← Previous day

Next day →
Day in brief

Intune guidance details Graph approval coverage and RHEL 9.8 Tunnel requirements

The 7 August updates are documentation-led, but several carry operational weight. Intune’s Multi Admin Approval guidance now explicitly covers delegated actions and app-authenticated Graph calls; Tunnel prerequisites detail a manual kernel-module step for RHEL 9.8; and Collect Diagnostics publishes region-specific upload URLs. Configuration Manager also updates its SQL dependency guidance, while macOS ADE documentation flags a PSSO conflict for userless devices.

  • The updated Intune guide documents MAA enforcement for delegated actions and app-authenticated Microsoft Graph API calls. Per-policy enterprise application exclusions apply only to app-auth calls, allow up to 50 applications, require second-admin approval, and are audited. Approver permissions and direct group membership are also clarified. Review service principals, scripts, third-party applications, and approver-group assignments against this documented scope.

  • The Microsoft Tunnel prerequisites now list RHEL 9.8 with Podman 5.8.2 or later as the default and explain that the ip_tables kernel module must be loaded manually before Tunnel installation. Administrators deploying Tunnel on RHEL 9.8 should complete that step before installation.

  • The Collect Diagnostics page now lists new blob storage URLs for each region and directs administrators to Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center. Review network allowlists and firewall rules and permit the applicable URLs so diagnostics uploads succeed.

  • The version 2603 guidance now states that SQLSysClrTypes.msi and SharedManagementObjects.msi are no longer included in Configuration Manager media. It also documents the move from deprecated SQL Server 2014 versions to SQL Server 2025 versions, including SMO 17. Administrators relying on those files should review packaging and dependency validation.

  • The automated macOS enrollment guidance warns against targeting userless ADE devices with profiles that enable PSSO registration during Setup Assistant. The combination can cause unexpected enrollment behavior and loss of expected device affinity. Review profile assignments for this configuration combination.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

32 updates

5

Assign Apps to Groups in Microsoft Intune

Doc update

The documentation now states that apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices can use Available assignments for either user or device groups, alongside the existing Win32 exception.

Assign Apps

Doc update

The article now only directs administrators to the iOS app configuration policy guidance; the Sophos Intercept X for Mobile iOS reference link was removed.

Managed Apps Android

Doc update

The Android managed apps documentation now describes the Azure Information Protection mobile apps without the Google Play link.

Blackberry

Doc update

The BlackBerry Intune integration page no longer includes the link to BlackBerry UES documentation.

Ref Protected Apps

Doc update

The protected apps reference no longer includes the Klaxoon for Intune listing.

4

Licensing

Doc update

The licensing documentation now explains that eligible shared-device and no-user-affinity enrollment scenarios support device-targeted management through a device-only subscription. It also states that an unlicensed signed-in user doesn't prevent device-targeted policies, apps, or management actions from processing.

Setup Automated Macos

Doc updateAction required

The macOS ADE guidance warns not to target profiles that enable PSSO registration during Setup Assistant to userless ADE devices, because this can cause unexpected enrollment behavior and loss of expected device affinity.

Add Apps Unenrolled Devices

Doc update

The guidance now links to the general Android and iOS store-app instructions without including direct CylancePROTECT Play Store or App Store URLs.

Index

Feature update

The documentation now states that enrollment time grouping is available for iOS/iPadOS and macOS, along with the new Apple enrollment policies experience.

3

Mam Android

Doc update

The Microsoft Tunnel MAM for Android page updates links for MAM certificate trust APIs, including the MAMCertTrustWebViewClient reference link.

3

Collect Device Properties

Doc update

The documentation now notes that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information.

Government Service

Doc update

The Remediations link now includes the `.md` file extension in its relative path.

Government Service

Doc update

The government service page now includes Remediations with a value of “n/a” in its table.

2

Use Multi Admin Approval in Intune

Doc update

The documentation now covers MAA enforcement for delegated actions and app-authenticated Microsoft Graph API calls, clarifies approver permissions and direct group membership, and documents per-policy enterprise application exclusions. Exclusions apply only to app-auth calls, allow up to 50 applications, require second-admin approval, and are audited.

Use Multi Admin Approval with the Microsoft Graph API

Doc update

The documentation now describes missing approval headers as returning HTTP 400, and pending approval as HTTP 412 with a Graph `BadRequest` code and `x-msft-approval-code` header. It also instructs callers to retain the original request details for resubmission.

2

Device Action: Sync

Feature update

The sync documentation now says to turn on the “Preview new device view” toggle in the Intune admin center to see new device sync improvements. The “Compliance policy evaluation” item was also removed from the documented sync behavior.

Index

New feature

The documentation adds Windows settings catalog entries for Windows App, custom Microsoft Store package removal, disabling Get Started, several OneDrive behaviors, and the Disable Model Context Protocol Visual Studio policy.

1

Create Custom Role

Doc update

The permissions table now lists Android Enterprise’s “Manage zero touch enrollment” permission for managing or changing the Google Zero-Touch Enrollment portal connection.

1
1

Collect Diagnostics

Feature updateAction required

The documentation now lists new blob storage URLs for each region and directs administrators to Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center.

2

Manually Register Devices with Windows Autopilot

Doc update

The page title capitalization was updated, and its description now states that administrators can gather hardware hashes and import, edit, and delete device records in the Intune admin center.

Add Devices

Doc update

The three metadata tag lines on the Add devices page were reverted to their previous formatting.

1

Endpoints

Feature update

The documented endpoint list changed from lgmsape*.blob.core.windows.net destinations to ams* lmsas.blob.core.windows.net destinations.

5

What's new in version 2603

Doc update

The page date was updated, and the SQL Server note now states that SQLSysClrTypes.msi and SharedManagementObjects.msi are no longer included. It also documents the move from deprecated SQL Server 2014 versions to SQL Server 2025 versions (SMO 17).

Manually register Microsoft Entra apps

Doc update

The guide no longer instructs administrators to set `oauth2AllowIdTokenImplicitFlow` to `true` in the app manifest. The page date was also updated.

Whats New In Version 2603

Doc update

The documentation now clarifies that SQL Server Management Objects and SQL Server CLR Types use SQL Server 2025 versions (SMO 17), and that the related MSI files are no longer included in Configuration Manager media.

1

Azure Virtual Desktop

Doc update

The documentation now states that deployment must use an Azure subscription associated with the same Entra ID tenant as Intune.

1

Software Center User Guide

Doc update

The title capitalization was standardized, and the description now highlights installing apps, software updates, and Windows upgrades, plus the required Software Center setting.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…