Week in brief

Controlled Defender configuration preview locks devices to Intune-delivered security settings

The week of 27 July was update-heavy—35 items were updated, one was new, and none were removed—but several changes have direct administrator relevance. Intune introduced preview documentation for controlled Defender configuration, while service release 2607 lists Samsung Knox E-FOTA and new Windows and Edge catalog settings. The Windows Sync page specifies expanded Windows processing, and Configuration Manager guidance changes the proxy context for MISE token validation. Configuration Manager’s new SQL Server page and related cross-reference edits are primarily guidance clarification. The supplied evidence does not label any of these feature entries generally available.

  • The **Controlled Configuration (Device)** setting is documented under the **Windows Security experience** profile for Antivirus policy. Its values are **Not configured**, **Off (Default)**, **Tamper Protection (On)**, and **Controlled Configuration (On)**. The new mode makes Intune-delivered Defender settings take exclusive precedence over other management channels; settings not configured in Intune use secure defaults. **Tamper Protection (On)** retains the existing secure-default behavior.

  • The July 27 service-release entry says Intune now integrates Samsung Knox E-FOTA for Android Enterprise corporate-owned dedicated (COSU), fully managed (COBO), and corporate-owned with work profile (COPE) devices. Admins can select firmware versions, deploy without user interaction, and schedule downloads and installations. The same entry adds Windows Settings catalog options for camera behavior, Keyboard Filter controls for Windows Insider devices, and WSL, plus Edge 149 templates (version 149.0.4022.21) with new,

  • The updated Sync page states that selecting **Sync** on Windows initiates on-demand processing across compliance evaluation, configuration policies, app detection and deployment state, scripts and remediations, and other device-management signals. Administrators can track progress in the **Device sync status** tab in the device overview. The page explicitly says this behavior and tab apply only to Windows.

  • For version 2603, Microsoft Entra token validation on the management point runs in the **Local System** context through the .NET Framework HTTP stack. A site-system proxy or machine-wide WinHTTP proxy set with `netsh winhttp set proxy` is not used. Configure the proxy in the Local System account’s WinINET settings, including `ProxyEnable` and `ProxyServer` under `HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings`, or configure Internet Options in the system context.

  • The KB 38232642 page now explicitly says its security update for importing console extensions resolves **CVE-2026-47301**. This is updated security guidance identifying the affected vulnerability; the supplied evidence does not provide a deployment deadline or indicate a new Intune capability.

For Intune administrators

Treat Controlled Configuration as a preview and note that **Off (Default)** leaves the capability disabled; review existing Group Policy, Configuration Manager, third-party, and local-script conflicts before a scoped test. For service release 2607, verify that devices use one of the listed corporate-owned Android Enterprise modes before evaluating E-FOTA, and use the documented Settings catalog path for the new Windows controls. On Windows, the expanded Sync flow and **Device sync status** tab can support troubleshooting, but the page limits this behavior to Windows. Configuration Manager 2603 management points using a proxy require Local System WinINET settings, not site-system or WinHTTP proxy settings. Also review KB 38232642 for CVE-2026-47301 and the Message Center recommendation for

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

5

Upgrade

Updated

Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/upgrade.md.

30 July 2026

Prerequisites

Updated

Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/prerequisites.md.

30 July 2026

Endpoint Security Policies

Updated

Updated Microsoft Intune documentation in intune/device-security/endpoint-security-policies.md.

27 July 2026

Overview

Updated

Updated Microsoft Intune documentation in intune/device-security/overview.md.

27 July 2026
4

Sync

Updated

Updated Microsoft Intune documentation in intune/device-management/actions/sync.md.

27 July 2026
2

Azure Virtual Desktop

Updated

Updated Microsoft Intune documentation in intune/solutions/azure-virtual-desktop.md.

27 July 2026
2

Servicing Information

Updated

Updated Microsoft Intune documentation in intune/fundamentals/servicing-information.md.

27 July 2026

Endpoints China

Updated

Updated Microsoft Intune documentation in intune/fundamentals/endpoints-china.md.

27 July 2026
2
1

Create Custom Role

Updated

Updated Microsoft Intune documentation in intune/fundamentals/role-based-access-control/create-custom-role.md.

27 July 2026
17

Supported SQL Server versions

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/support-for-sql-server-versions.md.

29 July 2026

Supported Configurations

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/configs/supported-configurations.md.

29 July 2026

37864969

Updated

Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/37864969.md.

29 July 2026

38232642

Updated

Updated Microsoft Intune documentation in intune/configmgr/hotfix/2603/38232642.md.

29 July 2026

International Support

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/hierarchy/international-support.md.

29 July 2026

List Of Prerequisite Checks

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/servers/deploy/install/list-of-prerequisite-checks.md.

29 July 2026

Modify Your Infrastructure

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/servers/manage/modify-your-infrastructure.md.

29 July 2026

Plan For The Site Database

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/hierarchy/plan-for-the-site-database.md.

29 July 2026

Prepare To Install Sites

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/servers/deploy/install/prepare-to-install-sites.md.

29 July 2026

37864969

Updated

Updated Microsoft Intune documentation in intune/configmgr/hotfix/2509/37864969.md.

28 July 2026

38232642

Updated

Updated Microsoft Intune documentation in intune/configmgr/hotfix/2603/38232642.md.

28 July 2026

Internet Endpoints

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/internet-endpoints.md.

27 July 2026

Use The Service Connection Tool

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/servers/manage/use-the-service-connection-tool.md.

27 July 2026

Whats New In Version 2603

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/changes/whats-new-in-version-2603.md.

27 July 2026
1
1

Azure Virtual Desktop

Updated

Updated Microsoft Intune documentation in intune/solutions/azure-virtual-desktop.md.

30 July 2026
1

Proxy Server Support

Updated

Updated Microsoft Intune documentation in intune/configmgr/core/plan-design/network/proxy-server-support.md.

27 July 2026
1

Plan

Updated

Updated Microsoft Intune documentation in intune/remote-help/plan.md.

27 July 2026
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Email signup will appear here once the Kit form is configured. Until then, use the daily RSS feed.