← Previous week
Week in brief

Configuration Manager 2609 raises upgrade prerequisites while Intune guidance flags Apple VPP assignment loss

The strongest changes this week are upgrade-readiness and retirement guidance rather than a broad Intune feature rollout. Configuration Manager 2609 gets concrete ODBC and SQL prerequisites, Asset Intelligence removals, and a version-specific SQLCLR security-setting change. Intune’s most consequential Apple updates warn about VPP/DDM assignment loss and require a specific automated iOS enrollment value; other edits largely clarify existing administration paths and support boundaries.

For Intune administrators

For Configuration Manager 2609 planning, validate ODBC Driver 18.6.2.1 or later and SQL Server 2017 CU2 or later, review Asset Intelligence dependencies, and apply the version-specific TRUSTWORTHY guidance. For Intune Apple administration, do not re-upload VPP tokens that carry available assignments; create a separate token for DDM, and set Run Company Portal in Single App Mode until authentication to No in applicable enrollment policies.

This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.

Updates this week

35

In Development

New feature

The page now lists Apple OS 27 DDM inventory data, MEFERI OEMConfig support for Android Enterprise, removal of legacy Apple MDM software-update workloads, and two Administrator protection settings for Windows 11 24H2 and 25H2.

1 October 2026

Index

Doc update

The index now links to the device management overview, uses updated titles for device categories and primary-user tasks, and removes links for endpoint security device management, admin tasks, and encryption status details.

29 September 2026

Retire

Doc update

The instructions now direct administrators to select **Remove data** > **Retire** from the device overview action icons, instead of selecting **Retire** directly.

29 September 2026

View device details - Microsoft Intune | Microsoft Learn

Doc update

The article now explains how to open a device’s Device details tab, distinguishes read-only inventory from editable Properties, and documents hardware and software inventory refreshing every seven days from enrollment.

29 September 2026

Locate

Doc update

The instructions specify selecting **Locate device** on Windows and **Locate** > **Locate device** on iOS and Android. Location details remain available from the map pin.

29 September 2026

Play Lost Mode Sound

Doc update

The instructions now direct administrators to select Locate before choosing either Play Lost Mode sound or Play lost device sound.

29 September 2026

Archive

Doc update

The archive page now links to the Admin tasks content under Governance instead of Device management.

29 September 2026

Autopilot Reset

Doc update

The device overview instructions now direct administrators to select Remove data, then Autopilot reset.

29 September 2026

Disable Activation Lock

Doc update

The instructions now say to select **Secure** before choosing **Disable Activation Lock** in the device overview action menu.

29 September 2026

Fresh Start

Doc update

The instructions now direct administrators to select **Remove data** before selecting **Fresh Start** in the device overview pane.

29 September 2026

Full Scan

Doc update

The documented steps changed from selecting **Full scan** directly to selecting **Microsoft Defender** > **Run full malware scan**.

29 September 2026

Index

Doc update

The Intune What’s new page was updated, including a new metadata date, and the entry describing bulk eSIM actions for corporate-owned Android Enterprise devices was removed.

29 September 2026

Logout User

Doc update

The instructions now direct administrators to select **Remote actions** before choosing **Logout current user** from the device overview pane.

29 September 2026

Lost Mode

Doc update

The instructions now direct administrators to select **Locate** and then **Lost mode (supervised only)** from the device overview action icons.

29 September 2026

Pause Config Refresh

Doc update

The documented steps now direct administrators to select Remote actions > Pause Config Refresh from the device overview pane.

29 September 2026

Quick Scan

Doc update

The instructions now direct administrators to select Microsoft Defender > Run quick malware scan from the device overview action icons.

29 September 2026

Remote Lock

Doc update

The instructions now direct administrators to select **Secure** > **Remote lock** from the device overview action icons.

29 September 2026

Remove Passcode

Doc update

The instructions now direct administrators to select **Secure** and then **Remove passcode** from the device overview action icons.

29 September 2026

Reset Passcode

Doc update

The instructions now direct administrators to select **Secure** > **Reset passcode** from the device overview action icons.

29 September 2026

Restart

Doc update

The restart procedure now instructs administrators to select **Remote actions** > **Restart** > **Yes** from the device overview pane.

29 September 2026

Restore Managed Home Screen

Doc update

The instructions now direct administrators to select Remote actions > Restore Managed Home Screen from the device overview pane.

29 September 2026

Rotate Bitlocker Keys

Doc update

The instructions now direct administrators to select **Secure** > **BitLocker key rotation** from the device overview action icons.

29 September 2026

Rotate Filevault Recovery Key

Doc update

The action is now accessed through **Secure** > **Rotate FileVault recovery key** in the device overview pane.

29 September 2026

Rotate Local Admin Password

Doc update

The device overview instructions now direct admins to select **Secure** before choosing **Rotate Local admin password**.

29 September 2026

Rotate Recovery Lock Passcode

Doc update

The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode from the device overview action icons.

29 September 2026

Shutdown

Doc update

The documented path changed from selecting Shut down directly to selecting Remote actions > Shut down > Yes.

29 September 2026

Suspend Managed Home Screen

Doc update

The instructions now direct administrators to select **Remote actions** before choosing **Suspend Managed Home Screen**.

29 September 2026

Wipe

Doc update

The documented steps now direct administrators to select Remove data > Wipe from the device overview action icons.

29 September 2026

Rename

Doc update

The page documenting the Rename device action, including supported platforms, role requirements, and admin-center steps, was deleted.

29 September 2026
5

Configure Managed Home Screen

Doc update

The app-exclusion setting description now spells out “Managed Home Screen” instead of using the abbreviation “MHS” when referring to authentication.

30 September 2026

Add Managed Google Play

Feature update

During onboarding, the Intune, Microsoft Authenticator, and Company Portal apps are installed as required apps on dedicated devices, in addition to fully managed and corporate-owned work profile devices.

30 September 2026

Add Unmanaged Pkg Macos

Feature update

The documentation now states that failed macOS app installations are retried at the next agent check-in, with up to three retries while the app remains assigned.

30 September 2026

Configure Managed Ios

Feature update

The guide now states that app configuration policies support only MDM-managed apps and cannot configure DDM apps. The setup steps were also renumbered.

29 September 2026

Manage Vpp Apple

Doc updateAction required

The documentation now warns that re-uploading an existing VPP token for DDM causes available app assignments to be lost. It recommends creating a new Apple Business token for DDM and using MDM for available assignments and apps requiring app configuration policies.

29 September 2026
4

Platform Guide Ios Ipados

Doc update

The iOS/iPadOS platform guide now links to the endpoint security devices page at a new URL; the link description is unchanged.

29 September 2026

Platform Guide Macos

Doc update

The macOS platform guide now links to the endpoint security devices page at its updated documentation path.

29 September 2026

Encrypt Filevault Macos

Doc update

The article now points to the encryption report and instructs admins to select Secure > Rotate FileVault recovery key from the device overview, then confirm with Yes.

29 September 2026

Configure Recovery Lock Macos

Doc update

The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode, choose Yes, and note that Intune generates a new passcode.

29 September 2026
4

Overview

Doc update

The page now uses simpler wording for device actions and updates the Intune security policies link path.

29 September 2026

Ref Zero Trust Devices

Doc update

Two references to “Monitor device encryption with Intune” now point to /intune/device-configuration/endpoint-security/monitor-encryption instead of /intune/device-management/monitor-encryption.

29 September 2026

Endpoint Security Policies

Doc update

The endpoint security policies page now uses an updated link to the guidance for managing devices with endpoint security in Intune.

29 September 2026

Remediate Vulnerabilities

Doc update

The documentation now links to the Admin tasks pane under the governance path instead of the device-management path.

29 September 2026
3

Help Desk Operators

Doc update

The “Managed by” documentation now links to the endpoint security devices location for details by management type.

29 September 2026

Collect Diagnostics

Doc update

The procedure now instructs administrators to select **Collect data** instead of **Yes** to confirm the action.

29 September 2026

Multi Admin Approval

Doc update

The multi-admin approval documentation now links to the centralized Admin tasks pane under the governance path instead of the device management path.

29 September 2026
2

Collect Device Properties

Doc update

The documentation now states that active devices collect inventory multiple times per day, while initial collection can take up to 24 hours because full synchronization runs once daily.

29 September 2026

Disk Encryption

Doc update

The Disk encryption documentation now uses the relative link `monitor-encryption` instead of `../../device-management/monitor-encryption`.

29 September 2026
2

Setup Automated Ios

RetirementAction required

The option must be set to No and will soon be removed. The Sync with computers setting was deprecated by Apple in iOS 13 and is no longer included in enrollment policies.

30 September 2026
2

Run Remediation

Doc update

The documented action and pane names changed from “Run remediation (preview)” to “Run remediation.”

29 September 2026

Index

Doc update

The device management actions index updates its Rename entries to link to the bulk-rename-devices section of the device inventory and status documentation.

29 September 2026
2

Platform Guide Windows

Doc update

The Windows platform guide now links to the endpoint security devices page at a new documentation path; the link description is unchanged.

29 September 2026

Encrypt Bitlocker Windows

Doc update

The BitLocker documentation now uses updated links for the encryption report and Monitor disk encryption, and clarifies that recovery keys can be viewed and managed from the encryption report.

29 September 2026
1

Platform Guide Android

Doc update

The Android platform guide now links to the endpoint security devices article at its updated documentation path.

29 September 2026
1

Setup Teamviewer

Doc update

The documented navigation now directs administrators to select a device and choose **Remote actions** > **Begin a remote assistance session**.

29 September 2026
1
16

Operations For Asset Intelligence

Retirement

Starting in version 2609, the Catalog Synchronization and Inventoried Software Status sections, along with Asset Intelligence reports, are removed. The page instead provides deprecation information and links to the product lifecycle dashboard and Asset Intelligence client settings. Earlier procedures apply only to version 2603 and earlier.

28 September 2026

Deprecation

Retirement

The documentation now states that built-in Asset Intelligence reports are removed from Monitoring > Reporting > Reports in version 2609. References apply to version 2603 and earlier.

28 September 2026

Support For Sql Server Versions

RetirementAction required

The documentation marks SQL Server 2016 and SQL Server 2016 Express as deprecated in version 2609. SQL Server editions earlier than SQL Server 2017 CU2 must be upgraded before installing or updating to 2609; the Visual C++ Redistributable on secondary sites must also be updated.

28 September 2026

Site And Site System Prerequisites

Feature update

The documentation now specifies Microsoft ODBC Driver for SQL Server and links to minimum, validated, and blocking versions. Starting in version 2609, Configuration Manager automatically installs the Microsoft OLE DB Driver for SQL Server and no longer requires SQL Server Native Client; versions 2603 and earlier retain the previous Native Client behavior.

28 September 2026

List Of Prerequisite Checks

Feature updateAction required

The documentation now requires ODBC Driver 18.6.2.1 or later for Configuration Manager 2609 and later, and SQL Server 2017 CU2 or later starting with 2609. Unsupported versions can block installation or upgrades; it also identifies version-specific incompatible ODBC releases and adds a non-blocking warning about automatic client approval.

28 September 2026

Introduction To Asset Intelligence

Retirement

The documentation states that version 2609 removes the Catalog Synchronization and Inventoried Software Status sections from the Asset Intelligence home page and removes Asset Intelligence reports from Monitoring > Reporting > Reports.

28 September 2026

Supported Configurations For Sql Server

Feature update

Starting with Configuration Manager version 2609, the TRUSTWORTHY database property is not required to load Microsoft-signed SQLCLR assemblies, including for databases using SQL Server Always On availability groups. Version 2603 and earlier still require TRUSTWORTHY to be enabled.

28 September 2026

Index

Doc update

The index now includes Configuration Manager 2609 and links to KB 2377842. Entries for versions 2107 through 2211 were removed, and the page date was updated.

28 September 2026

Supported Operating Systems For Clients And Devices

Retirement

Starting with Configuration Manager version 2609, Windows Server 2012, Windows Server 2012 R2, and their Windows Storage Server editions will no longer be supported as client operating systems.

28 September 2026

Updates

Doc update

The page now lists version 2609 (5.00.9152.1000), released September 28, 2026, with support through March 28, 2028. Version 2503 is now shown as plain text.

28 September 2026

Whats New In Version 2309

Doc update

The Configuration Manager version 2309 documentation now links to the prerequisite-checks page for minimum required versions, validated versions, and known blocking issues for the ODBC driver for SQL Server.

28 September 2026

Enable Tls 1 2 Server

Feature updateAction required

The documentation now states that all SQL Server versions currently supported by Configuration Manager support TLS 1.1 and TLS 1.2. Secondary site servers now require SQL Server 2017 Express with CU2 or later, replacing the previous SQL Server 2016 Express SP2 minimum.

28 September 2026

Release Notes

Doc update

The page date changed to September 22, 2026, and the “What’s new” link changed from version 2503 to version 2609.

28 September 2026

Support For Virtualization Environments

Feature update

The documentation no longer lists Windows Server 2012 R2, Microsoft Hyper-V Server 2012, or Windows Server 2012. The page date was updated to September 21, 2026.

28 September 2026

Upgrade On Premises Infrastructure

Feature update

The documentation now lists SQL Server 2025 and removes SQL Server 2016, SQL Server 2014, and the SQL Server 2016 upgrade link.

28 September 2026
5

Support For Windows 11

Feature update

The documentation now lists Windows 11 version 26H2 (build 10.0.26300) with support indicators shown as ❌, ✅, and ✅.

30 September 2026

Support For Windows 11

Feature update

The documentation now lists Windows 11 25H2 as supported with ConfigMgr 2503, 2509, and 2603, and adds ConfigMgr 2609 to the matrix.

28 September 2026

Support For Windows 10

Doc update

The documentation date was updated, and the support table now lists ConfigMgr 2509, 2603, and 2609 instead of 2503, 2509, and 2603.

28 September 2026

Support For Windows Adk

Doc update

The documentation table now lists ConfigMgr 2509, 2603, and 2609 instead of 2503, 2509, and 2603. The page date was also updated.

28 September 2026

Support For Windows Features And Networks

Feature update

The documentation now states that Configuration Manager supports data deduplication with distribution points on supported Windows Server versions, replacing the explicit “Windows Server 2012 or later” wording.

28 September 2026
2

Endpoint Antimalware Policies

New feature

The documentation now states that Microsoft Defender Antivirus contextual file and folder exclusions can be specified in the policy setting or with the Set-CMAntimalwarePolicy cmdlet starting in version 2609.

28 September 2026
1

List Of Reports

Retirement

Starting with version 2609, the Asset Intelligence report category and its 67 reports will be removed. They apply to version 2603 and earlier.

28 September 2026
1

Manage Support Approvals

Doc update

The documentation now links to the centralized Admin tasks pane under the governance path instead of the device-management path.

29 September 2026
Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…