Scenarios
UpdatedUpdated Microsoft Intune documentation in intune/device-security/conditional-access-integration/scenarios.md.
Intune’s period was maintenance-heavy: 239 entries were updated, no Message Center items appeared, and many representative edits changed links, headings, terminology, or requirements formatting rather than documented service behavior. The meaningful exceptions concern security and platform changes: Controlled Configuration is explicitly headed to public preview; Apple’s 26.4 guidance redirects deprecated Intelligence controls to DDM; Strict Tunnel Mode is in development for Android; and the MTD connector guidance defines a tightly scoped Android role.
The In Development guidance explicitly says Intune is bringing Controlled Configuration (CC) to public preview for Microsoft Defender antivirus settings. When enabled, settings delivered by Intune or Microsoft Defender for Endpoint security settings management override Group Policy, Configuration Manager, local changes, and scripts. CC also extends Tamper Protection by allowing administrators to lock settings to defined values rather than only defaults. This is a policy-precedence change to plan for, not a general-
For iOS/iPadOS and macOS devices running version 26.4 and later, the guidance says Apple deprecated Intelligence-related settings in the MDM restrictions payload. It directs administrators to the DDM configurations released in March 2026. The deprecated list includes controls for Assistant, Dictation, Genmoji, Writing Tools, Siri, predictive keyboards, spell check, and related features. This is a platform-driven migration path, not a new Intune setting launch.
The roadmap says Microsoft Tunnel will add Strict Tunnel Mode for Android Enterprise devices enrolled through Android Management API, configured with Always On VPN. It will force traffic through the tunnel and block traffic if the connection drops, while an app exclusion list allows specified apps to bypass the tunnel. The guidance also describes support for unenrolled devices using Microsoft Tunnel for Mobile Application Management. The capability remains in development.
The connector documentation adds a fourth category, Mobile Threat Defense role, with a toggle that grants the selected partner exemptions from app suspension, hibernation, power restrictions, and user controls on Android Enterprise corporate-owned fully managed and corporate-owned work profile devices. Only one MTD partner can hold the role per tenant; the connector must be configured, its app targeted, and devices enrolled through Android Management API. Personally owned work profiles are not supported. The change
An added warning in Create Policy says discovery-script output is limited to 2,048 characters. Output beyond that may be truncated, producing invalid JSON and error 65009 during compliance evaluation. Administrators should keep output concise or split large rule sets across multiple policies. This is operational guidance about custom compliance, not a launch or support change.
Treat Controlled Configuration and Strict Tunnel Mode as preview or roadmap planning material, not general-availability announcements. For design reviews, account for Controlled Configuration’s precedence over Group Policy, Configuration Manager, and local changes; verify Android Management API and Always On VPN dependencies for Tunnel; and map Apple Intelligence controls to DDM for version 26.4 and later. Audit custom-compliance scripts against the 2,048-character output limit and error 65009 risk. The MTD role has a one-partner-per-tenant constraint and excludes personally owned work profiles; ordinary link and heading edits do not call for tenant changes.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/scenarios.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment.md.
Updated Microsoft Intune documentation in intune/device-enrollment/configure-multifactor-authentication.md.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
Updated Microsoft Intune documentation in intune/device-enrollment/setup-notifications.md.
Updated Microsoft Intune documentation in intune/device-enrollment/setup-time-grouping.md.
Updated Microsoft Intune documentation in intune/device-enrollment/windows/attestation.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-web-based-ios.md.
Updated Microsoft Intune documentation in intune/device-enrollment/add-corporate-identifiers.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-account-service-access.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-configurator-ios.md.
Updated Microsoft Intune documentation in intune/device-enrollment/add-corporate-identifiers.md.
Updated Microsoft Intune documentation in intune/device-enrollment/windows/create-bulk-package.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-macos.md.
Updated Microsoft Intune documentation in intune/device-enrollment/setup-enrollment-manager.md.
Updated Microsoft Intune documentation in intune/device-enrollment/create-device-limit-restrictions.md.
Updated Microsoft Intune documentation in intune/device-enrollment/create-device-limit-restrictions.md.
Updated Microsoft Intune documentation in intune/device-enrollment/create-device-limit-restrictions.md.
Updated Microsoft Intune documentation in intune/device-enrollment/create-device-limit-restrictions.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-macos.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-web-based-ios.md.
Updated Microsoft Intune documentation in intune/device-enrollment/setup-time-grouping.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-macos.md.
The guide preserves the required Managed apps permissions and explains that Application Manager has sufficient permissions and scope tags control administrator visibility.
The Delete device action article replaces iOS/iPadOS with Apple mobile while preserving the behavior: Delete triggers Retire for Apple mobile, macOS, and Windows; Android behavior continues to depend on enrollment type.
The MFA article now explicitly lists Android, iOS/iPadOS, macOS, and Windows support and states that users need Microsoft Entra ID P1 or later.
The article restructures requirements for Windows Autopilot device preparation, Android Enterprise, and tvOS/visionOS ADE, including the relevant enrollment-time device membership assignment permissions.
The backup and restore guide structures requirements for Entra-joined or hybrid-joined devices and supported Windows builds.
The bulk package guide moves Windows support and Microsoft Entra role requirements into a formal Requirements section.
The guide restructures prerequisites while retaining Android 10+, Google Mobile Services connectivity, regional and device support checks, and the existing tenant setup guidance.
The guide reformats its requirements while retaining Android 8.0+, Google Mobile Services connectivity, regional Android Enterprise availability, and device-support checks.
The dedicated-device guide restructures requirements while retaining Android 8.0+, Google Mobile Services connectivity, regional availability, and device support checks.
The JIT registration article restructures supported iOS/iPadOS enrollment scenarios and the compliance-policy requirement for JIT remediation.
The guide restructures Android Enterprise availability, tenant connection, and platform support prerequisites into dedicated requirement sections.
The article reformats requirements and explicitly lists Android, iOS/iPadOS, and Windows support plus Policy and Profile Manager or Intune Administrator role requirements.
The connection guide now groups country availability, Microsoft Entra account/mailbox, and Intune Administrator or custom organization read/update permissions as requirements.
The AOSP setup guide separates platform, licensing, and tenant requirements and states that specialized-device users need valid licenses.
The userless AOSP guide now separates platform, licensing, and tenant requirements and calls out valid licenses for specialized-device users.
The Vision Pro ADE guide separates device eligibility from Apple Business/School Manager portal, token, and Intune push-certificate requirements.
The direct macOS enrollment guide explicitly identifies macOS support and retains the requirement to unenroll a Mac from another MDM provider first.
The guide restructures Apple School Manager enrollment prerequisites, including supported Apple mobile platforms and portal-based setup.
The device-staging article separates the Android 8+ requirement and supported corporate-owned fully managed and work-profile enrollment methods from its overview.
The ADE guide now separately identifies new or wiped Apple Business Manager or School Manager devices and the required Apple portal access, token, and MDM push certificate.
The tvOS ADE guide separates eligible new or wiped Apple TV hardware from portal access, active Apple token, and Intune MDM push-certificate requirements.
The userless corporate Apple enrollment guide now presents platform support and setup prerequisites in requirement sections.
The guide explicitly identifies iOS/iPadOS 15+ support; devices on 14.9 and earlier use Company Portal user enrollment.
The macOS ADE guide now separates device eligibility from tenant requirements, including Apple portal access, a macOS ADE token, and an Intune MDM push certificate.
The iOS/iPadOS Configurator guide adds explicit platform and tenant-configuration requirement sections for MDM authority and Apple MDM push certificate.
The guide identifies support for iOS 13+ and iPadOS 13.1+ and restructures setup requirements.
The attestation guide explicitly lists supported Windows 10 and Windows 11 build levels, TPM 2.0+, and physical-device-only support.
The guide lists Android, iOS/iPadOS, macOS, and Windows support and confirms Intune Service Administrator can create, edit, delete, and reprioritize restrictions; custom and other built-in roles are read-only.
The guide lists Android, iOS/iPadOS, macOS, and Windows support and confirms Intune Administrator can create, edit, delete, and reprioritize platform restrictions while other built-in roles are read-only.
The guide now requires Intune Administrator to create enrollment notifications and calls out Intune branding and customization setup under Tenant administration > Customization.
The guide explicitly states iOS/iPadOS 15+ support, with earlier versions automatically using app-based enrollment, and identifies MDM authority and push-certificate prerequisites.
The guide now structures the Intune Administrator requirement separately and documents Update permission for creating or deleting DEM accounts and Read permission for viewing them.
The connector guide now groups Google Admin console and ChromeOS-device-management access with the Intune Service Administrator or equivalent custom-role requirement.
The education tutorial changes its bulk enrollment token reference from Roles and permissions to the renamed Requirements section.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
The Remote lock procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, Endpoint Security Manager, or a custom role as the supported role destinations.
The Restart procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, Endpoint Security Manager, or a custom role as the supported role destinations.
The restart procedure now uses direct Devices and All devices navigation and current Help Desk Operator, School Administrator, Endpoint Security Manager, and custom-role references.
The shutdown procedure now directs operators to Devices and All devices and presents Help Desk Operator, School Administrator, Endpoint Security Manager, and custom roles directly.
Replaces reference-style Intune admin center and role links with direct Devices > All devices links and named Help Desk, School Administrator, Endpoint Security Manager, and custom-role links.
The Fresh Start procedure now points directly to Devices and All devices and provides direct links for Help Desk Operator, School Administrator, Endpoint Security Manager, and custom roles.
The Full scan procedure replaces indirect portal references with direct Intune admin center links for Devices and All devices, and direct role links for Help Desk Operator, Endpoint Security Manager, and custom roles.
The Quick scan procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, Endpoint Security Manager, or a custom role as the supported role destinations.
The Retire procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, or a custom role as the supported role destinations.
The BitLocker key rotation steps now point directly to Devices and All devices and identify Help Desk Operator, Endpoint Security Manager, and custom roles as the role references.
The FileVault recovery-key procedure now links directly to Devices and All devices and identifies Help Desk Operator, Endpoint Security Manager, and custom roles.
Fresh Start instructions replace reference-style role and navigation links with direct Intune admin-center links.
The rename procedure now points directly to Devices and All devices and to current Help Desk Operator, School Administrator, and custom-role definitions.
The Reset passcode procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, or a custom role as the supported role destinations.
Autopilot Reset documentation replaces reference-style links with direct Intune admin-center Devices and All devices links.
Changes Autopilot Reset link-section comments and removes .md from built-in-role link targets.
Delete action instructions replace reference-style role and admin-center navigation links with direct links.
Deprovision action instructions replace reference-style role and navigation links with direct Intune admin-center links.
Both enable and disable Lost Mode steps now link directly to Devices and All devices, with direct Help Desk Operator, School Administrator, and custom-role references.
The Rename procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, or a custom role as the supported role destinations.
Replaces reference-style role and admin-center links with direct Microsoft Intune admin center, Devices, and All devices destinations.
Replaces reference-style role and admin-center links with direct Microsoft Intune admin center, Devices, and All devices destinations.
Disable Activation Lock instructions replace reference-style links with direct Intune admin-center and role links.
The Locate device procedure replaces generic portal and relative RBAC references with direct Devices and All devices links plus direct Custom role, Help Desk Operator, and School Administrator links.
The supervised-device sound procedure now links directly to Devices and All devices and to Help Desk Operator, School Administrator, and custom-role definitions.
The Remove apps and configuration procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, or a custom role as the supported role destinations.
The Remove passcode procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, or a custom role as the supported role destinations.
The Restore Managed Home Screen procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator, School Administrator, or a custom role as the supported role destinations.
The custom notification procedure now leads directly to Devices and All devices and provides direct role references for Help Desk Operator and custom roles.
The suspension procedure now points directly to Devices and All devices and names Help Desk Operator, School Administrator, and custom roles.
Updated Microsoft Intune documentation in intune/device-management/actions/wipe.md.
The shared-device logout procedure now links directly to the Devices and All devices pages and to Help Desk Operator and custom-role definitions.
The Remove user procedure replaces generic portal references with direct Microsoft Intune admin center links for Devices and All devices, and names Help Desk Operator or a custom role as the supported role destinations.
The enable and disable Lost Mode procedures now point directly to Devices and All devices and provide direct links for Help Desk Operator, School Administrator, and custom roles.
The procedure now links directly to Devices and All devices and names Intune Administrator and custom-role destinations; its 1,440-minute maximum remains documented.
Updated Microsoft Intune documentation in intune/device-management/actions/rotate-local-admin-password.md.
The macOS Recovery Lock procedure now uses direct Devices and All devices navigation and includes direct links for Intune Administrator, custom, Help Desk Operator, and School Administrator roles.
Updated Microsoft Intune documentation in intune/privacy/data-handling/data-storage-processing.md.
The device-action overview adds direct links for All devices, Device actions, Devices, and Bulk device actions instead of generic portal destinations.
The local administrator password procedure now directs admins through Devices and All devices and provides the custom-role destination for Remote tasks/Rotate Local Admin Password.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
The planned Android Managed Home Screen actions to temporarily suspend and restore the launcher were removed from the in-development article.
The in-development article adds planned macOS Wi-Fi MAC-randomization control, iOS/iPadOS 802.1X wired-network profiles, Android Enterprise Bluetooth-sharing control, Apple ADE enrollment-time grouping, and in-place renewal for eligible Cloud PKI issuing CAs.
A planned enhancement will make the Windows Sync device action perform a more comprehensive immediate synchronization across compliance, configuration policies, apps, and scripts instead of waiting for scheduled check-ins.
Intune plans custom macOS compliance checks using scripts and JSON rules, with results displayed alongside standard compliance reporting.
The planned iOS/iPadOS wired-network profile entry now links to the current wired-networks configuration article instead of a broken path.
The What's New entry adds that the Direct Android LOB feature is gradually rolling out, with full availability expected by mid-May 2026.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/enable-connector.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-wsl.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-wsl.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/custom-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-ios-ipados-settings.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/app-based-policies.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Clarifies that the Company Portal retries check-in before issuing retire after 30 days or Lost contact; other edits are wording-only.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-windows-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-administrator-settings.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/install.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/configure-noncompliance-actions.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-aosp-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/overview.md.
Updated Microsoft Intune documentation in intune/device-security/mobile-threat-defense/overview.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-linux-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-macos-settings.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-defender/configure-integration.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/ref-android-enterprise-settings.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/third-party-partners.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-json.md.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-custom-script.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/overview.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/overview.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/block-no-modern-auth.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/install.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/overview.md.
Corrects reporting prose and renumbers the compliance-reporting option step; the Noncompliant devices report remains under Devices > Monitor.
Changes Android support wording to “later,” corrects “device is reported,” and clarifies Google Mobile Services unavailable regions fail Play Protect evaluation.
Updated Microsoft Intune documentation in intune/device-security/compliance/create-policy.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/upgrade.md.
The Microsoft Tunnel upgrade article adds a May 1, 2026 release-notes section for version 20260407.1 and its image hashes.
The retirement procedure now uses direct Devices and All devices navigation and current Help Desk Operator, School Administrator, and custom-role references.
The Remote lock procedure now points directly to Devices and All devices and to current Help Desk Operator, School Administrator, Endpoint Security Manager, and custom-role definitions.
The FileVault recovery-key procedure now points directly to Devices and All devices and current Help Desk Operator, Endpoint Security Manager, and custom-role references.
The BitLocker key rotation procedure now points directly to Devices and All devices and current Help Desk Operator, Endpoint Security Manager, and custom-role references.
Updated Microsoft Intune documentation in intune/device-management/actions/shutdown.md.
The Locate device procedure now points directly to Devices and All devices and provides direct links for Help Desk Operator, School Administrator, and custom roles.
The passcode-reset procedure now points directly to Devices and All devices and to current Help Desk Operator, School Administrator, and custom-role definitions.
Changes Delete action link-section comments and removes .md from role-reference link targets.
The Activation Lock removal procedure reorganizes Intune admin center and role link references without changing the action flow.
The pause workflow now uses direct Devices and All devices navigation and directs Intune Administrator and custom-role references to their current destinations. The documented maximum pause remains 1,440 minutes.
The removal procedure now provides direct Devices and All devices navigation and current Help Desk Operator, School Administrator, and custom-role references.
Updated Microsoft Intune documentation in intune/device-management/actions/rotate-recovery-lock-passcode.md.
Updated Microsoft Intune documentation in intune/device-management/actions/suspend-managed-home-screen.md.
Updated Microsoft Intune documentation in intune/device-management/actions/sync.md.
The passcode-removal procedure now directs operators to Devices and All devices and to current Help Desk Operator, School Administrator, and custom-role definitions.
The restoration procedure now points directly to Devices and All devices and current Help Desk Operator, School Administrator, and custom-role definitions.
The deprovisioning procedure reorganizes its Intune admin center and role link references without changing the deprovisioning steps.
The supervised-device sound procedure now uses direct Devices and All devices navigation and current Help Desk Operator, School Administrator, and custom-role references.
Updated Microsoft Intune documentation in intune/device-management/actions/send-custom-notification.md.
Updated Microsoft Intune documentation in intune/device-management/actions/update-cellular-data-plan.md.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-wifi-settings-apple.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-wifi-settings-apple.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-wifi-settings-apple.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-wifi-settings-apple.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-wifi-settings-apple.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/ref-wifi-settings-apple.md.
Updated Microsoft Intune documentation in intune/whats-new/in-development.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-macos.md.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-platform-sso-scenarios-macos.md.
The shared-device user-removal procedure now provides direct Devices and All devices navigation and current Help Desk Operator and custom-role references.
The Logout current user procedure now points directly to Devices and All devices and provides direct links for Help Desk Operator and custom roles.
Updated Microsoft Intune documentation in intune/device-configuration/settings-catalog/configure-recovery-lock-macos.md.
Updated Microsoft Intune documentation in intune/whats-new/index.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/mam-android.md.
Updated Microsoft Intune documentation in intune/device-security/conditional-access-integration/create-app-based-policy.md.
Updated Microsoft Intune documentation in intune/device-security/microsoft-tunnel/mam-android.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-dmg-macos.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-lob-android.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-lob-ios.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-lob-macos.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/add-unmanaged-pkg-macos.md.
Updated Microsoft Intune documentation in intune/app-management/deployment/management-agent-macos.md.
Updated Microsoft Intune documentation in intune/device-management/tools/management-extension-windows.md.
Updated Microsoft Intune documentation in intune/device-enrollment/apple/setup-automated-macos.md.
Changes Endpoint analytics role references from relative ../fundamentals paths to absolute /intune/fundamentals paths for Help Desk, School Administrator, Read Only Operator, Endpoint Security Manager, and custom roles.
Changes Endpoint analytics role references from relative ../fundamentals paths to absolute /intune/fundamentals paths for Help Desk, School Administrator, Read Only Operator, Endpoint Security Manager, and custom roles.
Updated Microsoft Intune documentation in intune/endpoint-analytics/configure.md.
Updated Microsoft Intune documentation in intune/endpoint-analytics/index.md.
Updated Microsoft Intune documentation in intune/endpoint-analytics/index.md.
Updated Microsoft Intune documentation in intune/endpoint-analytics/index.md.
The Full scan procedure now points directly to Devices and All devices and provides direct links for Help Desk Operator, Endpoint Security Manager, and custom roles.
The Quick scan procedure now directs operators to Devices and All devices and to current Help Desk Operator, Endpoint Security Manager, and custom-role definitions.
Updated Microsoft Intune documentation in intune/privacy/enable-windows-diagnostic-data.md.
Changes Windows diagnostic-data custom-role and Help Desk Operator links from relative paths to absolute /intune/fundamentals paths.
The BitLocker documentation now identifies pre-boot PIN modification events in Event Viewer: Microsoft-Windows-Bitlocker-API/Management, Bitlocker PIN Modification Task category, Event ID 789.
Updated Microsoft Intune documentation in intune/user-help/vpn/microsoft-tunnel-android.md.
Updated Microsoft Intune documentation in intune/user-help/vpn/microsoft-tunnel-android.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/configure-per-app-vpn-android.md.
Updated Microsoft Intune documentation in intune/device-configuration/templates/configure-per-app-vpn-android.md.
Updated Microsoft Intune documentation in intune/fundamentals/licensing/unlicensed-admins.md.
Removed Microsoft Intune documentation in intune/fundamentals/tenant-administration/classic-groups.md.
Removed Microsoft Intune documentation in intune/fundamentals/device-lifecycle.md.
Updated Microsoft Intune documentation in intune/privacy/data-handling/data-storage-processing.md.
Removes the obsolete Graph link reference block and renames the admin-center link section in Collect diagnostics documentation.
Collect diagnostics instructions replace reference-style links with direct Intune admin-center navigation links.
The remediation procedure now points directly to Devices and All devices and identifies Help Desk Operator, School Administrator, and custom roles for the Run Remediation action.
Updated Microsoft Intune documentation in intune/device-management/actions/run-remediation.md.
Changes cleanup-rule role references from relative paths to absolute /intune/fundamentals paths for Help Desk, School Administrator, Endpoint Security Manager, and custom roles.
Updated Microsoft Intune documentation in intune/governance/configure-cleanup-rules.md.
Updated Microsoft Intune documentation in intune/governance/configure-cleanup-rules.md.
Updated Microsoft Intune documentation in intune/privacy/index.md.
Removed Microsoft Intune documentation in intune/governance/compliance-and-regulatory-alignment.md.
The In development entry for Android Enterprise Bluetooth sharing updates its Settings catalog and Android settings-list links to their current device-configuration locations.
Converts numbered Notes, included hotfixes, and dependency changes into bullet lists; the listed KBs and dependencies remain the same.
A new checklist documents installing Configuration Manager current-branch update 2603, including early-ring opt-in, hierarchy and site-system behavior, prerequisites, backup, replication, ADK, and update-installation checks. The update applies to sites on version 2409 or later.
Uses “Azure Virtual Machine Scale Set,” “Arm64,” and “nonfunctional” terminology in release notes while retaining the documented 2603 fixes.
The 2603 What's New article corrects all installation and post-update checklist links from the 2509 checklist to the new 2603 checklist.
The supported-versions table now lists Configuration Manager 2603 (5.00.9146.1000), with an early-ring availability date of May 5, 2026 and support through November 5, 2027. Its availability-date note now points to the 2603 checklist.
The release-notes index adds a link to the Configuration Manager 2603 What's New article.
The release-notes page updates its troubleshooting link to the Configuration Manager welcome page.
The supported-versions page retains its explanation that availability dates refer to early-ring release but removes the hyperlink to the 2603 early-ring checklist section.
The 2603 What's New article now says Microsoft SQL Server Management Objects and System CLR Types move from SQL Server 2014 versions to SQL Server 2025 versions (SMO 17), replacing the prior SQL Server 2016 wording.
The checklist changes early update ring wording from “opt-in” to “opt in” without changing the described process.
Expands the CMGv2 acronym in the outbound-traffic alert and Total Outbound data metric description to Azure Virtual Machine Scale Sets.
The 2603 What's New article corrects an ARM64 version reference and a troubleshooting URL.
The Configuration Manager 2603 installation checklist removes the SQL Server 2012 Native Client prerequisite section while retaining the SQL ODBC driver requirement.
Updated Microsoft Intune documentation in intune/remote-help/plan.md.
Updated Microsoft Intune documentation in intune/remote-help/plan.md.
The Remote Assist procedure now uses direct Intune navigation for Devices and All devices and current role references.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-scopes.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-scopes.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query-multiple-devices.md.
Updated Microsoft Intune documentation in intune/advanced-analytics/device-query.md.
Device Scopes documentation changes links for custom roles and built-in operator roles to absolute Intune paths.
Device Query documentation changes custom-role and Help Desk Operator links to absolute Intune paths.
Device Query multiple-devices documentation changes custom-role and Help Desk Operator links to absolute Intune paths.