What's new in Microsoft Intune
New featureThe documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.
This week’s meaningful changes are operational: Remote Help deployment guidance now specifies Windows unattended-support prerequisites; Apple DDM App Settings guidance covers supervised iOS/iPadOS 27+ and macOS 27+ devices; and Android eSIM guidance details activation, removal, permissions, and device eligibility. Intune also deprecated osVersion for new assignment filters, while Security Copilot documented an Intune licensing gate for its Vulnerability Remediation Agent. Other edits mainly refine enrollment, schema, monitoring, and reference pages, including removal of a planned Linux Defender Antivirus Audit entry from the in-development page.
The updated deployment guidance specifies required permissions, Azure Virtual Desktop agent and bootloader prerequisites, and Win32 deployment steps. To enable unattended control, create a custom Intune role with the required permission, deploy the agent before the bootloader, and make the bootloader depend on the agent.
The new Settings catalog guidance covers allowed or denied apps and binaries, along with managed-app allowances. Existing iOS app-launch restrictions in the Restrictions profile must be migrated because those settings are deprecated in iOS 27.
The updated workflow applies to supported corporate-owned Android Enterprise devices and documents supported Android versions, activation-code and inventory-reported ICCID requirements, device-view steps, and required permissions.
The osVersion property is now documented as deprecated. New assignment filters can’t use it, while existing filters continue to work. Use operatingSystemVersion when creating new filters; no immediate migration is required for current filters.
The agentic user must have an Intune license unless Allow admins without an Intune license is enabled under Tenant administration > Roles > Settings. Verify one of those conditions before relying on the agent.
Review Remote Help custom-role permissions, Azure Virtual Desktop agent and bootloader sequencing, and required session-host endpoints before enabling unattended access. Plan migration of iOS app-launch restrictions from the deprecated Restrictions profile settings in iOS 27. Use operatingSystemVersion for new assignment filters; existing osVersion filters continue to work. For Security Copilot, license the agentic user or enable Allow admins without an Intune license under Tenant administration > Roles > Settings. Android eSIM actions require supported corporate-owned Android Enterprise devices, required permissions, an activation code, and an inventory-reported ICCID.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.
The archive now documents EPM support for AVD single-session VMs, a Lenovo Device Orchestration link, four protected apps, and additional Windows settings catalog policies for Edge, Chrome, Windows AI, Firewall, and other components.
The documentation now explains that eSIMs are preserved by default on specified Android Enterprise corporate-owned devices and can be removed during a single-device wipe using the new device view.
The page date changed from July 27 to August 21, 2026, and the section describing a planned Audit value for the Microsoft Defender Antivirus template for Linux was removed.
The article now documents additional Android settings, including work profile inactivity, eSIM removal during wipes, screen power behavior, and separate device and work profile locks, with supported enrollment types, platform versions, defaults, and value requirements.
The documentation now lists Accessibility appearance for iOS/iPadOS 17 and later and Liquid Glass for iOS/iPadOS 27 and later.
The macOS setup documentation now lists the Liquid Glass pane as skippable for macOS 27.0 and later.
The osVersion property is now documented as deprecated. New assignment filters can’t use it, while existing filters continue to work; operatingSystemVersion is the replacement.
The documentation now distinguishes Android unattended control, which requires a dedicated Intune-enrolled device, and adds Windows unattended remote sign-in for targeted physical corporate-owned devices. Both permissions must be explicitly assigned and scoped.
The endpoints documentation now states that Remote Sign-in for Remote Help on Windows requires Azure Virtual Desktop session host endpoints.
The monitoring guidance now lists log collection status—completed, failed, or in progress—instead of an Incident ID. It also says Microsoft can use logs collected after reproducing an issue during verbose log collection for investigation.
The prerequisites page no longer lists `powerlift-frontdesk.acompli.net` as a Diagnostic Endpoint.
The documentation adds activation and removal of eSIM plans on supported Android Enterprise corporate-owned devices, including supported Android versions, activation-code and ICCID requirements, device-view steps, and required permissions.
Intune now documents the Apple DDM App Settings configuration for supervised iOS/iPadOS 27+ and macOS 27+ devices, including allowed or denied apps, binaries, and managed-app allowances.
The device details documentation now covers ICCID, EID, phone number, carrier, activation state, and SIM origin for supported Android Enterprise corporate-owned devices, including Android version requirements.
The plan page now defines unattended sessions as authorized helper access without an active participant and documents support for Windows and Android. It adds guidance on dedicated Intune roles, Conditional Access, privacy, and limitations.
The documentation adds Windows unattended support, including required permissions, Azure Virtual Desktop agent and bootloader prerequisites, and Win32 deployment steps.
The troubleshooting guide now lists view-only, full-control, and unattended sessions in Remote Help records and clarifies session logging, Android device identifiers, and the configuration link.
The documentation now describes Remote Help remote sign-in, allowing an authorized helper to troubleshoot a corporate Windows device using their own credentials without an end user present or signed in. Unattended control supports only Intune-enrolled Windows devices.
The documentation now covers initiating attended and unattended Remote Help sessions from the Intune admin center, including connection steps, account types, local-resource access, and eligibility checks.
The schema documentation now lists Android Enterprise personally owned devices with a work profile as supported for Inventory and identifies Android support for several hardware fields. It also documents unsupported fields and the limited network fields available on these devices.
The documentation now states that the agentic user must have an Intune license unless Allow admins without an Intune license is enabled under Tenant administration > Roles > Settings.