<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ct-p/microsoftintune</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Thu, 30 Apr 2026 23:56:31 GMT</pubDate>
    <dc:creator>microsoftintune</dc:creator>
    <dc:date>2026-04-30T23:56:31Z</dc:date>
    <item>
      <title>App Enforced Restrictions not working on Chrome</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/app-enforced-restrictions-not-working-on-chrome/m-p/4516309#M23409</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;Anyway, a strange one here.&lt;/P&gt;&lt;P&gt;We have implemented App Enforced Restrictions on unmanaged / BYOD macOS devices.&lt;/P&gt;&lt;P&gt;This seems to have taken effect on Edge and Safari browsers but not Chrome.&lt;/P&gt;&lt;P&gt;Is there anything we can do to resolve this or force BYOD macOS to use Edge?&lt;/P&gt;&lt;P&gt;Info appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 18:14:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/app-enforced-restrictions-not-working-on-chrome/m-p/4516309#M23409</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-04-30T18:14:53Z</dc:date>
    </item>
    <item>
      <title>What’s new in Microsoft Intune – April</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-april/ba-p/4493135</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;April's Intune updates focus on three areas administrators have consistently asked us to improve: fresher device data, streamlined identity foundations across platforms, and simpler management for non-traditional endpoints. This month includes advancements in Windows app inventory, Linux single sign-on (SSO), and expanded enrollment and control for Apple devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Higher‑frequency app inventory updates &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;for Windows devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IT administrators monitoring applications often rely on a feature known as&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/app-discovered-apps" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Discovered apps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. With the general release of enhanced app inventory &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;capabilities in the “All Apps” tab, this function provides more detailed and more frequently refreshed inventory data. Some platforms refresh Discovered apps inventory every seven days. App inventory now updates Windows apps on a more frequent schedule, uploading only changes since the last sync, which can help limit additional network usage.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;App inventory data is updated across the fleet, with most active, healthy Windows devices refreshed multiple times per day.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Besides more frequent data, the range of properties collected by the inventory agent has expanded. Install paths, install dates, uninstall commands, estimated size, architecture, and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;per-user install scope are now included. Store-specific identifiers and supported languages, which were not part of the Discovered apps before, are also included here. IT admins also benefit with how inventory collection takes place across all users who have accessed the device and not just the logged-in user, helping reduce issues of applications coming and going as users change.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To take advantage of app inventory, a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/?tabs=sc-search-filter%2Csc-reporting" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;new device configuration policy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;should be set up based on&amp;nbsp;Properties&amp;nbsp;Catalog and assigned to corporate-owned Windows 11 devices enrolled in&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/fundamentals/what-is-entra" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Entra ID&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. Once configured, inventory data will start coming in on subsequent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;check-ins.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Modernized&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;SSO&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Linux&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;endpoints&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The new sign-in process offers Linux users a low-friction and phishing-resistant sign-in option similar to Windows and macOS, alongside a smaller footprint and more integrated use of Entra ID technology.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;This introduces advanced SSO functionality for Linux endpoints, utilizing the Microsoft Identity Broker. This is a modern C++ identity broker that integrates Linux devices with Microsoft Entra ID and replaces the legacy Java broker for Intune. To learn more visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/sso-linux?tabs=password-auth%2Cdebian-install%2Cdebian-update%2Cdebian-uninstall%2Cdebian-sc-example" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft single sign-on for Linux&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Microsoft Identity Broker supports a more integrated trust model between the endpoint and Microsoft Entra ID by using full device join to issue device-bound authentication tokens, going beyond what basic enrollment supports. This way, admins can employ Phishing-Resistant Multi-Factor Authentication (PRMFA ) to authenticate, which includes certificate-based authentication, smart cards, and Personal Identity Verification (PIV) enabled security keys. Additionally, the same SSO flow now works on iOS as it does on Windows and macOS, where Microsoft Authentication Library (MSAL) APIs can provide SSO for non-Microsoft applications. For configuration details about SSO on Linux with Entra ID, read our&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-device-registration-tool-linux" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device Registration Command Tool for Linux&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; instructions.&amp;nbsp;It's a win for admins and end users alike:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;End users&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;receive a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-device-registration-tool-linux" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Primary Refresh Token (PRT)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and see fewer credential prompts, improving the sign-in experience.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;IT admins&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; get full Conditional Access and device compliance through Entra ID join, plus a smaller installation package and reduced background authentication tasks now that the Java runtime dependency is gone.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Expanded management capabilities for Apple devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune has worked to enhance endpoint management for iOS, iPadOS, macOS, visionOS, and tvOS devices in enterprise environments. In this section, we will look at some of the capabilities released this month to help simplify management of Apple devices at scale and set up end users for success with an identity-ready setup.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;visionOS&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; and tvOS enrollment, including government cloud&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Expanding Intune Plan 2 specialty devices, automated device enrollment (ADE) for visionOS and tvOS is now available, including Government Community Cloud High, all government cloud tenants, and will be included from July 1 for&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft 365 E3 and E5 licenses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; Organizations managing large-scale Apple device deployments in unattended and shared-use scenarios can now leverage userless ADE for visionOS and tvOS. This includes devices like Apple TVs in conference rooms, patient rooms, or retail locations, and Vision Pro headsets deployed to training and design teams. These devices can now be enrolled and managed without user affinity or individual sign-in.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;After enrollment, visionOS and tvOS devices can be remotely deleted, retired, restarted, renamed, or synced, individually or in bulk. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Admins can send down configuration profiles via custom file upload for these devices. They can also restrict enrollment by specifying if these operating systems can enroll into their organization.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;With&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/device-enrollment/setup-time-grouping" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;enrollment time grouping&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; within the ADE enrollment policy, administrators will have the ability to group devices at enrollment time within the new ADE enrollment policies experience, helping ensure critically assigned policies, scripts, and apps start installation during Setup Assistant. Read our&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-iosipados-and-macos-ade-enrollment-policies-experience/4393531" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;blog post about the new iOS/iPadOS and macOS ADE enrollment policies experience&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; to learn more.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Example of how to create&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;visionOS&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;/tvOS enrollment policy using ADE in the Intune admin cente&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;r.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;H5 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Tighter control over Managed Apple Accounts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Rounding out this month's Apple updates, Intune now allows organizations to choose whether&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.apple.com/en-gb/guide/business/axm53xk34bq/web" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Managed Apple Accounts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can be used on any Apple device or only on organization-owned devices. In practice, this means corporate identities stay on corporate hardware, and personal Apple Accounts can be blocked from signing in to organization-owned devices entirely. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;This is especially important in regulated sectors, such as financial services, where organizations need to prevent corporate data from residing on unmanaged,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;non-organization-owned devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune: Myth vs. Reality (new &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;segment&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Starting this month, the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;What’s New in Intune&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;blog includes a new segment,&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune: Myth vs. Reality&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;. This series will address common assumptions about endpoint management and how Intune works in practice.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;This month’s topic: Change-based delivery speed and responsiveness&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Myth: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;App and policy changes take 8-hours to apply&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Reality:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Intune processes 90% of device changes in less than an hour&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;How&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;The commonly cited “8‑hour” timing reflects a routine maintenance check‑in — not how Intune delivers meaningful changes today. Most high-impact app deployments, policy updates, and device actions are delivered through prioritized, change‑based delivery paths that typically reach online devices much faster. By distinguishing these time-sensitive changes from routine maintenance activity and handling them differently, Intune helps reduce the likelihood that important changes aren’t unnecessarily delayed.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;To go deeper, &lt;A href="https://aka.ms/IntuneMythSlowSync" data-outlook-id="1c89dcdc-4b75-4243-bc95-633b94823ce9" target="_blank"&gt;read our latest blog&lt;/A&gt;, which explains how Intune processes updates at scale, including priority‑aware check‑ins, push‑based signaling, and platform‑specific optimizations that improve consistency and responsiveness across devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;That’s a wrap for April. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Whether you were interested in device data improvements, Apple enrollment expansions, or the Myth vs. Reality section, we'd love to hear your thoughts in the comments below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 19:21:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-april/ba-p/4493135</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-04-30T19:21:31Z</dc:date>
    </item>
    <item>
      <title>Speed where it matters: How Microsoft Intune helps IT prioritize time-sensitive actions</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/speed-where-it-matters-how-microsoft-intune-helps-it-prioritize/ba-p/4515942</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Albert Cabello Serrano | Principal Product Manager - Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;A closer look at how Intune delivers updates to devices and the investments we’re making to help important changes move faster and more predictably.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;A common concern we hear from IT admins is, “How quickly will this change actually reach my device?” In many cases, the answer is much faster than expected. Today, &lt;STRONG&gt;90%&lt;/STRONG&gt; of policy updates, app deployments, and device actions in Intune are completed in under an hour.&lt;/P&gt;
&lt;P&gt;So where does the idea of “8-hour latency” come from? That number reflects a routine maintenance check-in used when devices are idle - not how Intune processes meaningful changes. Intune uses notification-based, priority-driven processing so that high-impact actions,&amp;nbsp;&lt;EM&gt;like security policy changes or remediation steps, &lt;/EM&gt;are handled promptly and reliably as possible.&lt;/P&gt;
&lt;P&gt;In this context, latency isn’t about making every action instant - it’s about providing predictable, prioritized delivery at global scale. The sections below break down how Intune prioritizes different types of updates and recent investments that are helping time-sensitive changes complete more consistently.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;How Intune delivers changes to devices&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Cloud-based device management is designed for real-world conditions; devices are not always online, fully charged, or on stable networks. Intune uses an eventual consistency model so devices can continue to be productive while converging to the desired state over time, without management actions unnecessarily disrupting users or workflows.&lt;/P&gt;
&lt;P&gt;Because devices operate in different conditions, not all device activity is handled the same way. To manage change reliably at scale, Intune uses different types of device check-ins depending on what needs to happen.&lt;/P&gt;
&lt;H2&gt;Types of device check-ins in Intune&lt;/H2&gt;
&lt;P&gt;Device check-ins generally fall into several categories, each triggered by a different type of action:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Single&lt;/STRONG&gt;‑&lt;STRONG&gt;device check&lt;/STRONG&gt;‑&lt;STRONG&gt;ins:&lt;/STRONG&gt; Occurs when an admin or user initiates an action on a specific device, such as starting a device action or installing an app from the Intune Company Portal.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Change&lt;/STRONG&gt;‑&lt;STRONG&gt;based check&lt;/STRONG&gt;‑&lt;STRONG&gt;ins:&lt;/STRONG&gt; Push‑triggered check‑ins used to deliver meaningful changes to devices as soon as possible.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Client&lt;/STRONG&gt;‑&lt;STRONG&gt;initiated check&lt;/STRONG&gt;‑&lt;STRONG&gt;ins:&lt;/STRONG&gt; Background activity that helps keep devices healthy, such as when a user signs in to a device or when malware status changes.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Maintenance check-ins: &lt;/STRONG&gt;Scheduled syncs that occur at predetermined intervals and can be client or service-initiated, depending on the platform. These typically occur approximately every 8 hours.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Regardless of what triggers a check-in, any pending changes will be applied to the device when it occurs.&lt;/P&gt;
&lt;H2&gt;What happens when an admin makes a change&lt;/H2&gt;
&lt;P&gt;When an admin makes a change in Intune, such as updating a &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/intune-service/protect/device-compliance-get-started" target="_blank" rel="noopener"&gt;device compliance policy&lt;/A&gt;, &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/add-microsoft-store" target="_blank" rel="noopener"&gt;deploying an app&lt;/A&gt;, or &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-management/actions/?tabs=windows" target="_blank" rel="noopener"&gt;setting a configuration, &lt;/A&gt;Intune identifies the devices impacted by that change and initiates a change‑based check‑in for affected devices.&lt;/P&gt;
&lt;P&gt;For online devices, Intune sends a push notification prompting the device to establish a management session with the service, apply the change, and report enforcement status back to Intune. If a device is offline or unreachable, the change is applied when the device next checks in through available mechanisms.&lt;/P&gt;
&lt;H2&gt;Four investments that help critical updates move forward faster&lt;/H2&gt;
&lt;P&gt;The following product changes focus on reducing device‑change latency by shortening the time between an admin action in Intune and enforcement on the device, especially during peak or constrained conditions.&lt;/P&gt;
&lt;H3&gt;1. Check-in prioritization focused on what matters most&lt;/H3&gt;
&lt;P&gt;Not all device activity carries the same urgency. Routine background check-ins can compete for service resources with devices that have important pending changes, such as compliance updates, remediation actions, or administrator-initiated configuration changes.&lt;/P&gt;
&lt;P&gt;Intune evaluates the potential impact of delaying a device check-in on security posture, compliance state or user productivity, and dynamically prioritizes processing accordingly. This real-time prioritization model ensures that high-impact actions move forward without being delayed by lower‑impact background activity. Prioritization adapts as conditions change, helping important updates reach devices more quickly and predictably without being delayed by lower-impact background activity.&lt;/P&gt;
&lt;H3&gt;2. Built-in resilience when multiple changes occur in quick succession&lt;/H3&gt;
&lt;P&gt;Change activity often happens in bursts, with several related updates occurring in rapid succession. These periods of activity may be driven by operational needs or background processes, and can involve adjusting assignments, updating multiple policies, or rolling out configuration changes across the same set of devices.&lt;/P&gt;
&lt;P&gt;Intune dynamically coordinates notifications, so that each change requiring action triggers a corresponding device notification, even during high-activity periods. This helps improve consistency when applying multiple updates and reduces delays across consecutive changes on devices.&lt;/P&gt;
&lt;P&gt;Over the next several months, these improvements will extend to additional payloads delivered through the Intune Management Extension (IME), including scripts, Win32 apps, and custom compliance across both Windows and macOS platforms.&lt;/P&gt;
&lt;H3&gt;3. More timely notifications on Windows&lt;/H3&gt;
&lt;P&gt;Intune notifies devices to check-in when changes require action. If the device is offline, on an unstable network, or low on battery, notifications may be delayed. This can cause missed check-ins or delayed actions.&lt;/P&gt;
&lt;P&gt;When notification services are delayed, blocked, or unavailable, devices may fall back to scheduled maintenance check‑ins to apply changes. For timely delivery, required notification service endpoints need to remain accessible so devices can receive management signals when updates occur.&lt;/P&gt;
&lt;P&gt;On Windows devices, Intune complements the Windows Notification Service (WNS) with the same notification protocol that powers Microsoft Teams via the Intune Management Extension. This helps increase the likelihood that devices receive management notifications when they’re online and reachable, improving visibility into whether policy updates or device actions have reached their destination.&lt;/P&gt;
&lt;P&gt;For more information, see the &lt;A class="lia-external-url" href="https://aka.ms/intune-endpoints" target="_blank" rel="noopener"&gt;network endpoints for Intune documentation&lt;/A&gt;.&lt;/P&gt;
&lt;H3&gt;4. Optimized maintenance check-ins for iOS devices&lt;/H3&gt;
&lt;P&gt;Background check-ins are still important to keep devices healthy when nothing else is going on. Unlike Windows devices, iOS devices don’t have client scheduled check‑ins and depend on service‑initiated maintenance check‑ins to ensure device health and compliance.&lt;/P&gt;
&lt;P&gt;During peak usage periods, these maintenance check‑ins can account for a significant portion of overall traffic, which can compete with devices that require immediate updates.&lt;/P&gt;
&lt;P&gt;Intune considers device activity in the scheduling of maintenance check‑ins during peak activity, making room for higher‑impact updates, while continuing to ensure devices check in regularly. This helps manage traffic and improves responsiveness when applying policies or remediation actions.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;What this means for you&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;For IT admins:&lt;/STRONG&gt; No additional configuration or workflow changes are required to benefit from Intune’s built-in notification system. When bidirectional communication with &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/endpoints" target="_blank" rel="noopener"&gt;notification service endpoints&lt;/A&gt; is open, devices can receive and act on updates as they become available.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For security teams:&lt;/STRONG&gt; Faster delivery of device changes helps shorten the time between a policy update, a tightened Conditional Access rule, an updated compliance baseline, and a remediation action. For Zero Trust frameworks, where posture signals drive access decisions, this helps narrow the window during which a device could be out of compliance or vulnerable. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Together, these improvements reflect how Intune is evolving into a more intelligent, priority-aware system. Rather than making every action instant, the focus is on prioritizing high-impact updates so they are delivered without unnecessary delays. This approach is expanding across a number of scenarios to provide a more consistent and predictable experience, helping reduce delays for key updates.&lt;/P&gt;
&lt;H2&gt;Resources to learn more&lt;/H2&gt;
&lt;P&gt;For another perspective on this topic, read an MVP’s take on demystifying the “8-hour” timing myth in this &lt;A class="lia-external-url" href="https://www.linkedin.com/pulse/intune-timing-demystified-why-8hour-delay-myth-jon-jarvis-bzdge" target="_blank" rel="noopener"&gt;LinkedIn post&lt;/A&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You can also&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-occasion" href="https://techcommunity.microsoft.com/event/microsoftintuneevents/intune-timing-demystified-what-really-happens-behind-the-scenes/4490580" target="_blank" rel="noopener" data-lia-auto-title="watch the recent Tech Takeoff" data-lia-auto-title-active="0"&gt;watch the recent Tech Takeoff&lt;/A&gt; about this same topic to learn more about these improvements.&lt;/P&gt;
&lt;P&gt;Also, in the April edition of the &lt;A class="lia-external-url" href="https://aka.ms/IntuneWN2604" target="_blank" rel="noopener"&gt;What's New in Intune blog&lt;/A&gt;&lt;EM&gt;,&lt;/EM&gt; we introduced a new segment called &lt;STRONG&gt;Myth vs. Reality. &lt;/STRONG&gt;This post is part of that series. To stay current on new capabilities and updates as they ship, follow the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="What's New in Microsoft Intune blog" data-lia-auto-title-active="0"&gt;What's New in Microsoft Intune blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;What myth should we debunk next? Leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt; or &lt;A class="lia-external-url" href="https://aka.ms/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 15:47:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/speed-where-it-matters-how-microsoft-intune-helps-it-prioritize/ba-p/4515942</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-04-30T15:47:22Z</dc:date>
    </item>
    <item>
      <title>Reporting on Device CPU and Memory</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/reporting-on-device-cpu-and-memory/m-p/4515752#M23402</link>
      <description>&lt;P&gt;I have a requirement to produce a monthly report on all our Intune managed Windows devices and the applications they have installed.&amp;nbsp; I have written a script that is able to report on UPN, Device Name, Manufacturer, Model, Serial Number, OS, Total HHD and Free space along with all the applications installed.&amp;nbsp; I am however unable to output the devices CPU and Memory details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried using the Get-MgBetaDeviceManagementManagedDevices with the ProcessorArchitecture and PhysicalMemoryInBytes parameters but these just report 0 or NULL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to report on the CPU and Memory from Intune?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 07:31:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/reporting-on-device-cpu-and-memory/m-p/4515752#M23402</guid>
      <dc:creator>StuartW</dc:creator>
      <dc:date>2026-04-29T07:31:50Z</dc:date>
    </item>
    <item>
      <title>SCCM PXE Boot Deep Dive – Backend Flow &amp; DP Migration</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager/sccm-pxe-boot-deep-dive-backend-flow-dp-migration/m-p/4515258#M375</link>
      <description>&lt;P&gt;&lt;STRONG&gt;SCCM PXE Boot Deep Dive – Backend Flow &amp;amp; DP Migration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I recently worked on a Distribution Point migration and noticed PXE requests were still routing to the old DP due to DHCP/IP helper configuration.&lt;/P&gt;&lt;P&gt;I put together a deep dive explaining:&lt;/P&gt;&lt;P&gt;PXE flow (DHCP and TFTP sequence)&lt;/P&gt;&lt;P&gt;Role of Distribution Points&lt;/P&gt;&lt;P&gt;What changes during DP migration&lt;/P&gt;&lt;P&gt;Common failure points&lt;/P&gt;&lt;P&gt;One key takeaway:&lt;/P&gt;&lt;P&gt;PXE issues are almost always network and routing related, not SCCM itself.&lt;/P&gt;&lt;P&gt;Curious how others are handling PXE in large environments.&lt;/P&gt;&lt;P&gt;Are you standardizing on IP helpers or still using DHCP options?&lt;/P&gt;&lt;P&gt;Full article:&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="http://SCCM%20PXE%20Boot%20Deep%20Dive%20–%20Backend%20Flow%20&amp;amp;%20DP%20Migration" target="_blank"&gt;https://medium.com/@ureddy.techno/sccm-pxe-boot-distribution-point-backend-flow-e7adcc6119c4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 01:14:25 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager/sccm-pxe-boot-deep-dive-backend-flow-dp-migration/m-p/4515258#M375</guid>
      <dc:creator>UdayKumarDevarapalli</dc:creator>
      <dc:date>2026-04-28T01:14:25Z</dc:date>
    </item>
    <item>
      <title>Protect org data on BYOD Windows / macOS devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/protect-org-data-on-byod-windows-macos-devices/m-p/4514964#M23387</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;Anyway, I have a need to protect org data on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Window personal / BYOD devices&lt;/LI&gt;&lt;LI&gt;MacOS personal&amp;nbsp; / BYOD devices&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What's the best way to achieve this?&lt;/P&gt;&lt;P&gt;My thinking is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1 X Conditional Access policy that blocks&lt;/LI&gt;&lt;LI&gt;1 X Conditional Access policy that allows via Edge, no persistent session, no downloads etc&lt;/LI&gt;&lt;LI&gt;Device filter on both policies that target unmanaged devices&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 07:38:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/protect-org-data-on-byod-windows-macos-devices/m-p/4514964#M23387</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-04-27T07:38:28Z</dc:date>
    </item>
    <item>
      <title>Unpacking Endpoint Management is back - and we’ve got a lot to talk about</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/unpacking-endpoint-management-is-back-and-we-ve-got-a-lot-to/ba-p/4514599</link>
      <description>&lt;P&gt;If you've been missing real, candid conversations about endpoint management, good news! &lt;EM&gt;Unpacking Endpoint Management&lt;/EM&gt; is officially back.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;This series is all about what actually works. No fluff, just practical tips, proven strategies, and honest discussions to help you optimize and simplify the way you manage and secure endpoints today (and prepare for what's next).&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;We're bringing together people from across Microsoft Intune, Security, and Customer Experience engineering and product teams, along with guest practitioners, to share what's worked, what hasn't, and what we've learned along the way. And yes…we're absolutely here for the tough questions.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;A quick update on the hosts&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;Danny Guillory, a familiar face to the community and a Product Manager for Intune and Configuration Manager, will continue to host the series. He's joined this season by Rachelle Blanchard as co‑host, bringing a strong community and discovery lens to the series. Rachelle focuses on surfacing real customer questions and guiding conversations toward practical outcomes, helping ensure each episode reflects how endpoint management works in the real world.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Up next&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy: from hybrid to cloud-native&lt;/STRONG&gt;&lt;BR /&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-occasion" style="background-color: rgb(255, 255, 255); font-style: normal; font-weight: 400;" href="https://techcommunity.microsoft.com/event/microsoftintuneevents/unpacking-endpoint-management---may-2026/4514324" target="_blank" rel="noopener" data-lia-auto-title="9:00 a.m. PDT" data-lia-auto-title-active="0"&gt;May 28, 2026 - 9:00 a.m. PDT&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;June 2026 episode (topic TBD)&lt;/STRONG&gt;&lt;BR /&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-occasion" href="https://techcommunity.microsoft.com/event/microsoftintuneevents/unpacking-endpoint-management---june-2026/4514325" target="_blank" rel="noopener" data-lia-auto-title="June 30 – 9:00 AM PDT" data-lia-auto-title-active="0"&gt;June 30, 2026 – 9:00 a.m. PDT&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;July 2026 episode (topic TBD)&lt;/STRONG&gt;&lt;BR /&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-occasion" href="https://techcommunity.microsoft.com/event/microsoftintuneevents/unpacking-endpoint-management---july-2026/4514326" target="_blank" rel="noopener" data-lia-auto-title="July 29 – 9:00 AM PDT" data-lia-auto-title-active="0"&gt;July 29, 2026 – 9:00 a.m. PDT&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;Sign in to the Tech Community and follow this post for the latest updates on upcoming episodes.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Catch up on demand&lt;/H2&gt;
&lt;P&gt;Curious what it takes to secure endpoints in today’s Zero Trust world? &lt;BR /&gt;Watch our most recent episode on &lt;STRONG&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/device-security-with-microsoft-intune/4514323" data-lia-auto-title="Device security with Microsoft Intune" data-lia-auto-title-active="0" target="_blank"&gt;Device security with Microsoft Intune&lt;/A&gt;&lt;/STRONG&gt;, now on demand!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;div data-video-id="https://www.youtube.com/watch?v=PcmiamFoARM/1777584888079" data-video-remote-vid="https://www.youtube.com/watch?v=PcmiamFoARM/1777584888079" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FPcmiamFoARM%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DPcmiamFoARM&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FPcmiamFoARM%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;What's the format?&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;This web series is streamed live on Tech Community, LinkedIn, YouTube, and X. In addition to open discussion, we answer &lt;STRONG&gt;your&lt;/STRONG&gt; questions so sign in (or sign up for) the Tech Community and RSVP to submit questions early and throughout the live show.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;How do I join?&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;There's no call or meeting to join. Simply head to &lt;A class="lia-external-url" href="https://aka.ms/JoinUEM" target="_blank" rel="noopener"&gt;aka.ms/JoinUEM&lt;/A&gt;. Show up at start time, watch live, and jump into the discussion with us.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 24px; color: #333333;"&gt;Help shape the series&lt;/H2&gt;
&lt;P style="margin-top: 16px;"&gt;This series is for you - so tell us what you want to hear. Drop a comment below with:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Topics you'd like us to cover&lt;/LI&gt;
&lt;LI&gt;Tough questions you want answered&lt;/LI&gt;
&lt;LI&gt;Speakers you'd love to hear from&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 16px;"&gt;We can't wait to get started - and even more excited to hear from you along the way.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;Join the Community to get early insight into what's coming for Intune, connect with experts, and share real-world feedback that helps shape the product. 👉 &lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 21:37:19 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/unpacking-endpoint-management-is-back-and-we-ve-got-a-lot-to/ba-p/4514599</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-04-30T21:37:19Z</dc:date>
    </item>
    <item>
      <title>Best approach for migrating AD joined devices to Entra ID without wiping user profiles?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/best-approach-for-migrating-ad-joined-devices-to-entra-id/m-p/4514425#M23382</link>
      <description>&lt;P&gt;We’ve seen many organizations struggle with device migration when moving from traditional Active Directory (AD) or hybrid environments to Microsoft Entra ID.&lt;/P&gt;&lt;P&gt;The biggest challenge is avoiding user disruption especially when wiping devices causes profile loss, app reconfiguration, and downtime.&lt;/P&gt;&lt;P&gt;In large environments, wipe-and-reload becomes difficult to scale and impacts productivity significantly.&lt;/P&gt;&lt;P&gt;Curious to know how others are handling this:&lt;/P&gt;&lt;P&gt;Are you still using wipe/reimage methods, or are you using alternative approaches that preserve user profiles, applications, and settings?&lt;/P&gt;&lt;P&gt;Would love to hear practical experiences from the community.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 08:12:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/best-approach-for-migrating-ad-joined-devices-to-entra-id/m-p/4514425#M23382</guid>
      <dc:creator>Pranavsethuraman10</dc:creator>
      <dc:date>2026-04-24T08:12:47Z</dc:date>
    </item>
    <item>
      <title>Autopilot V1 vs “Device Preparation” (V2): Great direction — but is it enterprise-ready yet?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/autopilot-v1-vs-device-preparation-v2-great-direction-but-is-it/m-p/4514362#M23381</link>
      <description>&lt;P&gt;We evaluated &lt;STRONG&gt;Autopilot v2&lt;/STRONG&gt; but decided to stay on &lt;STRONG&gt;Autopilot v1&lt;/STRONG&gt; for large‑enterprise scale.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Group Tags + dynamic groups&lt;/STRONG&gt; are still essential for our device naming, segmentation, and governance model.&lt;/P&gt;&lt;P&gt;We intentionally limit apps in EAS to speed up provisioning, so EAS‑based app deployment in v2 isn’t a compelling advantage for us.&lt;/P&gt;&lt;P&gt;v2 looks promising, but until there’s stronger parity for &lt;STRONG&gt;enterprise‑scale targeting and naming&lt;/STRONG&gt;, v1 remains the better fit.&lt;/P&gt;&lt;P&gt;Curious how others at scale are balancing provisioning speed vs. segmentation without Group Tags.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 06:39:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/autopilot-v1-vs-device-preparation-v2-great-direction-but-is-it/m-p/4514362#M23381</guid>
      <dc:creator>christiandominguezjp</dc:creator>
      <dc:date>2026-04-24T06:39:18Z</dc:date>
    </item>
    <item>
      <title>Unpacking Endpoint Management - July 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/unpacking-endpoint-management-july-2026/ec-p/4514326#M5950</link>
      <description>&lt;P&gt;Let's talk about what actually works. Each month, Unpacking Endpoint Management brings you practical tips, proven strategies, and honest discussions. Our goal? To help you optimize and simplify the way you manage and secure endpoints today (and prepare for what’s next). Topics change monthly and are informed by &lt;EM&gt;your feedback&lt;/EM&gt; so visit https://aka.ms/UEM and leave a comment to let us know you want to hear about.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 22px; color: #333333;"&gt;How do I participate?&lt;/H2&gt;
&lt;P&gt;Registration is not required. Simply add this event to your calendar and select &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive reminders. Post your questions in advance, or any time during the live broadcast.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 01:02:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/unpacking-endpoint-management-july-2026/ec-p/4514326#M5950</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-04-24T01:02:13Z</dc:date>
    </item>
    <item>
      <title>Unpacking Endpoint Management - June 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/unpacking-endpoint-management-june-2026/ec-p/4514325#M5949</link>
      <description>&lt;P&gt;Let's talk about what actually works. Each month, Unpacking Endpoint Management brings you practical tips, proven strategies, and honest discussions. Our goal? To help you optimize and simplify the way you manage and secure endpoints today, and prepare for what’s nex). Topics change monthly and are informed by &lt;EM&gt;your feedback&lt;/EM&gt; so visit https://aka.ms/UEM and leave a comment to let us know you want to hear about.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 22px; color: #333333;"&gt;How do I participate?&lt;/H2&gt;
&lt;P&gt;Registration is not required. Simply add this event to your calendar and select &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive reminders. Post your questions in advance, or any time during the live broadcast.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 01:00:12 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/unpacking-endpoint-management-june-2026/ec-p/4514325#M5949</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-04-24T01:00:12Z</dc:date>
    </item>
    <item>
      <title>Policy: From hybrid to cloud-native</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/policy-from-hybrid-to-cloud-native/ec-p/4514324#M5948</link>
      <description>&lt;P&gt;Policy management has evolved fast: from on‑prem Group Policy/ADMX and domain‑joined assumptions to hybrid realities and truly cloud‑native configuration at scale. Tune in as we unpack what changes (and what should change) as you modernize policy in Microsoft Intune—including how to take inventory of what you have today, map it to modern equivalents, and decide what to migrate, redesign, or retire. We’ll share practical tips for creating cloud policies, talk about when to use templates vs. the settings catalog, and discuss how to avoid overlapping policy assignments during hybrid transition. Bring your edge cases! This is designed to be interactive, with plenty of time for your questions.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 22px; color: #333333;"&gt;How do I participate?&lt;/H2&gt;
&lt;P&gt;Registration is not required. Simply add this event to your calendar and select &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive reminders. Post your questions in advance, or any time during the live broadcast.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Let's talk about what actually works. Each month, &lt;STRONG&gt;Unpacking Endpoint Management&lt;/STRONG&gt; brings you practical tips, proven strategies, and honest discussions. Our goal? To help you optimize and simplify the way you manage and secure endpoints today, and prepare for what’s next). Topics change monthly and are informed by &lt;EM&gt;your feedback&lt;/EM&gt; so visit &lt;A href="https://aka.ms/UEM" target="_blank" rel="noopener"&gt;https://aka.ms/UEM&lt;/A&gt; and leave a comment to let us know you want to hear about.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 30 Apr 2026 21:27:52 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/policy-from-hybrid-to-cloud-native/ec-p/4514324#M5948</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-04-30T21:27:52Z</dc:date>
    </item>
    <item>
      <title>Device security with Microsoft Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/device-security-with-microsoft-intune/ec-p/4514323#M5947</link>
      <description>&lt;P&gt;For tips and best practices to help you stay ahead of evolving threats and modern device management challenges with Microsoft Intune, tune in to this month's episode of &lt;STRONG&gt;Unpacking Endpoint Management&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P style="margin-top: 16px;"&gt;We'll break down what it really takes to secure endpoints in today’s Zero Trust world—from implementing compliance policies and Conditional Access to enforcing least privilege with Endpoint Privilege Management. Bring your questions and leave with&amp;nbsp;actionable insights you can apply today.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 22px; color: #333333;"&gt;How do I participate?&lt;/H2&gt;
&lt;P&gt;Registration is not required. Simply add this event to your calendar and select &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive reminders. Post your questions and thoughts in advance, or any time during the live broadcast.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;If you're looking for practical tips, proven strategies, and honest discussions to help you optimize and simplify the way you manage and secure endpoints today (and prepare for what’s next), save the date for future episodes of &lt;STRONG&gt;&lt;A href="https://aka.ms/UEM" target="_blank"&gt;Unpacking Endpoint Management&lt;/A&gt;&lt;/STRONG&gt;!&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 29 Apr 2026 22:42:04 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/device-security-with-microsoft-intune/ec-p/4514323#M5947</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-04-29T22:42:04Z</dc:date>
    </item>
    <item>
      <title>Autopatch - Microsoft 365 Apps Update Rings</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-microsoft-365-apps-update-rings/m-p/4513986#M23376</link>
      <description>&lt;P&gt;I’m trying to understand how the&amp;nbsp;UpdateDeferredVersions&amp;nbsp;registry value is updated in an Intune Autopatch scenario, specifically the&amp;nbsp;&lt;STRONG&gt;version and FileTime values&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Registry path:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Updates&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example value:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;UpdateDeferredVersions = 16.0.19725.20170:13420719560293 | 16.0.19822.20180:13421142577563&lt;/P&gt;&lt;P&gt;I’ve observed the following and would appreciate any clarification:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When I modify&amp;nbsp;&lt;STRONG&gt;deadline or deferral settings&lt;/STRONG&gt;&amp;nbsp;via Autopatch (policy changes), the&amp;nbsp;&lt;STRONG&gt;FileTime value does not update&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Is there a&amp;nbsp;&lt;STRONG&gt;delay or specific trigger&lt;/STRONG&gt;&amp;nbsp;(e.g., policy refresh, scheduled task, CDN sync) that updates this FileTime?&lt;/LI&gt;&lt;LI&gt;How exactly is this&amp;nbsp;&lt;STRONG&gt;FileTime calculated&lt;/STRONG&gt;? Is it tied to when the build was released, assigned, or when the policy was applied?&lt;/LI&gt;&lt;LI&gt;Is there any&amp;nbsp;&lt;STRONG&gt;supported way to force or influence&lt;/STRONG&gt;&amp;nbsp;this FileTime update?&lt;/LI&gt;&lt;LI&gt;Or is this value simply tracking when the&amp;nbsp;&lt;STRONG&gt;build cap was issued&lt;/STRONG&gt;, with deferral logic calculated relative to that timestamp?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Additionally, I’ve noticed that updates only seem to apply when the FileTime is approximately&amp;nbsp;&lt;STRONG&gt;4 days behind the current date,&lt;/STRONG&gt; is this expected behavior with Autopatch deferral logic? I was able to successfully test this updating FileTime 4 days behind ((Get-Date).AddDays(-4)).ToFileTime().&lt;/P&gt;&lt;P&gt;Any insights into how this mechanism works under the hood (especially with Click-to-Run + Autopatch interaction) would be really helpful.&lt;/P&gt;&lt;P&gt;Below is Autopatch group settings for Microsoft 365 update rings that we set in our environment:&lt;/P&gt;&lt;P&gt;Test - Deferral 0 - Deadline 0&lt;/P&gt;&lt;P&gt;Ring 1 - Deferral 1 - Deadline 0&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ring 2 - Deferral 2 - Deadline 0&lt;/P&gt;&lt;P&gt;Last - Deferral 4 - Deadline 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 10:49:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-microsoft-365-apps-update-rings/m-p/4513986#M23376</guid>
      <dc:creator>PaulJebastin</dc:creator>
      <dc:date>2026-04-23T10:49:32Z</dc:date>
    </item>
    <item>
      <title>As vulnerability discovery moves at AI speed, keeping current is foundational to reduce exposure</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is/ba-p/4513766</link>
      <description>&lt;P&gt;Recent advances in automation and AI are accelerating vulnerability discovery and shortening the window between disclosure and exploitation. As Microsoft outlined in our recent&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/prioritizingdefense" target="_blank" rel="noopener"&gt;Security blog&lt;/A&gt;, this shift raises the bar for how quickly organizations need to reduce exposure across their environments.&lt;/P&gt;
&lt;P&gt;For IT and security teams, this makes staying current on updates more critical than before. While responding to individual Common Vulnerabilities Exposures (CVE) remains essential, keeping current across devices and applications is foundational to reducing exposure as threats evolve.&lt;/P&gt;
&lt;P&gt;This post focuses on the endpoint execution layer - how Microsoft Intune helps organizations understand their update posture, prioritize action, and reduce the time it takes for protections to land.&lt;/P&gt;
&lt;H2&gt;Introducing the security update status dashboard in Microsoft Intune&lt;/H2&gt;
&lt;P&gt;To act decisively, teams need clear visibility into where systems are current, where gaps exist, and how update deployments are progressing. Without a shared, defensible view of update status, it’s difficult to prioritize remediation or answer a basic question from leadership: &lt;EM&gt;“Are we patched?” &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;To address this, Intune is introducing the General Availability of a new &lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?LinkId=2361207" target="_blank" rel="noopener"&gt;security update status&lt;/A&gt; dashboard providing centralized visibility into update compliance across Windows Clients, Windows Servers, and Microsoft 365 Apps. The dashboard provides a clear, current view for leadership, backed by current data — without switching between multiple reports or tools.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 1: Security update dashboard showing patch status for Windows clients, servers, and Microsoft 365 apps.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;The dashboard surfaces:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Visibility into which devices are current on quality and feature updates, which are falling behind, and where remediation gaps exist across your Intune-managed estate&lt;/LI&gt;
&lt;LI&gt;The data needed to prioritize action, track progress across deployment rings, and help demonstrate a more accurate compliance posture&lt;/LI&gt;
&lt;LI&gt;Insight to where exposure is critical and needs immediate attention&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Four ways to shrink your vulnerability window&lt;/H2&gt;
&lt;P&gt;The dashboard delivers visibility. The capabilities below help you act on it.&lt;/P&gt;
&lt;H3 class="lia-indent-padding-left-30px"&gt;1) Windows Autopatch: deploy updates at scale with control&lt;/H3&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Windows Autopatch manages update orchestration through predefined deployment rings, releasing updates progressively across representative device groups so that quality and security updates reach broad production populations only after passing validation in pilot environments. IT teams shift from manually coordinating deployment schedules each month to focusing on policy and exception management while Windows Autopatch handles sequencing, scheduling, and rollout logic.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;When critical vulnerabilities emerge, expedited update deployment allows devices to advance more quickly through the rollout process, providing security teams with an additional lever for reducing time-to-secure when AI-driven discovery shortens the window between disclosure and exploitation.&lt;/P&gt;
&lt;H3 class="lia-indent-padding-left-30px"&gt;2) Hotpatch updates: Windows updates without the reboot&lt;/H3&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Even when updates deploy rapidly, protection is not realized until a device restarts, and users routinely defer reboots for hours or days. Hotpatch updates for Windows reduces this gap by applying supported security updates to in-memory processes without requiring frequent restarts. Eligible Windows 11 Enterprise devices can reach a protected state immediately after installation, helping reduce the vulnerability window.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Operationally, hotpatch updates shifts the restart requirement from monthly update to a smaller number of planned baseline updates per year, enabling organizations to deploy critical fixes without the productivity impact of forced restarts. You can enable hotpatch updates through quality update policies in Intune on supported systems.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;In addition, with &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/windows-autopatch/monitor/windows-autopatch-update-readiness-overview" target="_blank" rel="noopener"&gt;Autopatch update readiness&lt;/A&gt;, IT admins can better anticipate when planned quality or feature updates won’t reach a device, understand Autopatch and hotpatch enrollment coverage, and quickly identify blockers to bringing devices into a ready state.&lt;/P&gt;
&lt;H3 class="lia-indent-padding-left-30px"&gt;3) Microsoft 365 Apps patching: keep Office and other apps current in lockstep&lt;/H3&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;The Microsoft 365 Apps admin center includes Inventory and Cloud Update, giving administrators visibility into update status across connected devices by update channel so they can quickly spot systems missing the latest security updates and track progress. When an accelerated response is required, teams can tighten deadlines and move from staged rollout to immediate enforcement by removing waves, deferrals, or exclusion windows that may delay availability for specific groups, especially where channel divergence or scoped targeting leaves devices outside policy. Because expedited servicing reduces time for testing across diverse configurations, Cloud Update controls such as pausing a deployment or rolling back an update help mitigate risk while closing security gaps quickly.&lt;/P&gt;
&lt;H3 class="lia-indent-padding-left-30px"&gt;4) Server updates: Configuration Manager or Azure Arc to accelerate compliance and operational workloads&lt;/H3&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;For organizations managing servers, &lt;STRONG&gt;Configuration Manager&lt;/STRONG&gt; helps streamline the identification, packaging, and assignment of security updates (for example, with Automatic Deployment Rules) based on classification and severity. Cloud-based sourcing through the Microsoft Update service can prevent deployment failures in distributed environments, while maintenance windows let you pre-stage updates for highly available systems and install them during defined downtime intervals - achieving compliance without unplanned service interruptions. For server estates that are&amp;nbsp;&lt;STRONG&gt;Arc-enabled&lt;/STRONG&gt;, you can also use &lt;STRONG&gt;Azure Arc&lt;/STRONG&gt; to extend visibility and management across hybrid and multicloud infrastructure.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;If you need even deeper coverage and insight, consider integrating &lt;STRONG&gt;Microsoft Defender Vulnerability Management (MDVM)&lt;/STRONG&gt; to enrich update posture with vulnerability intelligence and prioritize remediation based on real exposure.&lt;/P&gt;
&lt;H2&gt;Using update currency as an enforcement signal&lt;/H2&gt;
&lt;P&gt;Deploying updates is half the job. Verifying they land - and holding the line when they don't - is the other half. Intune compliance policies let you define minimum OS build numbers, required update levels, and grace periods. Devices that fall out of compliance are flagged automatically.&lt;/P&gt;
&lt;P&gt;Paired with Microsoft Entra ID Conditional Access, update currency can become a condition of access - checking that only current, healthy devices connect to corporate resources. This turns update posture into an enforceable control, not just a reporting metric.&lt;/P&gt;
&lt;H2&gt;Actions you can take today&lt;/H2&gt;
&lt;P&gt;The increasing use of AI in vulnerability discovery, combined with a rapidly evolving threat landscape, underscores the importance of taking proactive security measures. Here are actions you can take today:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess. &lt;/STRONG&gt;Open the new security update status dashboard and know the baseline of your fleet. See&lt;STRONG&gt; &lt;/STRONG&gt;how many Windows devices are behind on feature releases, quality updates, and Microsoft 365 Apps patches.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Automate. &lt;/STRONG&gt;Configure Windows Autopatch for ring-based deployment, enable hotpatch updates on eligible devices, and set Microsoft 365 Apps servicing profiles. Enable expedited updates so you can respond to critical vulnerabilities quickly.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enforce. &lt;/STRONG&gt;Pair compliance policies with Conditional Access. Make being current a condition of access to corporate data.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Monitor. &lt;/STRONG&gt;Review the dashboard weekly. Investigate deployment failures promptly and deploy proactive remediations to clear blockers.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Communicate. &lt;/STRONG&gt;Share dashboard trends with security leadership and application owners. When stakeholders see the data, update compliance becomes a shared priority, not just an IT burden.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Evolve. &lt;/STRONG&gt;Revisit your deployment rings, deferral windows, and compliance thresholds quarterly. Use failure patterns from the dashboard to refine your approach and evaluate Windows Autopatch for a fully managed experience that scales with your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Every day a device remains out of date is potential exposure to unnecessary vulnerabilities. Intune gives you the tools, and now the visibility, to get current, stay current, and defend your organization at the speed the threat landscape demands.&lt;/P&gt;
&lt;H2&gt;Closing&lt;/H2&gt;
&lt;P&gt;Reducing exposure starts with knowing where you stand. The &lt;STRONG&gt;security update status dashboard in Intune&lt;/STRONG&gt; provides a single place to understand update status across Windows devices and Microsoft 365 Apps, helping you identify lagging systems and prioritize action.&lt;/P&gt;
&lt;P&gt;Make the dashboard part of your regular operational rhythm: review it, act on the gaps it surfaces, and track progress over time. With the right visibility and tooling, staying current becomes repeatable - not reactive.&lt;/P&gt;
&lt;P&gt;Feature availability varies by license. Learn more about plan details and requirements &lt;A class="lia-external-url" href="https://www.microsoft.com/security/business/microsoft-intune-pricing" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/prioritizingdefense" target="_blank" rel="noopener"&gt;Read the latest Microsoft Security blog&lt;/A&gt; to learn how turning AI‑driven discovery into protection at scale can help secure your estate in an AI‑driven threat landscape.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://security.microsoft.com/securenow" target="_blank" rel="noopener"&gt;Get started with Microsoft Secure Now&lt;/A&gt; for guidance in assessing risk and take recommended actions.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2026 22:35:25 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is/ba-p/4513766</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-04-22T22:35:25Z</dc:date>
    </item>
    <item>
      <title>Intune application migration &amp; app management</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-application-migration-app-management/m-p/4513415#M23369</link>
      <description>&lt;P&gt;Migrating applications from Configuration Manager and other on-prem solutions to Microsoft Intune cloud native remains a challenging and time consuming undertaking, especially when dealing with complex line-of-business, legacy, and custom home-grown applications. Some organizations pursuing a full cloud-native management vision are encountering blockers related to application compatibility, re-packaging, and the scale of existing app estates - all while trying to maintain business continuity, device compliance, and preparing for the AI and Copilot era.&lt;/P&gt;
&lt;H3 style="margin-top: 16px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Start here&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Read &lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/face-the-future-today-by-moving-your-application-to-cloud-native/4453681" target="_blank" rel="noopener"&gt;Face the future today by moving your application to cloud native&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Bookmark the &lt;A href="https://learn.microsoft.com/intune/intune-service/fundamentals/intune-planning-guide" target="_blank" rel="noopener"&gt;Microsoft Intune planning guide&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin-top: 24px; margin-bottom: 36px;"&gt;&lt;STRONG&gt;Navigate to&lt;/STRONG&gt;:&lt;BR /&gt;&lt;A href="#community--1-why" target="_self"&gt;Why app migration matters&lt;/A&gt; | &lt;A href="#community--1-partners" target="_self"&gt;Application packaging partners&lt;/A&gt; | &lt;A href="#community--1-faq" target="_self"&gt;Frequently asked questions&lt;/A&gt;&lt;/P&gt;
&lt;!-- Why app migration matters --&gt;
&lt;DIV style="display: flex; align-items: center; height: 50px; background-color: rgb(0, 24, 93);"&gt;
&lt;H2 style="font-size: 20px; text-align: center; color: #ffffff; margin: 0px 20px 0px 20px;"&gt;&lt;a id="community--1-why" class="lia-anchor"&gt;&lt;/a&gt;Why app packaging matters&lt;/H2&gt;
&lt;/DIV&gt;
&lt;DIV style="padding: 20px 0; border: 1px dashed #00185d;"&gt;
&lt;P style="margin: 0px 20px 0px 20px;"&gt;Centralizing application management in Intune can deliver operational benefits such as unified enforcement and improved security posture—while supporting broader modernization goals.&lt;/P&gt;
&lt;P style="margin: 16px 20px 0px 20px;"&gt;Common blockers that slow cloud-native adoption include:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;App compatibility and dependency complexity&lt;/LI&gt;
&lt;LI&gt;Manual repackaging effort at scale&lt;/LI&gt;
&lt;LI&gt;Risk of disruption during cutover&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;!-- Application packaging partners --&gt;
&lt;DIV style="display: flex; align-items: center; height: 50px; background-color: rgb(0, 24, 93);"&gt;
&lt;H2 style="font-size: 20px; text-align: center; color: #ffffff; margin: 0px 20px 0px 20px;"&gt;&lt;a id="community--1-app-packaging" class="lia-anchor"&gt;&lt;/a&gt;Application packaging partners&lt;/H2&gt;
&lt;/DIV&gt;
&lt;DIV style="padding: 20px 0; border: 1px dashed #2E8AE5;"&gt;
&lt;P style="margin: 0px 20px 0px 20px;"&gt;To address the complex realities of app migration, the Microsoft partner ecosystem has stepped up with specialized offers designed to reduce risk and accelerate cloud adoption. As part of this initiative our Microsoft partners Rimo3 and Robopack are offering no-cost, time-limited app migration service to all Intune customers who are looking to move from Configuration Manager to Intune. These services can help IT teams automate assessment, package conversion, and remediation for various app types, helping organizations realize the full value of Intune faster and with less disruption.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 0px 20px 0px 20px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;The app migration services listed on this page are offered directly by partners and are subject to their terms. Microsoft makes no guarantees or commitments regarding availability or outcome.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN" style="margin-left: 20px;"&gt;&lt;img /&gt;&lt;/DIV&gt;
&lt;P style="margin: 0px 20px 0px 20px;"&gt;&lt;A href="https://aka.ms/IntuneRimo3Package" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Rimo3&lt;/STRONG&gt;&lt;/A&gt; helps IT professionals modernize, migrate, and manage applications at enterprise scale. The platform eliminates manual effort by automating packaging, validation, and patch testing. With patented IP, Rimo3 ensures every app is compatible, secure, and visible for dependencies and update readiness before deployment. Automated, unattended workflows reduce migration timelines from months to days, while contextual patch validation minimizes production risk. Rimo3 keeps environments evergreen with zero-touch app management and enhances Microsoft Intune with bulk operations, advanced controls, and unified reporting.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN" style="margin-left: 20px; margin-top: 20px; margin-bottom: 0px;"&gt;&lt;img /&gt;&lt;/DIV&gt;
&lt;P style="margin: 0px 20px 0px 20px;"&gt;&lt;A href="https://aka.ms/IntuneRobopackPackage" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Robopack&lt;/STRONG&gt;&lt;/A&gt; is a cloud-native Intune app lifecycle platform that lets you package, deploy, and keep third-party apps updated, across one or many tenants, with phased control and PowerShell App Deployment Toolkit (PSADT)-based customization. Start with a self-service migration readiness report, mapped to the library of 41,000 pre-packaged, fully documented apps ready to go, or upload your own apps to be analysed and converted. Robopack Radar discovers apps installed across your estate, allowing you to quickly migrate to Intune and uncover Shadow IT.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;!-- Additional resources --&gt;
&lt;DIV style="display: flex; align-items: center; height: 50px; background-color: rgb(0, 24, 93);"&gt;
&lt;H2 style="font-size: 20px; text-align: center; color: #ffffff; margin: 0px 20px 0px 20px;"&gt;&lt;a id="community--1-faq" class="lia-anchor"&gt;&lt;/a&gt;Frequently asked questions&lt;/H2&gt;
&lt;/DIV&gt;
&lt;DIV style="padding: 20px 0; border: 1px dashed #00185d;"&gt;
&lt;P style="margin: 0px 20px 0px 20px;"&gt;&lt;STRONG&gt;Q: Is this a Microsoft-managed service?&lt;/STRONG&gt;&lt;BR /&gt;A: No. Partner offers are provided directly by partners and subject to partner terms; Microsoft makes no guarantees regarding availability or outcomes.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P style="margin: 0px 20px 0px 20px;"&gt;&lt;STRONG&gt;Q: What kinds of apps can these paths help with?&lt;/STRONG&gt;&lt;BR /&gt;A: The published focus is on helping migrations from Conifguration Manager to Intune, including complex legacy and line-of-business apps.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P style="margin: 0px 20px 0px 20px;"&gt;&lt;STRONG&gt;Q: Where do I start if I’m early in planning?&lt;/STRONG&gt;&lt;BR /&gt;A: Start with the Intune Planning Guide and Migration Guide.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 15:50:59 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-application-migration-app-management/m-p/4513415#M23369</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2026-04-21T15:50:59Z</dc:date>
    </item>
    <item>
      <title>Adobe reader update deployment via Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/adobe-reader-update-deployment-via-intune/m-p/4512784#M23360</link>
      <description>&lt;P&gt;Hi Team, can we integrate and deploy Adobe reader update automatically via Intune or we need to create package and deploy latest version every month.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 06:28:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/adobe-reader-update-deployment-via-intune/m-p/4512784#M23360</guid>
      <dc:creator>KarthickJokirathinam</dc:creator>
      <dc:date>2026-04-20T06:28:32Z</dc:date>
    </item>
    <item>
      <title>Edge update deployment via Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/edge-update-deployment-via-intune/m-p/4512783#M23359</link>
      <description>&lt;P&gt;Hi Team, I am planning to deploy edge stable channel update from intune every month. Can anyone share the process &amp;amp; configuration settings in intune&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 06:25:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/edge-update-deployment-via-intune/m-p/4512783#M23359</guid>
      <dc:creator>KarthickJokirathinam</dc:creator>
      <dc:date>2026-04-20T06:25:02Z</dc:date>
    </item>
    <item>
      <title>Which Entra account are you supposed to use to connect to a managed Google Play account?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/which-entra-account-are-you-supposed-to-use-to-connect-to-a/m-p/4512536#M23355</link>
      <description>&lt;P&gt;At &lt;A href="https://learn.microsoft.com/en-ca/intune/device-enrollment/android/connect-managed-google-play" target="_blank"&gt;Connect Intune account to managed Google Play account - Microsoft Intune | Microsoft Learn&lt;/A&gt;, it says:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;We recommend using the Microsoft Entra account you're signed into to create the Google Admin account.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;So I used my Entra account to set it up. Now, though, when I look at the Managed Google Play item in Intune under Devices &amp;gt; Android &amp;gt; Enrollment, it has &lt;STRONG&gt;my &lt;/STRONG&gt;email address under "Linked account".&lt;/P&gt;&lt;P&gt;Was I supposed to create a shared Entra account to make this connection? What happens when I leave the org?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 20:47:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/which-entra-account-are-you-supposed-to-use-to-connect-to-a/m-p/4512536#M23355</guid>
      <dc:creator>RyanSteele-CoV</dc:creator>
      <dc:date>2026-04-17T20:47:42Z</dc:date>
    </item>
    <item>
      <title>How to repair an application deployed via Intune with no admin rights</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/how-to-repair-an-application-deployed-via-intune-with-no-admin/m-p/4512489#M23354</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know how to repair an applcation deployed by Intune. User has no admin rights , so via control panel is not an option. User is not set as primary user on device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thks for all comments&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 15:42:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/how-to-repair-an-application-deployed-via-intune-with-no-admin/m-p/4512489#M23354</guid>
      <dc:creator>sylsimp1</dc:creator>
      <dc:date>2026-04-17T15:42:40Z</dc:date>
    </item>
  </channel>
</rss>

