Starting Configuration Manager version 2403, Microsoft Azure Active Directory is renamed to Microsoft Entra ID within Configuration Manager.
Automated diagnostic Dashboard for Software Update Issues
A new dashboard is added to the console under monitoring workspace, which shows the diagnosis of the software update issues in your environment this feature can easily identify any issues related to software updates. You can fix software update issues based on troubleshooting documentations.
Special credit to Shankar Subramanian and Smita Jadhav for their details and troubleshooting notes.
For more information, see Software update health dashboard.
Users can now use the global search box in CM console, which streamlines the search experience and centralizes access to information. This feature enhances the overall usability, productivity and effectiveness of CM. Users no longer need to navigate through multiple nodes or sections/ folders to find information they require, saving valuable time and effort.
For more information, see Improvements to console search.
You can now organize scripts by using folders. This change allows for better categorization and management of scripts. Full Administrator and Operations Administrator roles can manage the folders.
For more information, see Folder support for scripts.
HTTPS or Enhanced HTTP should be enabled for client communication from this version of Configuration Manager
HTTP-only communication is deprecated, and support is removed from this version of Configuration Manager. Enable HTTPS or Enhanced HTTP for client communication.
For more information, see Enable site system roles for HTTPS or Enhanced HTTP. and Deprecated features
Windows Server 2012/2012 R2 operating system site system roles are not supported from this version of Configuration Manager
Starting 2403, Windows Server 2012/2012 R2 operating system site system roles aren't supported in any CB releases. Clients with extended support (ESU) will continue to support.
For more information, see Supported-operating-systems-for-site-system-servers.
Any configured Resource access profiles and deployments block Configuration manager upgrade. Consider deleting them and moving the co-management workload for Resource Access (if co-managed) to Intune.
For more information, see FAQ and Resource access policies are no longer supported.
A new parameter SoftwareUpdateO365Language is now added to PowerShell Save-CMSoftwareUpdate cmdlet. Customers now don't have to check a specific language in the SUP Properties (causing a metadata download for that language for all updates).
PowerShell Commandlet: Save-CMSoftwareUpdate – SoftwareUpdateO365Language <language name> (<region name>)"
Note
Languages need to be in O365 format to be consistent with Admin Console UI. E.g. "Hungarian (Hungary)".
Configuration Manager operating system deployment support is now added on Windows 11 ARM 64 devices. Currently Importing and customizing Arm 64 boot images, Wipe and load TS, Media creation TS, WDS PXE for Arm 64 and CMPivot is supported.
Administrators while deploying the "Install Software Package" via Dynamic variable with "Continue on error" unchecked to clients, will not be notified with task sequence failures even if package versions on the distribution point are updated.
For more information, see Options for Install Application.
The option to upgrade Configuration Manager 2403 is blocked if you're running cloud management gateway V1 (CMG) as a cloud service (classic). All CMG deployments should use a virtual machine scale set.
For more information, see Check for a cloud management gateway (CMG) as a cloud service (classic).
Learn about support changes before they're implemented in removed and deprecated items.
- System Center Update Publisher (SCUP) and integration with ConfigMgr planned end of support Jan 2024.
For more information, see Removed and deprecated features for Configuration Manager.
This release includes the following improvements to BitLocker:
- Starting in this release, this feature ensures proper verification of key escrow and prevents message drops. We now validate whether the key is successfully escrowed to the database, and only on successful escrow we add the key protector.
- This feature now prevents a potential data loss scenario where BitLocker is protecting the volumes with keys that are never backed up to the database, in any failures to escrow happens.
For more information on BitLocker management, see Deploy BitLocker management. and Plan for BitLocker management..
- From this version of Configuration Manager, the Windows 11 readiness dashboard shows charts for Windows 23H2.
- Defender Exploit Guards policy for controlled folder now accepts regex in the file path for apps. For example, [C:\Folder\Subfolder\app?.exe] [C:\Folder1\Sub*Name]
At this time, version 2403 is released for slow ring (all in console update), Baseline will be updated in portal soon.