Week in brief

Per-setting firewall and ASR reporting requires Defender security settings management

The week of 3 August 2026 was quiet in release terms: all 34 recorded items were documentation updates, with no new, removed, or Message Center entries. Most edits were wording, links, examples, or navigation, but several clarified consequential reporting limits, enrollment risks, data sensitivity, API handling, and infrastructure prerequisites. The evidence supports documentation clarification and operational guidance—not a new Intune launch, general-availability announcement, or retirement.

  • The Firewall page adds an IMPORTANT note that per-setting reporting is available for most Endpoint Security policies, but Firewall Rules and Attack Surface Reduction (ASR) Rules policies managed through MDM provide only policy-level status and no per-setting reporting statuses. Viewing per-setting status requires devices to be enrolled with Defender for Endpoint security settings management. This is a reporting-scope clarification, so align monitoring expectations accordingly.

  • The Automated Device Enrollment guidance warns against targeting userless ADE devices with PSSO configuration profiles that enable PSSO registration during Setup Assistant. Doing so can cause unexpected enrollment behavior and loss of expected device affinity. Review assignments and exclude userless ADE devices from these profiles.

  • Collect Device Properties now states that collected registry key data is accessible through existing Device Inventory permissions and may expose sensitive device configuration information. Review the security and privacy implications of those permissions and the registry data being collected; the update does not describe a new permission model.

  • The Microsoft Graph guidance now specifies HTTP 400 when approval headers are missing. A pending approval returns HTTP 412 (Precondition Failed), a Microsoft Graph BadRequest code, and an x-msft-approval-code header. Integrations should preserve the original method, URL, and request body so the request can be resubmitted after approval.

  • The prerequisites page now lists Red Hat Enterprise Linux 9.8 with Podman 5.8.2 or later as the default and notes that RHEL 9.8 does not automatically load the ip_tables kernel module. Administrators installing Microsoft Tunnel on RHEL 9.8 should manually load ip_tables before installation.

For Intune administrators

Prioritize review of MDM Firewall Rules and ASR reporting expectations, registry inventory access, userless macOS ADE profile assignments, Multi Admin Approval integrations, and Microsoft Tunnel installation prerequisites. Apply administrator action only where the updated guidance states a concrete requirement; the supplied records do not establish broader product availability changes.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

5

Assign Apps to Groups in Microsoft Intune

Doc update

The documentation now states that apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices can use Available assignments for either user or device groups, alongside the existing Win32 exception.

7 August 2026

Assign Apps

Doc update

The article now only directs administrators to the iOS app configuration policy guidance; the Sophos Intercept X for Mobile iOS reference link was removed.

7 August 2026

Managed Apps Android

Doc update

The Android managed apps documentation now describes the Azure Information Protection mobile apps without the Google Play link.

7 August 2026

Blackberry

Doc update

The BlackBerry Intune integration page no longer includes the link to BlackBerry UES documentation.

7 August 2026

Ref Protected Apps

Doc update

The protected apps reference no longer includes the Klaxoon for Intune listing.

7 August 2026
4

Licensing

Doc update

The licensing documentation now explains that eligible shared-device and no-user-affinity enrollment scenarios support device-targeted management through a device-only subscription. It also states that an unlicensed signed-in user doesn't prevent device-targeted policies, apps, or management actions from processing.

7 August 2026

Setup Automated Macos

Doc updateAction required

The macOS ADE guidance warns not to target profiles that enable PSSO registration during Setup Assistant to userless ADE devices, because this can cause unexpected enrollment behavior and loss of expected device affinity.

7 August 2026

Add Apps Unenrolled Devices

Doc update

The guidance now links to the general Android and iOS store-app instructions without including direct CylancePROTECT Play Store or App Store URLs.

7 August 2026

Index

Feature update

The documentation now states that enrollment time grouping is available for iOS/iPadOS and macOS, along with the new Apple enrollment policies experience.

7 August 2026
4

Mam Android

Doc update

The Microsoft Tunnel MAM for Android page updates links for MAM certificate trust APIs, including the MAMCertTrustWebViewClient reference link.

7 August 2026

Firewall

Updated

Updated Microsoft Intune documentation in intune/device-configuration/endpoint-security/firewall.md.

6 August 2026
3

Collect Device Properties

Doc update

The documentation now notes that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information.

7 August 2026

Government Service

Doc update

The Remediations link now includes the `.md` file extension in its relative path.

7 August 2026

Government Service

Doc update

The government service page now includes Remediations with a value of “n/a” in its table.

7 August 2026
2

Use Multi Admin Approval in Intune

Doc update

The documentation now covers MAA enforcement for delegated actions and app-authenticated Microsoft Graph API calls, clarifies approver permissions and direct group membership, and documents per-policy enterprise application exclusions. Exclusions apply only to app-auth calls, allow up to 50 applications, require second-admin approval, and are audited.

7 August 2026

Use Multi Admin Approval with the Microsoft Graph API

Doc update

The documentation now describes missing approval headers as returning HTTP 400, and pending approval as HTTP 412 with a Graph `BadRequest` code and `x-msft-approval-code` header. It also instructs callers to retain the original request details for resubmission.

7 August 2026
2

Device Action: Sync

Feature update

The sync documentation now says to turn on the “Preview new device view” toggle in the Intune admin center to see new device sync improvements. The “Compliance policy evaluation” item was also removed from the documented sync behavior.

7 August 2026

Index

New feature

The documentation adds Windows settings catalog entries for Windows App, custom Microsoft Store package removal, disabling Get Started, several OneDrive behaviors, and the Disable Model Context Protocol Visual Studio policy.

7 August 2026
1

Create Custom Role

Doc update

The permissions table now lists Android Enterprise’s “Manage zero touch enrollment” permission for managing or changing the Google Zero-Touch Enrollment portal connection.

7 August 2026
1
1

Monitor Device Profile

Updated

Updated Microsoft Intune documentation in intune/device-configuration/monitor-device-profile.md.

6 August 2026
1

Collect Diagnostics

Feature updateAction required

The documentation now lists new blob storage URLs for each region and directs administrators to Tenant Status in endpoint.microsoft.com to identify their tenant’s geo and data center.

7 August 2026
2

Manually Register Devices with Windows Autopilot

Doc update

The page title capitalization was updated, and its description now states that administrators can gather hardware hashes and import, edit, and delete device records in the Intune admin center.

7 August 2026

Add Devices

Doc update

The three metadata tag lines on the Add devices page were reverted to their previous formatting.

7 August 2026
1

Endpoints

Feature update

The documented endpoint list changed from lgmsape*.blob.core.windows.net destinations to ams* lmsas.blob.core.windows.net destinations.

7 August 2026
5

What's new in version 2603

Doc update

The page date was updated, and the SQL Server note now states that SQLSysClrTypes.msi and SharedManagementObjects.msi are no longer included. It also documents the move from deprecated SQL Server 2014 versions to SQL Server 2025 versions (SMO 17).

7 August 2026

Use The Service Connection Tool

Doc update

The service connection tool example adds port 8080 to the proxy server URI and updates the heading accordingly.

7 August 2026

Manually register Microsoft Entra apps

Doc update

The guide no longer instructs administrators to set `oauth2AllowIdTokenImplicitFlow` to `true` in the app manifest. The page date was also updated.

7 August 2026

Whats New In Version 2603

Doc update

The documentation now clarifies that SQL Server Management Objects and SQL Server CLR Types use SQL Server 2025 versions (SMO 17), and that the related MSI files are no longer included in Configuration Manager media.

7 August 2026
1

Azure Virtual Desktop

Doc update

The documentation now states that deployment must use an Azure subscription associated with the same Entra ID tenant as Intune.

7 August 2026
1

Software Center User Guide

Doc update

The title capitalization was standardized, and the description now highlights installing apps, software updates, and Windows upgrades, plus the required Software Center setting.

7 August 2026
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…