Ref Windows Mdm Settings
Doc updateThe documentation now includes the Windows 11 version 26H2 security baseline and its default settings across areas including SMB, network security, DNS, and Windows Connection Manager.
The period's strongest Intune item is new guidance for the Windows 11 version 26H2 security baseline and Settings Catalog support. It explicitly says existing baseline profiles don't update automatically, so adopting the 26H2 baseline means creating a new profile or updating an existing one. Remote Help availability is also documented for GCCH Android and Windows devices. For administrators who operate Configuration Manager, version 2609 adds a hierarchy-update prerequisite, changes several security and approval behaviors, and removes support for the listed Windows Server 2012 client operating systems.
Intune guidance now covers the Windows 11 version 26H2 security baseline and Settings Catalog support, including new settings, updated defaults, and revised guidance. Existing security baseline profiles don't update automatically; administrators who want the 26H2 baseline must create a new profile or update an existing one.
Configuration Manager 2609 no longer supports Windows Server 2012, Windows Server 2012 R2, or their Windows Storage Server editions as client operating systems. Administrators should identify affected devices and upgrade them to a supported Windows Server version.
The 2609 update checklist requires a top-level service connection point. After the parent site is updated, secondary sites require manual updating.
The 2609 documentation records that CMPivot clients trust its signing certificate, SQLCLR no longer requires TRUSTWORTHY, and CMG storage shared-key access is automatically disabled. Upgrade checks warn about automatic computer approval, with the planned removal of automatic approval for all computers also called out.
Remote Help is stated as available in US Government Community Cloud High (GCCH) for Android and Windows devices. GCCH IT support staff can provide real-time troubleshooting for enrolled devices using role-based access controls and Microsoft Entra ID sign-in.
Intune administrators targeting 26H2 should create a new baseline profile or update an existing one; profiles won't update automatically. GCCH support teams can use Remote Help for enrolled Android and Windows devices with role-based access controls and Microsoft Entra ID sign-in. Configuration Manager teams planning 2609 should use a top-level service connection point, manually update secondary sites after their parent, review the changed behaviors, and identify affected Server 2012 devices for upgrade to a supported Windows Server version.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The documentation now includes the Windows 11 version 26H2 security baseline and its default settings across areas including SMB, network security, DNS, and Windows Connection Manager.
The overview now links to Version 26H2 Windows MDM settings and updates its documentation metadata.
The documentation now states that Remote Help is available in US Government Community Cloud High (GCCH) environments for Android and Windows devices.
Intune now documents the Windows 11 version 26H2 security baseline and Settings Catalog support, including new settings, updated defaults, and revised guidance.
A checklist now documents prerequisites and installation behavior for updating a Configuration Manager hierarchy to version 2609, including service connection point and site update requirements.
Version 2609 includes fixes and improvements: CMPivot clients trust its signing certificate, SQLCLR no longer requires TRUSTWORTHY, CMG storage shared-key access is automatically disabled, and upgrade checks warn about automatic computer approval.
Configuration Manager 2609 no longer supports Windows Server 2012, Windows Server 2012 R2, or their Windows Storage Server editions as client operating systems.