Cross-product topic

Device security

A cross-product view of Microsoft Intune changes related to Device security.

Latest Device security changes

Plan for Change: Intune migration for Windows Health Attestation to Microsoft Azure Attestation for Windows 11 devices

Message CenterMC1473156 on mc.merill.net ↗Plan for change
Device security

Intune will migrate Windows Health Attestation from Device Health Attestation to Microsoft Azure Attestation by early 2027. Organizations must ensure network access to Azure Attestation endpoints to maintain compliance evaluation for Windows 11 devices using health-based policies, or risk compliance failures.

About the BitLocker recovery service

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`; `ms.subservice` remains `protect`.

Antivirus exclusions

Device security

The page metadata now uses `core-infra` and `configuration-manager` instead of `core-infrastructure` and `microsoft-endpoint-configuration-manager`.

BitLocker event logs

Device security

The article’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

BitLocker self-service portal

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

BitLocker settings reference

Device security

The BitLocker settings documentation now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`.

Client event logs

Device security

The documentation now uses `configuration-manager` instead of `microsoft-endpoint-configuration-manager` for the `ms.service` metadata value.

Configure certificate infrastructure

Device security

The page’s ms.service value changed from microsoft-endpoint-configuration-manager to configuration-manager while retaining ms.subservice: protect.

Configure Endpoint Protection

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

Create certificate profiles

Device security

The page now uses `configuration-manager` instead of `microsoft-endpoint-configuration-manager` for its service metadata.

Create Wi-Fi profiles

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

Customize the self-service portal

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

Deploy BitLocker management

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

Encrypt recovery data in the database

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

Encrypt recovery data over the network

Device security

The page metadata now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`, while retaining `ms.subservice: protect`.

Endpoint Protection

Device security

The page metadata now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`.

Endpoint Protection Client Help

Device security

The page metadata now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`.

Microsoft Defender for Endpoint

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

Migrate from MBAM

Device security

The document’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`, paired with `ms.subservice: protect`.

Network infrastructure

Device security

The page metadata now uses `core-infra` and `configuration-manager` instead of `core-infrastructure` and `microsoft-endpoint-configuration-manager`.

Non-compliance codes

Device security

The documentation metadata now uses `configuration-manager` instead of `microsoft-endpoint-configuration-manager` for the service association.

Plan for BitLocker management

Device security

The page metadata now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`.

Protect data and site infrastructure

Device security

The page metadata now uses `configuration-manager` instead of `microsoft-endpoint-configuration-manager` for `ms.service`.

Server event logs

Device security

The page’s ms.service value changed from microsoft-endpoint-configuration-manager to configuration-manager while remaining paired with the protect subservice.

Set up BitLocker portals

Device security

The page’s service metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`, while the `protect` subservice remains paired with it.

Troubleshoot BitLocker

Device security

The page metadata now uses `ms.service: configuration-manager` instead of `microsoft-endpoint-configuration-manager`.

View BitLocker reports

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

VPN profiles in Configuration Manager

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

AllowThreat Method in Class SMS_ClientOperation

Device security

The documentation metadata changes the `ms.service` value from `microsoft-endpoint-configuration-manager` to `configuration-manager`, while retaining `ms.subservice: sdk`.

SMS_AmPolicySummary Server WMI Class

Device security

The documentation’s `ms.service` value changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`.

SMS_ClientAction Server WMI Class

Device security

The `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager` for the SDK subservice.

SMS_ClientOperation Server WMI Class

Device security

The page's `ms.service` value changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`, while retaining `ms.subservice: sdk`.

SMS_ClientOperationStatus Server WMI Class

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`, while retaining `ms.subservice: sdk`.

SMS_ConfigurationPolicy Server WMI Class

Device security

The page’s `ms.service` metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager`; the `sdk` subservice pairing remains.

SMS_FirewallPolicy Server WMI Class

Device security

The documentation metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager` for `ms.service`.

SMS_TopThreatPath Server WMI Class

Device security

The page’s ms.service metadata changed from microsoft-endpoint-configuration-manager to configuration-manager while retaining the SDK subservice.

SMS_TopThreatsDetected Server WMI Class

Device security

The documentation service metadata changed from `microsoft-endpoint-configuration-manager` to `configuration-manager` for the `SMS_TopThreatsDetected` WMI class reference.

Configure Baselines

Device security

The Configure baselines documentation now links to the Windows 365 for Agents security baseline settings reference.

Overview

Device security

The security baselines overview now links to the Windows 365 for Agents security baseline, including its Version 24H1 settings reference.

Monitor

Device security

The monitoring guidance now lists log collection status—completed, failed, or in progress—instead of an Incident ID. It also says Microsoft can use logs collected after reproducing an issue during verbose log collection for investigation.

Prerequisites

Device security

The prerequisites page no longer lists `powerlift-frontdesk.acompli.net` as a Diagnostic Endpoint.

Windows Antivirus policy settings for Microsoft Defender Antivirus for Intune

Device security

The documentation now explains that Yes disables and No enables catch-up scans because the settings are named “Disable catch-up...”. Full-scan catch-up is disabled when not configured, while quick-scan catch-up is enabled by default; the scan triggers after two missed scheduled scans are also specified.

Migrate from MBAM

Device security

The documentation now explains how to retrieve existing MBAM groups with PowerShell and map them to equivalent Configuration Manager BitLocker portal groups during migration.

Mam Android

Device security

The Microsoft Tunnel MAM for Android page updates links for MAM certificate trust APIs, including the MAMCertTrustWebViewClient reference link.

Firewall

Device security

Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/firewall.md.

Prerequisites

Device security

Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/prerequisites.md.

Upgrade

Device security

Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/upgrade.md.

Endpoint Security Policies

Device security

Updated Microsoft Intune documentation in intune/device-security/endpoint-security-policies.md.

Overview

Device security

Updated Microsoft Intune documentation in intune/device-security/overview.md.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…