Product

Microsoft Intune

Track documentation and Message Center changes for Microsoft Intune.

Microsoft Learn documentation ↗

Latest Microsoft Intune changes

Plan for Change: Intune migration for Windows Health Attestation to Microsoft Azure Attestation for Windows 11 devices

Message CenterMC1473156 on mc.merill.net ↗Plan for change
Device security

Intune will migrate Windows Health Attestation from Device Health Attestation to Microsoft Azure Attestation by early 2027. Organizations must ensure network access to Azure Attestation endpoints to maintain compliance evaluation for Windows 11 devices using health-based policies, or risk compliance failures.

Endpoints China

Fundamentals

The China endpoints documentation now lists `https://graph.chinacloudapi.cn` instead of `https://graph.chinacloudapi.us`.

Planning Guide

General

The planning guide now links to `integrate-windows-update-client-policies.md` instead of the previous `integrate-windows-update-for-business-windows-10.md` article.

Deploy Remediations

Troubleshooting

The page now recommends limiting script assignments, avoiding resource-intensive or frequent schedules, and using stable, actionable detection-script results to reduce device performance impact.

In development - Microsoft Intune

General

The page adds upcoming features including MHS authentication for protected app activities, declarative VPP downloads, deployment plans, Defender launch during Android setup, bulk eSIM actions, new Apple settings, and Quick Machine Recovery policies. It also documents future macOS and iOS/iPadOS support changes and the September 2609 single-device page default.

Ref Settings Ios

App management

The iOS app protection settings reference updated the Screen capture entry, documenting that Block prevents capture of work or school data, while Allow is the default and permits capture and sharing without restrictions.

Servicing Information

Compliance

The servicing information page changed the callout from Caution to Important; its message about impacts to updates, reliability, security mitigations, and feature enablement remains the same.

Configure Baselines

Device security

The Configure baselines documentation now links to the Windows 365 for Agents security baseline settings reference.

Endpoints

Fundamentals

The Intune client and host service endpoint entry now includes 150.171.109.0/24 and 150.171.110.0/24.

Manage Vpp Apple

App management

The VPP token settings now include a Management type option: MDM (default) or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later, and supports only Required or Uninstall assignments.

Overview

Device security

The security baselines overview now links to the Windows 365 for Agents security baseline, including its Version 24H1 settings reference.

Ref Protected Apps

App management

The reference now includes Ben for Intune, Calven, Heijmans, Notability, Notion, SDP - On Premises | Intune, and Superhuman Mail, with descriptions and app links.

Setup Personal Work Profile

Device enrollment

The documentation now lists Chrome, Edge, and Samsung browser as supported for web-based enrollment. The note about phone-call MFA potentially breaking enrollment and its workaround was removed.

What's new in Microsoft Intune

General

The page now states that the listed eSIM features are rolling out and might not yet be available to all tenants. The page date and authoring metadata were also updated.

Android settings catalog in Microsoft Intune

Device enrollment

The article now documents additional Android settings, including work profile inactivity, eSIM removal during wipes, screen power behavior, and separate device and work profile locks, with supported enrollment types, platform versions, defaults, and value requirements.

In development - Microsoft Intune

General

The page date changed from July 27 to August 21, 2026, and the section describing a planned Audit value for the Microsoft Defender Antivirus template for Linux was removed.

Manage eSIM plans in Microsoft Intune

Android

The documentation adds activation and removal of eSIM plans on supported Android Enterprise corporate-owned devices, including supported Android versions, activation-code and ICCID requirements, device-view steps, and required permissions.

Setup Automated Ios

Device enrollment

The documentation now lists Accessibility appearance for iOS/iPadOS 17 and later and Liquid Glass for iOS/iPadOS 27 and later.

Setup Automated Macos

Device enrollment

The macOS setup documentation now lists the Liquid Glass pane as skippable for macOS 27.0 and later.

View device details with Microsoft Intune

Compliance

The device details documentation now covers ICCID, EID, phone number, carrier, activation state, and SIM origin for supported Android Enterprise corporate-owned devices, including Android version requirements.

What's new in Microsoft Intune

General

The documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.

What's new in previous months in the Microsoft Intune

General

The archive now documents EPM support for AVD single-session VMs, a Lenovo Device Orchestration link, four protected apps, and additional Windows settings catalog policies for Edge, Chrome, Windows AI, Firewall, and other components.

Wipe devices with Microsoft Intune

General

The documentation now explains that eSIMs are preserved by default on specified Android Enterprise corporate-owned devices and can be removed during a single-device wipe using the new device view.

Create a custom role in Intune

Fundamentals

The documentation now distinguishes Android unattended control, which requires a dedicated Intune-enrolled device, and adds Windows unattended remote sign-in for targeted physical corporate-owned devices. Both permissions must be explicitly assigned and scoped.

Monitor

Device security

The monitoring guidance now lists log collection status—completed, failed, or in progress—instead of an Incident ID. It also says Microsoft can use logs collected after reproducing an issue during verbose log collection for investigation.

Network endpoints for Microsoft Intune

Fundamentals

The endpoints documentation now states that Remote Sign-in for Remote Help on Windows requires Azure Virtual Desktop session host endpoints.

Prerequisites

Device security

The prerequisites page no longer lists `powerlift-frontdesk.acompli.net` as a Diagnostic Endpoint.

Windows Antivirus policy settings for Microsoft Defender Antivirus for Intune

Device security

The documentation now explains that Yes disables and No enables catch-up scans because the settings are named “Disable catch-up...”. Full-scan catch-up is disabled when not configured, while quick-scan catch-up is enabled by default; the scan triggers after two missed scheduled scans are also specified.

Device Action: Delete

General

The documentation now states that a tenant can submit up to 1,000 Delete actions per day, cumulatively across individual actions, bulk actions, and Microsoft Graph requests. The limit also applies when Delete triggers Retire or Wipe.

Device Action: Retire

General

The documentation now states that a tenant can submit up to 1,000 Retire actions per day, cumulative across individual, bulk, and Microsoft Graph API requests.

Device Action: Wipe

General

The documentation now states that individual, bulk, and Microsoft Graph Wipe requests share a cumulative tenant-wide daily limit of 500 actions.

Device Actions - Wipe, Lock, Locate, and More

Android

The documentation now lists tenant-wide daily limits of 500 Wipe actions and 1,000 each for Retire and Delete. Counts are cumulative across individual, bulk, and Microsoft Graph submissions.

Android Management Api Overview

Device enrollment

The documentation now directs administrators to the “Personal Devices on Android Management API” report under Devices > Monitor and clarifies that reporting is not shown in the policy’s device assignment status or the device configuration tab.

Management Extension Windows

Windows

The documentation now states that Sync from Windows Settings or the Intune admin center initiates both MDM and IME check-ins, including policy, app, script, and remediation processing. Sync progress can be viewed in the Device sync status tab.

Sync

General

The sync documentation now explains that selecting Sync triggers multiple workloads, including policy processing, app state updates, and scripts/remediations. Admins can monitor progress in the Device sync status tab. This behavior applies to iOS/iPadOS and Windows devices.

Sync

Fundamentals

The sync behavior and Device sync status tab are documented as applying to Windows and iOS/iPadOS devices, rather than Windows only. The Preview new device view toggle remains required to see the described improvements.

Plan for Change: Intune moving to support iOS/iPadOS 18 and higher later this year

Message CenterMC1454371 on mc.merill.net ↗Major updatePlan for change
App management

Microsoft Intune will require iOS/iPadOS 18 or higher after Apple releases iOS/iPadOS 27 later this year. Organizations should check device compatibility and Intune reports to identify affected devices. Userless devices via Automated Device Enrollment have specific OS version requirements. Use Intune controls to manage OS versions.

Collect Device Properties

Device configuration

The documentation for collecting device properties now states that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information. It identifies this as an accepted risk and calls for reviewing security and privacy implications.

Add Apps Unenrolled Devices

Device enrollment

The guidance now links to the general Android and iOS store-app instructions without including direct CylancePROTECT Play Store or App Store URLs.

Assign Apps

App management

The article now only directs administrators to the iOS app configuration policy guidance; the Sophos Intercept X for Mobile iOS reference link was removed.

Assign Apps to Groups in Microsoft Intune

App management

The documentation now states that apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices can use Available assignments for either user or device groups, alongside the existing Win32 exception.

Blackberry

App management

The BlackBerry Intune integration page no longer includes the link to BlackBerry UES documentation.

Collect Device Properties

Windows

The documentation now notes that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information.

Collect Diagnostics

Troubleshooting

The documentation now lists new blob storage URLs for each region and directs administrators to Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center.

Create Custom Role

Android

The permissions table now lists Android Enterprise’s “Manage zero touch enrollment” permission for managing or changing the Google Zero-Touch Enrollment portal connection.

Device Action: Sync

General

The sync documentation now says to turn on the “Preview new device view” toggle in the Intune admin center to see new device sync improvements. The “Compliance policy evaluation” item was also removed from the documented sync behavior.

Government Service

Windows

The Remediations link now includes the `.md` file extension in its relative path.

Government Service

Windows

The government service page now includes Remediations with a value of “n/a” in its table.

Index

Device enrollment

The documentation now states that enrollment time grouping is available for iOS/iPadOS and macOS, along with the new Apple enrollment policies experience.

Index

General

The documentation adds Windows settings catalog entries for Windows App, custom Microsoft Store package removal, disabling Get Started, several OneDrive behaviors, and the Disable Model Context Protocol Visual Studio policy.

Licensing

Device enrollment

The licensing documentation now explains that eligible shared-device and no-user-affinity enrollment scenarios support device-targeted management through a device-only subscription. It also states that an unlicensed signed-in user doesn't prevent device-targeted policies, apps, or management actions from processing.

Mam Android

Device security

The Microsoft Tunnel MAM for Android page updates links for MAM certificate trust APIs, including the MAMCertTrustWebViewClient reference link.

Managed Apps Android

App management

The Android managed apps documentation now describes the Azure Information Protection mobile apps without the Google Play link.

Ref Protected Apps

App management

The protected apps reference no longer includes the Klaxoon for Intune listing.

Setup Automated Macos

Device enrollment

The macOS ADE guidance warns not to target profiles that enable PSSO registration during Setup Assistant to userless ADE devices, because this can cause unexpected enrollment behavior and loss of expected device affinity.

Use Multi Admin Approval in Intune

Fundamentals

The documentation now covers MAA enforcement for delegated actions and app-authenticated Microsoft Graph API calls, clarifies approver permissions and direct group membership, and documents per-policy enterprise application exclusions. Exclusions apply only to app-auth calls, allow up to 50 applications, require second-admin approval, and are audited.

Use Multi Admin Approval with the Microsoft Graph API

Fundamentals

The documentation now describes missing approval headers as returning HTTP 400, and pending approval as HTTP 412 with a Graph `BadRequest` code and `x-msft-approval-code` header. It also instructs callers to retain the original request details for resubmission.

Firewall

Device security

Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/firewall.md.

Monitor Device Profile

Endpoint analytics

Updated Microsoft Intune documentation in intune/device-configuration/monitor-device-profile.md.

Prerequisites

Device security

Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/prerequisites.md.

Upgrade

Device security

Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/upgrade.md.

Azure Virtual Desktop

Device enrollment

Updated Microsoft Intune documentation in intune/solutions/azure-virtual-desktop.md.

Create Custom Role

Android

Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/create-custom-role.md.

Endpoint Security Policies

Device security

Updated Microsoft Intune documentation in intune/device-security/endpoint-security-policies.md.

Endpoints China

Fundamentals

Updated Microsoft Intune documentation in intune/fundamentals/endpoints-china.md.

Overview

Device security

Updated Microsoft Intune documentation in intune/device-security/overview.md.

Servicing Information

Fundamentals

Updated Microsoft Intune documentation in intune/fundamentals/servicing-information.md.

Sync

General

Updated Microsoft Intune documentation in intune/device-management/actions/sync.md.

Add Groups

Compliance

Updated Microsoft Intune documentation in intune/fundamentals/tenant-administration/add-groups.md.

Assign Groups

App management

Updated Microsoft Intune documentation in intune/app-management/deployment/assign-groups.md.

Blackberry

App management

Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/blackberry.md.

Configure Company Portal

App management

Updated Microsoft Intune documentation in intune/app-management/configuration/configure-company-portal.md.

Grouping And Targeting

General

Updated Microsoft Intune documentation in intune/solutions/education/tutorial-school-deployment/grouping-and-targeting.md.

Manage Devices Tokens Apple

Device enrollment

Updated Microsoft Intune documentation in intune/device-enrollment/apple/manage-devices-tokens-apple.md.

Overview

Fundamentals

Updated Microsoft Intune documentation in intune/fundamentals/filters/overview.md.

Planning Guide

Fundamentals

Updated Microsoft Intune documentation in intune/fundamentals/planning-guide.md.

Planning Guide

Fundamentals

Updated Microsoft Intune documentation in intune/solutions/cloud-native-endpoints/planning-guide.md.

Scale Guidelines

Endpoint analytics

Updated Microsoft Intune documentation in intune/fundamentals/scale-guidelines.md.

Endpoints China

Fundamentals

Updated Microsoft Intune documentation in intune/fundamentals/endpoints-china.md.

Index

General

Updated Microsoft Intune documentation in intune/whats-new/index.md.

Ref Macos Settings

Device security

Updated Microsoft Intune documentation in intune/device-security/compliance/ref-macos-settings.md.

Setup Automated Tv Os

Device enrollment

Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-tv-os.md.

Setup Automated Vision Os

Device enrollment

Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-vision-os.md.

Android Phase 4

Device enrollment

Updated Microsoft Intune documentation in intune/developer/app-sdk/android-phase-4.md.

Android Phase 7

Android

Updated Microsoft Intune documentation in intune/developer/app-sdk/android-phase-7.md.

Endpoints Us Government

Fundamentals

Updated Microsoft Intune documentation in intune/fundamentals/endpoints-us-government.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…