The documentation now states that apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices can use Available assignments for either user or device groups, alongside the existing Win32 exception.
Intune guidance details Graph approval coverage and RHEL 9.8 Tunnel requirements
The 7 August updates are documentation-led, but several carry operational weight. Intune’s Multi Admin Approval guidance now explicitly covers delegated actions and app-authenticated Graph calls; Tunnel prerequisites detail a manual kernel-module step for RHEL 9.8; and Collect Diagnostics publishes region-specific upload URLs. Configuration Manager also updates its SQL dependency guidance, while macOS ADE documentation flags a PSSO conflict for userless devices.
- Multi Admin Approval guidance covers app-authenticated Graph calls
Intune · Fundamentals
The updated Intune guide documents MAA enforcement for delegated actions and app-authenticated Microsoft Graph API calls. Per-policy enterprise application exclusions apply only to app-auth calls, allow up to 50 applications, require second-admin approval, and are audited. Approver permissions and direct group membership are also clarified. Review service principals, scripts, third-party applications, and approver-group assignments against this documented scope.
- Tunnel prerequisites call out manual ip_tables loading on RHEL 9.8
Intune · Device security
The Microsoft Tunnel prerequisites now list RHEL 9.8 with Podman 5.8.2 or later as the default and explain that the ip_tables kernel module must be loaded manually before Tunnel installation. Administrators deploying Tunnel on RHEL 9.8 should complete that step before installation.
- Collect Diagnostics adds regional blob URLs and a tenant geo lookup
Intune · Troubleshooting
The Collect Diagnostics page now lists new blob storage URLs for each region and directs administrators to Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center. Review network allowlists and firewall rules and permit the applicable URLs so diagnostics uploads succeed.
- Configuration Manager guidance names SQL Server 2025 versions and missing MSIs
Configuration Manager · General
The version 2603 guidance now states that SQLSysClrTypes.msi and SharedManagementObjects.msi are no longer included in Configuration Manager media. It also documents the move from deprecated SQL Server 2014 versions to SQL Server 2025 versions, including SMO 17. Administrators relying on those files should review packaging and dependency validation.
- macOS ADE guidance flags PSSO conflicts on userless devices
Intune · Device enrollment
The automated macOS enrollment guidance warns against targeting userless ADE devices with profiles that enable PSSO registration during Setup Assistant. The combination can cause unexpected enrollment behavior and loss of expected device affinity. Review profile assignments for this configuration combination.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
32 updates
Microsoft Intune
22 updatesAssign Apps
Doc updateThe article now only directs administrators to the iOS app configuration policy guidance; the Sophos Intercept X for Mobile iOS reference link was removed.
Managed Apps Android
Doc updateThe Android managed apps documentation now describes the Azure Information Protection mobile apps without the Google Play link.
Blackberry
Doc updateThe BlackBerry Intune integration page no longer includes the link to BlackBerry UES documentation.
Ref Protected Apps
Doc updateThe protected apps reference no longer includes the Klaxoon for Intune listing.
Licensing
Doc updateThe licensing documentation now explains that eligible shared-device and no-user-affinity enrollment scenarios support device-targeted management through a device-only subscription. It also states that an unlicensed signed-in user doesn't prevent device-targeted policies, apps, or management actions from processing.
Setup Automated Macos
Doc updateAction requiredThe macOS ADE guidance warns not to target profiles that enable PSSO registration during Setup Assistant to userless ADE devices, because this can cause unexpected enrollment behavior and loss of expected device affinity.
Add Apps Unenrolled Devices
Doc updateThe guidance now links to the general Android and iOS store-app instructions without including direct CylancePROTECT Play Store or App Store URLs.
Index
Feature updateThe documentation now states that enrollment time grouping is available for iOS/iPadOS and macOS, along with the new Apple enrollment policies experience.
Mam Android
Doc updateThe Microsoft Tunnel MAM for Android page updates links for MAM certificate trust APIs, including the MAMCertTrustWebViewClient reference link.
The setup page removes the direct link to BlackBerry UES integration instructions and now tells administrators to sign in with Microsoft Entra and complete setup.
Prerequisites the Microsoft Tunnel VPN for Microsoft Intune
Feature updateAction requiredThe prerequisites now list RHEL 9.8 with Podman 5.8.2 or later as the default and explain that the ip_tables kernel module must be loaded manually before Tunnel installation.
Collect Device Properties
Doc updateThe documentation now notes that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information.
Government Service
Doc updateThe Remediations link now includes the `.md` file extension in its relative path.
Government Service
Doc updateThe government service page now includes Remediations with a value of “n/a” in its table.
Use Multi Admin Approval in Intune
Doc updateThe documentation now covers MAA enforcement for delegated actions and app-authenticated Microsoft Graph API calls, clarifies approver permissions and direct group membership, and documents per-policy enterprise application exclusions. Exclusions apply only to app-auth calls, allow up to 50 applications, require second-admin approval, and are audited.
The documentation now describes missing approval headers as returning HTTP 400, and pending approval as HTTP 412 with a Graph `BadRequest` code and `x-msft-approval-code` header. It also instructs callers to retain the original request details for resubmission.
Device Action: Sync
Feature updateThe sync documentation now says to turn on the “Preview new device view” toggle in the Intune admin center to see new device sync improvements. The “Compliance policy evaluation” item was also removed from the documented sync behavior.
Index
New featureThe documentation adds Windows settings catalog entries for Windows App, custom Microsoft Store package removal, disabling Get Started, several OneDrive behaviors, and the Disable Model Context Protocol Visual Studio policy.
Create Custom Role
Doc updateThe permissions table now lists Android Enterprise’s “Manage zero touch enrollment” permission for managing or changing the Google Zero-Touch Enrollment portal connection.
The PKCS profiles documentation now states that device configuration profiles containing PKCS certificate profiles aren't supported on Microsoft Teams devices running AOSP. The page date was also updated.
Collect Diagnostics
Feature updateAction requiredThe documentation now lists new blob storage URLs for each region and directs administrators to Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center.
Windows Autopilot
3 updatesThe page title capitalization was updated, and its description now states that administrators can gather hardware hashes and import, edit, and delete device records in the Intune admin center.
Add Devices
Doc updateThe three metadata tag lines on the Add devices page were reverted to their previous formatting.
Endpoints
Feature updateThe documented endpoint list changed from lgmsape*.blob.core.windows.net destinations to ams* lmsas.blob.core.windows.net destinations.
Microsoft Configuration Manager
7 updatesWhat's new in version 2603
Doc updateThe page date was updated, and the SQL Server note now states that SQLSysClrTypes.msi and SharedManagementObjects.msi are no longer included. It also documents the move from deprecated SQL Server 2014 versions to SQL Server 2025 versions (SMO 17).
Use The Service Connection Tool
Doc updateThe service connection tool example adds port 8080 to the proxy server URI and updates the heading accordingly.
Boundary Groups Software Update Points
Doc updateThe documentation now refers to the CMG SUP server instead of the CGM SUP server when describing boundary group configuration.
Manually register Microsoft Entra apps
Doc updateThe guide no longer instructs administrators to set `oauth2AllowIdTokenImplicitFlow` to `true` in the app manifest. The page date was also updated.
Whats New In Version 2603
Doc updateThe documentation now clarifies that SQL Server Management Objects and SQL Server CLR Types use SQL Server 2025 versions (SMO 17), and that the related MSI files are no longer included in Configuration Manager media.
Azure Virtual Desktop
Doc updateThe documentation now states that deployment must use an Azure subscription associated with the same Entra ID tenant as Intune.
Software Center User Guide
Doc updateThe title capitalization was standardized, and the description now highlights installing apps, software updates, and Windows upgrades, plus the required Software Center setting.