune · Endpoint analytics
The new how-to documents an integration that, according to the article, can launch, manage, and monitor Samsung firmware campaigns from the Intune admin center; lock devices to an OS version or selected firmware; and schedule download and installation windows. It says deployments require a Samsung Knox E-FOTA license and at least Microsoft 365 E3, support Android Enterprise corporate-owned dedicated, fully managed, and COPE enrollment types, and require an Intune Administrator plus a Samsung Knox administrator for-
- A new guide separates group scope from Intune policy targeting
Intune · Device enrollment
The new targeting guide recommends starting with a broad audience and refining it with assignment filters, rather than creating many policy-specific groups. It distinguishes groups, which define the audience, from filters, which determine which devices in that audience receive a policy, and says group membership is processed when identity attributes change while filters evaluate at each device check-in. This is targeting guidance, not evidence of a new targeting behavior.
- Intune guidance says to avoid memberOf in dynamic group rules
Intune · Fundamentals
The performance guidance now explicitly says not to use the memberOf operator in dynamic group rules. It recommends direct comparisons such as -eq, -startsWith, and -in, explaining that transitive membership lookups can add significant processing complexity and, in large environments, lead to long evaluation times or unexpected results. Where possible, it suggests using a direct device property or an assignment filter instead.
- EPM scope tags remain unsupported by two documented roles
Endpoint Privilege Management · Windows
The known-issues page states that the built-in Endpoint Privilege Manager role and the custom Endpoint Privilege Management Policy Authoring role do not support scope tags. The documented workaround for restricting an administrator's view with scope tags is to grant permissions that include Read for Device configurations.
- Apple token procedures now use the Apple enrollment tab
Intune · Device enrollment
The token-management procedure replaces the Intune Apple mobile tab with the Apple tab. For renewal, it now directs administrators to Apple Business's Devices and Management Services areas, or Apple School Manager's Preferences and Your MDM servers areas, then to the relevant service or server and Download Token; in Apple Business, Download Token is under the top-right Actions menu. This is a procedural and terminology clarification rather than evidence of a product behavior change.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
20 updates
Microsoft Intune
19 updatesPlanning Guide
UpdatedUpdated Microsoft Intune documentation in intune/solutions/cloud-native-endpoints/planning-guide.md.
Overview
UpdatedUpdated Microsoft Intune documentation in intune/fundamentals/filters/overview.md.
Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/multi-admin-approval.md.
Planning Guide
UpdatedUpdated Microsoft Intune documentation in intune/fundamentals/planning-guide.md.
Blackberry
UpdatedUpdated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/blackberry.md.
Assign Groups
UpdatedUpdated Microsoft Intune documentation in intune/app-management/deployment/assign-groups.md.
Configure Company Portal
UpdatedUpdated Microsoft Intune documentation in intune/app-management/configuration/configure-company-portal.md.
Added Microsoft Intune documentation in intune/fundamentals/choose-targeting-method.md.
Manage Devices Tokens Apple
UpdatedUpdated Microsoft Intune documentation in intune/device-enrollment/apple/manage-devices-tokens-apple.md.
Updated Microsoft Intune documentation in intune/device-updates/android/setup-zebra-lifeguard.md.
Updated Microsoft Intune documentation in intune/device-updates/android/manage-fota.md.
Added Microsoft Intune documentation in intune/device-updates/android/setup-samsung-knox.md.
Scale Guidelines
UpdatedUpdated Microsoft Intune documentation in intune/fundamentals/scale-guidelines.md.
Add Groups
UpdatedUpdated Microsoft Intune documentation in intune/fundamentals/tenant-administration/add-groups.md.
Updated Microsoft Intune documentation in intune/device-configuration/assign-device-profile.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/setup-blackberry.md.
Grouping And Targeting
UpdatedUpdated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/grouping-and-targeting.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/tutorial-group-policy-migration.md.
Endpoint Privilege Management
1 updateTroubleshoot Known Issues
UpdatedUpdated Microsoft Intune documentation in intune/epm/troubleshoot-known-issues.md.