← Previous day

Next day →
Day in brief

Defender controlled configuration preview makes Intune authoritative for all applicable settings

Most of the 15 entries are documentation maintenance, but the most consequential Intune update documents Controlled Configuration for Microsoft Defender settings (preview). In the Windows Security experience Antivirus profile, the setting makes Intune—or Defender for Endpoint security settings management—the exclusive authority for configured Defender settings and applies secure defaults to unconfigured settings, addressing conflicts with Group Policy, Configuration Manager, third-party tools, and local scripts. The period also adds important Configuration Manager 2603 proxy guidance and expands the documented scope of the Properties Catalog and Windows Sync behavior. Controlled Configuration is explicitly marked preview; no supplied Message Center announcements, retirements, or general-availability notices change that status.

  • The antivirus policy guidance now documents Controlled Configuration for Microsoft Defender settings (preview) in the Windows Security experience profile, under Defender, as the Controlled Configuration (Device) setting. It locks all applicable settings to Intune-configured values, while unconfigured settings use secure platform defaults. The documented values are Not configured, Off (Default), Tamper Protection (On), and Controlled Configuration (On); the last gives Intune-delivered settings exclusive precedence.

  • The revised article changes the documented scope from hardware information to device properties. It describes collecting selected Windows registry key values, such as configuration settings, application state, and security-posture signals, alongside hardware details, configuration data, and application signals. The prerequisites now state that the feature supports Windows devices managed by Intune, co-managed with Configuration Manager, Microsoft Entra joined, or Microsoft Entra hybrid joined.

  • For Configuration Manager version 2603, Microsoft Entra token validation through MISE runs in the system (Local System) context using the .NET Framework HTTP stack. A management point using a proxy must therefore use the Local System account's WinINET settings. The updated guidance explicitly says that site-system proxy settings and a machine-wide WinHTTP proxy set with netsh winhttp set proxy are not used, and identifies ProxyEnable, ProxyServer, and optional ProxyOverride values or system-context Internet Options

  • The Sync article now describes Windows synchronization as covering compliance evaluation, configuration policy processing, app detection and deployment-state updates, script and remediation processing, and other device-management signals. Administrators can track progress through the Device sync status tab. The article explicitly limits this described behavior and tab to Windows devices, making this a documentation clarification rather than evidence of a new sync command.

  • The servicing page now explains that Intune uses Experimentation and Configuration Service (ECS) for service configurations, controlled feature rollouts, and experimentation data. It cautions that disabling required Microsoft cloud-service communication can affect critical service updates, reliability improvements, security mitigations, and feature enablement. The page also states that Intune currently uses controlled feature rollout rather than experimental testing, with a Message Center announcement if that later

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

15 updates

3

Overview

Updated

Updated Microsoft Intune documentation in intune/device-security/overview.md.

2

Azure Virtual Desktop

Updated

Updated Microsoft Intune documentation in intune/solutions/azure-virtual-desktop.md.

2

Servicing Information

Updated

Updated Microsoft Intune documentation in intune/fundamentals/servicing-information.md.

Endpoints China

Updated

Updated Microsoft Intune documentation in intune/fundamentals/endpoints-china.md.

1

Create Custom Role

Updated

Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/create-custom-role.md.

1

Sync

Updated

Updated Microsoft Intune documentation in intune/device-management/actions/sync.md.

1
3

Internet Endpoints

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/internet-endpoints.md.

Whats New In Version 2603

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/changes/whats-new-in-version-2603.md.

1

Proxy Server Support

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/proxy-server-support.md.

1

Plan

Updated

Updated Microsoft Intune documentation in intune/remote-help/plan.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…