Upgrade
UpdatedUpdated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/upgrade.md.
The week of 27 July was update-heavy—35 items were updated, one was new, and none were removed—but several changes have direct administrator relevance. Intune introduced preview documentation for controlled Defender configuration, while service release 2607 lists Samsung Knox E-FOTA and new Windows and Edge catalog settings. The Windows Sync page specifies expanded Windows processing, and Configuration Manager guidance changes the proxy context for MISE token validation. Configuration Manager’s new SQL Server page and related cross-reference edits are primarily guidance clarification. The supplied evidence does not label any of these feature entries generally available.
The **Controlled Configuration (Device)** setting is documented under the **Windows Security experience** profile for Antivirus policy. Its values are **Not configured**, **Off (Default)**, **Tamper Protection (On)**, and **Controlled Configuration (On)**. The new mode makes Intune-delivered Defender settings take exclusive precedence over other management channels; settings not configured in Intune use secure defaults. **Tamper Protection (On)** retains the existing secure-default behavior.
The July 27 service-release entry says Intune now integrates Samsung Knox E-FOTA for Android Enterprise corporate-owned dedicated (COSU), fully managed (COBO), and corporate-owned with work profile (COPE) devices. Admins can select firmware versions, deploy without user interaction, and schedule downloads and installations. The same entry adds Windows Settings catalog options for camera behavior, Keyboard Filter controls for Windows Insider devices, and WSL, plus Edge 149 templates (version 149.0.4022.21) with new,
The updated Sync page states that selecting **Sync** on Windows initiates on-demand processing across compliance evaluation, configuration policies, app detection and deployment state, scripts and remediations, and other device-management signals. Administrators can track progress in the **Device sync status** tab in the device overview. The page explicitly says this behavior and tab apply only to Windows.
For version 2603, Microsoft Entra token validation on the management point runs in the **Local System** context through the .NET Framework HTTP stack. A site-system proxy or machine-wide WinHTTP proxy set with `netsh winhttp set proxy` is not used. Configure the proxy in the Local System account’s WinINET settings, including `ProxyEnable` and `ProxyServer` under `HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings`, or configure Internet Options in the system context.
The KB 38232642 page now explicitly says its security update for importing console extensions resolves **CVE-2026-47301**. This is updated security guidance identifying the affected vulnerability; the supplied evidence does not provide a deployment deadline or indicate a new Intune capability.
Treat Controlled Configuration as a preview and note that **Off (Default)** leaves the capability disabled; review existing Group Policy, Configuration Manager, third-party, and local-script conflicts before a scoped test. For service release 2607, verify that devices use one of the listed corporate-owned Android Enterprise modes before evaluating E-FOTA, and use the documented Settings catalog path for the new Windows controls. On Windows, the expanded Sync flow and **Device sync status** tab can support troubleshooting, but the page limits this behavior to Windows. Configuration Manager 2603 management points using a proxy require Local System WinINET settings, not site-system or WinHTTP proxy settings. Also review KB 38232642 for CVE-2026-47301 and the Message Center recommendation for
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/upgrade.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/prerequisites.md.
Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/antivirus.md.
Updated Microsoft Intune documentation in intune/device-security/endpoint-security-policies.md.
Updated Microsoft Intune documentation in intune/device-security/overview.md.
Updated Microsoft Intune documentation in intune/whats-new/index.md.
Updated Microsoft Intune documentation in intune/whats-new/archive.md.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
Updated Microsoft Intune documentation in intune/device-management/actions/sync.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/security-settings-management.md.
Updated Microsoft Intune documentation in intune/solutions/azure-virtual-desktop.md.
Updated Microsoft Intune documentation in intune/fundamentals/servicing-information.md.
Updated Microsoft Intune documentation in intune/fundamentals/endpoints-china.md.
The message recommends installing the Windows cumulative update KB5101684 Preview to fully remediate the issue from IT1431577. This update provides a client fix and platform improvements. Organizations should deploy this update following their usual update and validation procedures.
Updated Microsoft Intune documentation in intune/device-configuration/collect-device-properties.md.
Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/create-custom-role.md.
Added Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/supported-configurations-for-sql-server.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-sql-server-versions.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/supported-configurations.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/37864969.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2603/38232642.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/deploy/configure/boundary-groups-software-update-points.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/deploy/configure/database-replicas-for-management-points.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/hierarchy/international-support.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/deploy/install/list-of-prerequisite-checks.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/manage/modify-your-infrastructure.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/hierarchy/plan-for-the-site-database.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/deploy/install/prepare-to-install-sites.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/37864969.md.
Updated Microsoft Intune documentation in intune/configmgr/hotfix/2603/38232642.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/internet-endpoints.md.
Updated Microsoft Intune documentation in intune/configmgr/core/servers/manage/use-the-service-connection-tool.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/changes/whats-new-in-version-2603.md.
Updated Microsoft Intune documentation in intune/configmgr/core/understand/supported-configurations-for-ltsb.md.
Updated Microsoft Intune documentation in intune/solutions/azure-virtual-desktop.md.
Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/proxy-server-support.md.
Updated Microsoft Intune documentation in intune/remote-help/plan.md.