Microsoft Defender for Android will end support for protecting personal profiles on enrolled devices by March 2026, focusing solely on securing corporate work profiles. This change enhances enterprise security and user privacy, requires no admin action, and does not affect work profiles or unenrolled devices.
Device Query documents more join types as migration roles and remediation limits sharpen
23 January was maintenance-heavy: all supplied entries were updates, with no new, removed, or message-center items. The meaningful changes are procedural and behavioral clarifications rather than an evidenced feature launch: the Basic Mobility and Security migration guide now identifies Conditional Access roles and license assignment, Device Query guidance adds four join types and a scalar-use limitation, Remediations states a firmer delivery boundary, and Configuration Manager clarifies Software Center placement. Edge for Business pages were mostly refreshed, but one policy-conflict warning was shortened—an editorial change that does not by itself prove a product rule changed.
- Migration guidance now names the Conditional Access roles
Intune · Fundamentals
Step 3 changes “assign the policies” to “assign the licenses and policies.” It identifies Endpoint Security Manager for creating and assigning app-based Conditional Access policies in the Intune admin center, and Conditional Access Administrator for device-based Conditional Access policies in the Microsoft Entra admin center. The guide also links to the procedure for removing no-longer-needed Basic Mobility and Security policies. This is a migration-procedure and RBAC clarification, not evidence of a new migration,
- Device Query guidance lists four more supported join types and a Device limitation
Advanced Analytics · Endpoint analytics
The Advanced Analytics page now lists `leftsemi`, `rightsemi`, `leftanti`, and `rightanti` alongside the existing join types. It also states that the `Device` entity can't be used directly with scalar-requiring operators such as `distinct`, `summarize`, and `order by`; use a specific property such as `Device.DeviceId`. The edit updates query guidance and does not establish a service-side capability rollout.
- Remediations now states Run remediation will not arrive offline
Intune · Fundamentals
The Remediations page changes “might not receive” to “will not receive” the Run remediation device action when a device is offline or can't successfully communicate with Intune or Windows Push Notification Service when the action is sent. Administrators should plan around that documented no-delivery condition.
- Edge guide removes its explicit prohibition on co-targeting two policy types
Intune · App management
Step 4 no longer includes: “Never deploy both App Configuration Policies and Settings Catalog policies targeting Microsoft Edge to the same client.” The remaining guidance says to choose the appropriate policy type based on device enrollment status to avoid conflicts. This is a wording change in the guide, not evidence that co-targeting is now supported.
- High-impact task sequence placement in Software Center is spelled out
Configuration Manager · General
New Configuration Manager guidance says a task sequence deployed as High-impact appears under Software Center's Operating Systems node. If it isn't marked High-impact, the deployment appears under Applications, clarifying the user-facing placement.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
20 updates
Microsoft Intune
14 updatesUpdated Microsoft Intune documentation in intune/intune-service/apps/mamedge-7-troubleshoot.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/mamedge-1-mamca.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/mamedge-4-acp-edge.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/mamedge-5-settings-catalog.md.
Mamedge 4 Acp Edge
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/apps/mamedge-4-acp-edge.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/mamedge-2-app.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/mamedge-3-scc.md.
Updated Microsoft Intune documentation in intune/intune-service/apps/mamedge-6-end-user-experience.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/migrate-to-intune.md.
Updated Microsoft Intune documentation in intune/intune-service/fundamentals/migrate-to-intune.md.
Migrate To Intune
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/migrate-to-intune.md.
Migrate To Intune
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/migrate-to-intune.md.
Remediations
UpdatedUpdated Microsoft Intune documentation in intune/intune-service/fundamentals/remediations.md.
Microsoft Configuration Manager
1 updateUpdated Microsoft Intune documentation in intune/configmgr/osd/deploy-use/high-impact-task-sequence-settings.md.
Microsoft Intune Advanced Analytics
5 updatesUpdated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.