Ref Corporate Methods
The page now explains that Settings resets don't enforce FRP when Factory reset protection emails is Not configured. For Android 15 devices with a configured Google account email, the account must be re-entered after the reset.
Track documentation and Message Center changes for Microsoft Intune.
Microsoft Learn documentation ↗The page now explains that Settings resets don't enforce FRP when Factory reset protection emails is Not configured. For Android 15 devices with a configured Google account email, the account must be re-entered after the reset.
The documentation updates the COPE device table and explains that a Settings reset doesn’t enforce factory reset protection when Factory reset protection emails is Not configured.
The page’s authoring metadata changed, and the description for excluding apps from the silence setting was revised.
The page now lists Apple OS 27 DDM inventory data, MEFERI OEMConfig support for Android Enterprise, removal of legacy Apple MDM software-update workloads, and two Administrator protection settings for Windows 11 24H2 and 25H2.
During onboarding, the Intune, Microsoft Authenticator, and Company Portal apps are installed as required apps on dedicated devices, in addition to fully managed and corporate-owned work profile devices.
The documentation now states that failed macOS app installations are retried at the next agent check-in, with up to three retries while the app remains assigned.
The app-exclusion setting description now spells out “Managed Home Screen” instead of using the abbreviation “MHS” when referring to authentication.
The option must be set to No and will soon be removed. The Sync with computers setting was deprecated by Apple in iOS 13 and is no longer included in enrollment policies.
The archive page now links to the Admin tasks content under Governance instead of Device management.
The device overview instructions now direct administrators to select Remove data, then Autopilot reset.
The article was retitled and updated to explain how to change or remove a device’s primary user from the Properties tab, along with how Intune assigns and uses the primary user.
The documentation now states that active devices collect inventory multiple times per day, while initial collection can take up to 24 hours because full synchronization runs once daily.
The procedure now instructs administrators to select **Collect data** instead of **Yes** to confirm the action.
The guide now states that app configuration policies support only MDM-managed apps and cannot configure DDM apps. The setup steps were also renumbered.
The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode, choose Yes, and note that Intune generates a new passcode.
The article now defines device categories as labels, explains their relationship to dynamic Microsoft Entra security groups, and covers creating categories, building groups, and assigning categories to devices.
The documentation consistently renames the action to “Remove apps and configurations” and updates the steps to select Remove data > Remove apps and configurations.
A new overview describes the Devices area in the Intune admin center, including device details, actions, inventory, reports, tools, and related guidance.
The instructions now say to select **Secure** before choosing **Disable Activation Lock** in the device overview action menu.
The Disk encryption documentation now uses the relative link `monitor-encryption` instead of `../../device-management/monitor-encryption`.
The documentation now explains how to edit a managed device’s name, ownership, primary user, notes, and scope tags from the Properties tab.
The BitLocker documentation now uses updated links for the encryption report and Monitor disk encryption, and clarifies that recovery keys can be viewed and managed from the encryption report.
The article now points to the encryption report and instructs admins to select Secure > Rotate FileVault recovery key from the device overview, then confirm with Yes.
The endpoint security policies page now uses an updated link to the guidance for managing devices with endpoint security in Intune.
The instructions now direct administrators to select **Remove data** before selecting **Fresh Start** in the device overview pane.
The documented steps changed from selecting **Full scan** directly to selecting **Microsoft Defender** > **Run full malware scan**.
The “Managed by” documentation now links to the endpoint security devices location for details by management type.
The device management actions index updates its Rename entries to link to the bulk-rename-devices section of the device inventory and status documentation.
The index now links to the device management overview, uses updated titles for device categories and primary-user tasks, and removes links for endpoint security device management, admin tasks, and encryption status details.
The Intune What’s new page was updated, including a new metadata date, and the entry describing bulk eSIM actions for corporate-owned Android Enterprise devices was removed.
The instructions specify selecting **Locate device** on Windows and **Locate** > **Locate device** on iOS and Android. Location details remain available from the map pin.
The instructions now direct administrators to select **Remote actions** before choosing **Logout current user** from the device overview pane.
The instructions now direct administrators to select **Locate** and then **Lost mode (supervised only)** from the device overview action icons.
The documentation now warns that re-uploading an existing VPP token for DDM causes available app assignments to be lost. It recommends creating a new Apple Business token for DDM and using MDM for available assignments and apps requiring app configuration policies.
The multi-admin approval documentation now links to the centralized Admin tasks pane under the governance path instead of the device management path.
The page now uses simpler wording for device actions and updates the Intune security policies link path.
The documented steps now direct administrators to select Remote actions > Pause Config Refresh from the device overview pane.
The Android platform guide now links to the endpoint security devices article at its updated documentation path.
The iOS/iPadOS platform guide now links to the endpoint security devices page at a new URL; the link description is unchanged.
The macOS platform guide now links to the endpoint security devices page at its updated documentation path.
The Windows platform guide now links to the endpoint security devices page at a new documentation path; the link description is unchanged.
The instructions now direct administrators to select Locate before choosing either Play Lost Mode sound or Play lost device sound.
The instructions now direct administrators to select Microsoft Defender > Run quick malware scan from the device overview action icons.
Two references to “Monitor device encryption with Intune” now point to /intune/device-configuration/endpoint-security/monitor-encryption instead of /intune/device-management/monitor-encryption.
The documentation now links to the Admin tasks pane under the governance path instead of the device-management path.
The instructions now direct administrators to select **Secure** > **Remote lock** from the device overview action icons.
The instructions now direct administrators to select **Secure** and then **Remove passcode** from the device overview action icons.
The page documenting the Rename device action, including supported platforms, role requirements, and admin-center steps, was deleted.
The new guidance explains how to rename managed devices from the Intune admin center, supported platforms, platform-specific naming rules, bulk-renaming variables, and limitations such as hybrid-joined Windows devices not being supported.
The instructions now direct administrators to select **Secure** > **Reset passcode** from the device overview action icons.
The restart procedure now instructs administrators to select **Remote actions** > **Restart** > **Yes** from the device overview pane.
The instructions now direct administrators to select Remote actions > Restore Managed Home Screen from the device overview pane.
The instructions now direct administrators to select **Remove data** > **Retire** from the device overview action icons, instead of selecting **Retire** directly.
The instructions now direct administrators to select **Secure** > **BitLocker key rotation** from the device overview action icons.
The action is now accessed through **Secure** > **Rotate FileVault recovery key** in the device overview pane.
The device overview instructions now direct admins to select **Secure** before choosing **Rotate Local admin password**.
The instructions now direct administrators to select Secure > Rotate Recovery Lock Passcode from the device overview action icons.
The documented action and pane names changed from “Run remediation (preview)” to “Run remediation.”
The documented navigation now directs administrators to select a device and choose **Remote actions** > **Begin a remote assistance session**.
The documented path changed from selecting Shut down directly to selecting Remote actions > Shut down > Yes.
The instructions now direct administrators to select **Remote actions** before choosing **Suspend Managed Home Screen**.
The Company Portal help page now links to “Rename a device in Microsoft Intune” at a new documentation location.
The article now links to `/device-management/inventory-and-status/rename-device` instead of `/device-management/actions/rename`.
The article now explains how to open a device’s Device details tab, distinguishes read-only inventory from editable Properties, and documents hardware and software inventory refreshing every seven days from enrollment.
The documented steps now direct administrators to select Remove data > Wipe from the device overview action icons.
Windows Autopatch enhancements, rolling out Sept 1–Oct 15, 2026, offer improved control over Windows quality, .NET Framework, and quick machine recovery updates. Features include customizable automatic/manual approvals, deferral settings, update pausing, and detailed per-device reporting for better update management.
What and why: Microsoft Intune will migrate Windows Health Attestation compliance evaluation from the current Device Health Attestation (DHA) service to Microsoft Azure Attestation (MAA). This is an Intune service-side change that will happen automatically.
Intune will migrate Windows Health Attestation from Device Health Attestation to Microsoft Azure Attestation by early 2027. Organizations must ensure network access to Azure Attestation endpoints to maintain compliance evaluation for Windows 11 devices using health-based policies, or risk compliance failures.
The China endpoints documentation now lists `https://graph.chinacloudapi.cn` instead of `https://graph.chinacloudapi.us`.
The planning guide now links to `integrate-windows-update-client-policies.md` instead of the previous `integrate-windows-update-for-business-windows-10.md` article.
The page now recommends limiting script assignments, avoiding resource-intensive or frequent schedules, and using stable, actionable detection-script results to reduce device performance impact.
The page adds upcoming features including MHS authentication for protected app activities, declarative VPP downloads, deployment plans, Defender launch during Android setup, bulk eSIM actions, new Apple settings, and Quick Machine Recovery policies. It also documents future macOS and iOS/iPadOS support changes and the September 2609 single-device page default.
The iOS app protection settings reference updated the Screen capture entry, documenting that Block prevents capture of work or school data, while Allow is the default and permits capture and sharing without restrictions.
The servicing information page changed the callout from Caution to Important; its message about impacts to updates, reliability, security mitigations, and feature enablement remains the same.
The prerequisites now list RHEL 10.1 with Podman 5.8.2 as the default and explain that the ip_tables kernel module must be manually loaded before Tunnel installation.
The page now documents version 20260818.1, agent and server image digests, minor bug fixes, and package and security updates for the August 18, 2026 release.
The Configure baselines documentation now links to the Windows 365 for Agents security baseline settings reference.
A new article explains how to trigger and cancel remote enhanced log collection on supervised macOS 27+, iOS 27+, and iPadOS 27+ devices. Logs are sent directly to Apple for support analysis.
The Intune client and host service endpoint entry now includes 150.171.109.0/24 and 150.171.110.0/24.
The VPP token settings now include a Management type option: MDM (default) or DDM. DDM applies to app deployment and configuration on iOS/iPadOS 18 and later, and supports only Required or Uninstall assignments.
The security baselines overview now links to the Windows 365 for Agents security baseline, including its Version 24H1 settings reference.
The reference now includes Ben for Intune, Calven, Heijmans, Notability, Notion, SDP - On Premises | Intune, and Superhuman Mail, with descriptions and app links.
Intune now documents the Windows 365 for Agents security baseline version 24H1, including default settings for Cloud PCs running agentic workloads across Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint.
The documentation now lists Chrome, Edge, and Samsung browser as supported for web-based enrollment. The note about phone-call MFA potentially breaking enrollment and its workaround was removed.
The page now states that the listed eSIM features are rolling out and might not yet be available to all tenants. The page date and authoring metadata were also updated.
The article now documents additional Android settings, including work profile inactivity, eSIM removal during wipes, screen power behavior, and separate device and work profile locks, with supported enrollment types, platform versions, defaults, and value requirements.
Intune now documents the Apple DDM App Settings configuration for supervised iOS/iPadOS 27+ and macOS 27+ devices, including allowed or denied apps, binaries, and managed-app allowances.
The osVersion property is now documented as deprecated. New assignment filters can’t use it, while existing filters continue to work; operatingSystemVersion is the replacement.
The page date changed from July 27 to August 21, 2026, and the section describing a planned Audit value for the Microsoft Defender Antivirus template for Linux was removed.
The documentation adds activation and removal of eSIM plans on supported Android Enterprise corporate-owned devices, including supported Android versions, activation-code and ICCID requirements, device-view steps, and required permissions.
The documentation now lists Accessibility appearance for iOS/iPadOS 17 and later and Liquid Glass for iOS/iPadOS 27 and later.
The macOS setup documentation now lists the Liquid Glass pane as skippable for macOS 27.0 and later.
The device details documentation now covers ICCID, EID, phone number, carrier, activation state, and SIM origin for supported Android Enterprise corporate-owned devices, including Android version requirements.
The documentation adds capabilities including unattended Remote Help for physical Windows devices, DDM for Apple VPP apps, additional protected apps, and new Android and Apple settings catalog controls.
The archive now documents EPM support for AVD single-session VMs, a Lenovo Device Orchestration link, four protected apps, and additional Windows settings catalog policies for Edge, Chrome, Windows AI, Firewall, and other components.
The documentation now explains that eSIMs are preserved by default on specified Android Enterprise corporate-owned devices and can be removed during a single-device wipe using the new device view.
The documentation now distinguishes Android unattended control, which requires a dedicated Intune-enrolled device, and adds Windows unattended remote sign-in for targeted physical corporate-owned devices. Both permissions must be explicitly assigned and scoped.
The monitoring guidance now lists log collection status—completed, failed, or in progress—instead of an Incident ID. It also says Microsoft can use logs collected after reproducing an issue during verbose log collection for investigation.
The endpoints documentation now states that Remote Sign-in for Remote Help on Windows requires Azure Virtual Desktop session host endpoints.
The prerequisites page no longer lists `powerlift-frontdesk.acompli.net` as a Diagnostic Endpoint.
The documentation now explains that Yes disables and No enables catch-up scans because the settings are named “Disable catch-up...”. Full-scan catch-up is disabled when not configured, while quick-scan catch-up is enabled by default; the scan triggers after two missed scheduled scans are also specified.
The documentation now states that a tenant can submit up to 1,000 Delete actions per day, cumulatively across individual actions, bulk actions, and Microsoft Graph requests. The limit also applies when Delete triggers Retire or Wipe.
The documentation now states that a tenant can submit up to 1,000 Retire actions per day, cumulative across individual, bulk, and Microsoft Graph API requests.
The documentation now states that individual, bulk, and Microsoft Graph Wipe requests share a cumulative tenant-wide daily limit of 500 actions.
The documentation now lists tenant-wide daily limits of 500 Wipe actions and 1,000 each for Retire and Delete. Counts are cumulative across individual, bulk, and Microsoft Graph submissions.
The new Intune single device page, offering a consolidated device management view, will become the default in the September (2609) release, replacing the legacy page. All management features remain, but admins should update documentation and familiarize themselves with the new interface beforehand.
The documentation now directs administrators to the “Personal Devices on Android Management API” report under Devices > Monitor and clarifies that reporting is not shown in the policy’s device assignment status or the device configuration tab.
The documentation now states that Sync from Windows Settings or the Intune admin center initiates both MDM and IME check-ins, including policy, app, script, and remediation processing. Sync progress can be viewed in the Device sync status tab.
The sync documentation now explains that selecting Sync triggers multiple workloads, including policy processing, app state updates, and scripts/remediations. Admins can monitor progress in the Device sync status tab. This behavior applies to iOS/iPadOS and Windows devices.
The sync behavior and Device sync status tab are documented as applying to Windows and iOS/iPadOS devices, rather than Windows only. The Preview new device view toggle remains required to see the described improvements.
Microsoft Intune will require iOS/iPadOS 18 or higher after Apple releases iOS/iPadOS 27 later this year. Organizations should check device compatibility and Intune reports to identify affected devices. Userless devices via Automated Device Enrollment have specific OS version requirements. Use Intune controls to manage OS versions.
Intune will support macOS 15 and later after macOS Golden Gate 27 release this year. Existing devices on macOS 14.x or below remain enrolled but new enrollments on these versions won't be allowed. Organizations should identify and upgrade affected macOS devices in Intune before the change.
The documentation for collecting device properties now states that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information. It identifies this as an accepted risk and calls for reviewing security and privacy implications.
The page metadata date changed from 08/02/2024 to 08/10/2026. No substantive documentation or product changes are shown.
The page’s metadata date changed from August 2, 2024, to August 10, 2026. No substantive content change is shown.
The guidance now links to the general Android and iOS store-app instructions without including direct CylancePROTECT Play Store or App Store URLs.
The article now only directs administrators to the iOS app configuration policy guidance; the Sophos Intercept X for Mobile iOS reference link was removed.
The documentation now states that apps targeting Android Enterprise fully managed (COBO) and corporate-owned personally enabled (COPE) devices can use Available assignments for either user or device groups, alongside the existing Win32 exception.
The BlackBerry Intune integration page no longer includes the link to BlackBerry UES documentation.
The documentation now notes that registry key inventory uses existing Device Inventory permissions and may expose sensitive device configuration information.