What's new in Microsoft Intune
New featureThe documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.
The highest-impact material is a Remote Help guidance expansion: unattended remote sign-in is now described for corporate Windows devices, with planning, security, and deployment boundaries. A new Apple DDM App Settings page covers supervised iOS/iPadOS 27+ and macOS 27+, while the assignment-filter deprecation and Android eSIM instructions provide concrete migration and operating rules. Most other changes are lower-impact reference additions covering Android settings applicability, enrollment panes, and inventory schema.
The Windows guidance now covers initiating attended and unattended sessions from the Intune admin center. Remote sign-in lets an authorized helper troubleshoot a corporate Windows device with their own credentials without an end user present or signed in; unattended control is limited to Intune-enrolled Windows devices, and personal devices or devices missing prerequisites aren’t supported.
A new page documents Apple DDM App Settings configuration for supervised iOS/iPadOS 27+ and macOS 27+. Settings catalog controls include allowed or denied apps, binaries, and managed-app allowances. Existing iOS app-launch restrictions in the Restrictions profile must be migrated because those settings are deprecated in iOS 27.
The updated deployment guidance documents Windows unattended support and specifies a custom Intune role with required permissions, the Azure Virtual Desktop agent, and a bootloader as prerequisites. It directs administrators to deploy the agent before the bootloader and configure the bootloader to depend on the agent.
The assignment-filter reference now marks osVersion as deprecated. New filters can’t use it, existing filters continue to work, and operatingSystemVersion is the replacement.
Updated guidance covers activation and removal of eSIM plans on supported Android Enterprise corporate-owned devices. It specifies supported Android versions, a carrier activation code, an inventory-reported ICCID, and required permissions.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.
The archive now documents EPM support for AVD single-session VMs, a Lenovo Device Orchestration link, four protected apps, and additional Windows settings catalog policies for Edge, Chrome, Windows AI, Firewall, and other components.
The documentation now explains that eSIMs are preserved by default on specified Android Enterprise corporate-owned devices and can be removed during a single-device wipe using the new device view.
The page date changed from July 27 to August 21, 2026, and the section describing a planned Audit value for the Microsoft Defender Antivirus template for Linux was removed.
The article now documents additional Android settings, including work profile inactivity, eSIM removal during wipes, screen power behavior, and separate device and work profile locks, with supported enrollment types, platform versions, defaults, and value requirements.
The documentation now lists Accessibility appearance for iOS/iPadOS 17 and later and Liquid Glass for iOS/iPadOS 27 and later.
The macOS setup documentation now lists the Liquid Glass pane as skippable for macOS 27.0 and later.
The documentation adds activation and removal of eSIM plans on supported Android Enterprise corporate-owned devices, including supported Android versions, activation-code and ICCID requirements, device-view steps, and required permissions.
Intune now documents the Apple DDM App Settings configuration for supervised iOS/iPadOS 27+ and macOS 27+ devices, including allowed or denied apps, binaries, and managed-app allowances.
The device details documentation now covers ICCID, EID, phone number, carrier, activation state, and SIM origin for supported Android Enterprise corporate-owned devices, including Android version requirements.
The osVersion property is now documented as deprecated. New assignment filters can’t use it, while existing filters continue to work; operatingSystemVersion is the replacement.
The plan page now defines unattended sessions as authorized helper access without an active participant and documents support for Windows and Android. It adds guidance on dedicated Intune roles, Conditional Access, privacy, and limitations.
The documentation adds Windows unattended support, including required permissions, Azure Virtual Desktop agent and bootloader prerequisites, and Win32 deployment steps.
The troubleshooting guide now lists view-only, full-control, and unattended sessions in Remote Help records and clarifies session logging, Android device identifiers, and the configuration link.
The documentation now describes Remote Help remote sign-in, allowing an authorized helper to troubleshoot a corporate Windows device using their own credentials without an end user present or signed in. Unattended control supports only Intune-enrolled Windows devices.
The documentation now covers initiating attended and unattended Remote Help sessions from the Intune admin center, including connection steps, account types, local-resource access, and eligibility checks.
The schema documentation now lists Android Enterprise personally owned devices with a work profile as supported for Inventory and identifies Android support for several hardware fields. It also documents unsupported fields and the limited network fields available on these devices.