Configure Integration
UpdatedUpdated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-integration.md.
The week was mostly documentation maintenance: 129 of 132 changes were updates involving terminology, links, numbering, formatting, and procedure clarification. The notable administrator-facing exceptions were Windows Autopilot device preparation for Windows 365, the Security Copilot Vulnerability Remediation Agent permission model, and Intune’s Defender for Endpoint and Mobile Threat Defense setup guidance. The Autopilot articles remove “preview” and replace Windows 365 Frontline references with Windows 365 Flex. A new device-based Conditional Access how-to also makes its licensing, role, and compliance-policy prerequisites explicit. One standalone app-based Conditional Access how-to was removed, which the supplied evidence supports as documentation consolidation rather than retirement of the capability.
The Windows Autopilot device-preparation automatic-mode article removes “(preview)” from its title, description, headings, and public-preview note. It also replaces Windows 365 Frontline shared and dedicated references with Windows 365 Flex. This is a documentation status and terminology change; it does not establish general availability on its own.
Security Copilot guidance now describes an agentic-user permission model for running the Vulnerability Remediation Agent. Permissions are delegated outside the Intune admin center in Microsoft Entra and Microsoft Defender. On the Intune side, the guidance names Read Only Operator or a custom role with Mobile apps/read and Device configurations/read; users viewing results need corresponding read access.
The Mobile Threat Defense connector guidance documents an “Automatically launch Microsoft Defender for Endpoint during setup” toggle for Android Enterprise corporate-owned fully managed and corporate-owned work profile devices. It is available only for the Microsoft Defender for Endpoint connector and requires the “Grant MTD role permissions” toggle to be enabled as well.
Intune added a dedicated how-to requiring a Microsoft Entra ID P1 or P2 license and either the Security administrator or Conditional Access administrator role. The procedure also requires Intune device compliance policies to be configured before creating the Conditional Access policy. This is a new documentation path, not evidence of a newly introduced Conditional Access capability.
The revised custom-script guidance makes the limitation explicit: the upload workflow does not support scope tags. Administrators must have the default scope tag to create, edit, or view custom compliance discovery scripts.
Treat the Autopilot edit as a documentation and availability signal, not proof of general availability; confirm current Windows 365 and Autopilot availability before changing rollout plans. For the Vulnerability Remediation Agent, review the agentic user and delegated permissions assigned in Microsoft Entra and Microsoft Defender; the guidance lists Intune Read Only Operator or a custom role with Mobile apps/read and Device configurations/read. The agent remains documented as limited public preview and public-cloud only. If enabling the Defender for Endpoint automatic-launch toggle, also enable Grant MTD role permissions for Android Enterprise COBO and COPE devices. For device-based Conditional Access, confirm a Microsoft Entra ID P1 or P2 license, Security Administrator or Conditional
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-integration.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/enable-connector.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/overview.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/enable-connector.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/remediate-vulnerabilities.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-integration.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-integration.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/enable-connector.md.
Updated Microsoft Intune documentation in intune/device-security/endpoint-security-policies.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/overview.md.
Updated Microsoft Intune documentation in intune/device-security/laps/setup-macos.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/scenarios.md.
Updated Microsoft Intune documentation in intune/device-security/laps/setup-macos.md.
Updated Microsoft Intune documentation in intune/device-security/security-baselines/ref-defender-settings.md.
Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/antivirus.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-wsl.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/quickstart-noncompliance-notification.md.
Updated Microsoft Intune documentation in intune/device-security/security-baselines/ref-defender-settings.md.
Added Microsoft Intune documentation in intune/device-security/conditional-access-integration/device-based-policies.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/scenarios.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/overview.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/scenarios.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/create-app-based-policy.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/third-party-partners.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/monitor-policy.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/overview.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-windows-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-enterprise-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-macos-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-ios-ipados-settings.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/manage-exchange-access.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/app-based-policies.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-wsl.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/overview.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-administrator-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-administrator-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-aosp-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-enterprise-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-enterprise-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-linux-settings.md.
Removed Microsoft Intune documentation in intune/device-security/conditional-access-integration/create-app-based-policy.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/device-based-policies.md.
Changes Android support wording to “later,” corrects “device is reported,” and clarifies Google Mobile Services unavailable regions fail Play Protect evaluation.
Changes the Microsoft Tunnel release entry from May 1 version 20260407.1 to May 7 version 20260507.2.
Corrects the most secure MTD compliance threat level from Secured to Clear; devices with any threats remain noncompliant.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/enable-connector.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/overview.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/setup-jamf-manually.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment.md.
Refines Company Portal app bundle ID guidance for configuring Platform SSO during enrollment.
Updates the publication date metadata for setup-automated-macos.
Corrects reporting prose and renumbers the compliance-reporting option step; the Noncompliant devices report remains under Devices > Monitor.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-macos.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/configure-wired-networks.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-wired-network-settings-macos.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-device-restrictions-apple.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-device-restrictions-apple.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/common-tasks.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-macos.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/configure-bios-windows.md.
Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/ref-endpoint-protection-settings-windows.md.
Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/multi-admin-approval.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-universal-print.md.
Adds a Cupra device to the Android Open Source Project supported-devices list.
Updated Microsoft Intune documentation in intune/fundamentals/aosp-supported-devices.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/ref-android-settings.md.
Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/deploy-edr.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-universal-print.md.
Changes Universal Print troubleshooting tracing reference from Print-Collect to TSS.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/app-based-policies.md.
Adds Known issues explaining direct Android Enterprise LOB apps install correctly while only Intune admin-center install-status reporting is affected.
Updated Microsoft Intune documentation in intune/fundamentals/zero-trust.md.
Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/multi-admin-approval.md.
Updated Microsoft Intune documentation in intune/whats-new/archive/index.md.
The automatic-workflow article removes its preview tag, indicating the documented device-preparation scenario is no longer labeled preview.
The whats-new article removes its preview tag, indicating the documented device-preparation scenario is no longer labeled preview.
The automatic-device-group article removes its preview tag, indicating the documented device-preparation scenario is no longer labeled preview.
The automatic-monitor article removes its preview tag, indicating the documented device-preparation scenario is no longer labeled preview.
The scenarios article removes its preview tag, indicating the documented device-preparation scenario is no longer labeled preview.
Updated Microsoft Intune documentation in autopilot/device-preparation/tutorial/automatic/automatic-autopilot-policy.md.
Updated Microsoft Intune documentation in autopilot/device-preparation/tutorial/automatic/automatic-cloud-pc-provisioning-policy.md.
Updated Microsoft Intune documentation in autopilot/device-preparation/tutorial/automatic/automatic-automatic-enrollment.md.
Updated Microsoft Intune documentation in autopilot/device-preparation/tutorial/automatic/automatic-assign-apps-scripts.md.
Updated Microsoft Intune documentation in autopilot/device-preparation/overview.md.
Updated Microsoft Intune documentation in autopilot/device-preparation/overview.md.
Adds GA for automatic-mode device-preparation policies that provision Cloud PCs at creation; Windows 365 Reserve remains preview.
Adds GA for automatic-mode device-preparation policies that provision Cloud PCs at creation; Windows 365 Reserve remains preview.
Adds that device-preparation deployment records created after feature introduction are automatically removed after 28 days; older Windows 365 records need one-time manual removal.
Updated Microsoft Intune documentation in autopilot/device-preparation/whats-new.md.
Added Microsoft Intune documentation in intune/configmgr/core/servers/deploy/configure/example-management-point-deployment.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/core/understand/how-to-read-lazy-properties-by-using-managed-code.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/core/understand/how-to-read-a-configuration-manager-object-by-using-managed-code.md.
Updated Microsoft Intune documentation in intune/configmgr/tenant-attach/atp-onboard.md.
Updated Microsoft Intune documentation in intune/configmgr/tenant-attach/atp-onboard.md.
Updates the Configuration Manager ODBC redistributable version requirement.
Updated Microsoft Intune documentation in intune/configmgr/core/misc/pre-release-construction.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/36949461.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2603/37426535.md.
Updated Microsoft Intune documentation in intune/configmgr/develop/core/understand/about-configuration-manager-schedules.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-windows-adk.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-windows-10.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-windows-11.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-windows-10.md.
Updates the SQL Server Always On guidance for the Basic availability groups requirement.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-windows-10.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-windows-adk.md.
Updated Microsoft Intune documentation in intune/configmgr/tenant-attach/atp-onboard.md.
Updated Microsoft Intune documentation in intune/configmgr/protect/deploy-use/troubleshoot-endpoint-client.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/36949461.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/manage/cmpivot-tsg.md.
Updated Microsoft Intune documentation in intune/copilot/agents/vulnerability-remediation-agent.md.
Updated Microsoft Intune documentation in intune/copilot/agents/manage-vulnerability-remediation-agent.md.
Updated Microsoft Intune documentation in intune/copilot/agents/manage-vulnerability-remediation-agent.md.
Flags images in the vulnerability-remediation-agent guidance for product-manager review or update.
Flags images in the vulnerability-remediation-agent guidance for product-manager review or update.
Updated Microsoft Intune documentation in intune/copilot/agents/vulnerability-remediation-agent.md.
Flags images in the manage-vulnerability-remediation-agent guidance for product-manager review or update.
Flags images in the manage-vulnerability-remediation-agent guidance for product-manager review or update.