<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Intune Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/microsoftintuneblog</link>
    <description>Microsoft Intune Blog articles</description>
    <pubDate>Sat, 08 Aug 2026 13:48:23 GMT</pubDate>
    <dc:creator>microsoftintuneblog</dc:creator>
    <dc:date>2026-08-08T13:48:23Z</dc:date>
    <item>
      <title>What’s new in Microsoft Intune – July</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-july/ba-p/4537392</link>
      <description>&lt;P&gt;Ask an IT admin what a good day looks like, and it usually comes down to one word: control. Control means you push a change and know it landed. It means you have a clear view into your device fleet, from compliance status to sync health. That certainty is what helps IT stay ahead and deliver.&lt;/P&gt;
&lt;P&gt;Still, endpoint management gets harder as fleets grow across locations and device types. More devices and policies rarely mean fewer admin hours. This month's updates focus on giving IT clearer visibility and more confident action.&lt;/P&gt;
&lt;H4&gt;Demystify Windows device sync status&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;When admins troubleshoot a device, they need visibility into what’s happening. The updated per-device sync experience in the Intune admin center now shows progress, making it easier for admins to confirm actions are running and understand where they are in the process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The updated sync action also triggers both the mobile device management check-in and the Intune Management Extension (Windows only) check-in. One sync can now pull-down policy, app, and script changes in a single pass. For admins working through a single-device issue, this makes sync more transparent, more complete, and easier to trust as a troubleshooting step. &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-management/actions/sync?pivots=windows" target="_blank" rel="noopener"&gt;Learn more about sync actions for Windows&lt;/A&gt; and how to use them to troubleshoot and validate device state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1: The Sync status pane tracks each step live, from notifying the device to calculating compliance.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;Want a deeper story about how we delivered this change? Read the&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/speed-where-it-matters-how-microsoft-intune-helps-it-prioritize-time-sensitive-a/4515942" target="_blank" rel="noopener" data-lia-auto-title="blog" data-lia-auto-title-active="0"&gt;blog&lt;/A&gt; about how Intune helps IT prioritize time-sensitive actions or catch the recent &lt;A class="lia-external-url" href="https://www.youtube.com/live/dUN6cAI6nhA?is=3kHcspq7ZUYMxU6v" target="_blank" rel="noopener"&gt;Microsoft Technical Takeoff video&lt;/A&gt; on Intune timing demystified.&lt;/P&gt;
&lt;H4&gt;Help ensure compliance for macOS&lt;/H4&gt;
&lt;P&gt;This month, custom compliance settings for macOS became generally available. Admins can use these settings to apply organization-specific requirements that built-in compliance settings don’t cover. This extended coverage helps reduce risk and unblock macOS deployments by aligning compliance and Conditional Access requirements with the Intune security policies organizations need to manage them. To learn more about compliance policies and what they do, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/overview" target="_blank" rel="noopener"&gt;"Use compliance policies to set rules for devices you manage with Intune."&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Additionally, using discovery scripts and JSON rules, admins can inspect many macOS device attributes and conditions. Think about installed software, running processes, app versions, or security posture that no Apple built-in setting captures. Now macOS devices report compliance the same way Windows and Linux devices do, giving you one consistent view instead of three different ones. Read more about how to set up the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/custom-settings" target="_blank" rel="noopener"&gt;custom compliance settings documentation for Microsoft Intune&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;More control over Samsung firmware updates&lt;/H4&gt;
&lt;P&gt;Keeping firmware current becomes harder as your mobile device fleet grows. For example, a new version may need testing against line-of-business apps before reaching production devices. In a Zero Trust environment, every unpatched device can become a compliance gap waiting to happen.&lt;/P&gt;
&lt;P&gt;The &lt;A class="lia-external-url" href="https://www.samsungknox.com/en/solutions/it-solutions/samsung_e-fota" target="_blank" rel="noopener"&gt;Samsung Knox Enterprise Firmware-Over-The-Air (E-FOTA)&lt;/A&gt; integration brings precise control over firmware and OS updates across their Galaxy devices into the Microsoft Intune console. Existing Intune device groups determine which devices receive each version. If group membership changes, the firmware assignment follows.&lt;/P&gt;
&lt;P&gt;Admins can keep production devices on their current version while testing an update. After validation, they can roll it out gradually during planned maintenance windows. Battery requirements and postponement limits provide more control over installation timing. This helps maintain consistent firmware and compliance across the fleet.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;H4&gt;Intune: Myth vs. reality&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Myth: &lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/overview" target="_blank" rel="noopener"&gt;Windows Autopilot&lt;/A&gt; requires device registration for new PCs.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Reality: &lt;/STRONG&gt;Device registration is not required in all Windows Autopilot scenarios. Many IT admins associate Windows Autopilot with device registration because the original Windows Autopilot solution uses registration to identify devices. Today, organizations can choose from multiple Autopilot approaches depending on their deployment needs.&lt;/P&gt;
&lt;P&gt;Windows Autopilot helps IT remotely provision devices at scale across a range of deployment scenarios, including existing devices, pre-provisioning, self-deploying deployments, and remote users.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/overview" target="_blank" rel="noopener"&gt;Windows Autopilot device preparation&lt;/A&gt; helps streamline Windows 11 provisioning without requiring Windows Autopilot registration. It uses enrollment-time grouping to deliver selected apps and scripts during setup, with near real-time deployment reporting.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to choose the right Autopilot approach:&lt;/STRONG&gt; If you need registration-based deployment scenarios, such as pre-provisioning, self-deploying deployments, or existing device provisioning, use the original Windows Autopilot solution. Use Windows Autopilot device preparation when you want to streamline Windows 11 onboarding without Windows Autopilot registration and deliver selected apps and scripts during setup before users reach the desktop.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Windows Autopilot in action:&lt;/STRONG&gt; &lt;A class="lia-external-url" href="https://aka.ms/Onboarding-AutopilotVideo" target="_blank" rel="noopener"&gt;Watch Microsoft MVP Jonathan Edwards walk through remote, at-scale onboarding with Intune&lt;/A&gt;. You will get a step-by-step look at both Windows Autopilot and Autopilot device preparation in action, along with guidance on choosing the right approach for your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;Keep the conversation going&lt;/H4&gt;
&lt;P&gt;Control rarely arrives as one big feature or capability. It shows up in the smaller updates admins lean on daily. A sync they can watch, a compliance rule they can shape, or a firmware update they can run with confidence. Together, these capabilities add more certainty and give time back. That is how modern endpoint management should work.&lt;/P&gt;
&lt;P&gt;In that same spirit, staying in control means staying current as threat response speeds up. &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/build-a-patch-strategy-for-today%E2%80%99s-threat-pace-with-microsoft/4535115" target="_blank" rel="noopener" data-lia-auto-title="Read our recent post by Jason Roszak" data-lia-auto-title-active="0"&gt;Read our recent post by Jason Roszak&lt;/A&gt; for practical guidance on building a patch strategy with Microsoft. Let us know in the comments what you think of these new capabilities and stay tuned for more next month.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on&amp;nbsp;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt;or&amp;nbsp;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune &lt;/A&gt;and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 22:03:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-july/ba-p/4537392</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-07-28T22:03:17Z</dc:date>
    </item>
    <item>
      <title>Advanced Microsoft Intune capabilities now available in Microsoft 365 E3 and E5</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/advanced-microsoft-intune-capabilities-now-available-in/ba-p/4529335</link>
      <description>&lt;P&gt;Across industries, customers are already using advanced Microsoft Intune Suite capabilities to solve real endpoint challenges, such as reducing standing privilege, improving IT response times, modernizing certificate management, and preparing for AI-assisted operations.&lt;/P&gt;
&lt;P&gt;Now, more Microsoft 365 customers can put these same capabilities to work. The &lt;A class="lia-external-url" href="https://aka.ms/IntuneM365Blog" target="_blank" rel="noopener"&gt;packaging changes announced in December 2025&lt;/A&gt; are now in effect. As of July 1, advanced Intune Suite capabilities are included in Microsoft 365 E5, with select capabilities available in Microsoft 365 E3,&lt;SUP&gt;1&lt;/SUP&gt; as shown below:&lt;/P&gt;
&lt;P&gt;​&lt;/P&gt;
&lt;img&gt;T&lt;SPAN data-ccp-parastyle="caption"&gt;he above table highlights how &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;advanced&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt; Microsoft Intune capabilities are included across Microsoft &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;365 E3 and E5.&lt;/SPAN&gt;&lt;/img&gt;
&lt;H4&gt;&lt;SPAN class="lia-text-color-21"&gt;Why this change matters now&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;Endpoint management is being redefined as IT and security teams look beyond disconnected tools toward a platform that brings identity, security, compliance, and AI governance together across endpoints.&lt;/P&gt;
&lt;P&gt;Microsoft Intune helps organizations move from principle to execution. It gives admins visibility and control across devices, with clear audit trails and consistent policy enforcement, reducing potential risk before attackers can exploit it. Microsoft was recently recognized as a Leader in &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/blog/2026/06/25/microsoft-a-leader-in-the-forrester-wave-for-endpoint-management-platforms/" target="_blank" rel="noopener"&gt;The Forrester Wave™: Endpoint Management Platforms, Q2 2026.&lt;/A&gt; Strengthening endpoint management using Microsoft Intune can help advance Zero Trust through healthier devices, least-privilege access, consistent policies, and trusted data—an essential foundation for AI-era operations.&lt;/P&gt;
&lt;P&gt;The customer stories below show what this looks like in practice: protecting endpoints, empowering IT teams, and optimizing IT operations with AI-driven capabilities, including Microsoft Security Copilot in Intune.&lt;SUP&gt;2&lt;/SUP&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN class="lia-text-color-21"&gt;Protect endpoints&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;Protecting endpoints starts with reducing everyday risks, such as standing admin rights and certificate infrastructure that can be difficult to manage.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/epm/overview" target="_blank" rel="noopener"&gt;Microsoft Intune Endpoint Privilege Management&lt;/A&gt; (EPM) removes broad local admin rights while still allowing users to complete approved tasks that require elevation. This supports a Zero Trust approach such as least privilege, without slowing productivity.&lt;/P&gt;
&lt;P&gt;Organizations like &lt;A class="lia-external-url" href="https://www.microsoft.com/en/customers/story/1779428638140338265-hino-motors-azure-professional-services-en-japan" target="_blank" rel="noopener"&gt;Hino Motors&lt;/A&gt; are applying EPM across both Cloud PCs and physical PCs to maintain a consistent security posture. For Hino Motors, EPM is part of a broader Windows 365 and Intune security model that helps reduce administrative privilege while keeping work moving.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;“Intune allows us to manage both Cloud PCs and physical PCs without distinction, and I feel that it is a big plus. With the introduction of Windows 365, we will eliminate administrative privileges as part of our security enhancements, and to do so, we are using Microsoft Intune Endpoint Privilege Management (EPM).”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;Masahiro Kimura, Office Head of Communication Infrastructure Office, Hino Computer System Co, Ltd&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Traditional Public Key Infrastructure (PKI) solutions can be complex to deploy, costly to maintain, and slow to scale. &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/cloud-pki/" target="_blank" rel="noopener"&gt;Microsoft Cloud PKI&lt;/A&gt; addresses this with a fully managed, cloud-based service that automates certificate lifecycle management, removing the need for on-premises infrastructure and establishing a path for certificate-based authentication.&lt;/P&gt;
&lt;P&gt;Türkiye’s largest integrated industrial group, &lt;A class="lia-external-url" href="https://www.microsoft.com/en/customers/story/23304-socar-turkiye-microsoft-365-e5" target="_blank" rel="noopener"&gt;SOCAR Türkiye&lt;/A&gt;, applied advanced Microsoft Cloud PKI features across its devices, helping establish a unified Zero Trust security model that verifies all access explicitly.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;“[Cloud PKI] was a very important feature because the devices may be used by executives who have access to highly confidential information. We wanted to ensure that they have streamlined access to do what they need to do while also ensuring security.”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;Fırat Bilmiş, IT System Services Supervisor, SOCAR Türkiye&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Across industries, the outcome is consistent: stronger security, reduced risk, and a foundation to build on. That foundation enables a faster response and more effective troubleshooting, helping IT teams keep operations running and users productive.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN class="lia-text-color-21"&gt;Empower IT&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;Empowering IT starts by reducing the time between identifying a problem and resolving it. Remote support is no longer just a help desk convenience. It can become a business continuity lever for organizations with distributed operations.&lt;/P&gt;
&lt;P&gt;Some remote support tools operate outside an organization’s identity and device management controls. &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/mem/intune/fundamentals/remote-help" target="_blank" rel="noopener"&gt;Microsoft Intune Remote Help&lt;/A&gt; supports Zero Trust principles through identity, role-based access, and policy controls.&lt;/P&gt;
&lt;P&gt;Manufacturing organization &lt;A class="lia-external-url" href="https://www.microsoft.com/en/customers/story/1628382245277876835-krones-ag-manufacturing-windows-11-enterprise" target="_blank" rel="noopener"&gt;Krones AG&lt;/A&gt; highlights this impact, demonstrating its importance for global operations and the ability to support users without delay.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;“We use Remote Help to support users wherever they are, without needing to be physically in front of their device.”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;David Meneses, User and Endpoint Services, Krones AG&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Remote Help provides a more secure, auditable way for IT admins to assist users, helping accelerate resolution while maintaining access and compliance controls.&lt;/P&gt;
&lt;P&gt;Empowerment also comes from increased visibility. &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/advanced-analytics/" target="_blank" rel="noopener"&gt;Microsoft Intune Advanced Analytics&lt;/A&gt; helps teams move from reactive troubleshooting to proactive endpoint management by surfacing device health, performance issues, and anomalies. Within Advanced Analytics, capabilities like near real-time device query and Multi-Device Query (MDQ) give IT the ability to investigate individual devices or analyze device data at scale, helping teams quickly identify issues, understand their impact, and take action with confidence.&lt;/P&gt;
&lt;P&gt;This level of visibility becomes even more important as estates grow beyond PCs to include shared, mobile, and frontline devices. European fashion retailer &lt;A class="lia-external-url" href="https://www.microsoft.com/en/customers/story/25972-lindex-microsoft-intune" target="_blank" rel="noopener"&gt;Lindex&lt;/A&gt; demonstrates how scalable access to device data can give IT the oversight needed across a distributed retail environment. By using Intune to manage shared Android devices across stores, Lindex helps employees spend more time with customers and less time addressing device issues.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;“With Intune, we can see the health of all the [Android] devices and keep them secure without disrupting store operations. It’s reliable, scalable, and gives us the control we need to support all our stores.”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;Niklas Jenslov, Platform Engineer, Lindex&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The advanced mobile capabilities that are part of Intune Plan 2 — and now included in Microsoft 365 E3 and E5 — help extend these same controls to Android, iOS, and specialized endpoint scenarios.&lt;/P&gt;
&lt;P&gt;This includes &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/device-management/specialty-devices" target="_blank" rel="noopener"&gt;purpose-built devices&lt;/A&gt;, firmware update management for supported &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/device-updates/android/setup-zebra-lifeguard" target="_blank" rel="noopener"&gt;Zebra Android devices&lt;/A&gt;, and &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/device-security/microsoft-tunnel/mam" target="_blank" rel="noopener"&gt;Microsoft Tunnel for Mobile Application Management&lt;/A&gt; (MAM), which also supports Android and iOS/iPadOS. MAM protects corporate data within apps without requiring device enrollment. Microsoft Tunnel for MAM extends this further by enabling secure access to on-premises app resources from unenrolled devices through per-app VPN, helping organizations support BYOD scenarios while maintaining secure access to corporate resources.&lt;/P&gt;
&lt;P&gt;Organizations are also simplifying application management with &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;Microsoft Intune Enterprise Application Management&lt;/A&gt; (EAM), helping streamline application deployment and keep apps consistently up to date. EAM reduces manual packaging and maintenance effort by automating application deployment and updates, while helping users get faster access to the tools they need to stay productive. Building on the application management capabilities already available in Intune, EAM further simplifies software delivery at scale.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en/customers/story/1785106654704924534-carlsberggroup-windows-autopilot-consumer-goods-en-denmark" target="_blank" rel="noopener"&gt;Carlsberg Group&lt;/A&gt; demonstrates this impact through less hands-on work for IT and fewer support delays for users.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;“With Microsoft Intune, our end-users can install all the permitted applications they need directly to their laptop without waiting for IT on-site support to help them,”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;Oleksii Giriiev, Service Owner for Endpoint Management and ServiceNow, Carlsberg Group&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;With secure remote support, access to scalable device data, and simplified application and mobile management within one solution, IT teams can move faster, act with greater confidence, and give users the support they need—wherever work happens.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN class="lia-text-color-21"&gt;Optimize with AI&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;With endpoints well-managed and IT equipped to act, the next opportunity is putting AI to work in the management workflow—surfacing insights, assessing risk, and guiding action.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/copilot/" target="_blank" rel="noopener"&gt;Microsoft Security Copilot in Intune&lt;/A&gt; brings AI directly into the endpoint management workflow, helping admins use natural language to explore Intune data, gather insights, and take action without leaving the Intune admin center. For EPM, Copilot can help assess applications risks before elevation requests are approved, giving admins more context for least-privilege decisions. In Advanced Analytics, Copilot can also help admins build and refine KQL queries, lowering the barrier to deeper endpoint analysis and helping teams translate complex device data into practical next steps.&lt;/P&gt;
&lt;P&gt;The &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/copilot/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;Vulnerability Remediation Agent for Security Copilot in Intune&lt;/A&gt; is an example of how AI-assisted endpoint management can work. It uses Defender Vulnerability Management data to identify and prioritize high-risk Common Vulnerabilities and Exposures (CVE) on managed devices, provides recommendations for remediation, and guides admins through the steps they can take within Intune. This brings advanced endpoint management and AI-assisted operations together, helping IT understand what is happening and determining what matters, while leveraging the tools they already use.&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/en/customers/story/25526-pepsico-microsoft-intune" target="_blank" rel="noopener"&gt;PepsiCo’s Intune story&lt;/A&gt; points to that next step, helping IT act faster, with better context and stronger controls.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;“We’re already working with Microsoft to understand new offerings like Security Copilot and Copilot in Intune, our goal is to eliminate repetitive tasks and provide a seamless, intelligent experience for our workforce.”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-center"&gt;Sameer Rane, Director, Global Workplace Services, PepsiCo&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As AI becomes part of everyday endpoint operations, advanced Intune capabilities help IT teams build the secure, data-rich foundation they need to adopt these experiences with greater clarity, control, and impact.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN class="lia-text-color-21"&gt;Get started with advanced endpoint management&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;Across these stories, the through-line is consistent: a strong, well-managed endpoint foundation enables stronger security, faster IT response, and trusted AI adoption. With advanced Microsoft Intune Suite capabilities now included in Microsoft 365 E5, and select capabilities in Microsoft 365 E3, more organizations can put these capabilities to work.&lt;/P&gt;
&lt;P&gt;Whether reducing standing privilege, modernizing certificate management, streamlining application delivery, or preparing for AI-assisted operations, these capabilities work together to help IT teams manage and secure endpoints from a trusted management solution. Organizations can realize these benefits sooner by adopting the advanced Intune capabilities available through their existing Microsoft 365 plans and subscriptions.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN class="lia-text-color-21"&gt;To get started:&lt;/SPAN&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI&gt;Check your Microsoft 365 E3 or E5 eligibility.&lt;/LI&gt;
&lt;LI&gt;Review Message Center notifications to see what is available in your tenant.&lt;/LI&gt;
&lt;LI&gt;Connect with your account team to discuss the right adoption path for your organization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P id="fn1" style="font-size: 0.85em; color: #666;"&gt;&lt;SUP&gt;1&lt;/SUP&gt; Feature availability and included capabilities vary by Microsoft 365 subscription plan. Some advanced Microsoft Intune capabilities may require additional licenses. Existing customers will receive a 30-day notice in their Microsoft Admin Center and will have access by August 2026.&lt;/P&gt;
&lt;P id="fn1" style="font-size: 0.85em; color: #666;"&gt;&lt;SUP&gt;2&lt;/SUP&gt; Microsoft Security Copilot and related AI capabilities may require separate licensing, &lt;A class="lia-external-url" href="https://aka.ms/SecurityCopilotPricing" target="_blank" rel="noopener"&gt;learn more here&lt;/A&gt;.&lt;/P&gt;
&lt;P style="font-size: 0.85em; color: #666;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on&amp;nbsp;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt;or&amp;nbsp;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune &lt;/A&gt;and &lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/advanced-microsoft-intune-capabilities-now-available-in/ba-p/4529335</guid>
      <dc:creator>jfd</dc:creator>
      <dc:date>2026-07-01T16:00:00Z</dc:date>
    </item>
    <item>
      <title>What’s new in Microsoft Intune – June</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-june/ba-p/4491983</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;STRONG&gt;Editor's note (July 2026):&lt;/STRONG&gt; This post has been updated since its original publication. Content related to Intune Endpoint Privilege Management capabilities for system-level network configuration has been removed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;AI agents are beginning to act on behalf of users, interact with company data, and even make decisions independently. Trusting AI depends on three endpoint fundamentals: they must be compliant, up to date, and secure from the moment they enroll. This month’s new capabilities for Intune emphasizes these important checkpoints.&lt;/P&gt;
&lt;H4&gt;Keep applications current and reduce vulnerability exposure&lt;/H4&gt;
&lt;P&gt;Keeping applications up to date sounds straightforward until you're managing hundreds of endpoints and dozens of application versions. Manual packaging processes lead to version drift and inconsistent application states, which makes vulnerability remediation harder and security posture less predictable. &lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-enterprise-app-management" target="_blank" rel="noopener"&gt;Microsoft Intune Enterprise Application Management (EAM)&lt;/A&gt; helps organizations move away from fragmented workflows toward a more unified, cloud-native approach, with deployments, updates, and policy configuration in one place. &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;EAM auto-updates&lt;/A&gt; is now generally available and automatically helps keep managed applications on the latest incremental release, such as 4.1 to 4.2, without manual packaging or admin intervention. This helps limit exposure to known vulnerabilities between full version upgrade cycles.&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1: View of the Intune admin center showing how to apply auto-updates for application management.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;But even with EAM auto-updates helping shrink the vulnerability window, new risks may still arise between update cycles. That's where the &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/copilot/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;Vulnerability Remediation Agent&lt;/A&gt; comes in. Operating within Microsoft Security Copilot and now in public preview, the agent draws on Microsoft Defender Vulnerability Management to prioritize Common Vulnerabilities and Exposures (CVEs) across your Intune-managed Windows devices and apps.&lt;/P&gt;
&lt;P&gt;When the agent runs, it ranks what matters most so you are not starting from a blank CVE list. Recommendations are prioritized by Common Vulnerability Scoring System (CVSS) score, exposure impact, affected device count, and appear directly in the Intune admin center on both the Agents page and the Endpoint security page. When IT admins examine any recommendation, they will see the related CVE count, a summary of the impact assisted by Copilot, suggested actions, the systems affected, the devices exposed, and detailed guidance on how to fix the issues. After taking action, administrators can mark the recommendation as completed.&lt;/P&gt;
&lt;P&gt;The Vulnerability Remediation Agent also operates under a dedicated Microsoft Entra agentic identity, provisioned during setup, rather than under a human user account. Admins delegate the required read permissions to that identity in the Intune and Defender admin centers before the first run. This keeps the agent's scope clearly bound and gives admins a clean audit trail of what it accessed and when. For more information, read our latest blog on &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/triage-vulnerabilities-with-the-vulnerability-remediation-agent-now-in-public-pr/4528646" target="_blank" rel="noopener" data-lia-auto-title="Triage vulnerabilities faster with the Vulnerability Remediation Agent" data-lia-auto-title-active="0"&gt;Triage vulnerabilities faster with the Vulnerability Remediation Agent&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Extend least-privilege controls to shared devices&lt;/H4&gt;
&lt;P&gt;Keeping apps current and staying ahead of known vulnerabilities reduces the attack surface. But risk does not only come from unpatched software; it also comes from who has access and how that access gets granted in the moment. This month, we’ve made support approval requests for non-primary users generally available in &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/epm/overview" target="_blank"&gt;Intune Endpoint Privilege Management&lt;/A&gt;. This capability helps address how elevations work in environments that do not follow a single-user-per-device model.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/epm/manage-support-approvals" target="_blank"&gt;Support approval requests for non-primary users&lt;/A&gt;&lt;/STRONG&gt; extends file elevation requests to any user on a device rather than just the primary enrollee. For example, in organizations running shared workstations across rotating shifts, elevation requests from non-primary users can push IT to create&amp;nbsp; workarounds that can erode a secure least-privilege posture over time. The new capability for support approval requests changes that by routing elevation requests through an auditable workflow regardless of who has signed in, keeping IT in control of every elevation decision.&lt;/P&gt;
&lt;H4&gt;Faster, more complete enrollment across all platforms&lt;/H4&gt;
&lt;P&gt;In the June release of Intune, iOS/iPadOS and macOS automated device enrollment (ADE) profiles will move to a new infrastructure that enables Intune to speed up the delivery of new features. This update rebuilds the enrollment policies experience for Apple ADE devices, reorganizing authentication and removing outdated settings to share more granular policy controls.&lt;/P&gt;
&lt;P&gt;The new experience completes Intune support of &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/device-enrollment/setup-time-grouping" target="_blank" rel="noopener"&gt;enrollment time grouping (ETG)&lt;/A&gt; across all platforms with the addition of iOS/iPadOS and macOS corporate device enrollment with ADE. ETG allows policies and apps targeted to a static group to apply at enrollment time for supported enrollment methods, so critical configurations (i.e., policies and apps targeted to the specific static group) are already in place when a user reaches the home screen. Devices arrive more secure, and users can be productive right away without waiting for policies to catch up. For a full walkthrough of the new experience, see the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-iosipados-visionos-tvos-and-macos-ade-enrollment-policies-experience/4393531" target="_blank" rel="noopener" data-lia-auto-title="New iOS/iPadOS, visionOS, tvOS and macOS ADE enrollment policies experience blog on Microsoft Tech Community" data-lia-auto-title-active="0"&gt;New iOS/iPadOS, visionOS, tvOS and macOS ADE enrollment policies experience blog on Microsoft Tech Community&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Intune: Myth vs. Reality&lt;/H4&gt;
&lt;P&gt;We hope you enjoyed last month’s reality check on &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune-%E2%80%93-may/4491984" target="_blank" rel="noopener" data-lia-auto-title="app migration" data-lia-auto-title-active="0"&gt;app migration&lt;/A&gt;. This month, we’re continuing the conversation on applications with a myth focused on app refresh data.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Myth:&lt;/STRONG&gt; Intune takes seven days for Discovered apps to refresh app inventory data.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Reality:&lt;/STRONG&gt; That seven-day figure was an oversimplification that stuck. No one refresh number existed for every app on every platform, and that seven-day calculation did not apply to the apps an organization’s workforce uses most. Win32 apps listed in Add/Remove Programs collect data every 24 hours, while Windows store apps and apps on non-Windows platforms can have refresh cycles of up to seven days. And now it's getting even better. The new app inventory experience in the All Apps page refreshes its data multiple times per day for active devices, including both Win32 and Windows store apps. This report also shows details that the earlier report did not capture, including install location, app size, and uninstall commands for each app.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How:&lt;/STRONG&gt; Intune continues to enhance its underlying platform infrastructure, resulting in a fresher, more detailed app inventory. This comes from sustained improvements across three fronts: a reconfigured data platform that collects app data; reduced latency that moves data faster; and reporting updates that brings it into the console.&lt;/P&gt;
&lt;P&gt;To learn more, take a closer look at the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/IntuneCustomerSuccess/speed-where-it-matters-how-microsoft-intune-helps-it-prioritize-time-sensitive-a/4515942" target="_blank" rel="noopener" data-lia-auto-title="investments we’re making to support faster, more predictable delivery to devices" data-lia-auto-title-active="0"&gt;investments we’re making to support faster, more predictable delivery to devices&lt;/A&gt;. You can also see how app data is &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enhanced-app-inventory" target="_blank" rel="noopener"&gt;collected and refreshed in the enhanced app inventory experience&lt;/A&gt;. Follow the What's New in Microsoft Intune blog each month to read how these improvements are reflected in the console.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The work behind each capability update is the same whether it shows up in a CVE list, an elevation workflow, or an enrollment screen. AI agents can only move as fast as the foundations beneath them allow. EPM and EAM are now part of Microsoft 365 E5 from July 1. If you missed the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener" data-lia-auto-title="December announcement" data-lia-auto-title-active="0"&gt;December announcement&lt;/A&gt; on what that means for your organization, it is worth a read before these capabilities land in your tenant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on&amp;nbsp;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt; or&amp;nbsp;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune &lt;/A&gt;and &lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2026 16:53:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-june/ba-p/4491983</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-07-06T16:53:47Z</dc:date>
    </item>
    <item>
      <title>IT experts weigh in: Advanced Intune capabilities coming to Microsoft 365 E3 and E5</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/it-experts-weigh-in-advanced-intune-capabilities-coming-to/ba-p/4516898</link>
      <description>&lt;P&gt;Back on December 4th, we shared that &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener" data-lia-auto-title="advanced capabilities from the Microsoft Intune Suite were coming to Microsoft 365 E3 and Microsoft 365 E5" data-lia-auto-title-active="0"&gt;advanced capabilities from the Microsoft Intune Suite were coming to Microsoft 365 E3 and Microsoft 365 E5&lt;/A&gt;. These packaging changes become effective on July 1st, with existing eligible customers expected to receive the capabilities in their tenants by August&lt;SUP&gt;1&lt;/SUP&gt;. So you can understand how these capabilities will help your organization, we’ve pulled together a select set of guides and reviews from IT experts who have earned Microsoft “Most Valuable Professionals” (MVP) status. These MVPs from across segments and industries have real-world experience and lots of hands-on time with Intune.&lt;/P&gt;
&lt;P&gt;So, whether you're a security admin sizing up Endpoint Privilege Management, an IT pro curious what Advanced Analytics reveals about your fleet, a help desk lead rethinking Remote Help, or someone just getting started with Intune, there's something here for you. This roundup is packed with practical, honest, in-practice perspectives from the people who know these capabilities best.&lt;SUP&gt;2&lt;/SUP&gt;&lt;/P&gt;
&lt;P&gt;The focus now is on the practical details: what each capability does, where it fits, and what to consider before deployment. The MVP resources below help answer those questions with implementation guidance, technical context, and comparisons that can help teams evaluate the right approach for their environment.&lt;/P&gt;
&lt;P&gt;Here’s a quick refresher on the Microsoft 365 plan changes related to Microsoft Intune:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 49.9518%" /&gt;&lt;col style="width: 49.9518%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft 365 plan&lt;SUP&gt;2&lt;/SUP&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Newly included Intune capabilities &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;EMS E3  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;(&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Included&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;in Microsoft 365 E3) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Remote Help  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Advanced Analytics  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Plan 2 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft 365 E5 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;All the above &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;plus&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Endpoint&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Privilege&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; Management  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft Cloud PKI   &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Enterprise App Management &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft Security Copilot &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4&gt;One place to manage it all&lt;/H4&gt;
&lt;P&gt;Customers have been clear that they want to make full use of the capabilities already included in their licenses and manage them from a more centralized platform. They also want to understand the tradeoffs: how consolidation changes day-to-day operations, how these capabilities work with Cloud PCs, and what it means to reduce reliance on multiple vendors, contracts, and support models.&lt;/P&gt;
&lt;P&gt;The Microsoft MVP resources below tackle those questions directly such as what's included in your license and how integrated endpoint management plays out in practice.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=oD-st6f2YvA" target="_blank" rel="noopener"&gt;Microsoft Intune Suite in E3 vs E5: What's Included from July 2026&lt;/A&gt; – &lt;EM&gt;Dean Ellerby&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.xplorethecloud.nl/l/intune-suite-not-an-add-on-but-a-part-of-your-microsoft-suite/" target="_blank" rel="noopener"&gt;Intune Suite: Not an Add-on but a part of your Microsoft 365 Suite&lt;/A&gt; – &lt;EM&gt;Johan Adreaan (Arno) van Dijk&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/pulse/one-console-every-endpoint-why-2026s-microsoft-365-update-jon-jarvis-vw1le" target="_blank" rel="noopener"&gt;One Console, Every Endpoint: Why 2026’s Microsoft 365 Update Actually Matters for Your Cloud PCs&lt;/A&gt; – &lt;EM&gt;Jon Jarvis&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.burgerhout.org%2Fp%2F7f5e1a0a-5c12-47e0-b1b2-a93911cd3315%2F%3Fmember_status%3Dfree&amp;amp;data=05%7C02%7Cv-olverjon%40microsoft.com%7C9ea6233a5d3749c0b89b08dec6c1d674%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639166733013660742%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=xniAE5MNVRGHG6QMw%2Bf3JbHQeA7ZdD74wc9asW7RdH0%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Windows 365 x Intune Suite: Looking Beyond the Feature List&lt;/A&gt; – &lt;EM&gt;Jeroen Burgerhout&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Our MVPs have also taken deep dives into the individual capabilities that are coming to E3 and E5 (and are still available to other license holders as an add-on).&lt;/P&gt;
&lt;H4&gt;Advanced Analytics&lt;/H4&gt;
&lt;P&gt;Advanced Analytics gives IT teams a clearer view of endpoint health and performance, with capabilities like device query, anomaly detection, and battery health reporting that build on endpoint analytics. For Microsoft 365 E3 and E5 customers, troubleshooting and fleet-wide visibility are now part of the plan. See the official documentation &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/advanced-analytics/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmsnugget.com%2Fget-ready-for-advanced-analytics-in-m365-e3-and-e5%2F&amp;amp;data=05%7C02%7Cv-olverjon%40microsoft.com%7C84a8dbcaeda74710ae5e08decbca4842%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639172266816406456%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=bvgn83JaCmtpm2ezxuu%2F%2BiEs%2B%2BjbzBhsMDX7SneV1KY%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Get Ready for Advanced Analytics in M365 E3 and E5&lt;/A&gt; – &lt;EM&gt;Florian Salzmann &amp;amp; Jannik Reinhard&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://rozemuller.com/microsoft-intune-advance-analytics-more-than-endpoint-analytics/" target="_blank" rel="noopener"&gt;Microsoft Intune Advanced Analytics more than Endpoint Analytics&lt;/A&gt; – &lt;EM&gt;Sander Rozemuller&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/pulse/using-intune-suite-advanced-analytics-solve-issues-faster-panu-saukko-0qcsf/" target="_blank" rel="noopener"&gt;Using Intune Suite Advanced Analytics to Solve Issues Faster&lt;/A&gt; – &lt;EM&gt;Panu Saukko&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://jannikreinhard.com/2026/06/13/intune-advanced-analytics-market-comparison/" target="_blank" rel="noopener"&gt;Intune Advanced Analytics: How It Compares to Other Tools&lt;/A&gt; – &lt;EM&gt;Jannik Reinhard&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Remote Help&lt;/H4&gt;
&lt;P&gt;Remote Help is a cloud-based solution that enables secure, role-based help desk connections to managed devices, with support for unattended scenarios and compliance with Intune's RBAC model. See the official documentation &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/remote-help/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://cracky96.blogspot.com/2026/06/how-to-implement-intune-remote-help.html" target="_blank" rel="noopener"&gt;How to Implement Intune Remote Help&lt;/A&gt; – &lt;EM&gt;Thant Zin Phyo&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://gerryhampsoncm.blogspot.com/2026/06/you-have-intune-remote-help-already-you.html" target="_blank" rel="noopener"&gt;You have Intune Remote Help already, you might as well use it&lt;/A&gt; – &lt;EM&gt;Gerry Hampson&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.rockenroll.tech/2026/06/14/microsoft-intune-remote-help-my-overview/" target="_blank" rel="noopener"&gt;Microsoft Intune Remote Help: My Overview&lt;/A&gt; – &lt;EM&gt;Nicklas Ahlberg&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Endpoint Privilege Management&lt;/H4&gt;
&lt;P&gt;Endpoint Privilege Management (EPM) lets organizations elevate permissions for specific, IT-approved tasks on a just-in-time basis, avoiding the need to create users with ‘admin’ privileges for routine activities, directly supporting a Zero Trust, least-privilege posture. See the official documentation &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/epm/overview" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://ccmexec.com/2026/06/microsoft-intune-endpoint-privilege-management-overview/" target="_blank" rel="noopener"&gt;Microsoft Intune Endpoint Privilege Management Overview&lt;/A&gt; – &lt;EM&gt;Jorgen Nilsson&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://msendpointmgr.com/2026/06/15/epm-part-1-the-end-of-local-admin-how-intune-endpoint-privilege-management-solves-a-problem-it-has-lived-with-for-decades/" target="_blank" rel="noopener"&gt;The end of local admin - How Intune Endpoint Privilege Management solves a problem IT has lived with for decades&lt;/A&gt; – &lt;EM&gt;Mattias Melkersen Kalvåg &amp;amp; Simon Skotheimsvik&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://scloud.work/intune-endpoint-privilege-management-vs-the-alternatives/" target="_blank" rel="noopener"&gt;When Intune Endpoint Privilege Management Wins, and When It Does Not&lt;/A&gt; – &lt;EM&gt;Florian Salzman&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Just getting started with Intune?&lt;/H4&gt;
&lt;P&gt;If all this is new to you, you don’t need to absorb every advanced capability at once. A great place to begin is &lt;A class="lia-external-url" href="https://www.indefent.com/advanced-microsoft-intune-capabilities-whats-changing-and-where-it-pros-should-start/" target="_blank" rel="noopener"&gt;Albin Klinaku's guide&lt;/A&gt;, which walks through what these E3 and E5 changes mean for someone getting started and breaks down the fundamentals in an approachable way. From there, the official &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/" target="_blank" rel="noopener"&gt;Microsoft Intune overview&lt;/A&gt; on Microsoft Learn provides tutorials. Start there, explore at your own pace, and you'll be ready to make the most of everything coming to your tenant.&lt;/P&gt;
&lt;H4&gt;A special thanks to our contributors&lt;/H4&gt;
&lt;P&gt;None of this guidance would exist without the community behind it, which brings me to the people who made this roundup possible. A big thank you to the MVPs who took the time to share their perspectives on this important news:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Nicklas Ahlberg | Thant Zin Phyo | Gerry Hampson | Dean Ellerby | Jorgen Nilsson | Mattias Melkersen Kalvåg | Florian Salzmann | Sander Rozemuller | Panu Saukko | Jannik Reinhard | Jon Jarvis | Jeroen Burgerhout | Simon Skotheimsvik | Arno van Dijk | Albin Klinaku&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Your expertise, generosity, and willingness to share continue to elevate the entire Intune community. Thank you for everything you do. Stay secure, stay innovative, and be well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt;or&amp;nbsp;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune &lt;/A&gt;&lt;/EM&gt;&lt;EM&gt;and &lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/it-experts-weigh-in-advanced-intune-capabilities-coming-to/ba-p/4516898</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2026-06-18T16:00:00Z</dc:date>
    </item>
    <item>
      <title>What’s new in Microsoft Intune – May</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-may/ba-p/4491984</link>
      <description>&lt;P&gt;Whether it's Android app deployment, identity setup on macOS, certificate authority renewal, or faster compliance evaluations, the throughline is the same: less friction for the IT admins doing the work.&lt;/P&gt;
&lt;H4&gt;More control over how admins manage and protect Android devices&lt;/H4&gt;
&lt;P&gt;A device that never got properly enrolled is still a risk, even if nobody's touched it in months. That's the kind of thing that keeps IT admins up at night. Three Android updates this month each address a different point where that risk shows up: getting devices onto the platform, making sure the right apps land on them, and keeping security policies running once they do.&lt;/P&gt;
&lt;P&gt;For enrollment, the Personal Work Profile Android Management API implementation is now generally available. One of the quieter but more effective changes here is that end users no longer have to hunt down the Company Portal app before they start enrollment. Organizations can opt into a web-based enrollment flow where everything begins from a browser, and policies are delivered through the &lt;A class="lia-external-url" href="https://developers.google.com/android/management" target="_blank" rel="noopener"&gt;Android Management API&lt;/A&gt; from there. That brings personally owned work profile devices onto the same underlying management technology as corporate-owned Android Enterprise scenarios and gives admins a more consistent policy experience across Android.&lt;/P&gt;
&lt;P&gt;On the app side, directly managing Android line-of-business (LOB) apps in Intune is now generally available for Android Enterprise fully managed and dedicated devices. Previously, even internally developed apps had to be uploaded and distributed via Managed Google Play. With this update, admins can upload APK files straight to Intune, deploy multiple versions of the same app to different user or device groups, and remove constraints like requiring unique package names. This provides admins more flexibility and control over how internal Android applications are managed and distributed.&lt;/P&gt;
&lt;P&gt;Finally, Mobile Threat Defense (MTD) apps can now request enhanced security permissions on Android Enterprise devices, building on the existing &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/device-security/mobile-threat-defense/enable-connector" target="_blank" rel="noopener"&gt;MTD connector&lt;/A&gt; in Intune. Google is introducing a capability that allows an MTD app to operate with additional security permissions on managed devices. You can use the MTD connector in the Intune admin center to grant those permissions to one MTD app of your choice, such as &lt;A class="lia-external-url" href="https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint" target="_blank" rel="noopener"&gt;Microsoft Defender for Endpoint&lt;/A&gt; or a supported third-party partner. On Android Enterprise fully managed devices and corporate-owned devices with a work profile, the selected MTD app can be exempted from app suspension, hibernation, and user-initiated restrictions. This helps threat detection and risk evaluation continue running even when the rest of the device is being optimized for battery life or user control.&lt;/P&gt;
&lt;H4&gt;Platform SSO registration built into macOS setup&lt;/H4&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/Intune/MacPSSO-Setup" target="_blank" rel="noopener"&gt;Platform SSO with registration during Automated Device Enrollment on macOS&lt;/A&gt; is now generally available for macOS devices.&lt;/P&gt;
&lt;P&gt;Previously, PSSO registration occurred after enrollment was complete, requiring users to click a notification on their desktop to finish setup. But these notifications are often missed, leading to incomplete SSO configuration, authentication failures in apps like Outlook, and devices that showed as non-compliant in Company Portal. IT teams managing Mac deployments at scale identified this as a consistent friction point.&lt;/P&gt;
&lt;P&gt;With this release, PSSO device registration completes automatically during ADE, bootstrapping identity and linking the device to Entra ID before the user ever reaches their desktop. The result is a setup experience where end users arrive at a desktop that is already PSSO-registered, authenticated, and equipped with the identities for accessing resources. This capability is designed for IT teams managing corporate-owned, single-user Mac devices where timing of when identity and enrollment are critical for compliance and productivity. To learn more, &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment" target="_blank" rel="noopener"&gt;read our documentation about configuring PSSO during ADE&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;Cloud PKI provides more control over certification authority (CA) renewal&lt;/H4&gt;
&lt;P&gt;Microsoft Intune now supports renewing an existing Cloud PKI issuing certification authority (CA) directly, helping administrators maintain uninterrupted certificate issuance as a CA approaches expiration. Previously, renewing a CA required creating a new issuing CA and manually updating all dependent Simple Certificate Enrollment Protocol (SCEP) certificate profiles. With this update, eligible Cloud PKI issuing CAs can be renewed in place, generating a new CA certificate and key pair to reduce operational overhead and lower the risk of configuration errors.&lt;/P&gt;
&lt;P&gt;This capability helps provide continued certificate-based access for scenarios such as Wi-Fi, VPN, and email without requiring changes to existing SCEP profiles or device assignments. As part of the renewal process, Intune automatically creates a staged CA with a temporary SCEP endpoint, enabling admins to validate issuance and compatibility across their environment in a safe, controlled manner before activation. This staged validation model helps organizations complete renewal with minimal disruption and without taking services offline. To learn more about prerequisites and implementation details, visit the &lt;A class="lia-external-url" href="https://learn.microsoft.com//intune/cloud-pki/renew-ca" target="_blank" rel="noopener"&gt;Microsoft Learn page&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;H4&gt;Intune: Myth vs. Reality&lt;/H4&gt;
&lt;P&gt;We hope you enjoyed last month’s Myth vs. Reality entry on &lt;A class="lia-external-url" href="https://aka.ms/IntuneWN2604" target="_blank" rel="noopener"&gt;latency&lt;/A&gt;. This month, the focus is on &lt;STRONG&gt;application management in Intune. &lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Myth: &lt;/STRONG&gt;App migration to Intune is all-or-nothing. You must move all apps at once or not at all.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reality: &lt;/STRONG&gt;App management in Intune supports phased adoption. With co-management, you can migrate apps gradually while Configuration Manager continues deploying apps that have not moved yet. Moving the apps workload to Intune enables cloud-native app delivery—apps reach devices anywhere over the Internet, with no distribution points or on-prem infrastructure to maintain. And you manage Windows app deployment in the same place as your macOS, iOS, and Android apps.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;How: &lt;/STRONG&gt;Move the Client apps workload when you're ready by starting with a pilot collection, then expand by app type or persona as confidence grows. When migrating by app type, prioritize low-risk and low-complexity categories and apps first to reduce early friction and validate your approach.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For example, start with Microsoft Store apps or apps delivered through Intune &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;Enterprise Application Management&lt;/A&gt;, as these often do not require repackaging or customization, then move to simple Win32 applications with minimal dependencies before addressing more complex scenarios. In parallel, or as a follow-on motion, migrate by persona. Start with user groups that have predictable, standardized requirements, such as knowledge workers who primarily use Microsoft 365 apps, a browser, and a small set of common utilities. This helps validate end-to-end deployment, user experience, and support readiness before you expand to more complex roles. From there, you can expand confidently to developers and engineers with customized tool chains.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/configmgr/comanage/workloads" target="_blank" rel="noopener"&gt;Start exploring co-management workloads&lt;/A&gt; in Configuration Manager and take the first step toward a more flexible, phased migration to Intune. To accelerate your migration, our partners &lt;A class="lia-external-url" href="https://www.rimo3.com/" target="_blank" rel="noopener"&gt;Rimo3&lt;/A&gt; and &lt;A class="lia-external-url" href="https://robopack.com/" target="_blank" rel="noopener"&gt;Robopack&lt;/A&gt; are offering a time-limited app migration service to all Intune customers who are looking to move from Configuration Manager to Intune&lt;SUP&gt;1&lt;/SUP&gt;.&amp;nbsp;To learn more, visit &lt;A class="lia-external-url" href="https://aka.ms/IntuneAppMigration" target="_blank" rel="noopener"&gt;aka.ms/IntuneAppMigration&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This month's features and the Myth vs. Reality section are making the same point: you do not need to solve everything at once. Enroll the predictable users first. Migrate the simple apps before the complex ones. Renew your CA without rebuilding your profiles. Start there, build confidence, and expand. Let us know what you think.&lt;/P&gt;
&lt;HR /&gt;&lt;FOOTER style="font-size: 12px; color: #666; margin-top: 40px;"&gt;
&lt;P id="fn1"&gt;&lt;SUP&gt;1&lt;/SUP&gt;&lt;STRONG&gt;Note: &lt;/STRONG&gt;The app migration services listed on this page are offered directly by partners and are subject to their terms. Microsoft makes no guarantees or commitments regarding availability or outcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/FOOTER&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on&amp;nbsp;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune &lt;/A&gt;and &lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 21:58:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-may/ba-p/4491984</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-05-28T21:58:33Z</dc:date>
    </item>
    <item>
      <title>What’s new in Microsoft Intune – April</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-april/ba-p/4493135</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;April's Intune updates focus on three areas administrators have consistently asked us to improve: fresher device data, streamlined identity foundations across platforms, and simpler management for non-traditional endpoints. This month includes advancements in Windows app inventory, Linux single sign-on (SSO), and expanded enrollment and control for Apple devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Higher‑frequency app inventory updates &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;for Windows devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IT administrators monitoring applications often rely on a feature known as&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/app-discovered-apps" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Discovered apps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. With the general release of enhanced app inventory &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;capabilities in the “All Apps” tab, this function provides more detailed and more frequently refreshed inventory data. Some platforms refresh Discovered apps inventory every seven days. App inventory now updates Windows apps on a more frequent schedule, uploading only changes since the last sync, which can help limit additional network usage.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;App inventory data is updated across the fleet, with most active, healthy Windows devices refreshed multiple times per day.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Besides more frequent data, the range of properties collected by the inventory agent has expanded. Install paths, install dates, uninstall commands, estimated size, architecture, and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;per-user install scope are now included. Store-specific identifiers and supported languages, which were not part of the Discovered apps before, are also included here. IT admins also benefit with how inventory collection takes place across all users who have accessed the device and not just the logged-in user, helping reduce issues of applications coming and going as users change.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To take advantage of app inventory, a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/device-configuration/settings-catalog/?tabs=sc-search-filter%2Csc-reporting" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;new device configuration policy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;should be set up based on&amp;nbsp;Properties&amp;nbsp;Catalog and assigned to corporate-owned Windows 11 devices enrolled in&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/fundamentals/what-is-entra" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Entra ID&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. Once configured, inventory data will start coming in on subsequent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;check-ins.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Modernized&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;SSO&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Linux&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;endpoints&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The new sign-in process offers Linux users a low-friction and phishing-resistant sign-in option similar to Windows and macOS, alongside a smaller footprint and more integrated use of Entra ID technology.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;This introduces advanced SSO functionality for Linux endpoints, utilizing the Microsoft Identity Broker. This is a modern C++ identity broker that integrates Linux devices with Microsoft Entra ID and replaces the legacy Java broker for Intune. To learn more visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/sso-linux?tabs=password-auth%2Cdebian-install%2Cdebian-update%2Cdebian-uninstall%2Cdebian-sc-example" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft single sign-on for Linux&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The Microsoft Identity Broker supports a more integrated trust model between the endpoint and Microsoft Entra ID by using full device join to issue device-bound authentication tokens, going beyond what basic enrollment supports. This way, admins can employ Phishing-Resistant Multi-Factor Authentication (PRMFA ) to authenticate, which includes certificate-based authentication, smart cards, and Personal Identity Verification (PIV) enabled security keys. Additionally, the same SSO flow now works on iOS as it does on Windows and macOS, where Microsoft Authentication Library (MSAL) APIs can provide SSO for non-Microsoft applications. For configuration details about SSO on Linux with Entra ID, read our&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-device-registration-tool-linux" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device Registration Command Tool for Linux&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; instructions.&amp;nbsp;It's a win for admins and end users alike:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;End users&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;receive a&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity/devices/troubleshoot-device-registration-tool-linux" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Primary Refresh Token (PRT)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; and see fewer credential prompts, improving the sign-in experience.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;IT admins&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; get full Conditional Access and device compliance through Entra ID join, plus a smaller installation package and reduced background authentication tasks now that the Java runtime dependency is gone.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Expanded management capabilities for Apple devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune has worked to enhance endpoint management for iOS, iPadOS, macOS, visionOS, and tvOS devices in enterprise environments. In this section, we will look at some of the capabilities released this month to help simplify management of Apple devices at scale and set up end users for success with an identity-ready setup.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;visionOS&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; and tvOS enrollment, including government cloud&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Expanding Intune Plan 2 specialty devices, automated device enrollment (ADE) for visionOS and tvOS is now available, including Government Community Cloud High, all government cloud tenants, and will be included from July 1 for&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft 365 E3 and E5 licenses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; Organizations managing large-scale Apple device deployments in unattended and shared-use scenarios can now leverage userless ADE for visionOS and tvOS. This includes devices like Apple TVs in conference rooms, patient rooms, or retail locations, and Vision Pro headsets deployed to training and design teams. These devices can now be enrolled and managed without user affinity or individual sign-in.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;After enrollment, visionOS and tvOS devices can be remotely deleted, retired, restarted, renamed, or synced, individually or in bulk. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Admins can send down configuration profiles via custom file upload for these devices. They can also restrict enrollment by specifying if these operating systems can enroll into their organization.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;With&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/device-enrollment/setup-time-grouping" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;enrollment time grouping&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; within the ADE enrollment policy, administrators will have the ability to group devices at enrollment time within the new ADE enrollment policies experience, helping ensure critically assigned policies, scripts, and apps start installation during Setup Assistant. Read our&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-iosipados-and-macos-ade-enrollment-policies-experience/4393531" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;blog post about the new iOS/iPadOS and macOS ADE enrollment policies experience&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; to learn more.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Example of how to create&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;visionOS&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;/tvOS enrollment policy using ADE in the Intune admin cente&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;r.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;H5 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Tighter control over Managed Apple Accounts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Rounding out this month's Apple updates, Intune now allows organizations to choose whether&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.apple.com/en-gb/guide/business/axm53xk34bq/web" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Managed Apple Accounts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can be used on any Apple device or only on organization-owned devices. In practice, this means corporate identities stay on corporate hardware, and personal Apple Accounts can be blocked from signing in to organization-owned devices entirely. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;This is especially important in regulated sectors, such as financial services, where organizations need to prevent corporate data from residing on unmanaged,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;non-organization-owned devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune: Myth vs. Reality (new &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;segment&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Starting this month, the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;What’s New in Intune&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;blog includes a new segment,&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune: Myth vs. Reality&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;. This series will address common assumptions about endpoint management and how Intune works in practice.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;This month’s topic: Change-based delivery speed and responsiveness&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Myth: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;App and policy changes take 8-hours to apply&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Reality:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Intune processes 90% of device changes in less than an hour&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;How&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;The commonly cited “8‑hour” timing reflects a routine maintenance check‑in — not how Intune delivers meaningful changes today. Most high-impact app deployments, policy updates, and device actions are delivered through prioritized, change‑based delivery paths that typically reach online devices much faster. By distinguishing these time-sensitive changes from routine maintenance activity and handling them differently, Intune helps reduce the likelihood that important changes aren’t unnecessarily delayed.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;To go deeper, &lt;A href="https://aka.ms/IntuneMythSlowSync" data-outlook-id="1c89dcdc-4b75-4243-bc95-633b94823ce9" target="_blank"&gt;read our latest blog&lt;/A&gt;, which explains how Intune processes updates at scale, including priority‑aware check‑ins, push‑based signaling, and platform‑specific optimizations that improve consistency and responsiveness across devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;That’s a wrap for April. &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Whether you were interested in device data improvements, Apple enrollment expansions, or the Myth vs. Reality section, we'd love to hear your thoughts in the comments below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 19:21:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-april/ba-p/4493135</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-04-30T19:21:31Z</dc:date>
    </item>
    <item>
      <title>Microsoft Intune announces Android Enterprise management support for Android XR</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-intune-announces-android-enterprise-management-support/ba-p/4508499</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune now supports the Android XR platform, including management of the Samsung Galaxy XR headset, which is built on Android XR platform. This means that IT admins can begin evaluating and deploying Android XR devices using familiar Intune management capabilities, building on the Android Enterprise security foundation they already have.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With the&amp;nbsp;&lt;A href="https://www.androidenterprise.community/product-updates/android-enterprise-management-arrives-for-android-xr-2392" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;April&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Android&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;XR&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;release&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Intune&amp;nbsp;will support&amp;nbsp;core Android Enterprise management scenarios on Android XR devices. This&amp;nbsp;means&amp;nbsp;IT admins&amp;nbsp;can&amp;nbsp;start evaluating and deploying XR devices using existing enrollment, policy, and app management workflows, while&amp;nbsp;planning ahead&amp;nbsp;for more advanced scenarios as the platform matures.&amp;nbsp;This release reflects close collaboration between Microsoft, Google, and&amp;nbsp;Samsung, and&amp;nbsp;extends familiar Intune and Android Enterprise enrollment, policy, and app management capabilities to Android XR, starting with a strong foundational set of features.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Android XR devices will be managed in Intune as specialty devices, consistent with other immersive and purpose-built form factors. This is currently tied to the Intune Plan 2 SKU. Availability within&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 E3 and E5 licenses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;is planned for later in 2026.&amp;nbsp;You can&amp;nbsp;check the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/fundamentals/licensing/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune licensing documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for current details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What is supported in Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With this release, IT admins can now manage their Android XR based devices in Intune with the following capabilities:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Android Enterprise enrollment and baseline management&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Devices can enroll using supported Android Enterprise flows for Fully Managed and Dedicated devices and receive policies as expected.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;App deployment with Managed Google Play&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Admins can distribute and manage approved applications through Managed Google Play.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Security and compliance policies&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Core Android Enterprise security and compliance settings will be supported, subject to Android XR platform constraints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Visibility in the Intune admin center&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Android XR devices appear in the Intune console and can be monitored and managed alongside other Android endpoints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These capabilities enable organizations to begin testing and deploying Android XR for user-assigned and managed scenarios where foundational device and app management are required.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;i&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;n&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ot&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;upported&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The following capabilities are not supported with this platform release:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Lock task (kiosk) mode&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Lock task mode—whether for 2D or 3D apps—will not be supported in Intune with the initial Android XR release. This means kiosk scenarios will not be supported at this time, even though assigning policy is not blocked.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Custom launchers and Managed Home Screen&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Custom launcher experiences, including Managed Home Screen, will not be supported.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;OEMConfig and OEM&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;specific&amp;nbsp;extensions&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Android XR devices do not&amp;nbsp;have&amp;nbsp;support&amp;nbsp;for&amp;nbsp;OEMConfig. As a result, OEM-specific management extensions (including&amp;nbsp;Knox&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;based APIs) are unavailable.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune Remote Help&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Intune Remote Help capabilities will not be available for Android XR with this latest release. On Samsung devices, Remote Help relies on Knox APIs, which are not present in Android XR at launch. These exclusions reflect the current state of the Android XR platform. As the platform matures and new capabilities become available, we anticipate opportunities to expand Intune's management coverage accordingly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Next &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;teps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Android XR is a new platform with an evolving management and validation model. As Android XR matures, Microsoft Intune intends to align with new platform management capabilities as they become available. Updates will be communicated through Intune release notes, documentation, and future blog posts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For now, you can begin&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;testing enrollment, policy application, and app deployment&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; with Intune,&amp;nbsp;while&amp;nbsp;planning for&amp;nbsp;kiosk, launcher, and remote support scenarios as future platform updates roll out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We look forward to supporting customers as Android XR evolves and becomes part of the modern endpoint landscape.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&amp;nbsp;&lt;/A&gt;or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 17:29:21 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-intune-announces-android-enterprise-management-support/ba-p/4508499</guid>
      <dc:creator>Priya_Ravichandran</dc:creator>
      <dc:date>2026-04-07T17:29:21Z</dc:date>
    </item>
    <item>
      <title>Windows 365 + Intune Advanced Endpoint Management Capabilities: Better Together</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/windows-365-intune-advanced-endpoint-management-capabilities/ba-p/4503802</link>
      <description>&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Overview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 and Microsoft Intune form a tightly integrated solution for modern endpoint management. With Windows 365 delivering secure Cloud PCs (full Windows desktops hosted in the Microsoft cloud) and Intune’s recently extended advanced endpoint management capabilities, organizations can manage Cloud PCs and physical devices side-by-side in a single view. This “better together” approach helps IT teams enforce consistent security and compliance policies across all endpoints following&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/zero-trust-with-microsoft-intune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Trust&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; principles&amp;nbsp;while improving the user experience.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Key technical integration highlights&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Before exploring the specific advantages that Intune features bring to Windows 365 Cloud PCs, let’s first outline some of the key overall advantages of the native integration between Windows 365 and Intune.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Unified Endpoint Management:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Windows 365 Cloud PCs are managed directly through Microsoft Intune, appearing alongside standard Windows devices in the same cloud-based admin portal. This unified approach eliminates the need for separate Virtual Desktop Infrastructure (VDI) tools or infrastructure; instead, Microsoft hosts and manages the Cloud PC platform so that IT admins can easily provision, configure, and monitor both Cloud and physical PCs in one interface by simply assigning licenses and policies. As a result, device management is streamlined and complexity is reduced.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;“Both the allocation and deletion of Windows 365 can be completed in just a few minutes using Microsoft Entra ID and Intune. It was exactly the same when we switched the environment to Windows 365 for employees participating in overseas projects. I did it while sitting in my seat at the office.” &lt;/EM&gt;&lt;STRONG&gt;Shunsuke Hanano&lt;/STRONG&gt;, Assistant Manager, IT Planning Group, Group IT Promotion Department,&amp;nbsp;&lt;A href="https://www.microsoft.com/en/customers/story/1777512359274259497-avantgroup-azure-professional-services-en-japan" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Avant Group Corporation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Identity &amp;amp; Zero Trust Security:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Cloud PCs use Microsoft Entra ID (formerly Azure&amp;nbsp;Active&amp;nbsp;Directory)&amp;nbsp;for authentication, allowing organizations to enforce Intune and Conditional Access policies,&amp;nbsp;including multi-factor authentication and device compliance checks,&amp;nbsp;before granting access to Cloud PCs. This ensures that only verified users on compliant devices can sign-in, supporting a Zero Trust security model. Integration with Microsoft Defender provides Cloud PCs with consistent security baselines, antivirus, and threat monitoring, just like physical endpoints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Security &amp;amp; Compliance Policies:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune treats Cloud PCs as equal to physical devices, applying security baselines, compliance policies, and updates consistently. It enforces requirements like up-to-date OS and antivirus, and monitors compliance—restricting access or prompting remediation if standards are not met. Cloud PCs send threat data to Microsoft Defender, integrating with company-wide security monitoring. Device compliance policies, configuration profiles, Windows Update rings, and application deployments are all uniformly managed through Intune, ensuring Cloud PCs meet the same security and update standards as other corporate devices.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Monitoring &amp;amp; Analytics:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Through&amp;nbsp;Endpoint Analytics&amp;nbsp;in Intune, admins get deep visibility into Cloud PC performance and reliability. Intune&amp;nbsp;reports can highlight&amp;nbsp;whether&amp;nbsp;a Cloud PC is under-resourced (e.g.,&amp;nbsp;frequent CPU or memory spikes) and recommend resizing that Cloud PC for better performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Now, let’s focus on each Intune advanced capability and how it can benefit Windows 365 users and admins. Intune Suite add-ons will soon be natively available within the E3/E5 Microsoft 365 offerings. Those add-ons are designed to work natively with Windows 365 too, using the same workflow as for physical devices&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Coming to e&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;nterprise mobility and security &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;E3&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;(Included in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;365 E3)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Remote Help (secure remote support&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;): &lt;/STRONG&gt;Allows IT to assist remote Cloud PC users in real time with secure, authenticated screen sharing/control. Both helper and user use corporate Entra ID accounts, preventing impersonation and non-compliant Cloud PCs trigger warnings so that issues are resolved safely. This also expedites troubleshooting and reduces downtime for distributed teams.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Advanced Endpoint Analytics:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Provides deep insight into Cloud PC performance and user experience. Advanced Analytics through Intune identifies patterns like high CPU/RAM usage or slow boot times on Cloud PCs and offers recommendations to fix issues (such as resizing a Cloud PC’s resources). Anomaly detection proactively surfaces device health issues like app crashes, hangs, and Stop Error restarts early, preventing user impact and allowing IT admins to spot and proactively resolve problems, as well as compare Cloud PC health across models or against industry benchmarks, resulting in better reliability and happier users.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;And coming into Microsoft 365 E5&lt;/SPAN&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Endpoint Privilege Management (EPM):&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Enables Cloud PC users to run with standard user rights (no local admin), improving security by minimizing privileges. Through EPM, specific tasks or apps can be elevated on demand via policy when needed, helping users stay productive (e.g., installing approved software) without permanent admin rights. Admins get full control and auditing of these elevations.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;“With the introduction of Windows 365, we will eliminate administrative privileges as part of our security enhancements, and to do so, we are testing &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-endpoint-privilege-management" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Endpoint Privilege Management.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;EM&gt; It will allow us to temporarily grant administrative privileges and install only specific applications.” &lt;/EM&gt;&lt;STRONG&gt;Masahiro Kimura&lt;/STRONG&gt;, Head of the OA and Communication Infrastructure Office, Network and OA Technology Department,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en/customers/story/1779428638140338265-hino-motors-azure-professional-services-en-japan" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Hino Motors&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Cloud PKI:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Enables an&amp;nbsp;enterprise&amp;nbsp;scale PKI to be deployed fully in the cloud, allowing for secure deployment of certificates to&amp;nbsp;end&amp;nbsp;user&amp;nbsp;devices&amp;nbsp;without the need for an&amp;nbsp;on-premises&amp;nbsp;network&amp;nbsp;connection&amp;nbsp;VPN&amp;nbsp;or&amp;nbsp;a traditional PKI infrastructure. This enables a move to modern management, both for Cloud PC’s&amp;nbsp;and physical enterprise devices.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Enterprise App Management:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Streamlines the entire application lifecycle for Windows 365 Cloud PCs. IT admins can use the Microsoft-hosted Enterprise App Catalog to easily deploy, update, and&amp;nbsp;maintain&amp;nbsp;essential Microsoft and third-party&amp;nbsp;Win32&amp;nbsp;apps—removing the need for manual packaging and updates.&amp;nbsp;This ensures Cloud PCs are provisioned with the necessary applications from the start and remain up to date without extra effort.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Conclusion and a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;dministrative benefits&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;For IT administrators, the “better together” solution of Windows 365 and Intune means simpler operations and more streamlined management. All endpoints, whether physical or Cloud PC, are handled with a common set of tools and processes, reducing the need for specialized expertise. Admins can provision or deprovision Cloud PCs quickly (no need to image devices or to maintain a complex VDI environment), and the unified policies in Intune ensure configuration drift is minimized. This integrated approach also means fewer vendors and agents to deal with: endpoint security, management, and virtualization all come from Microsoft, which improves reliability and support.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Many organizations are seeking to consolidate their security and endpoint tools to eliminate inefficiencies—and the Windows 365 + Intune combination is well-positioned to meet this need. In summary, Windows 365 and Intune provide a competitive edge: they simplify IT administration, strengthen security across all devices, and empower users—all within one holistic, cloud-first solution.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P aria-level="2"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt;or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/windows-365-intune-advanced-endpoint-management-capabilities/ba-p/4503802</guid>
      <dc:creator>tanialima</dc:creator>
      <dc:date>2026-04-02T16:00:00Z</dc:date>
    </item>
    <item>
      <title>What’s new in Microsoft Intune – March</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-march/ba-p/4493136</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In a typical week, IT admins are enrolling devices, deploying apps, enforcing policies, and making a hundred small decisions that keep their organizations running. This month’s updates focus on improving the experience around daily actions, compliance visibility, and management capabilities for Apple devices and mobile apps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;More&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;timely&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;notifications&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;Microsoft Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune sends notifications to devices when changes occur that require devices to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;check in. When those notifications are delayed, whether from devices being offline or in a particular state (network instability, low battery, etc.), the action can be delayed, and devices can miss the check in. Now, on Windows devices, we're complementing the Windows Notification Service (WNS) with the same notification protocol that powers Microsoft Teams to support more timely notification delivery that gives admins the traceability they need for troubleshooting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We're introducing this functionality with Remote Help for Windows to help reduce the likelihood of stalled session starts when devices are online and reachable. We recommend updating firewall rules to include this new endpoint: *&lt;U&gt;.&lt;/U&gt;&lt;/SPAN&gt;&lt;U&gt;&lt;SPAN data-contrast="auto"&gt;trouter.communications.svc.cloud.microsoft&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN data-contrast="auto"&gt;. Stay informed about our progress by bookmarking the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/intune-management-extension#intune-management-extension-logs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune Management Extension logs documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help-use?tabs=windows%2Cwindowsnative#provide-help" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Remote Help for Windows documentation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;New controls for role assignment, device setup, and update readiness&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Scope tags are used by Intune to control resources that an administrator can act on in Microsoft Intune. When an admin holds multiple role assignments with different scope tags, those tags can be combined and grant more access than intended. A new de-union setting lets admins keep these scopes discrete and within the boundaries they define. This prevents a role assignment from expanding based on how they overlap with permissions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before enabling the capability, admins can use the new ‘Permissions assessment report’ to review how changes to roles and permission allocation will affect their IT team’s day-to-day operations, giving them the chance to plan and adjust before implementing changes. To get started configuring permissions behaviors, read our learn page on&amp;nbsp;&lt;A href="https://learn.microsoft.com/intune/intune-service/fundamentals/scope-tags" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ermission behavior across role assignments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Turning to device setup, having to manually authorize each app before it can run can slow down deployment and create gaps that are hard to track. Managed installer policy helps address this by automatically marking apps deployed through Intune as authorized, removing the need to manually whitelist each app. This month, Managed installer policy now applies during Windows Autopilot device preparation, running during out-of-box experience (OOBE) so that Win32, Microsoft Store, and Enterprise App Catalog apps are trusted and available earlier in the setup experience, before the user reaches the desktop.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Beyond a great setup experience, the next job is keeping devices current.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Autopatch update readiness&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;is now generally available to help just that. With four additional experiences that provide visibility of the status across their tenant, device-level details into the quality update process, centralized alerts with remediation guidance, and an Update Readiness Checker, admins gain tools intended to support a more proactive approach to update management. For the full story, the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-update-readiness-brings-insights-to-it/4497611" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows IT Pro Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;has the complete announcement.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;M&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;anagement&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;options&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;further&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;protect&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Apple devices&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;and apps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune's adoption of&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-ios" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Apple's Declarative Device Management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; (DDM) protocol has moved quickly, from software update reporting and day zero configuration support to our most recent release of assignment filters. This month, DDM extends to line-of-business (LOB) apps on iOS and iPadOS devices. Until now, app install status was only reported once devices check in. With DDM-based LOB apps, devices proactively report installation status back to Intune as it changes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This change represents progress toward broader DDM support within the apps infrastructure, with additional capabilities under consideration for future releases. To dive deeper into these topics, check out the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/manage-apple-devices-at-scale-intune-security-best-practices/4490571" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Tech Takeoff session on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;iOS management at scale&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/lob-apps-ios" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;iOS line-of-business app documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;On Mac, admins previously had no MDM-based way to set a password on the recovery OS, leaving Apple Silicon devices with a potential exposure that could be difficult to address. With macOS Recovery lock, admins can now set that password directly, helping prevent users from booting into recovery mode to bypass security controls, and support both on-demand and scheduled password rotation. The March 2026 Tech Takeoff session on &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/manage-apple-devices-at-scale-intune-security-best-practices/4490571" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Apple device security best practices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; covers this in detail. With this improvement, Recovery Lock support in Intune helps organizations progress towards compliance with security baselines such as STIG, preventing users from booting into recovery mode to bypass security controls.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When I think of a month like this, I don't think about any one of those new capabilities in isolation. I think about the IT admins who have greater visibility into whether a device action reached its destination, or the help desk professionals who don't have to wonder whether a policy applied. It's not exactly headline grabbing, but it's exactly this kind of continuous improvement that makes for a strong foundation for our customers. That same idea holds whether we're talking about improvements aimed at supporting more reliable Windows device notifications, tighter permission boundaries, or Apple devices that are protected all the way down to its recovery partition. We'd love to hear what resonated most with you this month, so please leave a comment below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 18:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-march/ba-p/4493136</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-03-31T18:00:00Z</dc:date>
    </item>
    <item>
      <title>Secure apps: Where people, data, and AI intersect</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/secure-apps-where-people-data-and-ai-intersect/ba-p/4493201</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At RSAC, Microsoft is highlighting a foundational truth: more and more AI interactions—whether through Copilot, an agent, or an automated workflow—ultimately run through an application on a device.&amp;nbsp;&amp;nbsp;As organizations adopt more AI-driven workflows, the application layer is becoming an increasingly important enforcement point in modern security architecture.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security teams are working to maintain visibility and control as new categories of software are introduced into the environment. When applications are unknown, outdated, over-privileged, or allowed to run without control, organizations may face increased risk of unauthorized access to sensitive data or systems. Maintaining visibility into the application estate and helping ensure that users primarily interact with approved and trusted applications has therefore become an important part of reducing risk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/solutions/cloud-native-endpoints/cloud-native-endpoints-planning-guide" target="_blank" rel="noopener"&gt;Moving application management into cloud-native workflows&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can&amp;nbsp;support&amp;nbsp;cross-platform&amp;nbsp;visibility&amp;nbsp;and&amp;nbsp;help organizations&amp;nbsp;streamline&amp;nbsp;how they manage&amp;nbsp;their application estate.&amp;nbsp;This&amp;nbsp;strategy&amp;nbsp;supports&amp;nbsp;organization's&amp;nbsp;ability to&amp;nbsp;respond&amp;nbsp;to vulnerabilities&amp;nbsp;more quickly&amp;nbsp;and apply security policies more consistently across their environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune’s&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; upcoming releases and recent updates strengthen how organizations secure the application layer across discovery, version control, privilege management, execution control, and data protection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Upcoming releases include&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune&amp;nbsp;enhanced app inventory&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, designed to gain visibility into your app estate across devices.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune Enterprise Application Management auto-updates&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;are designed to help reduce&amp;nbsp;the time between new releases and deployment&amp;nbsp;of&amp;nbsp;business-critical apps.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Expanded Endpoint Privilege Management capabilities&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; help to&amp;nbsp;further&amp;nbsp;support&amp;nbsp;least-privilege enforcement with improved approvals and reporting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recent releases strengthen both execution control and data protection through&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;App Control for Business with managed installer&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;expanded app-level protection&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;with Intune Application Protection Policies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and Microsoft Edge for Business work profiles&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;STRONG&gt;Managed installer support now extends to Windows Autopilot device preparation&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, helping ensure applications deployed through trusted provisioning workflows are recognized by execution policies. Additionally, application migration partner motions also help organizations modernize and standardize their app estate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, these capabilities help IT and security teams address application-based attack paths and support AI-driven work in a more controlled way, without disrupting productivity. Securing the application layer can benefit from a clearer risk-to-control chain that improves visibility into what’s installed and reduces the time older app versions remain in use. This approach also helps organizations limit unnecessary privileges, support trusted execution, and apply app-level data protection in scenarios when device management isn’t feasible.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The following scenarios demonstrate how Intune can help strengthen application security.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;1. Reduce blind spots across the app estate installed on devices&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A secure application strategy starts with understanding what is running across their device environment. Without reliable application intelligence, it is difficult to accurately assess exposure, prioritize remediation, or enforce policy consistently. Cloud-native endpoint management with Intune enables organizations to view their app estate across Windows, macOS, iOS, and Android devices, helping teams understand their broader application footprint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune enhanced app inventory,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;generally available&amp;nbsp;starting in&amp;nbsp;May,&amp;nbsp;is&amp;nbsp;designed to provide&amp;nbsp;richer&amp;nbsp;and more current data for managed and user-installed Windows applications on Intune-enrolled devices. As Intune continues to expand app inventory,&amp;nbsp;additional&amp;nbsp;platforms and capabilities&amp;nbsp;are expected to&amp;nbsp;follow.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The improved app inventory experience is intended to help admins:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Help detect unexpected or risky applications more quickly through improved latency&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Target investigations and remediation using added application attributes&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use fine-grained controls to choose which devices and app attributes are included in inventory&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Access richer and more actionable reporting directly in the device blade&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With clearer visibility into application presence and state, IT and SecOps teams can better target remediation of unauthorized, unmanaged, or unexpected applications—and in turn, scope policies more precisely, investigate incidents faster, and reduce application-based attack paths.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;1 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View from &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Intune &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;app installer &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;showing &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;a list of installed &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;applications, including&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt; version and date.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;2&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Keep applications current &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; reduce vulnerability exposure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Keeping applications up to date across devices is an important part of managing application risk. Manual packaging processes often lead to version drift and inconsistent application states, making it harder to remediate vulnerabilities and maintain a predictable security posture.&lt;/SPAN&gt; &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-enterprise-app-management" target="_blank" rel="noopener"&gt;Intune&amp;nbsp;Enterprise&amp;nbsp;Application Management&amp;nbsp;(EAM)&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;helps organizations move away from fragmented workflows to a more unified, cloud-native application lifecycle management approach—bringing deployments, updates, and policy enforcement together.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;EAM auto-updates,&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;generally available&amp;nbsp;starting in July,&amp;nbsp;streamline&amp;nbsp;app&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;packaging&amp;nbsp;and keep&amp;nbsp;applications up to date&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. EAM auto-updates help organizations deploy new application versions faster and shorten the time between updates and deployment. This approach can help reduce version drift and exposure to known vulnerabilities. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;2 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of the Intune admin center showing how to apply auto‑updates for application management.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;While auto-updates help shrink the vulnerability window and attack surface, vulnerability-driven remediation is still required to identify new risks.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;The Vulnerability Remediation Agent&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;(part of Microsoft Security Copilot), &lt;SPAN data-contrast="auto"&gt;in limited public preview, helps connect vulnerability intelligence with remediation actions. When vulnerable application versions are identified through Common Vulnerabilities and Exposures (CVEs), remediation suggestions can be surfaced in Intune and used to drive targeted remediations, helping IT admins respond more quickly when new vulnerabilities are discovered.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-win32-app-management" target="_blank" rel="noopener"&gt;Script installer support for Enterprise Application Management and Win32&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; provides IT admins with greater customization and control over application installs and uninstalls, without relying solely on command-line logic or repackaging apps. By using script installer, admins can more effectively manage deployment complexities such as dependencies, configuration steps, and cleanup actions, while keeping installation logic easy to update as requirements change.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;3&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Replace standing admin rights with just-in-time elevation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Some applications and support tasks require elevated permissions to complete. When elevation is handled through broad local administrator rights, those permissions can extend beyond the intended task, creating opportunities for unwanted or untrusted processes to run with elevated privileges. These capabilities are intended to help admins manage elevation in complex environments while maintaining least-privilege access.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;By June, a set of expanded &lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-overview" target="_blank" rel="noopener"&gt;Endpoint Privilege Management&amp;nbsp;(EPM) capabilities&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;are expected to be available in Intune, helping organizations move from standing administrator rights toward just-in-time elevation with more controlled and auditable workflows.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recent EPM enhancements help improve how elevations are requested, approved, and reviewed:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Support approvals for non-primary users&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; allows&amp;nbsp;elevation requests on shared devices and helpdesk-managed scenarios without permanently expanding administrator access.&amp;nbsp;Generally&amp;nbsp;available&amp;nbsp;starting in&amp;nbsp;April.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Scope tag support for EPM reporting data&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;allows elevation activity to be segmented across teams and administrative scopes. Generally available starting in June.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;4. Enforce trusted application execution&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Trusted applications can still be weaponized. Even widely deployed software can be exploited to launch unauthorized tools or run malicious code—which is why controlling what’s allowed to run is as important as controlling what gets installed. Deployment and update controls help standardize the application estate, but execution policies determine which applications can run on managed devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;App Control for Business in Intune&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;helps enforce trusted application execution on Windows devices by specifying which applications are allowed to run&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Applications not permitted by these policies can be blocked, helping maintain a more controlled application environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Managed installer support in Intune&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;helps simplify policy management by automatically identifying trusted applications deployed through Intune. Applications installed by Intune are allowed to run without requiring individual rules, helping admins maintain execution policies as the application estate evolves.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The managed installer policy is now also applied during&amp;nbsp;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/autopilot/device-preparation/whats-new" target="_blank" rel="noopener"&gt;Windows Autopilot device preparation&lt;/A&gt;&lt;/STRONG&gt; before apps are installed, generally available starting in April. This update helps ensure that apps delivered during Autopilot device preparation are marked as trusted during provisioning. By aligning trusted deployment workflows with execution policy, organizations can support controlled application environments without introducing friction during device onboarding.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;3 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Intune's admin center via App Control for Business to begin configuring a policy from the managed installer.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security-app-control-policy" target="_blank" rel="noopener"&gt;Read more&lt;/A&gt;about App Control for Business and managed installer to help maintain a more predictable and policy-aligned application environment.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;5&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Protect corporate data &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;at the app level&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Work increasingly takes place on devices that an organization cannot enroll—agency-managed PCs, partner devices, and personal endpoints. In these scenarios, secure access to corporate resources is still required even when device-level controls cannot be applied.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/apps/app-protection-policy-settings-windows" target="_blank" rel="noopener"&gt;Intune Application Protection Policies (APP)&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;enable&amp;nbsp;organizations to protect&amp;nbsp;corporate data&amp;nbsp;at the application layer without requiring device enrollment.&amp;nbsp;APP&amp;nbsp;helps&amp;nbsp;enforce&amp;nbsp;data protection controls—such as restricting copy and paste—to&amp;nbsp;help&amp;nbsp;maintain&amp;nbsp;data boundaries between corporate and personal work.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;New support for&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Edge for Business work profiles on Windows PCs managed by another organization extends APP protection to browser-based work without creating tenant management conflicts. Recent Microsoft Entra sign-in improvements further help guide users into the intended app-protection experience and help prevent unintended device enrollment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/IntuneAPPWindowsPCs" target="_blank" rel="noopener"&gt;Read more&lt;/A&gt;about these&amp;nbsp;enhancements&amp;nbsp;and&amp;nbsp;how&amp;nbsp;Intune applies&amp;nbsp;Zero Trust-aligned&amp;nbsp;principles&amp;nbsp;to&amp;nbsp;the&amp;nbsp;browser&amp;nbsp;on externally managed Windows PCs.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Securing the application layer across the full lifecycle&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The application layer has long been the center of work, and with the rise of AI, it’s rapidly becoming the center of decision-making as well. As organizations adopt Copilot and agents, it becomes an increasingly important enforcement point—and the place where the next wave of security investments need to land. Securing this layer requires applying consistent controls across visibility, updates, controlled privilege, trusted execution, and app-level data protection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune is designed to help organizations secure the application layer end-to-end, across discovery, deployment, updates, privilege, execution, and data protection. As organizations modernize their app estates, moving them into cloud-native management can provide a foundation for more consistent visibility, streamlined remediation, and stronger security controls across the environment. By applying Zero Trust-aligned principles consistently throughout the application lifecycle, organizations can work to minimize application-related risks while enabling safer and more flexible ways of working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To support these modernization efforts, application migration partners can work to transition existing applications into cloud-native Intune management by automating assessment, packaging conversion, and remediation. Bringing applications into Intune-managed workflows helps organizations identify potential Shadow IT, help strengthen their security posture, manage updates, apply privilege controls and enforce policies more consistently across the environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Here are the next steps to take toward securing the application layer:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Connect with Intune experts at the Microsoft Booth #5744 at RSA Conference, Moscone Center, March 23–26.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=EKRwGZAZDfY" target="_blank" rel="noopener"&gt;Move Windows app packaging and updates into cloud-native management&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://microsoft.github.io/zerotrustassessment/docs/workshop-guidance/devices/RMD_019" target="_blank" rel="noopener"&gt;Learn how to apply Zero Trust principles&amp;nbsp;to data within the applications&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/face-the-future-today-by-moving-your-application-to-cloud-native/4453681" target="_blank" rel="noopener" data-lia-auto-title="Migrate app management to Intune with partner assistance" data-lia-auto-title-active="0"&gt;Migrate app management to Intune with partner assistance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener" data-lia-auto-title="Learn&amp;nbsp;which&amp;nbsp;Intune&amp;nbsp;advanced&amp;nbsp;solutions&amp;nbsp;will&amp;nbsp;be coming to the M365 E3 and E5 suites" data-lia-auto-title-active="0"&gt;Learn&amp;nbsp;which&amp;nbsp;Intune&amp;nbsp;advanced&amp;nbsp;solutions&amp;nbsp;will&amp;nbsp;be coming to the M365 E3 and E5 suites&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/secure-apps-where-people-data-and-ai-intersect/ba-p/4493201</guid>
      <dc:creator>Talal_Alqinawi</dc:creator>
      <dc:date>2026-03-20T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Announcing three new partners for multi-tenant management with Microsoft Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/announcing-three-new-partners-for-multi-tenant-management-with/ba-p/4501339</link>
      <description>&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;The challenge:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;S&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;caling&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Intune across customer environments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="auto"&gt;Managed service providers (MSPs) of all sizes are under pressure to manage an expanding portfolio of customer environments efficiently, securely, and profitably. Historically, MSPs have had to choose between building custom multi-tenant tooling or relying on third-party platforms that lack deep Microsoft integration. As client expectations rise and competitive pricing pressures intensify, MSPs need solutions that help them deliver more value from the Microsoft 365 investments their customers already have—investments that already include Microsoft Intune—without fragmenting data or security outside Microsoft's ecosystem.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="auto"&gt;Managing multiple tenants often means duplicating routine processes, reconciling policy inconsistencies, and navigating separate management portals. MSPs need centralized oversight across all tenants without sacrificing security, compliance, or operational efficiency. Microsoft Intune is the answer—and the right partner solutions make it scale.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;The solution: Microsoft Intune, extended by validated partners&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/addressing-multi-tenant-management-challenges-for-msps-with-microsoft-intune-and/4453682" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;September&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, we announced our collaboration with two leading multi-tenant management providers—inforcer&amp;nbsp;and&amp;nbsp;Nerdio—and the response was remarkable. The program, which we call&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Strong"&gt;#IntuneForMSPs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, has exceeded our expectations. We heard strong positive feedback from MSPs and enterprises at events around the world and across social media, from organizations that have long needed a better way to manage multiple tenants at scale.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;Today, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;we're&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;excited to announce three&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;additional&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;validated partners joining the&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Strong"&gt;#IntuneForMSPs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;ecosystem. Each has&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;been&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;validated&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;against&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; Microsoft's product and business requirements, enabling MSPs to scale efficiently, standardize operations, and deliver more secure, Intune-aligned experiences to their customers.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;Momentum in the MSP market&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Over the past year, we've seen strong momentum across the MSP market—through global events, partner sessions, and #IntuneForMSPs meetups. One message has been consistent across all of these conversations:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;MSPs want Intune-aligned solutions that respect Microsoft's security model, tenant boundaries, and licensing investments.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At recent in-person and virtual events, the energy around this shift has been clear. MSPs are actively moving away from traditional RMM-centric approaches toward models where Microsoft Intune serves as the control plane for device management, security, and compliance. That shift is what makes today's announcement particularly meaningful.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Welcoming &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;three&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;new&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;#IntuneForMSPs&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;artners&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We're pleased to welcome three new validated partners to the #IntuneForMSPs ecosystem. Each offers independent, complementary capabilities built on top of and alongside the Microsoft Intune platform—preserving their unique workflows and features while extending what Intune can do for MSPs at scale. Partners are presented in alphabetical order; the descriptions below were provided by each partner.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We encourage you to learn more about all validated partners at &lt;A class="lia-external-url" href="https://aka.ms/IntuneForMSPs" target="_blank" rel="noopener"&gt;https://aka.ms/IntuneForMSPs&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;AvePoint Confidence Platform: Elements Edition&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;AvePoint is&amp;nbsp;the&amp;nbsp;global leader&amp;nbsp;in data protection, unifying data security, governance, and resilience to provide a trusted foundation for AI. More than 28,000 customers rely on the AvePoint Confidence Platform to secure, govern, and rapidly recover data across multi&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;‑&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;cloud environments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Through AvePoint Confidence Platform: Elements Edition, AvePoint extends Microsoft Intune with secured multi&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;‑&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;tenant automation, lifecycle management, and centralized visibility—enabling partners to scale Intune delivery profitably and consistently across customers. With a single platform for governance, lifecycle control, and recovery, partners reduce operational overhead, prevent sprawl, and accelerate Copilot readiness.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;AvePoint supports a global partner ecosystem of 6,000 MSPs, VARs, and SIs, with solutions available in over 100 cloud marketplaces.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learn more at: &lt;A class="lia-external-url" href="https://www.avepoint.com/lp/microsoft-intune-for-msps" target="_blank" rel="noopener"&gt;avpt.is/intune&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;CyberDrain CIPP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;CyberDrain CIPP provides MSPs with a centralized, multi-tenant management platform for Microsoft 365. It enables partners to securely manage tenants at scale, automate common administrative tasks, enforce standards across environments, and gain deep visibility into tenant security and configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With built-in automation, governance controls, and extensibility, CIPP reduces reliance on custom scripts and manual processes. MSPs can standardize operations, streamline user and tenant management, monitor security posture, and respond quickly to issues across all customers from a single interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;CIPP is supported by one of the largest and most active MSP communities in the Microsoft ecosystem, with thousands of partners contributing feedback, automation ideas, and best practices. As one of the most widely adopted platforms for Microsoft 365 multi-tenant management, CyberDrain CIPP continues to evolve rapidly to meet the needs of modern MSPs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learn more at: &lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://cyberdrain.com/intuneformsps" target="_blank" rel="noopener"&gt;cyberdrain.com/intuneformsps&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&lt;SPAN data-contrast="auto"&gt;SoftwareCentral Tenant Manager&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;SoftwareCentral Tenant Manager helps MSPs run Microsoft Intune across multiple customer tenants with consistency and control. MSP teams can standardize policies, manage applications and devices across environments, monitor configuration drift, and maintain visibility into changes across tenants from a single platform. The platform runs entirely on Microsoft Azure with region-selectable deployment for your data protection requirements.&amp;nbsp;It includes CIS&amp;nbsp;certified&amp;nbsp;security baselines, helping MSPs deliver secure, repeatable Intune services as their customer portfolios grow, even without in-depth Intune knowledge.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learn more at: &lt;A class="lia-external-url" href="https://tenantmanager.com/intuneformsps/" target="_blank" rel="noopener"&gt;tenantmanager.com/intuneformsps/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What’s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;n&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ext&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;for #IntuneForMSPs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today's announcement reflects our continued and reinvigorated commitment to the MSP market. Going forward, you can expect:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;More news&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;about the&amp;nbsp;#IntuneForMSPs ecosystem&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Continued monthly meetups&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; and technical sessions for MSPs—open to any MSP interested in learning how Intune can help scale their business&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;MSP-specific guidance and resources&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;to help MSPs grow with Microsoft&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune MVP Jonathan Edwards (also known as the Bearded365Guy) created a video&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-fontsize="11"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;reviewing three of our partner solutions.&amp;nbsp;Watch the video&amp;nbsp;and explore all&amp;nbsp;our&amp;nbsp;validated partners at &lt;A class="lia-external-url" href="https://aka.ms/IntuneForMSPs" target="_blank" rel="noopener"&gt;https://aka.ms/IntuneForMSPs&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;Jonathan Edwards reviews Nerdio, inforcer, and CIPP in one video.&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If&amp;nbsp;you're&amp;nbsp;an MSP modernizing your management approach—or a partner building on Intune—we invite you to explore these&amp;nbsp;new solutions&amp;nbsp;and stay engaged with the #IntuneForMSPs partner program at our resource page&amp;nbsp;aka.ms/IntuneForMSPs&amp;nbsp;and monthly meetups.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="29" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;"Jonathan Edwards is a Microsoft Intune MVP. Microsoft's MVP program is an independent recognition program; Jonathan was not compensated by Microsoft for this video."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; on X to continue the conversation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 16:18:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/announcing-three-new-partners-for-multi-tenant-management-with/ba-p/4501339</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2026-03-17T16:18:31Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Intune – February</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-february/ba-p/4488307</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every IT environment has workarounds. Policies are duplicated instead of edited because&amp;nbsp;there's&amp;nbsp;no approval process. Apple software updates are pushed to every device because Declarative Device Management (DDM) policies&amp;nbsp;couldn't&amp;nbsp;filter by ownership type.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Workarounds aren't just inconvenient. They can increase risk. Duplicate policies, broad software updates, and unchecked changes expand the attack surface and undermine Zero Trust principles. This month’s Microsoft Intune updates focus on eliminating those workarounds by giving admins &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;greater control, clearer accountability, and more precise targeting.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Helping to ensure security policies are enforced the way they were intended, without slowing IT teams down.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;Reduce policy risk with greater oversight over compliance and configuration changes&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To provide an extra security measure against any unauthorized or accidental changes, additional &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval" target="_blank" rel="noopener"&gt;multi-administrator approval&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;options are now available&amp;nbsp;for device&amp;nbsp;configuration&amp;nbsp;policies created through the settings catalog and device&amp;nbsp;compliance&amp;nbsp;policies&amp;nbsp;(for more information see&amp;nbsp;&lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/device-cleanup-rules" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Compliance settings, and Device cleanup rules&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;). With this control enabled, critical policy changes (creation, alteration, or deletion) will need approval from a second administrator before they can be implemented.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This latest update expands the multi-admin approval capabilities introduced over the past year, which include apps, scripts, device actions like wipe, retire, and delete, RBAC roles, and device categories. The addition of compliance and configuration policies approvals help enable organizations to offer a more comprehensive safety net for their most critical policies. In environments where configuration drift can lead to non-compliance and security risks, this level of oversight is not simply a good practice, but rather a preventive control and governance option integrated into the IT workflow.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Furthermore, since every request, approval, and business justification is documented in the Intune audit logs, this control not only helps prevent potential problems but also documents them. &lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;Find and fix issues faster with updates for multiple device queries&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Zero Trust decisions depend on accurate, actionable data, and IT admins need precise queries to identify compliance gaps or missing configurations across their fleet.&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-advanced-analytics" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Advanced Analytics&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; now includes the operator details in multiple device query (MDQ) results, (including join types such as new leftanti and rightsemi operators). This assists in finding the specific settings of missing devices and helps you run fleet-wide queries more accurately, especially if you are managing thousands of devices of all OS types.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Additionally, Advanced Analytics device join syntax in MDQ results are now clickable for faster navigation to device details and improved error messaging. A good example to illustrate this improvement is a query to retrieve all devices with ARM processors, ordered alphabetically. The column for the Device field in the results is now clickable when the Device entity is joined. In addition, admins can now join the results on the Device field without using custom Device syntax.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Device query results showing x64 CPU data joined on Device. &lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more detail, please refer to the Microsoft Learn page on&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/advanced-analytics/device-query-multiple-devices" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;device query for multiple devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;.&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="none"&gt;Target Apple updates precisely—without overreaching&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When managing Apple devices, targeting matters; not every policy needs to reach every device. But until now, Declarative Device Management (DDM) policies did not account for assignment filters. Admins couldn't target devices by OS version or differentiate between company-owned and personally owned devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A common challenge for admins is enforcing software updates on company-owned devices while avoiding personal devices. The enhancements included in this month’s Intune release help resolve this challenge. Now admins can use DDM-based policies with &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/filters" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;assignment filters&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; in the same way they do for MDM-based policies. For instance, if an organization wants to target devices running iOS 17 or later with software updates, they can use an operating system version filter. To target Automated Device Enrollment (ADE) supervised devices while ignoring personal devices, they can use an enrollment profile name filter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;This capability is becoming more important as Apple has expanded Declarative Device Management across iOS, iPadOS, macOS, Vision OS, and Apple TV. Intune keeps pace with that shift by doing what it has always done: giving admins a consistent way to apply policies across every platform they manage.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;Fewer workarounds, stronger Zero Trust across every platform&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The capabilities rolling out in our February release all have something in common: multi-admin approval, multi-device queries, and assignment filters for Declarative Device Management collectively eliminate the need for workarounds.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;I know that workarounds are part of every IT environment. However, with each workaround there may be concessions: more access, more policies created without proper scrutiny, or updates not intended for particular devices. While this month’s new capabilities will not eliminate all workarounds, they are a step toward managing devices the way Zero Trust requires: precisely, reliably, and with built-in least privilege. &lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 19:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-february/ba-p/4488307</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-02-26T19:00:00Z</dc:date>
    </item>
    <item>
      <title>Protect browser-based work on agency-managed Windows PCs</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/protect-browser-based-work-on-agency-managed-windows-pcs/ba-p/4496538</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;From SaaS apps and internal web portals to AI-powered tools, the browser is now a major workspace for many employees and contractors alike. This shift has introduced new opportunities for organizations to enable an extended workforce. At the same time, it creates new data protection complexities for IT administrators.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Securing corporate data has traditionally relied on full device management. However, when work occurs on a Windows PC that your organization doesn't own—such as a device already enrolled and managed by a contractor’s home agency—full device enrollment isn't a viable option. Organizations need a flexible way to reduce these data blind spots without taking over the device itself.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To address this, Microsoft continues to expand data protection capabilities across Microsoft Edge for Business, Microsoft Entra, Microsoft Intune, and Microsoft Purview. Recent profile and sign-in updates with Edge for Business and Entra now help organizations to secure browser-based work on Windows PCs managed by another organization. And these updates work alongside inline data loss prevention with Purview and prescriptive deployment guidance from Intune to help administrators apply protections consistently rather than configuring policies in isolation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Support&amp;nbsp;and protection&amp;nbsp;for&amp;nbsp;agency-managed Windows&amp;nbsp;PCs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Edge for Business now extends Intune app protection policies (APP) to the Edge for Business work profile on Windows PCs managed by another organization. This new capability,&amp;nbsp;currently in&amp;nbsp;public&amp;nbsp;preview,&amp;nbsp;helps&amp;nbsp;organizations to&amp;nbsp;protect&amp;nbsp;work&amp;nbsp;contractors&amp;nbsp;do&amp;nbsp;in the&amp;nbsp;browser,&amp;nbsp;while respecting existing device ownership and management boundaries.&amp;nbsp;This protects corporate data&amp;nbsp;without&amp;nbsp;requiring full device enrollment or creating conflicts with another tenant’s management.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;div data-video-id="https://youtu.be/Ng2w_aBGgUw/1771962075551" data-video-remote-vid="https://youtu.be/Ng2w_aBGgUw/1771962075551" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FNg2w_aBGgUw%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DNg2w_aBGgUw&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FNg2w_aBGgUw%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1 &lt;SPAN data-teams="true"&gt;Demo showing Intune app protection policies in action within an Edge for Business work profile on a Windows PC managed by another organization.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Key capabilities include:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Browser-level protection&amp;nbsp;through the Edge work profile:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune APP policies can be applied directly to Edge for Business user profiles, helping to create a protected boundary for work data. Contractors can securely access corporate resources in an Edge for Business profile without enrolling the device or altering existing management.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Tenant-scoped controls within Edge for Business&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Organizations can&amp;nbsp;help&amp;nbsp;protect corporate data within the browser by redirecting downloads to OneDrive for Business, restricting copy and paste, and enforcing data boundaries inside the managed Edge for Business profile.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-cross-tenant-support-using-intune-mam?branch=pr-en-us-6771" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;How to get started with&amp;nbsp;agency-managed device&amp;nbsp;support&amp;nbsp;in&amp;nbsp;Edge&amp;nbsp;for Business&amp;nbsp;and apply&amp;nbsp;APP.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Simplified&amp;nbsp;onboarding&amp;nbsp;for&amp;nbsp;APP&amp;nbsp;policies&amp;nbsp;on&amp;nbsp;Windows&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recent Entra improvements to the Edge on Windows sign-in flow enable admins to configure the enrollment screen to create a more predictable setup and enrollment experience. These new sign-in updates help route users into Intune application protection polices, while reducing accidental full device enrollment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure 2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;Microsoft Entra updated sign-in experience pop-up window.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These Entra updates include: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Modernized&amp;nbsp;Entra registration&amp;nbsp;page&amp;nbsp;for the&amp;nbsp;user:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;An updated&amp;nbsp;account registration&amp;nbsp;flow&amp;nbsp;provides&amp;nbsp;clearer guidance during sign-in, helping users understand when they are registering an account versus&amp;nbsp;enrolling&amp;nbsp;a device.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Prevention of unintended device enrollment:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Administrators can enable the “Disable MDM enrollment when adding work or school account” setting to block the prompt for devince enrollment during the account registration flow. Users are directed into the intended app-protection experience without unnecessary prompts or management conflicts.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/windows-enroll" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Read more about&amp;nbsp;how to apply&amp;nbsp;the&amp;nbsp;updated&amp;nbsp;Entra&amp;nbsp;sign-in flow.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Apply&amp;nbsp;data&amp;nbsp;security&amp;nbsp;across&amp;nbsp;browser-based work&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview Data Loss Prevention (DLP) helps protect sensitive corporate data during browser-based work&amp;nbsp;on Windows PCs&amp;nbsp;that are managed by another organization or not enrolled at all. Purview DLP is built directly into Edge for Business and applies to the user’s work profile,&amp;nbsp;so&amp;nbsp;organizations&amp;nbsp;can&amp;nbsp;detect and control sensitive actions without requiring device onboarding into Purview or taking ownership of the device.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure 3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;Purview DLP: Displays&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;pop-up message to indicate&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;organizationa&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;l protection for a file download.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With Purview DLP in Edge for Business, organizations can:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Apply inline DLP protection in the browser:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Support detection&amp;nbsp;and control&amp;nbsp;for&amp;nbsp;sensitive actions, such as uploads, downloads, copy/paste, printing,&amp;nbsp;and&amp;nbsp;across cloud apps&amp;nbsp;accessed in the browser.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Extend coverage to unmanaged cloud apps:&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Apply DLP policies&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;to enrolled apps and extend protection to unenrolled&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;cloud apps, helping prevent oversharing or unintended data movement during browser activity.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Reduce data leakage without limiting productivity: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Detect and prevent risky actions involving sensitive data without blocking site access or disrupting normal workflows.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/purview/dlp-browser-dlp-learn" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Apply&amp;nbsp;Purview&amp;nbsp;Data Loss Prevention in Edge for Business&amp;nbsp;to protect sensitive data during browser-based work.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Guidance&amp;nbsp;to help&amp;nbsp;secure&amp;nbsp;corporate data&amp;nbsp;in the browser&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft&amp;nbsp;published&amp;nbsp;“&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/mamedge-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Secure&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Your Corporate Data in Intune with Microsoft Edge for Business&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;”&amp;nbsp;to provide&amp;nbsp;guidance&amp;nbsp;on&amp;nbsp;how administrators can&amp;nbsp;operationalize browser-based protections across platforms.&amp;nbsp;This&amp;nbsp;guidance&amp;nbsp;provides step-by-step configuration paths that align identity, app protection, browser configuration, and device controls into a single, structured deployment model rather than isolated policy setup.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The guide covers:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Three-level security framework&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Basic, Enhanced, and High protection tiers mapped to common industry standards such as NIST and DISA STIG,&amp;nbsp;enabling&amp;nbsp;organizations to align browser security posture with risk tolerance and user roles.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cross-platform policy mapping&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Clear guidance on when to use app protection policies, app configuration policies, settings catalog controls, and conditional access across Windows, macOS, iOS, and Android without creating policy conflicts&amp;nbsp;or double-applying browser policies.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Sequenced configuration paths&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Ordered implementation steps that show how identity enforcement, app protection, browser configuration, and device-level controls work together to form a cohesive&amp;nbsp;secure&amp;nbsp;enterprise&amp;nbsp;browser&amp;nbsp;strategy.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/mamedge-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ore:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Read more on how&amp;nbsp;to get&amp;nbsp;started with&amp;nbsp;Intune’s&amp;nbsp;configuration guidance&amp;nbsp;to&amp;nbsp;protect browser-based&amp;nbsp;work and align identity, app protection, and browser controls.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Apply&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;additional&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;protections for a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;more&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;consistent sign-in flow&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;today&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations do not need to treat browser-based work as an exception to endpoint protection. By combining identity routing in Entra, app-level boundaries through Intune, workspace separation in Edge for Business, and inline data governance with Purview, organizations can apply consistent controls even on Windows PCs they don’t own or manage. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With this approach, protection&amp;nbsp;moves from the device to the work context itself.&amp;nbsp;Administrators&amp;nbsp;can&amp;nbsp;secure corporate data where work happens,&amp;nbsp;while preserving productivity and respecting existing device ownership and management boundaries.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 19:41:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/protect-browser-based-work-on-agency-managed-windows-pcs/ba-p/4496538</guid>
      <dc:creator>LiMiller</dc:creator>
      <dc:date>2026-02-24T19:41:58Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Intune – January 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-january-2026/ba-p/4476487</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When trees lose their leaves, you see the structure beneath. The branches you couldn’t see. The shape that was always there.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;January is like that for IT admins. You get a fresh view of your endpoint management landscape, such as where elevation can get sharper, where application deployment process can be improved, and where admin tasks could be made more efficient.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The same is true for Intune. January isn’t just about celebrating what we’ve accomplished in the past year, but it’s also about looking forward to what new challenges we will face and new ways we can help IT admins be more productive. In this blog post, I’ll highlight the recent capabilities that I’m personally excited about.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Accelerate deployment with Power&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;S&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;hell&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;script&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;installers for Win&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;32 apps&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;Today, many organizations customize app deployments outside Intune using PowerShell scripts to handle prerequisite checks, post-install steps, dependencies, and registry updates. Previously, each time the script changed, the entire app binary needed to be repackaged and re-uploaded.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;That friction&amp;nbsp;often&amp;nbsp;can&amp;nbsp;add hours to deployment cycles and&amp;nbsp;kept&amp;nbsp;critical work outside the admin center.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;This month, that changes that. When creating a Win32 app in Intune, admins can now upload a PowerShell script that acts as the app installer, rather than specifying a command line. The script runs natively. Intune packages it with app content and runs it in the same context as the installer. Installation results show in the admin center as 'success' or 'failure' based on return codes, providing visibility into what happened.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;So, what does this mean? It means app deployment gets faster, customization gets easier, and teams in highly regulated industries like finance and healthcare can use the script to enforce compliance steps as part of the app installation process. It means system requirements can be checked before anything else runs, and app-specific settings can be configured after the app is installed. It means admins gain even more control.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;Endpoint Privilege Management gets sharper&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;When users need elevated privilege, we are introducing a new Endpoint Privilege Management (EPM) capability to elevate users in a way that preserves their current profile. For example, profile paths, environment variables, and personalized settings.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;This matters for installers and tools that depend on the active user’s profile. Before,&amp;nbsp;&amp;nbsp;&lt;BR /&gt;EPM isolated virtual accounts. Now, the user’s identity is maintained throughout elevation, meaning your audit trails stay cleaner and compliance records are more accurate.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;In addition, the ability to enforce scope tags for elevation scenarios safeguards admins can only view elevation requests for which they have permission. This is critical for compartmentalizing data in regulated environments. Together with 'Elevate as current user,' this enables organizations to easily oversee who is allowed to perform elevated actions, while avoiding the disclosure of excessive context. These two capabilities integrate seamlessly out of the box, with no configuration required.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;Admin tasks&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;capability&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;bring&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;&amp;nbsp;your work togethe&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;r&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The new year brings clarity. Admins manage privilege elevation, device offboarding, security alerts, and policy approvals. Admin tasks, now generally available (GA) in Microsoft Intune, brings that work into a single, prioritized queue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin tasks centralizes these workflows to help admins focus on high-impact actions that need their attention now. It is under Tenant Administration, where admins can search, filter, and sort across requests, tasks, and approvals. Currently, admin tasks includes Endpoint Privilege Management (EPM) requests, Multi Admin Approval (MAA) tasks, Microsoft Defender for Endpoint (MDE) security tasks, and the Device Offboarding Agent (part of Microsoft Security Copilot) for tasks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;EPM elevation requests help admins quickly approve or deny elevation needs and create reusable rules. Microsoft Defender for Endpoint security tasks enables admins to review recommended remediation actions, take corrective action on security issues, and monitor task status through a consistent Intune workflow. The Device Offboarding Agent helps detect unused or outdated devices that may no longer be needed or may pose a security risk, surfacing these findings as actionable tasks within admin tasks. Multi Admin Approval requests, such as scripts, device wipes, and role changes, are reviewed and approved with this same view. Each approval or rejection is recorded to support audit and compliance requirements. Learn more by taking a deeper dive in this blog on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/IntuneAdminTasksBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;admin tasks in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Apple enrollment keeps evolving with new &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;certificate support&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The technical foundation for enrollment of Apple devices just got stronger. We're rolling out support for the Automated Certificate Management Environment (ACME) protocol for new iOS, iPadOS, and macOS enrollments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;So, what’s the difference? ACME provides better protection than the previous SCEP approach against unauthorized certificate issuance. It includes improved validation mechanisms and automated processes that reduce errors in certificate management. Now, when new Apple devices enroll, they receive an ACME certificate instead of a SCEP certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;There's no change to your enrollment experience or Intune admin center doesn’t change. Its infrastructure works better in the background. This applies to Apple Device Enrollment, Apple Configurator enrollment, and automated device enrollment (ADE) methods. We also added 12 new Setup Assistant screens you can control during ADE. Want to skip the App Store screen? Hide camera settings? Now you can. This gives you more flexibility in how your end-users experience onboarding.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What's&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; ahead&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;January always feels like a restart. New year, fresh roadmap, the engineering teams recharged and looking at what's next. When I talk with the team building these capabilities, the energy is real. They're already thinking about solving more challenges&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;IT admins face. The momentum is here with the team at Microsoft Intune.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Stay up to date with Intune, please bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/MicrosoftIntuneBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-intune/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on X.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 17:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-january-2026/ba-p/4476487</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-02-05T17:00:00Z</dc:date>
    </item>
    <item>
      <title>Admin tasks in Microsoft Intune: Centralized control today, AI-ready for tomorrow</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/admin-tasks-in-microsoft-intune-centralized-control-today-ai/ba-p/4489448</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IT admins make daily, quiet decisions that determine whether an organization stays secure, compliant, and productive. They review privilege requests, security remediation actions, and high-impact configuration changes across multiple consoles. Given the growing breadth of their daily responsibilities, scattered decision points could lead to slower response times, increased risks, and make audit readiness harder to maintain.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune already consolidates endpoint management into one place. And now with the general availability (GA) of admin tasks it aggregates high-impact approvals and remediation workflows, into a single, prioritized queue, giving admins a unified view of what needs action right now.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Introduced at Microsoft &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-at-ignite/4471043" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Ign&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;i&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;te&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, admin tasks&amp;nbsp;brings&amp;nbsp;together three essential decision points:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-support-approved#manage-pending-elevation-requests" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Endpoint Privilege Managemen&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;t&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(EPM)&amp;nbsp;elevation requests,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/atp-manage-vulnerabilities" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defe&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;n&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;der&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;for Endpoint&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(MDE)&amp;nbsp;security tasks, and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval#approve-requests" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Multi&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Approval&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(MAA)&amp;nbsp;requests.&amp;nbsp;And now,&amp;nbsp;admin tasks&amp;nbsp;also&amp;nbsp;incorporates&amp;nbsp;actions from&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/agents/device-offboarding-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device O&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ff&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;boarding Agent&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;(part of&amp;nbsp;Microsoft&amp;nbsp;Security Copilot),&amp;nbsp;currently in&amp;nbsp;public preview, extending centralized decision-making to device lifecycle cleanup.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-contrast="auto"&gt;As organizations adopt&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust principles&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;prepare for&amp;nbsp;AI-assisted operations, IT teams need more automation without sacrificing oversight. As Intune expands automated and AI-assisted capabilities, admin tasks&amp;nbsp;adds&amp;nbsp;an&amp;nbsp;oversight layer that&amp;nbsp;helps&amp;nbsp;ensure AI-driven recommendations&amp;nbsp;remain&amp;nbsp;under administrator control.&amp;nbsp;Over time,&amp;nbsp;additional&amp;nbsp;task types will&amp;nbsp;continually&amp;nbsp;be integrated,&amp;nbsp;consolidating&amp;nbsp;even more&amp;nbsp;high-impact&amp;nbsp;operational decision points into a single experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-contrast="auto"&gt;“Admin tasks in Intune is a centralized, prioritized task view that cuts through the noise. The simplified processes boost our team’s ability to respond quickly and confidently to critical requests.” –Michael Meier, IT Workplace Design, Krones AG&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-contrast="auto"&gt;Admin tasks&amp;nbsp;is&amp;nbsp;available in the Intune admin center under Tenant administration. The following sections outline what admins can access today.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4 data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Four ways to streamline IT operations&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;dmin&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;asks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;OL style="padding-left: 0; margin-left: 0;"&gt;
&lt;LI style="font-weight: bold;" data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-endpoint-privilege-management" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Endpoint Privilege Managem&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;nt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;elevation&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;requests&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;SPAN data-contrast="auto"&gt;EPM&amp;nbsp;enables&amp;nbsp;standard users to run approved applications with elevated privileges without&amp;nbsp;granting&amp;nbsp;permanent local admin rights.&amp;nbsp;In admin tasks, elevation requests appear in the same prioritized queue as other high-impact actions, so&amp;nbsp;admins can review and approve&amp;nbsp;requests&amp;nbsp;from a single view.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Approve or deny elevation requests, create reusable rules based on file details, or add files to reusable settings.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;SPAN data-contrast="auto"&gt;What&amp;nbsp;EPM&amp;nbsp;enables:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Flexible&amp;nbsp;elevation&amp;nbsp;models:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Supports automatic, user-confirmed, and support-approved&amp;nbsp;workflows.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Granular controls:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Defines&amp;nbsp;elevation rules&amp;nbsp;based on publisher, file hash, or&amp;nbsp;command-line&amp;nbsp;arguments.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Audit and compliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Logs&amp;nbsp;elevation&amp;nbsp;activity&amp;nbsp;for visibility,&amp;nbsp;reporting, and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Improved user experience:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Helps standard&amp;nbsp;users stay productive,&amp;nbsp;while reducing help desk tickets and security&amp;nbsp;exposure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Contextual risk analysis*&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;With&amp;nbsp;EPM&amp;nbsp;and Security Copilot,&amp;nbsp;it&amp;nbsp;enables&amp;nbsp;admin tasks&amp;nbsp;to&amp;nbsp;surface contextual risk&amp;nbsp;signals&amp;nbsp;to help inform elevation approval decisions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="auto"&gt;*&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Note&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&amp;nbsp;This capability requires Microsoft Security Copilot,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/copilot/security/get-started-security-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;get started here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;Security&amp;nbsp;Copilot will be included for&amp;nbsp;Microsoft 365 E5 customers,&amp;nbsp;roll&amp;nbsp;out&amp;nbsp;began&amp;nbsp;for&amp;nbsp;existing Security Copilot&amp;nbsp;users&amp;nbsp;and&amp;nbsp;is&amp;nbsp;continuing&amp;nbsp;in the upcoming months,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;l&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;earn more here.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;EPM is&amp;nbsp;also&amp;nbsp;coming to&amp;nbsp;M365 E5;&amp;nbsp;learn&amp;nbsp;more about the Intune capabilities coming to both the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;E3 and E5 bundle here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;g&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;ranular controls for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;levation requests in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Intune&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Endpoint Privilege Management&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;within admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;OL style="padding-left: 0; margin-left: 0;" start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/atp-manage-vulnerabilities" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;D&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;efender for Endpoint&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ecurity tasks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;MDE requests for remediation generate security tasks that surface in the Intune admin center, when threats or configuration issues are detected on devices. Admins can track and complete security remediation work from the same queue used for other critical IT decisions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Mark tasks as complete or reject them, and review&amp;nbsp;impacted&amp;nbsp;device lists.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What&amp;nbsp;MDE security&amp;nbsp;task in Intune&amp;nbsp;enables:&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Unified&amp;nbsp;task management:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;View&amp;nbsp;and&amp;nbsp;act on&amp;nbsp;security&amp;nbsp;tasks&amp;nbsp;from Defender in&amp;nbsp;a single&amp;nbsp;queue.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Recommended&amp;nbsp;endpoint security profiles:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Supports&amp;nbsp;new configurations for&amp;nbsp;Endpoint Detection and Response (EDR)&amp;nbsp;and&amp;nbsp;Antivirus exclusions on Linux devices.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Audit and compliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Logs&amp;nbsp;all&amp;nbsp;task&amp;nbsp;activities&amp;nbsp;for visibility,&amp;nbsp;reporting, and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Integrated security settings management&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Manage&amp;nbsp;antivirus&amp;nbsp;and EDR settings&amp;nbsp;directly&amp;nbsp;through&amp;nbsp;Defender for Endpoint&amp;nbsp;security&amp;nbsp;settings&amp;nbsp;management&amp;nbsp;in Intune&amp;nbsp;using&amp;nbsp;security&amp;nbsp;tasks&amp;nbsp;recommendations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Defender for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;E&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;ndpoint&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;security tasks&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;surfaced&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;OL style="padding-left: 0; margin-left: 0;" start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/agents/device-offboarding-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device Offboarding&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin&amp;nbsp;tasks now&amp;nbsp;incorporates&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device Offboarding Agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;tasks.&amp;nbsp;Admins can review and act on&amp;nbsp;the&amp;nbsp;cleanup&amp;nbsp;of&amp;nbsp;stale&amp;nbsp;devices&amp;nbsp;using&amp;nbsp;the same flow used for other high-impact tasks.&amp;nbsp;The preview supports Intune&amp;nbsp;managed devices running Windows, iOS/iPadOS, macOS, Android, and Linux, and allows admins to disable Microsoft Entra ID objects with&amp;nbsp;guided&amp;nbsp;remediation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Download a CSV list of affected devices.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What&amp;nbsp;the&amp;nbsp;Device Offboarding Agent&amp;nbsp;enables*:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Routine reviews:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Pre-packaged tasks reduce manual investigation and help make cleanup repeatable.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Automated identification&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Detects&amp;nbsp;unused or outdated devices&amp;nbsp;using automated signals&amp;nbsp;across Intune and Microsoft Entra&amp;nbsp;to help reduce the attack surface.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Offboarding&amp;nbsp;insights:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Provides actionable recommendations and details requiring approval before offboarding.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;*&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Note&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;The Device&amp;nbsp;Offboarding Agent requires&amp;nbsp;Microsoft&amp;nbsp;Security Copilot,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/copilot/security/get-started-security-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;get started here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. Security Copilot will be included for all Microsoft 365 E5 customers,&amp;nbsp;roll out began for existing Security Copilot users and&amp;nbsp;is&amp;nbsp;continuing&amp;nbsp;in the upcoming months, &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;learn more here.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;potential devices&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;identified&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;for&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;removal&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;the&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;Device Offboarding Agent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;within&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;OL style="padding-left: 0; margin-left: 0;" start="4"&gt;
&lt;LI style="font-weight: bold;"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Multi&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Approval&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;requests&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Multi&amp;nbsp;Admin Approval requires a second administrator to approve&amp;nbsp;high-impact&amp;nbsp;actions,&amp;nbsp;such as scripts, remote actions, role changes, and device wipes before they are executed.&amp;nbsp;MAA requests now appear in admin tasks,&amp;nbsp;ensuring&amp;nbsp;sensitive configuration changes follow&amp;nbsp;a consistent, centralized review process.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;: &lt;/STRONG&gt;Approve or reject a request, complete a change, and add requester and approver notes for audit and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What&amp;nbsp;MAA&amp;nbsp;enables&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Alignment with access policies:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Applies to protected&amp;nbsp;configurations&amp;nbsp;that&amp;nbsp;require approvals, such as&amp;nbsp;scripts,&amp;nbsp;roles,&amp;nbsp;settings,&amp;nbsp;and&amp;nbsp;remote actions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Audit and compliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Logs&amp;nbsp;all&amp;nbsp;approval, rejection,&amp;nbsp;and completion&amp;nbsp;of&amp;nbsp;activity&amp;nbsp;for visibility,&amp;nbsp;reporting, and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Protection against compromised accounts:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Helps ensure&amp;nbsp;sensitive changes—such as script executions, device wipes, or&amp;nbsp;role&amp;nbsp;permission&amp;nbsp;updates—cannot be performed by a single administrator.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Contextual risk analysis*:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/agents/change-review-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Change Review Agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(part of Microsoft&amp;nbsp;Security Copilot)&amp;nbsp;analyzes&amp;nbsp;MAA script requests&amp;nbsp;in context&amp;nbsp;providing&amp;nbsp;detailed insights&amp;nbsp;on potential impact and clear recommendations.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;*&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Note&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&amp;nbsp;The Change Review Agent&amp;nbsp;requires&amp;nbsp;Microsoft&amp;nbsp;Security Copilot,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/copilot/security/get-started-security-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;get started here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. Security Copilot will be included for all Microsoft 365 E5 customers, roll out began for existing Security Copilot users and&amp;nbsp;is&amp;nbsp;continuing&amp;nbsp;in the upcoming months, &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;learn more here.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;4&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;: View of Multi Admin&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Approval&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;script requests&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;displayed within admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;S&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;implify&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;decisions&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;and prepare for AI-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;assisted&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;workflows&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Admin tasks in Intune&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;offers&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;a single, prioritized view to act quickly on what matters most—while building the secure foundation organization&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;need for agentic automation. As Intune continues t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;o expand its AI&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;driven capabilities, this centralized model&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;gives&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;IT more&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;control&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;deeper&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;insights&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;across the&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;platform.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Explore&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/admin-tasks" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;admin tasks in&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Microsoft&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;today and see how the expanded&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft 3&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;6&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;5 E3&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;E5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;value helps organizations&amp;nbsp;scale securely and confidently.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;FOOTER&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/FOOTER&gt;</description>
      <pubDate>Tue, 03 Feb 2026 17:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/admin-tasks-in-microsoft-intune-centralized-control-today-ai/ba-p/4489448</guid>
      <dc:creator>LiMiller</dc:creator>
      <dc:date>2026-02-03T17:00:00Z</dc:date>
    </item>
    <item>
      <title>What's in store for Intune at Microsoft Technical Takeoff 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-in-store-for-intune-at-microsoft-technical-takeoff-2026/ba-p/4489457</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;It’s&amp;nbsp;almost time&amp;nbsp;for Microsoft Technical Takeoff, our month‑long digital skilling event designed to help IT admins and technical decision-makers go deeper with Windows, Microsoft Intune, and Windows 365. Every Monday in March,&amp;nbsp;you’ll&amp;nbsp;get fresh technical content, hands‑on guidance, and direct engagement with the engineering teams who build the products you use every day.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This year’s event brings together technical deep dives, Ask Microsoft Anything (AMA) sessions, and feedback‑gathering sessions—all streamed live on the Microsoft Tech Community.&amp;nbsp;Expect deep, scenario‑driven guidance spanning security, automation, cloud management, and cross‑platform device administration.&amp;nbsp;You’ll&amp;nbsp;also be able to engage directly with the product engineering teams with&amp;nbsp;live Q&amp;amp;A&amp;nbsp;during the sessions.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Start your Technical Takeoff experience right&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="auto"&gt;As&amp;nbsp;you explore the full agenda,&amp;nbsp;make sure you&amp;nbsp;tune in to&amp;nbsp;our annual kickoff panel,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windowsevents/lets-talk-windows-intune-2026-edition/4490524" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Let’s Talk Windows &amp;amp; Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;Monday, March 2 at 7:00&amp;nbsp;AM&amp;nbsp;PT.&amp;nbsp;Engineering leaders&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/users/sangee_visweswaran/1808723" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Sangeetha Visweswaran&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/users/john_cable/586135" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;John Cable&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/users/bhavyachopra/313719" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Bhavya Chopra&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;will&amp;nbsp;share what they’re learning from IT admins around the world, as well as&amp;nbsp;what’s shaping the future of device management, security, and cloud‑powered productivity.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Explore&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;essions at Technical Takeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You&amp;nbsp;can bookmark and watch the full event at&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/TechnicalTakeoff" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://aka.ms/TechnicalTakeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;All the sessions are also listed&amp;nbsp;day-by-day&amp;nbsp;below.&amp;nbsp;From each session page, you can:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;“Add to Calendar” to save the date.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Click&amp;nbsp;“Attend”&amp;nbsp;to&amp;nbsp;hold your spot and&amp;nbsp;receive reminders.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Post your&amp;nbsp;Q&amp;amp;A&amp;nbsp;questions early for the engineering team. (Of course, you can also&amp;nbsp;post questions live as you learn!)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Tune in&amp;nbsp;live or watch on demand afterward.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;🔐 Zero Trust&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;and s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/zero-trust-in-action-securing-endpoints-with-intune/4490569" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust in Action: Securing&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ndpoints with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 9:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/least-privilege-on-windows-with-endpoint-privilege-management/4490591" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Least privilege on Windows with Intune Endpoint Privilege Management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 10:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;📦 Provisioning&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;device&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;anagement&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ama-migrating-from-windows-autopilot-to-windows-autopilot-device-prep/4490581" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AMA: Migrating from Windows Autopilot to Windows Autopilot Device Prep&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 9:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/one-platform-many-industries-smart-android-management-with-intune/4490570" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;One platform, many industries: smart Android management with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 11:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/intune-playbook-for-ios-management-at-scale/4490574" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune playbook for iOS management at scale&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 11:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/why-smarter-windows-management-starts-with-intune/4490586" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Why&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;marter Windows Management&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;tarts with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 7:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/manage-apple-devices-at-scale-intune-security-best-practices/4490571" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Manage Apple devices at scale: Intune security best practices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 9:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/intune-timing-demystified-what-really-happens-behind-the-scenes/4490580" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune timing demystified: what really happens behind the scenes&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16&amp;nbsp;–&amp;nbsp;11:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windowsevents/deploy-manage-windows-365-microsoft-intune/4490510" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Deploy and manage Windows 365 with Microsoft Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 23 – 8:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;🤖 Automation&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;and AI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ai-powered-admin-emerging-trends-in-endpoint-management/4490567" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AI‑powered admin: Emerging trends in endpoint management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 9:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ai-roundup-intune-agents-for-outcome-oriented-innovation/4490578" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AI roundup: Intune agents for outcome-oriented innovation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 8:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ama-getting-the-most-from-security-copilot-in-intune/4490590" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AMA: Getting the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ost from Security Copilot in Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 9:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;📊 Apps,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ata&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;, and r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;eporting&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/feedback-wanted-app-management-in-the-enterprise/4490584" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Feedback wanted:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;pp management in the enterprise&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 8:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/making-the-most-of-your-intune-data/4490577" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Making the most of your Intune data&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 9:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windowsevents/real-time-reporting-with-windows-autopatch-update-readiness/4490526" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Real-time reporting with Windows Autopatch update readiness&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 7:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/click-less-manage-more-simplify-app-deployment-with-intune/4490573" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Click less, manage more: simplify app deployment with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 10:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;🎥&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;All things endpoint management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/unpacking-endpoint-management-live-from-tech-takeoff-2026/4490583" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Unpacking Endpoint Management: Live from Tech Takeoff 2026&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 23&amp;nbsp;–&amp;nbsp;9:00 AM PT&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;See&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;y&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ou on Mondays in March!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Whether&amp;nbsp;you’re&amp;nbsp;modernizing your endpoint estate, strengthening security, or looking for practical configuration guidance, Microsoft Technical Takeoff is your chance to get actionable insights straight from engineering.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Can’t attend live? No problem. All sessions are recorded and available on demand shortly after they air. You can also post your Q&amp;amp;A questions in advance or anytime during the week of the session. In addition, although sessions will feature AI-generated captions during the live broadcast, we will update those with human-generated, human-verified captions (and transcripts) by the end of each week.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We hope to see you at Microsoft Technical Takeoff! Grab your seat, customize your agenda, and get answers directly from the experts behind Windows and Intune.&amp;nbsp;Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/TechnicalTakeoff" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://aka.ms/TechnicalTakeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;to get started&amp;nbsp;and see our sister&amp;nbsp;guide to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/WindowsAtTechTakeoff" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows and Windows 365 at Tech Takeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;FOOTER&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/FOOTER&gt;</description>
      <pubDate>Mon, 02 Feb 2026 17:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-in-store-for-intune-at-microsoft-technical-takeoff-2026/ba-p/4489457</guid>
      <dc:creator>Rachelle_Blanchard</dc:creator>
      <dc:date>2026-02-02T17:00:00Z</dc:date>
    </item>
    <item>
      <title>Save the date: Intune Tech Community Live – January 26</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/save-the-date-intune-tech-community-live-january-26/ba-p/4486086</link>
      <description>&lt;ARTICLE&gt;&lt;HEADER&gt;
&lt;P&gt;Level up your endpoint management skills at &lt;STRONG&gt;Tech Community Live: Intune Edition&lt;/STRONG&gt;. &lt;BR /&gt;&lt;BR /&gt;IT professionals:&amp;nbsp;mark your calendars for Monday, January 26, 2026. If you manage endpoints with Microsoft Intune, this is your chance to connect directly with the experts and get answers to your toughest questions.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/HEADER&gt;
&lt;SECTION&gt;
&lt;P&gt;This isn’t your typical webinar. It’s an interactive event packed with four Ask Microsoft Anything (AMA) sessions, where you can bring your toughest questions and get real answers from the experts. Here’s what’s on the agenda (all times in PST):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;8:00 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-secure-your-endpoints-with-policy-and-microsoft-defender/4485786" target="_blank" rel="noopener"&gt; Secure your endpoints with policy and Microsoft Defender &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;9:00 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-manage-apps-like-a-pro-with-microsoft-intune/4485787" target="_blank" rel="noopener"&gt; Manage apps like a pro with Microsoft Intune &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;10:00 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-best-practices-for-applying-zero-trust-principles-using-intune/4485788" target="_blank" rel="noopener"&gt; Best practices for applying Zero Trust using Intune &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;10:30 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-copilotagentic-centered-endpoint-management/4485789" target="_blank" rel="noopener"&gt; Copilot and agentic-centered endpoint management &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/SECTION&gt;
&lt;SECTION&gt;
&lt;H2&gt;Why Tech Community Live?&lt;/H2&gt;
&lt;P&gt;Endpoint management is evolving fast—and so are the challenges. This event gives you &lt;STRONG&gt;direct access to the Microsoft engineering teams&lt;/STRONG&gt; creating new features and capabilities in Intune. It’s your chance to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Get answers to real-world questions straight from the experts.&lt;/LI&gt;
&lt;LI&gt;Learn best practices you can apply immediately.&lt;/LI&gt;
&lt;LI&gt;Influence the future by sharing your feedback with the people who build the product.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Whether you’re looking to strengthen compliance, streamline app deployment, or embrace Zero Trust strategies, you’ll walk away with actionable insights to keep your organization secure and efficient.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;SECTION&gt;
&lt;H2&gt;How to join the fun&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Browse the session topics above.&lt;/LI&gt;
&lt;LI&gt;Hit &lt;STRONG&gt;Add to calendar&lt;/STRONG&gt; on the session pages to save them, well, to your calendar.&lt;/LI&gt;
&lt;LI&gt;Sign in to the Tech Community (top right corner of the site) then click &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive event reminders.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Post your questions in the Comments section at the bottom of each session page early and often. We’ll be ready to tackle them live! Don’t miss this opportunity to learn from Microsoft experts and elevate your Intune skills. &lt;STRONG&gt;See you there!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Community matters. Let your network know they get the Intune answers and insights they need on January 26 on the Microsoft Tech Community.&lt;/P&gt;
&lt;!-- Image placeholder: replace src with the final hosted image URL --&gt;
&lt;FIGURE&gt;&lt;/FIGURE&gt;
&lt;img /&gt;&lt;/SECTION&gt;
&lt;HR /&gt;&lt;FOOTER&gt;
&lt;P&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and &lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;
&lt;/FOOTER&gt;&lt;/ARTICLE&gt;</description>
      <pubDate>Fri, 30 Jan 2026 17:35:10 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/save-the-date-intune-tech-community-live-january-26/ba-p/4486086</guid>
      <dc:creator>Rachelle_Blanchard</dc:creator>
      <dc:date>2026-01-30T17:35:10Z</dc:date>
    </item>
    <item>
      <title>What's new in Microsoft Intune: December 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-december-2025/ba-p/4476486</link>
      <description>&lt;P&gt;Following Microsoft Ignite 2025, I caught up with colleagues and Intune MVPs who made the trip to San Francisco. There was a lot to talk about, but one conversation stood out: When I asked what surprised them most about this year for Microsoft Intune, the answer wasn't a single capability. It was witnessing busy IT admin work disappear by automating work that used to consume hours of admin time.&lt;/P&gt;
&lt;P&gt;Microsoft &lt;A href="https://learn.microsoft.com/en-us/intune/agents/" target="_blank" rel="noopener"&gt;Security Copilot agents in Intune&lt;/A&gt; exemplify that shift, but the introduction of additional agents doesn’t address other IT challenges. Throughout 2025, the Intune engineering team has shipped capabilities for cross-platform support, security, and more that has helped to remove many areas of friction from day-to-day operations. For a more complete story about what was delivered and what’s coming soon, watch the on-demand &lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK341?source=sessions" target="_blank" rel="noopener"&gt;Microsoft Ignite presentation&lt;/A&gt; or read the &lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-at-ignite/4471043" target="_blank" rel="noopener"&gt;What’s new in Microsoft Intune at Ignite&lt;/A&gt; blog.&lt;/P&gt;
&lt;P&gt;Today, I'll focus on several recent capabilities worth examining in detail from November and December.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Empowering IT by automating and enhancing workflows&lt;/H2&gt;
&lt;P&gt;For many of the customers I spoke with this year, context-switching drains productivity. Switching between multiple console nodes to manage security tasks, elevation requests, and admin approvals increases friction and the chance of missing something.&lt;/P&gt;
&lt;P&gt;The new Admin tasks node&lt;STRONG&gt; &lt;/STRONG&gt;under Tenant Administration in the Intune admin center consolidates this workflow into a single view. Now in public preview, this centralized location surfaces Endpoint Privilege Management (EPM) file elevation requests, Defender for Endpoint security tasks, and &lt;BR /&gt;Multi-Admin Approval requests in one place. Administrators can search, filter, and sort across all task types without jumping between console areas. The centralized view reduces time spent hunting for what needs attention and creates a more reliable review process.&lt;/P&gt;
&lt;P&gt;This helps centralize admin tasks, but visibility without boundaries can create noise. Until now, administrators with permission to review Endpoint Privilege Management elevation requests could see every request across the organization, regardless of their assigned scope. Scope tag enforcement adds role-based access control to this highly valued capability, aligning EPM with Zero Trust by ensuring admins only access the elevation requests required for their role. This reduces unnecessary visibility into devices and users outside their remit and lowers the risk of accidental or inappropriate actions.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Enhancing visibility and control across platforms&lt;/H2&gt;
&lt;P&gt;November's updates deliver improvements across three areas: app management, privacy controls, and policy targeting. These areas give IT administrators even more granular control for diverse device fleets running iOS, macOS, and Android.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Android: User experience and app management options&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Intune has introduced new capabilities to Managed Home Screen for IT to enhance the end user experience on frontline Android devices: Offline mode and App access without sign-in offers users greater flexibility to access critical applications, while improved volume controls now allow more granular adjustments for call, ring, notifications, alarms, and media.&lt;/P&gt;
&lt;P&gt;Additionally, if customizing your managed Google Play app catalog becomes too time consuming, you can use the new “Reset to Basic” mode. This reverts to the default "all approved apps visible" experience instantly, without support tickets or manual collection rebuilds. Taken together, these changes move Android app management away from low-level device plumbing and toward intentional experience design. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Android: Data protection and privacy controls&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Beneath the user-facing improvements, the November Intune release tightens Android data protection. This is critical for AI features that may not have been part of the original security model. The Intune Settings Catalog now provides access to Android controls, which include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;“Block assist content sharing with privileged apps", a setting that helps mitigate the emerging risk of AI assistants and screen readers from capturing work profile screenshots and app details. This stops AI services like Circle to Search from ingesting corporate context into external learning datasets while still allowing personal AI features to function.&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Work-profile privacy settings that block Bluetooth contact sharing and prevent work contacts from appearing in personal caller ID Control data flows.&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;New work profile password options (expiration, reuse history, and device wipe on failure).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Android: Policy targeting and security enforcement&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To help ensure your most sensitive controls reach only the devices that need them, IT can now use Device Management Type as an assignment filter property in Intune for precision policy targeting. Instead of over-applying rules to all Android devices, you can now differentiate between corporate and personal devices across Android Enterprise and AOSP.&lt;/P&gt;
&lt;P&gt;This precision extends into real-time security enforcement. When Microsoft Defender for Endpoint detects a rooted Android device, Microsoft Tunnel immediately blocks VPN access, dropping active connections until the device is remediated. Because Defender's detection works natively within Intune, your existing compliance policies are automatically enforced through Tunnel (across both MDM-managed and MAM scenarios) without manual reconfiguration.&lt;STRONG&gt; &lt;/STRONG&gt;Learn more in the following blog on&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/native-root-detection-support-for-microsoft-defender-on-android/4461576" target="_blank" rel="noopener"&gt;native root detection support for Microsoft Defender on Android&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;iOS and macOS: Enrollment experience design&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;First impressions during enrollment shape user expectations and IT confidence alike.&lt;/P&gt;
&lt;P&gt;When an employee unboxes a new device enrolled through your organization, those initial screens become an opportunity to empower users and position IT as an enabler. Finding the right balance has sometimes meant accepting trade-offs. IT admins could streamline the flow, or show every configuration option, but rarely both.&lt;/P&gt;
&lt;P&gt;Setup Assistant customization for iOS/iPadOS and macOS automated device enrollment, now generally available, delivers both of these benefits. Administrators can now hide or show specific Setup Assistant screens, enabling fine-grained control over the enrollment experience while preserving flexibility. Want to show App Store and camera configuration on some devices but hide privacy settings on others based on policy? You can do that now. The result is enrollment tailored to your actual requirements, not constrained by platform defaults.&lt;STRONG&gt; &lt;/STRONG&gt;For detailed configuration guidance, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-ios" target="_blank" rel="noopener"&gt;Set up automated device enrollment for iOS/iPadOS&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-macos" target="_blank" rel="noopener"&gt;Set up automated device enrollment for macOS&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In summary, whether Android users require precise privacy controls or iOS users benefit from a customized enrollment experience, the November Intune release emphasizes that effective, cross-platform management involves respecting each device platform's uniqueness and working to optimize for them.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Improving end-user onboarding experiences&lt;/H2&gt;
&lt;P&gt;Providing employees with immediate access to devices equipped with necessary applications can enhance employee satisfaction, optimize security measures, and increase overall productivity. Upon logging into a Cloud PC environment, end-users encounter pre-installed applications, enabling them to begin working efficiently without delay.&lt;/P&gt;
&lt;P&gt;Windows Autopilot device preparation in automatic mode is now available in public preview for Windows 365 Enterprise, Windows 365 Frontline dedicated mode, and Windows 365 Cloud Apps.&amp;nbsp;IT administrators now can include device preparation policies as part of their Cloud PC provisioning process.&lt;/P&gt;
&lt;P&gt;This capability streamlines the Cloud PC provisioning process, improves the end-user experience, and eliminates the need for custom images, while providing visibility into installation progress with both the CPC report and the Autopilot device prep deployment report. This ensures the device is set up with critical apps and scripts when the end-user logs in on day one.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Looking forward to 2026&lt;/H2&gt;
&lt;P&gt;Cloud-native endpoint management on a trusted platform is the foundation for how organizations will support AI safely across endpoints. The investments throughout 2025 focused on reducing friction at critical points, rather than painting with a broad brush, across every aspect of endpoint management, and showed what's possible when management infrastructure is built for modern threats and modern work.&lt;/P&gt;
&lt;P&gt;Whether it's automating tedious admin tasks, respecting platform-specific security needs, or accelerating device readiness, a cloud-powered, AI-driven approach helps move IT from firefighting to strategy. In 2026, we will continue to innovate with this focus and share more updates on &lt;A href="https://aka.ms/IntuneM365Blog" target="_blank" rel="noopener"&gt;Intune's advanced capabilities coming to Microsoft 365 E3 and Microsoft 365 E5&lt;/A&gt;, which will expand access to the solutions of the Microsoft Intune Suite to more customers. See you in 2026!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 19:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-december-2025/ba-p/4476486</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2025-12-11T19:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft 365 adds advanced Microsoft Intune solutions at scale</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/ba-p/4474272</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: &lt;EM&gt;New capabilities will begin to roll out CY26 Q3. Customers will receive a 30‑day notice in Message Center before the update becomes available in their tenant.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;In the last three years, Microsoft launched multiple endpoint management solutions with advanced capabilities that enable IT professionals to unify mission critical endpoint management functionality in one cost-effective plan with the &lt;STRONG&gt;Microsoft Intune Suite&lt;/STRONG&gt;. These capabilities are essential to accelerate every organization’s journey towards Zero Trust security, improving end user productivity, and empowering IT and security professionals to improve total cost of ownership (TCO).&lt;/P&gt;
&lt;P&gt;Today, IT teams face new challenges, as device inventories grow larger, more diverse, and are much more widely distributed and dynamic than just a few years ago. At the same time, they are still expected to keep systems protected, compliant, and operational with limited budgets. To meet evolving security needs and growing demands, organizations need &lt;STRONG&gt;more advanced security and management tools&lt;/STRONG&gt; capable of transforming IT operations in ways that can safeguard against AI-enhanced attack vectors and new risks while preserving productivity on every endpoint.&lt;/P&gt;
&lt;P&gt;To help organizations make this transition, Microsoft is bringing powerful capabilities of the &lt;STRONG&gt;Microsoft Intune Suite&lt;/STRONG&gt; to &lt;STRONG&gt;Microsoft 365 E3 and Microsoft 365 E5&lt;/STRONG&gt;. By expanding these offerings, more customers can confidently embrace transformation and stay secure in the age of AI.&lt;/P&gt;
&lt;P class="lia-align-left" style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;“Intune Suite makes managing 10,000 or 40,000 devices effortless through automation and unification. The capacity to scale effortlessly while simplifying processes has led to more efficient updates and quicker incorporation of new assets.” –Roman Kleyn, Head of Workplace Design, Krones AG&lt;SUP&gt;&lt;A href="#community--1-_note1" target="_self"&gt;i&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Unifying Endpoint Management: Key capabilities driving customer choice&lt;/H2&gt;
&lt;P&gt;Microsoft Intune empowers IT to solve issues faster, get proactive with data and secure diverse devices with Intune Remote Help, Intune Advanced Analytics, Microsoft Tunnel for Mobile Application Management, specialty device management and firmware updates. These capabilities will be added to Microsoft Enterprise Mobility and Security E3 (EMS E3) which also extends this value to Microsoft 365 E3. Furthermore, to unify advanced security and device management, Intune Endpoint Privilege Management, Intune Enterprise Application Management and Microsoft Cloud PKI will be added to Microsoft 365 E5.&lt;/P&gt;
&lt;P&gt;These changes, alongside the &lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;Microsoft Security Copilot&lt;/A&gt; and &lt;A href="https://aka.ms/M365-PIBlog" target="_blank" rel="noopener"&gt;Microsoft 365&lt;/A&gt; updates, will fundamentally expand the availability of Intune integrated, cloud powered capabilities. This expansion will provide seamless access to advanced management and security features as well as agentic, automated workflow capabilities within Microsoft’s most comprehensive commercial products. It will empower IT to help &lt;STRONG&gt;safeguard productivity&lt;/STRONG&gt; and &lt;STRONG&gt;strengthen their Zero Trust posture&lt;/STRONG&gt; by minimizing risk, maintaining compliance, and ensuring seamless, secure digital employee experiences. Ultimately, this change will enable proactive issue prevention, more secure work, and efficient ways to&amp;nbsp;&lt;STRONG&gt;scale &lt;/STRONG&gt;&lt;STRONG&gt;operations&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;With the rollout of &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/copilot/copilot-intune-overview" target="_blank" rel="noopener"&gt;Microsoft Security Copilot in Intune&lt;/A&gt;, we’ve helped organizations enter a new era where AI is increasingly incorporated into their IT operations. Last month at Microsoft Ignite 2025, we announced a significant step that goes even further, putting AI at the core of endpoint management. With the launch of a &lt;A href="https://aka.ms/IntuneAtIgnite2025" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;new wave of Security Copilot agents in Intune&lt;/STRONG&gt;&lt;/A&gt; and more ways to explore Intune data, IT can ask important questions, take action on the answers, and simplify complex tasks with intelligence and automation.&lt;/P&gt;
&lt;P&gt;Here’s a closer look at why organizations are choosing Intune and Security Copilot as their endpoint management solution.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Enhanced security simplifies implementation of Zero Trust principles &lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;In 2025, 79% of ransomware attacks involved remote management tools on endpoints, highlighting the critical need for Zero Trust controls and least-privilege access on every device.&lt;SUP&gt;&lt;A href="#community--1-_note2" target="_self"&gt;ii&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-endpoint-privilege-management" target="_blank" rel="noopener"&gt;Endpoint Privilege Management&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;enables organizations to adopt a least privilege approach, mitigating&lt;STRONG&gt; &lt;/STRONG&gt;systemic risks of local admin privileges by providing elevated access only to approved apps or services. Just-in-time elevation helps to maintain productivity without compromising security.
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot&lt;/STRONG&gt; in Intune offers assistance by providing valuable insights based on Microsoft Defender threat intelligence that assesses an app’s risk before IT approves an elevation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/microsoft-tunnel-mam" target="_blank" rel="noopener"&gt;Microsoft Tunnel for Mobile Application Management&lt;/A&gt; supports Zero Trust principles by providing secure per-app VPN connectivity access to company resources without requiring enrollment, protects corporate data and respects employee privacy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;AI-powered insights and remote assistance powers productivity &lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;“Remote Help closed the gap that we had for remote management. Now we have an enterprise-compatible solution with audit logs, allowing us to see what’s happened, who is connected to whom, etc. These are true benefits from an enterprise solution,” – Michael Meier, Senior System Administrator, Krones AG&lt;SUP&gt;&lt;A href="#community--1-_note3" target="_self"&gt;iii&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-advanced-analytics" target="_blank" rel="noopener"&gt;Advanced Analytics&lt;/A&gt; offers AI-powered anomaly detection to proactively identify device health and other forms of digital friction and gives IT visibility into areas of focus to keep operations running smoothly and ensure device compliance.
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Copilot in Intune assists admins of all experience levels in performing complex tasks such as writing KQL queries through the simple use of natural language.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-remote-help" target="_blank" rel="noopener"&gt;Remote Help&lt;/A&gt; allows IT teams to safely and remotely support and fix issues more quickly. All interactions are fully auditable and use strong authentication, trusted connections, role-based access control, and device compliance checks.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Streamlined app deployment and automated certificate lifecycle management helps maintain compliance and protection at scale &lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;“Cloud PKI within the Intune Suite allows you to go cloud native in terms of certificate deployment, which means you can provision PKIs with just a few clicks — that’s a blessing for all the IT administrators. With this built-in service, Microsoft hosts everything for you to manage certificates.” Niklas Tinner, Founder/Solution Architect, Oceanleaf GmbH&lt;SUP&gt;&lt;A href="#community--1-_note4" target="_self"&gt;iv&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-enterprise-application-management" target="_blank" rel="noopener"&gt;Enterprise Application Management&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;streamlines app deployment and updates, reduces IT overhead, and improves the digital user experience with a curated catalog of 1000+ of prepackaged applications.
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/microsoft-security-copilot-in-intune---pt-2-vulnerability-remediation-agent-in-l/4424824" target="_blank" rel="noopener"&gt;Vulnerability Remediation Agent&lt;/A&gt; helps reduce the effort of discovering and prioritizing breach or work disruption risks, giving IT insight on what patches to prioritize.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;S&gt; &lt;/S&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-cloud-PKI" target="_blank" rel="noopener"&gt;Microsoft Cloud PKI&lt;/A&gt; allows IT to streamline the management of the complete certificate lifecycle and reduce the dependency on on-premises infrastructure. It also helps prevent phishing and mitigate other risks with certificate based authentication to Wi-Fi and VPN services.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;A unified IT ecosystem for long term value&lt;/H2&gt;
&lt;P&gt;Including Intune’s advanced capabilities directly into Microsoft 365 is the latest step in our larger vision to create a unified, strategic foundation that enables companies to manage and secure their endpoints. Intune and Security Copilot are built to work seamlessly within Microsoft 365, Windows 11, Windows 365, Entra, Purview and Defender.&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;“One New Zealand saved $800K by modernizing with Windows 365 and Microsoft Intune, cutting provisioning-related tickets by 80%. Devices that once took four to six hours to provision are now ready in 30 minutes. User assignments take less than 15 seconds, and onboarding time for call center staff dropped almost 95%.&lt;SUP&gt;&lt;A href="#community--1-_note5" target="_self"&gt;v&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In addition to Intune’s upcoming changes within Microsoft 365, the recently announced Windows resiliency and security capabilities will be added to &lt;STRONG&gt;Windows Enterprise E3&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Resiliency Initiative recovery tools now include &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/scalable-windows-resiliency-with-new-recovery-tools/4470659" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;quick machine recovery&lt;/STRONG&gt;&lt;/A&gt; (QMR) with enterprise-level controls, point-in-time restore, and cloud rebuild for Windows 11. Through Intune, QMR enables fast restoration of apps, settings, and files, as well as Windows Backup and OneDrive.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Windows Autopatch now includes &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-%E2%80%94-elevate-your-update-experience-for-modern-work/4468111" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;update readiness&lt;/STRONG&gt;&lt;/A&gt;, in preview, giving IT teams real-time visibility into device compliance and risks through a pre-built Intune dashboard. Administrators can quickly identify, diagnose, and remediate updates, telemetry and policy issues directly within Autopatch.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;What does this mean for your organization?&lt;/H2&gt;
&lt;P&gt;Microsoft is committed to delivering a unified management and security foundation on a trusted, cloud platform that elevates how organizations operate and defend at scale. Aligning this with AI-powered and agentic automation enables stronger Zero Trust controls to help safeguard productivity, minimizes risks, and improves agility for IT teams and end users.&lt;/P&gt;
&lt;P&gt;When you’re ready to learn more, &lt;STRONG&gt;connect with your Microsoft account team&lt;/STRONG&gt; to discuss adoption roadmaps and discover how a comprehensive, AI-ready portfolio can help you solve even the most complex IT challenges.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;1. Which Intune related capabilities are included in each plan? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Here is a summary of the Microsoft 365 plan changes related to Microsoft Intune:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 835px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft 365 plans&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Included capabilities&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Enterprise Mobility and Security E3 (EMS E3)&lt;/P&gt;
&lt;P&gt;(&lt;EM&gt;included in Microsoft 365 E3&lt;/EM&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help" target="_blank" rel="noopener"&gt;Remote Help&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/advanced-analytics/" target="_blank" rel="noopener"&gt;Advanced Analytics&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune Plan 2&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft 365 E5&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;All Microsoft 365 E3&lt;/STRONG&gt; features plus:&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-overview" target="_blank" rel="noopener"&gt;Endpoint Privilege Management &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/microsoft-cloud-pki-overview" target="_blank" rel="noopener"&gt;Cloud PKI &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-enterprise-app-management" target="_blank" rel="noopener"&gt;Enterprise App Management &lt;/A&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft 365 E5&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft Security Copilot&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Enterprise E3 &amp;nbsp;&lt;/P&gt;
&lt;P&gt;(&lt;EM&gt;included in Microsoft 365 E3&lt;/EM&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Quick Machine Recovery (QMR)&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cloud rebuild for Windows 11&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Point-in-time restore for desktop&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Post-quantum security APIs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Autopatch update readiness&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Enterprise per-device license&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Basic resiliency features (QMR, point in time restore)&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Software Assurance&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. What is included in Intune Plan 2?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Intune Plan 2 capabilities planned to be included in Microsoft Enterprise Mobility and Security E3 include:&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/microsoft-tunnel-mam" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Tunnel for Mobile Application Management&lt;/STRONG&gt;&lt;/A&gt; (MAM) for secure per-app VPN connectivity access to company resources without requiring full device enrollment. &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/specialty-devices-with-intune" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Specialty device management&lt;/STRONG&gt;&lt;/A&gt; covers the protection for devices such as AR/VR headsets, smart screens, and certain meeting room systems for specialized business needs. &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/zebra-lifeguard-ota-integration" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Firmware over the air&lt;/STRONG&gt;&lt;/A&gt; (FOTA) updates for supported Zebra devices.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3. When do these changes take effect? &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;For the 2026 planned product additions to Microsoft 365, a Microsoft 365 admin center notification will be posted for administrators of eligible organizations 30 days in advance of the effective change.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;4. Do I need to change my plan to use the Intune Suite capabilities or any of its add-ons? &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;No action is necessary. All eligible tenants with Microsoft Enterprise Mobility and Security E3 and Microsoft 365 E5 will automatically be provisioned with the Intune Suite capabilities based on the table above. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P style="margin-top: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-size: 14px; font-weight: 400; color: #333333;"&gt;&lt;SUP&gt;i &lt;A href="https://www.microsoft.com/en/customers/story/19747-krones-ag-microsoft-intune?msockid=32d43ffd627f670a251d295f63b166f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Success with Intune Suite streamlines Krones AG global operations | Microsoft Customer Stories&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="endnote text"&gt;ii &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Digital Defense Report 2025 – Safeguarding Trust in the AI Era&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="endnote text"&gt;iii &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en/customers/story/19747-krones-ag-microsoft-intune?msockid=32d43ffd627f670a251d295f63b166f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Success with Intune Suite streamlines Krones AG global operations | Microsoft Customer Stories&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;iv &lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-cloud-PKI?msockid=32d43ffd627f670a251d295f63b166f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Cloud PKI—Certificate Management | Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;v &lt;A href="https://www.microsoft.com/en/customers/story/25487-one-new-zealand-microsoft-365-frontline-worker#customers-share-modal-dialog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;One New Zealand saves $800,000 by modernizing with Windows 365 and Microsoft Intune | Microsoft Customer Stories&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SUP&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 22:10:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/ba-p/4474272</guid>
      <dc:creator>Talal_Alqinawi</dc:creator>
      <dc:date>2026-06-18T22:10:47Z</dc:date>
    </item>
    <item>
      <title>Essential Intune reading list: MVP community content for 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/essential-intune-reading-list-mvp-community-content-for-2025/ba-p/4471897</link>
      <description>&lt;P&gt;As we head into the holiday season, I wanted to take a moment to celebrate something truly special: the incredible contributions from our Microsoft Intune MVP community this year. Last year, I released our &lt;A href="https://www.linkedin.com/feed/update/urn:li:activity:7274431599616626688/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;first Holiday Reading post&lt;/STRONG&gt;&lt;/A&gt;, which got a lot of traction, and I was asked to do it again this year — so I guess we are starting a new tradition!&lt;/P&gt;
&lt;P&gt;Whether you're a security-focused admin exploring Zero Trust architecture, a Windows specialist diving into the latest policy enforcement mechanisms, a Mac admin navigating the evolving Apple ecosystem, or an automation advocate building the next great community tool, there's something here for you.&lt;/P&gt;
&lt;P&gt;This collection represents the spirit of our community, packed with real-world lessons, practical insights, and suggested solutions from experts in the field. While this is a select set of collected content, I strongly recommend checking out all of the content created by our MVPs — you can find a list of our &lt;A href="https://mvp.microsoft.com/en-US/search?target=Profile&amp;amp;program=MVP"&gt;active Intune MVPs&lt;/A&gt; here (make sure to set the filter for Microsoft Intune under Technology).&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Introduction to Intune&lt;/H2&gt;
&lt;P&gt;Know someone who needs to get up to speed on Intune quickly? Share these resources:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://andrewstaylor.com/2025/08/20/getting-started-with-intune-some-things-to-watch/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Getting started with Intune&lt;/STRONG&gt;&lt;/A&gt; – Important hints and tips for Intune beginners — settings you won't want to overlook &lt;EM&gt;(Andrew Taylor)&lt;/EM&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=EKDWOGXpFKU" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;12 reasons why Intune&lt;/STRONG&gt;&lt;/A&gt; – A comprehensive podcast covering Zero Trust-ready, BYOD-friendly endpoint management &lt;EM&gt;(Sucheta Gawade)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Security &amp;amp; compliance&lt;/H2&gt;
&lt;P&gt;A stronger security posture is at the top of almost every organization’s wish list. Read and watch what MVPs are recommending:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://youtu.be/EJrCy4XrtAo?si=69o2y9fb_jvVD4OF" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cloud PKI essentials&lt;/STRONG&gt;&lt;/A&gt; – A deep dive into what Cloud PKI is, deployment approaches, and where organizations stand today with certificate distribution &lt;EM&gt;(Shady Khorshed)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=nWixi8ODMG4&amp;amp;list=PLhLCvUkszoFol8WFcxwQQZomqd8LBKQ9d" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Device-centric Zero Trust with Intune + Defender&lt;/STRONG&gt;&lt;/A&gt; – Learn how to implement a complete Zero Trust strategy using Intune and Microsoft Defender for Endpoint &lt;EM&gt;(Sucheta Gawade)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/pulse/windows-patching-common-mistake-intune-admins-do-mirochnitchenko-dvllf/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows patching best practices&lt;/STRONG&gt;&lt;/A&gt; – Common mistakes Intune admins make and how to patch Windows correctly &lt;EM&gt;(Pavel Mirochnitchenko)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.oceanleaf.ch/advanced-conditional-access/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Advanced conditional access scenarios&lt;/STRONG&gt;&lt;/A&gt; – Real-world field experience and best practices for complex conditional access setups &lt;EM&gt;(Niklas Tinner)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.vansurksum.com/2025/10/20/balancing-control-and-convenience-preventing-edge-password-sync-on-unmanaged-devices/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Edge password sync security&lt;/STRONG&gt;&lt;/A&gt; – How to manage Edge password sync on unmanaged devices when using Microsoft Password Manager &lt;EM&gt;(Kenneth van Surksum)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.nielskok.tech/intune/automate-applocker-configuration-for-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;AppLocker automation&lt;/STRONG&gt;&lt;/A&gt; – Automate your AppLocker configuration directly in Intune with scripts &lt;EM&gt;(Niels Kok)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.burgerhout.org/navigating-nis2-quality-marks-with-microsoft-security-from-qm10-to-qm30/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;NIS2 compliance with Microsoft 365&lt;/STRONG&gt;&lt;/A&gt; – Comprehensive guide to reaching NIS2 compliance using Intune and Azure &lt;EM&gt;(Jeroen Burgerhout)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://smbtothecloud.com/configure-mam-for-ios-android-with-one-script/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Mobile Application Management (MAM)&lt;/STRONG&gt;&lt;/A&gt; – Step-by-step setup for iOS and Android MAM with automation scripts &lt;EM&gt;(Gannon Novak)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Windows &amp;amp; Windows 365&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Master the latest Windows capabilities&lt;/STRONG&gt; with this guidance from our top experts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/09/09/windows11-kiosk-windows-app/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 11 kiosk multi-app mode&lt;/STRONG&gt;&lt;/A&gt; – Tackle the XML struggle and get your kiosk devices working with Edge and the Windows App &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/08/31/multi-admin-approval/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Multi-admin approval in Intune&lt;/STRONG&gt;&lt;/A&gt; – Set up Intune's multi-admin approval feature with ease, plus insights on the end-user experience &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/08/26/windows-backup-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows Backup for Organizations&lt;/STRONG&gt;&lt;/A&gt; – Introducing Windows Backup with Intune for smooth device upgrades and refreshes &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcaching.com/2025/05/08/windows-11-hotpatching-with-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 11 hotpatching&lt;/STRONG&gt;&lt;/A&gt; – A comprehensive deep-dive into applying critical security updates without reboots using Intune &lt;EM&gt;(Sucheta Gawade)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://joostgelijsteen.com/oma-dm-and-intunes-policy-enforcement/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;OMA-DM and policy enforcement&lt;/STRONG&gt;&lt;/A&gt; – Understanding how Intune uses the OMA-DM protocol to manage and enforce policies &lt;EM&gt;(Joost Gelijsteen)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://joostgelijsteen.com/declared-configuration/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Declared configuration&lt;/STRONG&gt;&lt;/A&gt; – The evolution of Windows policy enforcement with MMP-C and declared configuration &lt;EM&gt;(Joost Gelijsteen)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://joostgelijsteen.com/device-query-for-multiple-devices/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Device query for multiple devices&lt;/STRONG&gt;&lt;/A&gt; – Extract device data across your fleet using endpoint analytics &lt;EM&gt;(Joost Gelijsteen)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.burgerhout.org/mastering-windows-shared-pcs-with-microsoft-intune" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows shared PCs configuration&lt;/STRONG&gt;&lt;/A&gt; – Master Windows shared PCs with Intune and understand how it differs from kiosk mode &lt;EM&gt;(Jeroen Burgerhout)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://patchmypc.com/blog/administrator-protection-windows-11-25h2/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Administrator protection in Windows 11 25H2&lt;/STRONG&gt;&lt;/A&gt; – Explore the new isolated privilege model replacing traditional admin elevation &lt;EM&gt;(Rudy Ooms)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://patchmypc.com/blog/windows-finally-translates-entra-group-and-role-sids-to-real-names/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Entra group SID translation&lt;/STRONG&gt;&lt;/A&gt; – Finally! Translate Entra group SIDs into readable names on your devices &lt;EM&gt;(Rudy Ooms)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://patchmypc.com/blog/intune-policy-delivery-debugging-the-8-hour-sync-myth/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune policy delivery&lt;/STRONG&gt;&lt;/A&gt; – Debunking the 8-hour sync myth and understanding how policy delivery really works &lt;EM&gt;(Rudy Ooms)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.oceanleaf.ch/windows-365-link-experience/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 365 Link experience&lt;/STRONG&gt;&lt;/A&gt; – Best practice configurations and everything you need to know about Windows 365 Link &lt;EM&gt;(Niklas Tinner)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.joeyverlinden.com/entra-id-joined-kiosk-or-autologon-device-on-a-budget/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Entra ID joined kiosk devices&lt;/STRONG&gt;&lt;/A&gt; – Deploy fully functional, self-deploying kiosk devices on modern Windows endpoints &lt;EM&gt;(Joey Verlinden)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ccmexec.com/2025/11/application-control-for-business-and-the-story-of-the-unsigned-wix-dlls/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;App&lt;/STRONG&gt;&lt;STRONG&gt; Control for Business&lt;/STRONG&gt;&lt;/A&gt; – Solving unsigned WIX .dll issues with App Control for Business &lt;EM&gt;(Jörgen Nilsson)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;macOS &amp;amp; Apple ecosystem&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Apple device management is evolving fast&lt;/STRONG&gt;. The Intune community helps keep you up to date:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/07/28/macos-laps-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;macOS LAPS configuration&lt;/STRONG&gt;&lt;/A&gt; – Complete guide to setting up Local Administrator Password Solution for macOS with Intune &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://youtu.be/EKfTjysk_jw?si=Z2138B6xQ7ndTxl4" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;JUMP-IN: macOS MDM migration tool&lt;/STRONG&gt;&lt;/A&gt; – Discover this all-in-one macOS MDM migration tool and learn how it's revolutionizing transitions &lt;EM&gt;(Shady Khorshed)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intuneirl.com/macos-ios-26-for-enterprise-ddm-deployment-and-the-intel-mac-sunset/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;macOS 26 &amp;amp; iOS 26 for enterprises&lt;/STRONG&gt;&lt;/A&gt; – Apple's biggest shift in enterprise device management in years — key changes and deadlines for IT admins &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intuneirl.com/mac-admins-your-migration-glow-up-just-dropped/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;macOS migration glow-up&lt;/STRONG&gt;&lt;/A&gt; – Step-by-step process for switching macOS MDM using the new ABM update &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.burgerhout.org/introduction-to-macos-management-in-intune-beginner-friendly/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Introduction to macOS management&lt;/STRONG&gt;&lt;/A&gt; – Beginner-friendly guide to managing macOS with Intune &lt;EM&gt;(Jeroen Burgerhout)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.xplorethecloud.nl/l/ios-app-protection-policy-new-features/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;iOS app protection policy features&lt;/STRONG&gt;&lt;/A&gt; – New features in app protection policies for iOS and what they mean for your setup &lt;EM&gt;(Arno Van Dijk)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Updates, patching &amp;amp; device management&lt;/H2&gt;
&lt;P&gt;Get tips to keep your devices running smoothly and securely:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/pulse/install-update-drivers-microsoft-intune-my-script-ii-mirochnitchenko-mjskf" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Driver management in Intune&lt;/STRONG&gt;&lt;/A&gt; – Compare script-based driver updates vs. Intune's Driver Update Management solution &lt;EM&gt;(Pavel Mirochnitchenko)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.xplorethecloud.nl/l/blog-series-intune-suite-part-1-enterprise-app-management/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enterprise App Management&lt;/STRONG&gt;&lt;/A&gt; – Explore the Intune Suite's features for simplified app deployment and maintenance &lt;EM&gt;(Arno Van Dijk)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.xplorethecloud.nl/l/remove-default-windows-store-packages/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Remove Default Windows Store packages&lt;/STRONG&gt;&lt;/A&gt; – Control Windows 11 built-in apps using the Settings Catalog without scripts &lt;EM&gt;(Arno Van Dijk)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intunebrew.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;IntuneBrew&lt;/STRONG&gt;&lt;/A&gt; – Application and patch management for macOS apps made easy &lt;EM&gt;(Ugur Koc)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Community tools &amp;amp; automation&lt;/H2&gt;
&lt;P&gt;Supercharge your Intune management with these community-created solutions:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intuneassistant.cloud" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Assistant&lt;/STRONG&gt;&lt;/A&gt; – Empower yourself with unparalleled efficiency in Intune management through advanced visualization and analysis &lt;EM&gt;(Sander Rozemuller)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/AllwaysHyPe/IntuneStack" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;IntuneStack&lt;/STRONG&gt;&lt;/A&gt; – Manage Intune policy as code with GitHub Actions, OIDC authentication, and ring-based deployments &lt;EM&gt;(Hailey Phillips)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/Intune-Log-Reader-for-Windows" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Log Reader for Windows&lt;/STRONG&gt;&lt;/A&gt; – Real-time analysis and monitoring of Microsoft Intune Management Extension logs on Windows &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/Intune-Log-Reader" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Log Reader for macOS&lt;/STRONG&gt;&lt;/A&gt; – Real-time analysis and monitoring of Microsoft Intune MDM logs on macOS &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/ABM-API-Client" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;ABM API Client&lt;/STRONG&gt;&lt;/A&gt; – Native macOS client for Apple Business Manager and Apple School Manager APIs with an intuitive GUI &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/Fleetly" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Fleetly&lt;/STRONG&gt;&lt;/A&gt; – iOS app for IT administrators to manage and monitor Intune-enrolled devices on the go &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.tenuvault.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;TenuVault&lt;/STRONG&gt;&lt;/A&gt; – Backup and restore for Intune with full automation &lt;EM&gt;(Ugur Koc)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intunedocumentation.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Documentation Generator&lt;/STRONG&gt;&lt;/A&gt; – Generate PDF reports of all your Intune configurations in minutes &lt;EM&gt;(Ugur Koc)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.joeyverlinden.com/envoy-lightweight-user-environment-manager/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Envoy Lightweight UEM&lt;/STRONG&gt;&lt;/A&gt; – PowerShell-based User Environment Manager designed for Intune-managed Windows machines &lt;EM&gt;(Joey Verlinden)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://openintunebaseline.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;OpenIntuneBaseline&lt;/STRONG&gt;&lt;/A&gt; – Community-supported security baseline for Intune with real-world best practices &lt;EM&gt;(James Robinson)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intuneqlinks.net/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;IntuneQLinks&lt;/STRONG&gt;&lt;/A&gt; – Comprehensive catalog of community articles, blogs, videos, and diagrams — your go-to resource library &lt;EM&gt;(Andy Jones)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/srozemuller/azavd" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Azure Virtual Desktop PowerShell module&lt;/STRONG&gt;&lt;/A&gt; – Streamline Azure Virtual Desktop management with this powerful community tool &lt;EM&gt;(Sander Rozemuller)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dailychecks.euctoolbox.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Daily Checks&lt;/STRONG&gt;&lt;/A&gt; – Get a daily digest of what's happening in your tenant via email with this free service &lt;EM&gt;(Andrew Taylor)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Community groups &amp;amp; resources&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/groups/13067571/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Intune - Android and iOS Admins LinkedIn Group&lt;/STRONG&gt;&lt;/A&gt; – A focused community for mobile device management with Intune &lt;EM&gt;(Andy Jones)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Community Events&lt;/H2&gt;
&lt;P&gt;Participate in the Intune community in person at these upcoming events&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Workplace Ninjas US 2025 – Dallas, Texas, USA – Dec 9–10, 2025 &lt;BR /&gt;Event page: &lt;A href="https://workplaceninjas.us/" target="_blank" rel="noopener"&gt;https://workplaceninjas.us&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Experts Live Denmark 2026 – Copenhagen, Denmark – February 24–25, 2026 &lt;BR /&gt;Event page: &lt;A href="https://cloudway.com/calendar-event/experts-live-denmark/" target="_blank" rel="noopener"&gt;https://cloudway.com/calendar-event/experts-live-denmark&lt;/A&gt;/&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Modern Endpoint Management Summit 2026 EMEA Edition (MEM Summit Paris) – Paris, France – April 22–24, 2026 &lt;BR /&gt;Event page: &lt;A href="https://sessionize.com/MEMSummit2026/" target="_blank" rel="noopener"&gt;https://sessionize.com/MEMSummit2026/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Workplace Ninjas Norway 2026 – Oslo, Norway-May 27, 2026 &lt;BR /&gt;Event page: &lt;A href="https://wpninjas.no/" target="_blank" rel="noopener"&gt;https://wpninjas.no/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Workplace Ninja Summit 2026 – Baden, Switzerland – TBD &lt;BR /&gt;Event page: &lt;A href="https://summit.wpninjas.global/" target="_blank" rel="noopener"&gt;https://summit.wpninjas.global/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Intune Community Resources&lt;/H2&gt;
&lt;P&gt;Get trusted Intune tips and strategies from these blogs, videos, and podcasts from industry experts.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/andrew-taylor-41707916/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Andrew Taylor&lt;/STRONG&gt;&lt;/A&gt; Newsletter and blogs - &lt;A href="https://andrewstaylor.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://andrewstaylor.com/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/lewis-barry/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Lewis Barry&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://conditionalaccess.uk/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://conditionalaccess.uk/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MsEndpointmgr- &lt;A href="https://www.youtube.com/channel/UC3Kii1MYmVNmla5VgWIGqwA" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;(33) MSEndpointMgr - Jungling the Cloud - YouTube&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/peterwoude/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Peter van der Woude&lt;/STRONG&gt;&lt;/A&gt; – All about Microsoft Intune - &lt;A href="https://petervanderwoude.nl/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://petervanderwoude.nl/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/simonskotheimsvik/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Simon Skotheimsvik&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://skotheimsvik.no/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://skotheimsvik.no/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/niklas-tinner/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Niklas Tinner&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://www.oceanleaf.ch/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.oceanleaf.ch/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/asquaredozen/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Adam Gross&lt;/STRONG&gt;&lt;/A&gt; Intune Training -&amp;nbsp;&lt;A href="https://www.youtube.com/@IntuneTraining" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.youtube.com/@IntuneTraining&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/jonathanjedwards/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Jonathan Edwards&lt;/STRONG&gt;&lt;/A&gt; M365 Training - &lt;A href="https://www.youtube.com/@bearded365guy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.youtube.com/@bearded365guy&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/stevew25/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Steven Weiner&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://www.getrubix.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.getrubix.com/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://creators.spotify.com/pod/show/wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Workplace Ninjas Netherlands Podcast&lt;/STRONG&gt;&lt;/A&gt; - &lt;STRONG&gt;&lt;A class="lia-external-url" href="https://creators.spotify.com/pod/show/wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://creators.spotify.com/pod/show/wpninjasnl&lt;/STRONG&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/@wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Workplace Ninja User Group Netherlands Video&lt;/STRONG&gt;&lt;/A&gt; - &lt;STRONG&gt;&lt;A href="https://www.youtube.com/@wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.youtube.com/@wpninjasnl&lt;/STRONG&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.meetup.com/workplace-ninja-user-group-india/events/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Workplace Ninja User Group India&lt;/STRONG&gt;&lt;/A&gt; &lt;STRONG&gt;- &lt;A class="lia-external-url" href="https://www.meetup.com/workplace-ninja-user-group-india/events/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.meetup.com/workplace-ninja-user-group-india/events/&lt;/STRONG&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Microsoft Cloud and Client Management Community Belgium -&amp;nbsp;&lt;A href="https://www.linkedin.com/company/mc2mcbe/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.linkedin.com/company/mc2mcbe/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;A special thanks to our contributors&lt;/H2&gt;
&lt;P&gt;A heartfelt thank you to all the MVPs who contributed to this year's roundup:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Joery Van den Bosch&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://de.linkedin.com/in/shadykhorshed" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Shady Khorshed&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://techcaching.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://andrewstaylor.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Andrew Taylor&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.nielskok.tech/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Niels Kok&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.joeyverlinden.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Joey Verlinden&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.oceanleaf.ch/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Niklas Tinner&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.linkedin.com/in/pavelmiro/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Pavel Mirochnitchenko&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.vansurksum.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Kenneth van Surksum&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.linkedin.com/in/haileypc/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Hailey Phillips&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.burgerhout.org/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Jeroen Burgerhout&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://intuneirl.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Somesh Pathak&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.petervanderwoude.nl/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Peter van der Woude&lt;/STRONG&gt;&lt;/A&gt; | &lt;STRONG&gt;&lt;A href="https://www.xplorethecloud.nl/" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Arno van Dijk&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/STRONG&gt;| &lt;A href="https://smbtothecloud.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Gannon Novak&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.intuneqlinks.net/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Andy Jones&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://rozemuller.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Sander Rozemuller&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://scloud.work/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Florian Salzmann&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://openintunebaseline.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;James Robinson&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://call4cloud.nl/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Rudy Ooms&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://joostgelijsteen.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Joost Gelijsteen&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://ugurkoc.de/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Ugur Koc&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://ccmexec.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Jörgen Nilsson&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Your expertise, generosity, and passion for sharing knowledge continue to elevate the entire Intune community. Thank you for everything you do. Wishing you a wonderful holiday season and a successful 2026! Stay secure, stay innovative, and be well.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Disclaimer: This content has been created and curated by the community. Readers are encouraged to independently verify technical details and evaluate resources for their specific environments.&lt;/EM&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 20:04:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/essential-intune-reading-list-mvp-community-content-for-2025/ba-p/4471897</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2025-12-04T20:04:15Z</dc:date>
    </item>
  </channel>
</rss>

