Firewall
UpdatedUpdated Microsoft Intune documentation in intune/device-configuration/endpoint-security/firewall.md.
The week’s substantive Intune update clarified Endpoint Security reporting: Firewall Rules and Attack Surface Reduction (ASR) Rules policies managed through MDM show policy-level status only, while per-setting status requires devices enrolled with Defender for Endpoint security settings management. The other update corrected procedure numbering in Monitor Device Profile. The supplied evidence indicates documentation clarification rather than a feature launch, preview, general-availability change, retirement, or product behavior change.
The Firewall documentation states that per-setting reporting is available for most Endpoint Security policies, but MDM-managed Firewall Rules and ASR Rules policies are limited to policy-level status. Per-setting status for those policies requires enrollment with Defender for Endpoint security settings management.
The reporting procedure now labels “Go back to Device and user check-in status and select View report” as step 6 instead of step 5, and the following policy-property information step as 7 instead of 6. This is a documentation procedure correction, not evidence of a functional change.
Set reporting expectations for MDM-managed Firewall Rules and ASR Rules policies: policy-level status does not include per-setting statuses. If per-setting status is required, devices must be enrolled with Defender for Endpoint security settings management. The Monitor Device Profile renumbering requires no tenant action.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/firewall.md.
Updated Microsoft Intune documentation in intune/device-configuration/monitor-device-profile.md.