Product

Microsoft Intune

Track documentation and Message Center changes for Microsoft Intune.

Microsoft Learn documentation ↗

Latest Microsoft Intune changes

Ref Corporate Methods

Device enrollment

The page now explains that Settings resets don't enforce FRP when Factory reset protection emails is Not configured. For Android 15 devices with a configured Google account email, the account must be re-entered after the reset.

Ref Device Restrictions Android Enterprise

Android

The documentation updates the COPE device table and explains that a Settings reset doesn’t enforce factory reset protection when Factory reset protection emails is Not configured.

Configure Managed Home Screen

App management

The page’s authoring metadata changed, and the description for excluding apps from the silence setting was revised.

In Development

General

The page now lists Apple OS 27 DDM inventory data, MEFERI OEMConfig support for Android Enterprise, removal of legacy Apple MDM software-update workloads, and two Administrator protection settings for Windows 11 24H2 and 25H2.

Add Managed Google Play

App management

During onboarding, the Intune, Microsoft Authenticator, and Company Portal apps are installed as required apps on dedicated devices, in addition to fully managed and corporate-owned work profile devices.

Add Unmanaged Pkg Macos

App management

The documentation now states that failed macOS app installations are retried at the next agent check-in, with up to three retries while the app remains assigned.

Configure Managed Home Screen

App management

The app-exclusion setting description now spells out “Managed Home Screen” instead of using the abbreviation “MHS” when referring to authentication.

Setup Automated Ios

Device enrollment

The option must be set to No and will soon be removed. The Sync with computers setting was deprecated by Apple in iOS 13 and is no longer included in enrollment policies.

Archive

General

The archive page now links to the Admin tasks content under Governance instead of Device management.

Autopilot Reset

General

The device overview instructions now direct administrators to select Remove data, then Autopilot reset.

Collect Device Properties

Device configuration

The documentation now states that active devices collect inventory multiple times per day, while initial collection can take up to 24 hours because full synchronization runs once daily.

Collect Diagnostics

Fundamentals

The procedure now instructs administrators to select **Collect data** instead of **Yes** to confirm the action.

Configure Managed Ios

App management

The guide now states that app configuration policies support only MDM-managed apps and cannot configure DDM apps. The setup steps were also renumbered.

Configure Recovery Lock Macos

Apple

The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode, choose Yes, and note that Intune generates a new passcode.

Disable Activation Lock

General

The instructions now say to select **Secure** before choosing **Disable Activation Lock** in the device overview action menu.

Disk Encryption

Device configuration

The Disk encryption documentation now uses the relative link `monitor-encryption` instead of `../../device-management/monitor-encryption`.

Encrypt Bitlocker Windows

Windows

The BitLocker documentation now uses updated links for the encryption report and Monitor disk encryption, and clarifies that recovery keys can be viewed and managed from the encryption report.

Encrypt Filevault Macos

Apple

The article now points to the encryption report and instructs admins to select Secure > Rotate FileVault recovery key from the device overview, then confirm with Yes.

Endpoint Security Policies

Device security

The endpoint security policies page now uses an updated link to the guidance for managing devices with endpoint security in Intune.

Fresh Start

General

The instructions now direct administrators to select **Remove data** before selecting **Fresh Start** in the device overview pane.

Full Scan

General

The documented steps changed from selecting **Full scan** directly to selecting **Microsoft Defender** > **Run full malware scan**.

Help Desk Operators

Fundamentals

The “Managed by” documentation now links to the endpoint security devices location for details by management type.

Index

Troubleshooting

The device management actions index updates its Rename entries to link to the bulk-rename-devices section of the device inventory and status documentation.

Index

General

The index now links to the device management overview, uses updated titles for device categories and primary-user tasks, and removes links for endpoint security device management, admin tasks, and encryption status details.

Index

General

The Intune What’s new page was updated, including a new metadata date, and the entry describing bulk eSIM actions for corporate-owned Android Enterprise devices was removed.

Locate

General

The instructions specify selecting **Locate device** on Windows and **Locate** > **Locate device** on iOS and Android. Location details remain available from the map pin.

Logout User

General

The instructions now direct administrators to select **Remote actions** before choosing **Logout current user** from the device overview pane.

Lost Mode

General

The instructions now direct administrators to select **Locate** and then **Lost mode (supervised only)** from the device overview action icons.

Manage Vpp Apple

App management

The documentation now warns that re-uploading an existing VPP token for DDM causes available app assignments to be lost. It recommends creating a new Apple Business token for DDM and using MDM for available assignments and apps requiring app configuration policies.

Multi Admin Approval

Fundamentals

The multi-admin approval documentation now links to the centralized Admin tasks pane under the governance path instead of the device management path.

Overview

Device security

The page now uses simpler wording for device actions and updates the Intune security policies link path.

Pause Config Refresh

General

The documented steps now direct administrators to select Remote actions > Pause Config Refresh from the device overview pane.

Platform Guide Android

Android

The Android platform guide now links to the endpoint security devices article at its updated documentation path.

Platform Guide Ios Ipados

Apple

The iOS/iPadOS platform guide now links to the endpoint security devices page at a new URL; the link description is unchanged.

Platform Guide Macos

Apple

The macOS platform guide now links to the endpoint security devices page at its updated documentation path.

Platform Guide Windows

Windows

The Windows platform guide now links to the endpoint security devices page at a new documentation path; the link description is unchanged.

Play Lost Mode Sound

General

The instructions now direct administrators to select Locate before choosing either Play Lost Mode sound or Play lost device sound.

Quick Scan

General

The instructions now direct administrators to select Microsoft Defender > Run quick malware scan from the device overview action icons.

Ref Zero Trust Devices

Device security

Two references to “Monitor device encryption with Intune” now point to /intune/device-configuration/endpoint-security/monitor-encryption instead of /intune/device-management/monitor-encryption.

Remediate Vulnerabilities

Device security

The documentation now links to the Admin tasks pane under the governance path instead of the device-management path.

Remote Lock

General

The instructions now direct administrators to select **Secure** > **Remote lock** from the device overview action icons.

Remove Passcode

General

The instructions now direct administrators to select **Secure** and then **Remove passcode** from the device overview action icons.

Rename

General

The page documenting the Rename device action, including supported platforms, role requirements, and admin-center steps, was deleted.

Reset Passcode

General

The instructions now direct administrators to select **Secure** > **Reset passcode** from the device overview action icons.

Restart

General

The restart procedure now instructs administrators to select **Remote actions** > **Restart** > **Yes** from the device overview pane.

Restore Managed Home Screen

General

The instructions now direct administrators to select Remote actions > Restore Managed Home Screen from the device overview pane.

Retire

General

The instructions now direct administrators to select **Remove data** > **Retire** from the device overview action icons, instead of selecting **Retire** directly.

Rotate Bitlocker Keys

General

The instructions now direct administrators to select **Secure** > **BitLocker key rotation** from the device overview action icons.

Rotate Filevault Recovery Key

General

The action is now accessed through **Secure** > **Rotate FileVault recovery key** in the device overview pane.

Rotate Local Admin Password

General

The device overview instructions now direct admins to select **Secure** before choosing **Rotate Local admin password**.

Rotate Recovery Lock Passcode

General

The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode from the device overview action icons.

Run Remediation

Troubleshooting

The documented action and pane names changed from “Run remediation (preview)” to “Run remediation.”

Setup Teamviewer

Compliance

The documented navigation now directs administrators to select a device and choose **Remote actions** > **Begin a remote assistance session**.

Shutdown

General

The documented path changed from selecting Shut down directly to selecting Remote actions > Shut down > Yes.

Suspend Managed Home Screen

General

The instructions now direct administrators to select **Remote actions** before choosing **Suspend Managed Home Screen**.

View device details - Microsoft Intune | Microsoft Learn

General

The article now explains how to open a device’s Device details tab, distinguishes read-only inventory from editable Properties, and documents hardware and software inventory refreshing every seven days from enrollment.

Wipe

General

The documented steps now direct administrators to select Remove data > Wipe from the device overview action icons.

Plan for Change: Intune migration for Windows Health Attestation to Microsoft Azure Attestation for Windows 11 devices

Message CenterMC1473156 on mc.merill.net ↗Plan for change
Device security

Intune will migrate Windows Health Attestation from Device Health Attestation to Microsoft Azure Attestation by early 2027. Organizations must ensure network access to Azure Attestation endpoints to maintain compliance evaluation for Windows 11 devices using health-based policies, or risk compliance failures.

Endpoints China

Fundamentals

The China endpoints documentation now lists `https://graph.chinacloudapi.cn` instead of `https://graph.chinacloudapi.us`.

Planning Guide

General

The planning guide now links to `integrate-windows-update-client-policies.md` instead of the previous `integrate-windows-update-for-business-windows-10.md` article.

Deploy Remediations

Troubleshooting

The page now recommends limiting script assignments, avoiding resource-intensive or frequent schedules, and using stable, actionable detection-script results to reduce device performance impact.

In development - Microsoft Intune

General

The page adds upcoming features including MHS authentication for protected app activities, declarative VPP downloads, deployment plans, Defender launch during Android setup, bulk eSIM actions, new Apple settings, and Quick Machine Recovery policies. It also documents future macOS and iOS/iPadOS support changes and the September 2609 single-device page default.

Ref Settings Ios

App management

The iOS app protection settings reference updated the Screen capture entry, documenting that Block prevents capture of work or school data, while Allow is the default and permits capture and sharing without restrictions.

Servicing Information

Compliance

The servicing information page changed the callout from Caution to Important; its message about impacts to updates, reliability, security mitigations, and feature enablement remains the same.

Configure Baselines

Device security

The Configure baselines documentation now links to the Windows 365 for Agents security baseline settings reference.

Endpoints

Fundamentals

The Intune client and host service endpoint entry now includes 150.171.109.0/24 and 150.171.110.0/24.

Manage Vpp Apple

App management

The VPP token settings now include a Management type option: MDM (default) or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later, and supports only Required or Uninstall assignments.

Overview

Device security

The security baselines overview now links to the Windows 365 for Agents security baseline, including its Version 24H1 settings reference.

Ref Protected Apps

App management

The reference now includes Ben for Intune, Calven, Heijmans, Notability, Notion, SDP - On Premises | Intune, and Superhuman Mail, with descriptions and app links.

Setup Personal Work Profile

Device enrollment

The documentation now lists Chrome, Edge, and Samsung browser as supported for web-based enrollment. The note about phone-call MFA potentially breaking enrollment and its workaround was removed.

What's new in Microsoft Intune

General

The page now states that the listed eSIM features are rolling out and might not yet be available to all tenants. The page date and authoring metadata were also updated.

Android settings catalog in Microsoft Intune

Device enrollment

The article now documents additional Android settings, including work profile inactivity, eSIM removal during wipes, screen power behavior, and separate device and work profile locks, with supported enrollment types, platform versions, defaults, and value requirements.

In development - Microsoft Intune

General

The page date changed from July 27 to August 21, 2026, and the section describing a planned Audit value for the Microsoft Defender Antivirus template for Linux was removed.

Manage eSIM plans in Microsoft Intune

Android

The documentation adds activation and removal of eSIM plans on supported Android Enterprise corporate-owned devices, including supported Android versions, activation-code and ICCID requirements, device-view steps, and required permissions.

Setup Automated Ios

Device enrollment

The documentation now lists Accessibility appearance for iOS/iPadOS 17 and later and Liquid Glass for iOS/iPadOS 27 and later.

Setup Automated Macos

Device enrollment

The macOS setup documentation now lists the Liquid Glass pane as skippable for macOS 27.0 and later.

View device details with Microsoft Intune

Compliance

The device details documentation now covers ICCID, EID, phone number, carrier, activation state, and SIM origin for supported Android Enterprise corporate-owned devices, including Android version requirements.

What's new in Microsoft Intune

General

The documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.

What's new in previous months in the Microsoft Intune

General

The archive now documents EPM support for AVD single-session VMs, a Lenovo Device Orchestration link, four protected apps, and additional Windows settings catalog policies for Edge, Chrome, Windows AI, Firewall, and other components.

Wipe devices with Microsoft Intune

General

The documentation now explains that eSIMs are preserved by default on specified Android Enterprise corporate-owned devices and can be removed during a single-device wipe using the new device view.

Create a custom role in Intune

Fundamentals

The documentation now distinguishes Android unattended control, which requires a dedicated Intune-enrolled device, and adds Windows unattended remote sign-in for targeted physical corporate-owned devices. Both permissions must be explicitly assigned and scoped.

Monitor

Device security

The monitoring guidance now lists log collection status—completed, failed, or in progress—instead of an Incident ID. It also says Microsoft can use logs collected after reproducing an issue during verbose log collection for investigation.

Network endpoints for Microsoft Intune

Fundamentals

The endpoints documentation now states that Remote Sign-in for Remote Help on Windows requires Azure Virtual Desktop session host endpoints.

Prerequisites

Device security

The prerequisites page no longer lists `powerlift-frontdesk.acompli.net` as a Diagnostic Endpoint.

Windows Antivirus policy settings for Microsoft Defender Antivirus for Intune

Device security

The documentation now explains that Yes disables and No enables catch-up scans because the settings are named “Disable catch-up...”. Full-scan catch-up is disabled when not configured, while quick-scan catch-up is enabled by default; the scan triggers after two missed scheduled scans are also specified.

Device Action: Delete

General

The documentation now states that a tenant can submit up to 1,000 Delete actions per day, cumulatively across individual actions, bulk actions, and Microsoft Graph requests. The limit also applies when Delete triggers Retire or Wipe.

Device Action: Retire

General

The documentation now states that a tenant can submit up to 1,000 Retire actions per day, cumulative across individual, bulk, and Microsoft Graph API requests.

Device Action: Wipe

General

The documentation now states that individual, bulk, and Microsoft Graph Wipe requests share a cumulative tenant-wide daily limit of 500 actions.

Device Actions - Wipe, Lock, Locate, and More

Android

The documentation now lists tenant-wide daily limits of 500 Wipe actions and 1,000 each for Retire and Delete. Counts are cumulative across individual, bulk, and Microsoft Graph submissions.

Android Management Api Overview

Device enrollment

The documentation now directs administrators to the “Personal Devices on Android Management API” report under Devices > Monitor and clarifies that reporting is not shown in the policy’s device assignment status or the device configuration tab.

Management Extension Windows

Windows

The documentation now states that Sync from Windows Settings or the Intune admin center initiates both MDM and IME check-ins, including policy, app, script, and remediation processing. Sync progress can be viewed in the Device sync status tab.

Sync

General

The sync documentation now explains that selecting Sync triggers multiple workloads, including policy processing, app state updates, and scripts/remediations. Admins can monitor progress in the Device sync status tab. This behavior applies to iOS/iPadOS and Windows devices.

Sync

Fundamentals

The sync behavior and Device sync status tab are documented as applying to Windows and iOS/iPadOS devices, rather than Windows only. The Preview new device view toggle remains required to see the described improvements.

Plan for Change: Intune moving to support iOS/iPadOS 18 and higher later this year

Message CenterMC1454371 on mc.merill.net ↗Major updatePlan for change
App management

Microsoft Intune will require iOS/iPadOS 18 or higher after Apple releases iOS/iPadOS 27 later this year. Organizations should check device compatibility and Intune reports to identify affected devices. Userless devices via Automated Device Enrollment have specific OS version requirements. Use Intune controls to manage OS versions.

Collect Device Properties

Device configuration

The documentation for collecting device properties now states that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information. It identifies this as an accepted risk and calls for reviewing security and privacy implications.

Add Apps Unenrolled Devices

Device enrollment

The guidance now links to the general Android and iOS store-app instructions without including direct CylancePROTECT Play Store or App Store URLs.

Assign Apps

App management

The article now only directs administrators to the iOS app configuration policy guidance; the Sophos Intercept X for Mobile iOS reference link was removed.

Assign Apps to Groups in Microsoft Intune

App management

The documentation now states that apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices can use Available assignments for either user or device groups, alongside the existing Win32 exception.

Blackberry

App management

The BlackBerry Intune integration page no longer includes the link to BlackBerry UES documentation.

Collect Device Properties

Windows

The documentation now notes that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…