The documentation updates the COPE device table and explains that a Settings reset doesn’t enforce factory reset protection when Factory reset protection emails is Not configured.
Endpoint Privilege Management documents controlled network changes for standard Windows users
October’s clearest administrator-facing development is new Endpoint Privilege Management guidance for an Elevation system settings policy. It allows standard Windows users to change IPv4, IPv6, and DNS settings under confirmation, business-justification, Windows-authentication, or combined controls, with an EPM elevation settings policy enabled. Intune’s In Development page also lists Apple OS 27 DDM inventory data, MEFERI OEMConfig support, planned removal of legacy Apple MDM software-update workloads, and two Administrator protection settings for Windows 11 24H2 and 25H2. Android reset guidance and Advanced Analytics schema limitations were also made more explicit. The Managed Home Screen edit only changes authoring metadata and wording around excluding apps from the silence setting.
- EPM documents an elevation policy for controlled IPv4, IPv6, and DNS changes
Endpoint Privilege Management · Device security
The new Endpoint Privilege Management guidance describes allowing standard Windows users to change IPv4, IPv6, and DNS settings. Administrators can require confirmation, business justification, Windows authentication, or both; devices also need an enabled EPM elevation settings policy.
- Intune’s development roadmap lists Apple, Android, and Windows administration changes
Intune · General
The In Development page now lists Apple OS 27 DDM inventory data, MEFERI OEMConfig support for Android Enterprise, removal of legacy Apple MDM software-update workloads, and two Administrator protection settings for Windows 11 24H2 and 25H2. No action or deadline is stated.
- Android reset guidance defines the Factory reset protection emails behavior
Intune · Device enrollment
The documentation states that a Settings reset doesn’t enforce factory reset protection when Factory reset protection emails is Not configured. On Android 15 devices with a configured Google account email, that account must be re-entered after the reset.
- Advanced Analytics schema guidance excludes ICCID on Windows
Advanced Analytics · Endpoint analytics
The schema documentation now states that ICCID isn’t supported on Windows. It also continues to identify SimInfo as unsupported for Android Enterprise personally owned devices with a work profile.
Administrators designing delegated network changes should enable the required EPM elevation settings policy and select the appropriate confirmation, justification, and authentication controls. The In Development entries are planning signals; the supplied update gives no action or deadline. For Android 15 reset workflows, account for the configured Factory reset protection emails setting and required Google account re-entry. Analytics consumers should not expect ICCID on Windows or SimInfo for Android Enterprise personally owned devices with a work profile.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
7 updates by product
Microsoft Intune
4 updatesConfigure Managed Home Screen
Doc updateThe page’s authoring metadata changed, and the description for excluding apps from the silence setting was revised.
Ref Corporate Methods
Doc updateThe page now explains that Settings resets don't enforce FRP when Factory reset protection emails is Not configured. For Android 15 devices with a configured Google account email, the account must be re-entered after the reset.
In Development
New featureThe page now lists Apple OS 27 DDM inventory data, MEFERI OEMConfig support for Android Enterprise, removal of legacy Apple MDM software-update workloads, and two Administrator protection settings for Windows 11 24H2 and 25H2.
Endpoint Privilege Management
2 updatesManage system settings with Endpoint Privilege Management - Microsoft Intune | Microsoft Learn
New featureThe documentation describes policies that let standard Windows users change IPv4, IPv6, and DNS settings. Administrators can require confirmation, business justification, Windows authentication, or both.
Overview
New featureThe EPM overview now lists three policy types and adds an Elevation system settings policy for allowing standard users to change selected Windows settings, including IPv4, IPv6, and DNS configuration.
Ref Data Platform Schema
Feature updateThe schema documentation now states that ICCID isn’t supported on Windows. It continues to note that SimInfo isn’t supported for Android Enterprise personally owned devices with a work profile.