Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Configuration Manager guidance flags manual SQL collation checks before site database moves
Configuration Manager’s revised infrastructure guidance is the week’s highest-impact item: the Modify SQL Server configuration path doesn’t run the collation prerequisite check, so administrators must verify both the target instance and site database themselves before moving. Intune’s standout content change expands the documented custom-compliance workflow to macOS Bash discovery scripts, with a 10-minute maximum runtime and explicit format and exit-code rules. Most remaining updates are maintenance or clarification, including link corrections, support-matrix entries, and Software Center session wording. The supplied record contains no evidence of a new preview, GA release, launch, or retirement.
- Configuration Manager move guidance adds a manual SQL collation check
Configuration Manager · General
The updated Modify infrastructure article adds an IMPORTANT warning that the Modify SQL Server configuration maintenance path does not run the collation prerequisite check performed by a new install or upgrade. Both the target SQL Server instance and site database must use SQL_Latin1_General_CP1_CI_AS. A verification script must be run against the site database, CM_<sitecode>, rather than master, and every ERROR must be resolved before continuing. This is operational safety guidance, not a newly announced migration
- Intune custom-compliance guidance now documents macOS Bash constraints
Intune · Device security
The discovery-script article changes its documented scope from Linux and Windows to Linux, macOS, and Windows. macOS scripts use Bash, must run in 10 minutes or less, require a valid shebang such as #!/bin/bash, must be UTF-8 encoded without a BOM, and must return exit code 0 for success or a nonzero code for failure. The procedure adds an example that reads the Microsoft Intune Agent app version and directs administrators to set the logged-on credentials, signature-check, and hidden-notifications settings to Yes.
- Configuration Manager separates software-update scan forcing from WSUS connectivity
Configuration Manager · Compliance
The revised Software Updates Introduction treats forced versus non-forced and online versus offline as independent decisions. Non-forced scans reuse current cached results within the TTL; forced scans always run a new scan. Non-forced online scans contact WSUS only when the cache is outside the TTL, forced online scans always contact WSUS, and forced offline scans use local metadata without contacting WSUS. The page also clarifies that one scan evaluates the whole synchronized catalog, not an individual deployment.
- AllSigned task sequences should use packaged signed scripts
Configuration Manager · General
A new Configuration Manager note warns that Enter a PowerShell script may not preserve signed content byte-for-byte through task-sequence XML. The signature can become invalid, causing the client to reject the script and smsts.log to record a “hash does not match” error. Under AllSigned, the documented workaround is to place the signed .ps1 file in a Configuration Manager package and reference it with the Package and Script name options.
The revised action guidance states that Delete removes a device from Intune management and immediately hides it from the admin center; the Device actions report records the action as Completed. For MDM devices, Delete initiates Retire, but Completed means the server-side process is finished and does not confirm that the client device completed Retire.
Run the supplied SQL verification script against CM_<sitecode>, not master, and resolve every ERROR before using Modify SQL Server configuration; confirm that both the target SQL Server instance and site database use SQL_Latin1_General_CP1_CI_AS. For macOS custom compliance, use Bash scripts with a valid shebang, UTF-8 encoding without a BOM, a runtime of 10 minutes or less, and exit code 0 for success or nonzero for failure. When troubleshooting software-update scans, separate forced/cache behavior from online/WSUS and offline/local-metadata behavior. Under AllSigned, use a packaged signed .ps1 with the Package and Script name options rather than embedding the script. Treat MDM Delete status Completed as server-side completion only, not confirmation that the client finished Retire.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updates this week
Microsoft Intune
10 updatesUpdated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Overview
UpdatedUpdated Microsoft Intune documentation in intune/device-security/compliance/overview.md.
Create Policy
UpdatedUpdated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
Create Custom Json
UpdatedUpdated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.
Updated Microsoft Intune documentation in intune/device-management/actions/index.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/configure-managed-home-screen-permissions-android.md.
Multiple Managed Accounts
UpdatedUpdated Microsoft Intune documentation in intune/app-management/protection/multiple-managed-accounts.md.
Microsoft Intune Reports
UpdatedUpdated Microsoft Intune documentation in intune/device-management/reports/overview.md.
Device Action: Delete
UpdatedUpdated Microsoft Intune documentation in intune/device-management/actions/delete.md.
Microsoft Configuration Manager
6 updatesUpdated Microsoft Intune documentation in intune/configmgr/sum/understand/software-updates-introduction.md.
Modify infrastructure
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/core/servers/manage/modify-your-infrastructure.md.
Task Sequence Steps
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/osd/understand/task-sequence-steps.md.
Packages And Programs
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/apps/deploy-use/packages-and-programs.md.
Packages And Programs
UpdatedUpdated Microsoft Intune documentation in intune/configmgr/apps/deploy-use/packages-and-programs.md.
Updated Microsoft Intune documentation in intune/configmgr/sum/understand/software-updates-introduction.md.