Editor's note (July 2026): This post has been updated since its original publication. Content related to Intune Endpoint Privilege Management capabilities for system-level network configuration has been removed.
AI agents are beginning to act on behalf of users, interact with company data, and even make decisions independently. Trusting AI depends on three endpoint fundamentals: they must be compliant, up to date, and secure from the moment they enroll. This month’s new capabilities for Intune emphasizes these important checkpoints.
Keep applications current and reduce vulnerability exposure
Keeping applications up to date sounds straightforward until you're managing hundreds of endpoints and dozens of application versions. Manual packaging processes lead to version drift and inconsistent application states, which makes vulnerability remediation harder and security posture less predictable.
Microsoft Intune Enterprise Application Management (EAM) helps organizations move away from fragmented workflows toward a more unified, cloud-native approach, with deployments, updates, and policy configuration in one place. EAM auto-updates is now generally available and automatically helps keep managed applications on the latest incremental release, such as 4.1 to 4.2, without manual packaging or admin intervention. This helps limit exposure to known vulnerabilities between full version upgrade cycles.
Figure 1: View of the Intune admin center showing how to apply auto-updates for application management.But even with EAM auto-updates helping shrink the vulnerability window, new risks may still arise between update cycles. That's where the Vulnerability Remediation Agent comes in. Operating within Microsoft Security Copilot and now in public preview, the agent draws on Microsoft Defender Vulnerability Management to prioritize Common Vulnerabilities and Exposures (CVEs) across your Intune-managed Windows devices and apps.
When the agent runs, it ranks what matters most so you are not starting from a blank CVE list. Recommendations are prioritized by Common Vulnerability Scoring System (CVSS) score, exposure impact, affected device count, and appear directly in the Intune admin center on both the Agents page and the Endpoint security page. When IT admins examine any recommendation, they will see the related CVE count, a summary of the impact assisted by Copilot, suggested actions, the systems affected, the devices exposed, and detailed guidance on how to fix the issues. After taking action, administrators can mark the recommendation as completed.
The Vulnerability Remediation Agent also operates under a dedicated Microsoft Entra agentic identity, provisioned during setup, rather than under a human user account. Admins delegate the required read permissions to that identity in the Intune and Defender admin centers before the first run. This keeps the agent's scope clearly bound and gives admins a clean audit trail of what it accessed and when. For more information, read our latest blog on Triage vulnerabilities faster with the Vulnerability Remediation Agent.
Extend least-privilege controls to shared devices
Keeping apps current and staying ahead of known vulnerabilities reduces the attack surface. But risk does not only come from unpatched software; it also comes from who has access and how that access gets granted in the moment. This month, we’ve made support approval requests for non-primary users generally available in Intune Endpoint Privilege Management. This capability helps address how elevations work in environments that do not follow a single-user-per-device model.
Support approval requests for non-primary users extends file elevation requests to any user on a device rather than just the primary enrollee. For example, in organizations running shared workstations across rotating shifts, elevation requests from non-primary users can push IT to create workarounds that can erode a secure least-privilege posture over time. The new capability for support approval requests changes that by routing elevation requests through an auditable workflow regardless of who has signed in, keeping IT in control of every elevation decision.
Faster, more complete enrollment across all platforms
In the June release of Intune, iOS/iPadOS and macOS automated device enrollment (ADE) profiles will move to a new infrastructure that enables Intune to speed up the delivery of new features. This update rebuilds the enrollment policies experience for Apple ADE devices, reorganizing authentication and removing outdated settings to share more granular policy controls.
The new experience completes Intune support of enrollment time grouping (ETG) across all platforms with the addition of iOS/iPadOS and macOS corporate device enrollment with ADE. ETG allows policies and apps targeted to a static group to apply at enrollment time for supported enrollment methods, so critical configurations (i.e., policies and apps targeted to the specific static group) are already in place when a user reaches the home screen. Devices arrive more secure, and users can be productive right away without waiting for policies to catch up. For a full walkthrough of the new experience, see the New iOS/iPadOS, visionOS, tvOS and macOS ADE enrollment policies experience blog on Microsoft Tech Community.
Intune: Myth vs. Reality
We hope you enjoyed last month’s reality check on app migration. This month, we’re continuing the conversation on applications with a myth focused on app refresh data.
Myth: Intune takes seven days for Discovered apps to refresh app inventory data.
Reality: That seven-day figure was an oversimplification that stuck. No one refresh number existed for every app on every platform, and that seven-day calculation did not apply to the apps an organization’s workforce uses most. Win32 apps listed in Add/Remove Programs collect data every 24 hours, while Windows store apps and apps on non-Windows platforms can have refresh cycles of up to seven days. And now it's getting even better. The new app inventory experience in the All Apps page refreshes its data multiple times per day for active devices, including both Win32 and Windows store apps. This report also shows details that the earlier report did not capture, including install location, app size, and uninstall commands for each app.
How: Intune continues to enhance its underlying platform infrastructure, resulting in a fresher, more detailed app inventory. This comes from sustained improvements across three fronts: a reconfigured data platform that collects app data; reduced latency that moves data faster; and reporting updates that brings it into the console.
To learn more, take a closer look at the investments we’re making to support faster, more predictable delivery to devices. You can also see how app data is collected and refreshed in the enhanced app inventory experience. Follow the What's New in Microsoft Intune blog each month to read how these improvements are reflected in the console.
The work behind each capability update is the same whether it shows up in a CVE list, an elevation workflow, or an enrollment screen. AI agents can only move as fast as the foundations beneath them allow. EPM and EAM are now part of Microsoft 365 E5 from July 1. If you missed the December announcement on what that means for your organization, it is worth a read before these capabilities land in your tenant.
Stay up to date! Bookmark the Microsoft Intune Blog and follow us on LinkedIn or @MSIntune and @IntuneSuppTeam on X to continue the conversation.