← Previous day

Next day →
Day in brief

VPP token reuse can erase available assignments, Intune guidance warns

The period is dominated by documentation consolidation, but several updates have direct operational value. Apple guidance now warns about losing available app assignments when an existing VPP token is re-uploaded for DDM, and clarifies that app configuration policies support MDM-managed apps only. New Intune guidance also documents device renaming, editable device properties, and inventory collection timing. Most other edits correct URLs or reflect the current device-overview action paths, such as Remove data > Retire and Secure > Rotate FileVault recovery key.

  • The Manage VPP for Apple guidance says re-uploading an existing VPP token for DDM causes available app assignments to be lost. It recommends creating a new Apple Business token for DDM, while using MDM for available assignments and apps that require app configuration policies. Administrators should not re-upload tokens that already have available assignments.

  • The managed iOS guidance now states that app configuration policies support only MDM-managed apps and cannot configure DDM apps. The setup procedure was also renumbered, so DDM apps requiring this configuration path need a different management approach.

  • The new rename-device article covers renaming managed devices from the Intune admin center, supported platforms, platform-specific naming rules, and bulk-renaming variables. It explicitly documents that hybrid-joined Windows devices aren't supported, which should be accounted for when standardizing inventory names.

  • A new article explains how to edit a managed device's name, ownership, primary user, notes, and scope tags from the Properties tab. Scope-tag changes affect device visibility for delegated administrators, while the primary-user workflow is now documented alongside the other editable properties.

  • The Collect device properties guidance now says active devices collect inventory multiple times per day, while initial collection can take up to 24 hours because full synchronization runs once daily. Administrators should allow that window before treating missing initial inventory as a problem.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

58 updates

34

Index

Doc update

The index now links to the device management overview, uses updated titles for device categories and primary-user tasks, and removes links for endpoint security device management, admin tasks, and encryption status details.

Retire

Doc update

The instructions now direct administrators to select **Remove data** > **Retire** from the device overview action icons, instead of selecting **Retire** directly.

View device details - Microsoft Intune | Microsoft Learn

Doc update

The article now explains how to open a device’s Device details tab, distinguishes read-only inventory from editable Properties, and documents hardware and software inventory refreshing every seven days from enrollment.

Locate

Doc update

The instructions specify selecting **Locate device** on Windows and **Locate** > **Locate device** on iOS and Android. Location details remain available from the map pin.

Play Lost Mode Sound

Doc update

The instructions now direct administrators to select Locate before choosing either Play Lost Mode sound or Play lost device sound.

Archive

Doc update

The archive page now links to the Admin tasks content under Governance instead of Device management.

Autopilot Reset

Doc update

The device overview instructions now direct administrators to select Remove data, then Autopilot reset.

Disable Activation Lock

Doc update

The instructions now say to select **Secure** before choosing **Disable Activation Lock** in the device overview action menu.

Fresh Start

Doc update

The instructions now direct administrators to select **Remove data** before selecting **Fresh Start** in the device overview pane.

Full Scan

Doc update

The documented steps changed from selecting **Full scan** directly to selecting **Microsoft Defender** > **Run full malware scan**.

Index

Doc update

The Intune What’s new page was updated, including a new metadata date, and the entry describing bulk eSIM actions for corporate-owned Android Enterprise devices was removed.

Logout User

Doc update

The instructions now direct administrators to select **Remote actions** before choosing **Logout current user** from the device overview pane.

Lost Mode

Doc update

The instructions now direct administrators to select **Locate** and then **Lost mode (supervised only)** from the device overview action icons.

Pause Config Refresh

Doc update

The documented steps now direct administrators to select Remote actions > Pause Config Refresh from the device overview pane.

Quick Scan

Doc update

The instructions now direct administrators to select Microsoft Defender > Run quick malware scan from the device overview action icons.

Remote Lock

Doc update

The instructions now direct administrators to select **Secure** > **Remote lock** from the device overview action icons.

Remove Passcode

Doc update

The instructions now direct administrators to select **Secure** and then **Remove passcode** from the device overview action icons.

Reset Passcode

Doc update

The instructions now direct administrators to select **Secure** > **Reset passcode** from the device overview action icons.

Restart

Doc update

The restart procedure now instructs administrators to select **Remote actions** > **Restart** > **Yes** from the device overview pane.

Restore Managed Home Screen

Doc update

The instructions now direct administrators to select Remote actions > Restore Managed Home Screen from the device overview pane.

Rotate Bitlocker Keys

Doc update

The instructions now direct administrators to select **Secure** > **BitLocker key rotation** from the device overview action icons.

Rotate Filevault Recovery Key

Doc update

The action is now accessed through **Secure** > **Rotate FileVault recovery key** in the device overview pane.

Rotate Local Admin Password

Doc update

The device overview instructions now direct admins to select **Secure** before choosing **Rotate Local admin password**.

Rotate Recovery Lock Passcode

Doc update

The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode from the device overview action icons.

Shutdown

Doc update

The documented path changed from selecting Shut down directly to selecting Remote actions > Shut down > Yes.

Suspend Managed Home Screen

Doc update

The instructions now direct administrators to select **Remote actions** before choosing **Suspend Managed Home Screen**.

Wipe

Doc update

The documented steps now direct administrators to select Remove data > Wipe from the device overview action icons.

Rename

Doc update

The page documenting the Rename device action, including supported platforms, role requirements, and admin-center steps, was deleted.

4

Platform Guide Ios Ipados

Doc update

The iOS/iPadOS platform guide now links to the endpoint security devices page at a new URL; the link description is unchanged.

Platform Guide Macos

Doc update

The macOS platform guide now links to the endpoint security devices page at its updated documentation path.

Encrypt Filevault Macos

Doc update

The article now points to the encryption report and instructs admins to select Secure > Rotate FileVault recovery key from the device overview, then confirm with Yes.

Configure Recovery Lock Macos

Doc update

The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode, choose Yes, and note that Intune generates a new passcode.

4

Overview

Doc update

The page now uses simpler wording for device actions and updates the Intune security policies link path.

Ref Zero Trust Devices

Doc update

Two references to “Monitor device encryption with Intune” now point to /intune/device-configuration/endpoint-security/monitor-encryption instead of /intune/device-management/monitor-encryption.

Endpoint Security Policies

Doc update

The endpoint security policies page now uses an updated link to the guidance for managing devices with endpoint security in Intune.

Remediate Vulnerabilities

Doc update

The documentation now links to the Admin tasks pane under the governance path instead of the device-management path.

3

Help Desk Operators

Doc update

The “Managed by” documentation now links to the endpoint security devices location for details by management type.

Collect Diagnostics

Doc update

The procedure now instructs administrators to select **Collect data** instead of **Yes** to confirm the action.

Multi Admin Approval

Doc update

The multi-admin approval documentation now links to the centralized Admin tasks pane under the governance path instead of the device management path.

2

Configure Managed Ios

Feature update

The guide now states that app configuration policies support only MDM-managed apps and cannot configure DDM apps. The setup steps were also renumbered.

Manage Vpp Apple

Doc updateAction required

The documentation now warns that re-uploading an existing VPP token for DDM causes available app assignments to be lost. It recommends creating a new Apple Business token for DDM and using MDM for available assignments and apps requiring app configuration policies.

2

Collect Device Properties

Doc update

The documentation now states that active devices collect inventory multiple times per day, while initial collection can take up to 24 hours because full synchronization runs once daily.

Disk Encryption

Doc update

The Disk encryption documentation now uses the relative link `monitor-encryption` instead of `../../device-management/monitor-encryption`.

2

Run Remediation

Doc update

The documented action and pane names changed from “Run remediation (preview)” to “Run remediation.”

Index

Doc update

The device management actions index updates its Rename entries to link to the bulk-rename-devices section of the device inventory and status documentation.

2

Platform Guide Windows

Doc update

The Windows platform guide now links to the endpoint security devices page at a new documentation path; the link description is unchanged.

Encrypt Bitlocker Windows

Doc update

The BitLocker documentation now uses updated links for the encryption report and Monitor disk encryption, and clarifies that recovery keys can be viewed and managed from the encryption report.

1

Platform Guide Android

Doc update

The Android platform guide now links to the endpoint security devices article at its updated documentation path.

1

Setup Teamviewer

Doc update

The documented navigation now directs administrators to select a device and choose **Remote actions** > **Begin a remote assistance session**.

1
1
1

Manage Support Approvals

Doc update

The documentation now links to the centralized Admin tasks pane under the governance path instead of the device-management path.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…