<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Intune Blog articles</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/microsoftintuneblog</link>
    <description>Microsoft Intune Blog articles</description>
    <pubDate>Mon, 27 Apr 2026 22:30:15 GMT</pubDate>
    <dc:creator>microsoftintuneblog</dc:creator>
    <dc:date>2026-04-27T22:30:15Z</dc:date>
    <item>
      <title>Microsoft Intune announces Android Enterprise management support for Android XR</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-intune-announces-android-enterprise-management-support/ba-p/4508499</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune now supports the Android XR platform, including management of the Samsung Galaxy XR headset, which is built on Android XR platform. This means that IT admins can begin evaluating and deploying Android XR devices using familiar Intune management capabilities, building on the Android Enterprise security foundation they already have.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With the&amp;nbsp;&lt;A href="https://www.androidenterprise.community/product-updates/android-enterprise-management-arrives-for-android-xr-2392" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;April&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Android&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;XR&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;release&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Intune&amp;nbsp;will support&amp;nbsp;core Android Enterprise management scenarios on Android XR devices. This&amp;nbsp;means&amp;nbsp;IT admins&amp;nbsp;can&amp;nbsp;start evaluating and deploying XR devices using existing enrollment, policy, and app management workflows, while&amp;nbsp;planning ahead&amp;nbsp;for more advanced scenarios as the platform matures.&amp;nbsp;This release reflects close collaboration between Microsoft, Google, and&amp;nbsp;Samsung, and&amp;nbsp;extends familiar Intune and Android Enterprise enrollment, policy, and app management capabilities to Android XR, starting with a strong foundational set of features.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Android XR devices will be managed in Intune as specialty devices, consistent with other immersive and purpose-built form factors. This is currently tied to the Intune Plan 2 SKU. Availability within&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows 365 E3 and E5 licenses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;is planned for later in 2026.&amp;nbsp;You can&amp;nbsp;check the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/fundamentals/licensing/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune licensing documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for current details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What is supported in Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With this release, IT admins can now manage their Android XR based devices in Intune with the following capabilities:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Android Enterprise enrollment and baseline management&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Devices can enroll using supported Android Enterprise flows for Fully Managed and Dedicated devices and receive policies as expected.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;App deployment with Managed Google Play&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Admins can distribute and manage approved applications through Managed Google Play.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Security and compliance policies&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Core Android Enterprise security and compliance settings will be supported, subject to Android XR platform constraints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Visibility in the Intune admin center&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Android XR devices appear in the Intune console and can be monitored and managed alongside other Android endpoints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These capabilities enable organizations to begin testing and deploying Android XR for user-assigned and managed scenarios where foundational device and app management are required.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;i&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;n&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ot&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;upported&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The following capabilities are not supported with this platform release:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Lock task (kiosk) mode&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Lock task mode—whether for 2D or 3D apps—will not be supported in Intune with the initial Android XR release. This means kiosk scenarios will not be supported at this time, even though assigning policy is not blocked.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Custom launchers and Managed Home Screen&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Custom launcher experiences, including Managed Home Screen, will not be supported.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;OEMConfig and OEM&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;specific&amp;nbsp;extensions&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Android XR devices do not&amp;nbsp;have&amp;nbsp;support&amp;nbsp;for&amp;nbsp;OEMConfig. As a result, OEM-specific management extensions (including&amp;nbsp;Knox&lt;/SPAN&gt;‑&lt;SPAN data-contrast="auto"&gt;based APIs) are unavailable.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune Remote Help&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;Intune Remote Help capabilities will not be available for Android XR with this latest release. On Samsung devices, Remote Help relies on Knox APIs, which are not present in Android XR at launch. These exclusions reflect the current state of the Android XR platform. As the platform matures and new capabilities become available, we anticipate opportunities to expand Intune's management coverage accordingly.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Next &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;teps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Android XR is a new platform with an evolving management and validation model. As Android XR matures, Microsoft Intune intends to align with new platform management capabilities as they become available. Updates will be communicated through Intune release notes, documentation, and future blog posts.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For now, you can begin&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;testing enrollment, policy application, and app deployment&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; with Intune,&amp;nbsp;while&amp;nbsp;planning for&amp;nbsp;kiosk, launcher, and remote support scenarios as future platform updates roll out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We look forward to supporting customers as Android XR evolves and becomes part of the modern endpoint landscape.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&amp;nbsp;&lt;/A&gt;or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 17:29:21 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-intune-announces-android-enterprise-management-support/ba-p/4508499</guid>
      <dc:creator>Priya_Ravichandran</dc:creator>
      <dc:date>2026-04-07T17:29:21Z</dc:date>
    </item>
    <item>
      <title>Windows 365 + Intune Advanced Endpoint Management Capabilities: Better Together</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/windows-365-intune-advanced-endpoint-management-capabilities/ba-p/4503802</link>
      <description>&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Overview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Windows 365 and Microsoft Intune form a tightly integrated solution for modern endpoint management. With Windows 365 delivering secure Cloud PCs (full Windows desktops hosted in the Microsoft cloud) and Intune’s recently extended advanced endpoint management capabilities, organizations can manage Cloud PCs and physical devices side-by-side in a single view. This “better together” approach helps IT teams enforce consistent security and compliance policies across all endpoints following&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/zero-trust-with-microsoft-intune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Trust&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; principles&amp;nbsp;while improving the user experience.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Key technical integration highlights&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Before exploring the specific advantages that Intune features bring to Windows 365 Cloud PCs, let’s first outline some of the key overall advantages of the native integration between Windows 365 and Intune.&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Unified Endpoint Management:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Windows 365 Cloud PCs are managed directly through Microsoft Intune, appearing alongside standard Windows devices in the same cloud-based admin portal. This unified approach eliminates the need for separate Virtual Desktop Infrastructure (VDI) tools or infrastructure; instead, Microsoft hosts and manages the Cloud PC platform so that IT admins can easily provision, configure, and monitor both Cloud and physical PCs in one interface by simply assigning licenses and policies. As a result, device management is streamlined and complexity is reduced.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;“Both the allocation and deletion of Windows 365 can be completed in just a few minutes using Microsoft Entra ID and Intune. It was exactly the same when we switched the environment to Windows 365 for employees participating in overseas projects. I did it while sitting in my seat at the office.” &lt;/EM&gt;&lt;STRONG&gt;Shunsuke Hanano&lt;/STRONG&gt;, Assistant Manager, IT Planning Group, Group IT Promotion Department,&amp;nbsp;&lt;A href="https://www.microsoft.com/en/customers/story/1777512359274259497-avantgroup-azure-professional-services-en-japan" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Avant Group Corporation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Identity &amp;amp; Zero Trust Security:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Cloud PCs use Microsoft Entra ID (formerly Azure&amp;nbsp;Active&amp;nbsp;Directory)&amp;nbsp;for authentication, allowing organizations to enforce Intune and Conditional Access policies,&amp;nbsp;including multi-factor authentication and device compliance checks,&amp;nbsp;before granting access to Cloud PCs. This ensures that only verified users on compliant devices can sign-in, supporting a Zero Trust security model. Integration with Microsoft Defender provides Cloud PCs with consistent security baselines, antivirus, and threat monitoring, just like physical endpoints.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Security &amp;amp; Compliance Policies:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune treats Cloud PCs as equal to physical devices, applying security baselines, compliance policies, and updates consistently. It enforces requirements like up-to-date OS and antivirus, and monitors compliance—restricting access or prompting remediation if standards are not met. Cloud PCs send threat data to Microsoft Defender, integrating with company-wide security monitoring. Device compliance policies, configuration profiles, Windows Update rings, and application deployments are all uniformly managed through Intune, ensuring Cloud PCs meet the same security and update standards as other corporate devices.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Monitoring &amp;amp; Analytics:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; Through&amp;nbsp;Endpoint Analytics&amp;nbsp;in Intune, admins get deep visibility into Cloud PC performance and reliability. Intune&amp;nbsp;reports can highlight&amp;nbsp;whether&amp;nbsp;a Cloud PC is under-resourced (e.g.,&amp;nbsp;frequent CPU or memory spikes) and recommend resizing that Cloud PC for better performance.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Now, let’s focus on each Intune advanced capability and how it can benefit Windows 365 users and admins. Intune Suite add-ons will soon be natively available within the E3/E5 Microsoft 365 offerings. Those add-ons are designed to work natively with Windows 365 too, using the same workflow as for physical devices&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Coming to e&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;nterprise mobility and security &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;E3&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;(Included in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;365 E3)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Remote Help (secure remote support&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;): &lt;/STRONG&gt;Allows IT to assist remote Cloud PC users in real time with secure, authenticated screen sharing/control. Both helper and user use corporate Entra ID accounts, preventing impersonation and non-compliant Cloud PCs trigger warnings so that issues are resolved safely. This also expedites troubleshooting and reduces downtime for distributed teams.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Advanced Endpoint Analytics:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Provides deep insight into Cloud PC performance and user experience. Advanced Analytics through Intune identifies patterns like high CPU/RAM usage or slow boot times on Cloud PCs and offers recommendations to fix issues (such as resizing a Cloud PC’s resources). Anomaly detection proactively surfaces device health issues like app crashes, hangs, and Stop Error restarts early, preventing user impact and allowing IT admins to spot and proactively resolve problems, as well as compare Cloud PC health across models or against industry benchmarks, resulting in better reliability and happier users.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;And coming into Microsoft 365 E5&lt;/SPAN&gt;&lt;/H4&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Endpoint Privilege Management (EPM):&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Enables Cloud PC users to run with standard user rights (no local admin), improving security by minimizing privileges. Through EPM, specific tasks or apps can be elevated on demand via policy when needed, helping users stay productive (e.g., installing approved software) without permanent admin rights. Admins get full control and auditing of these elevations.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;“With the introduction of Windows 365, we will eliminate administrative privileges as part of our security enhancements, and to do so, we are testing &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-endpoint-privilege-management" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Endpoint Privilege Management.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;EM&gt; It will allow us to temporarily grant administrative privileges and install only specific applications.” &lt;/EM&gt;&lt;STRONG&gt;Masahiro Kimura&lt;/STRONG&gt;, Head of the OA and Communication Infrastructure Office, Network and OA Technology Department,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en/customers/story/1779428638140338265-hino-motors-azure-professional-services-en-japan" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Hino Motors&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Cloud PKI:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Enables an&amp;nbsp;enterprise&amp;nbsp;scale PKI to be deployed fully in the cloud, allowing for secure deployment of certificates to&amp;nbsp;end&amp;nbsp;user&amp;nbsp;devices&amp;nbsp;without the need for an&amp;nbsp;on-premises&amp;nbsp;network&amp;nbsp;connection&amp;nbsp;VPN&amp;nbsp;or&amp;nbsp;a traditional PKI infrastructure. This enables a move to modern management, both for Cloud PC’s&amp;nbsp;and physical enterprise devices.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Enterprise App Management:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;Streamlines the entire application lifecycle for Windows 365 Cloud PCs. IT admins can use the Microsoft-hosted Enterprise App Catalog to easily deploy, update, and&amp;nbsp;maintain&amp;nbsp;essential Microsoft and third-party&amp;nbsp;Win32&amp;nbsp;apps—removing the need for manual packaging and updates.&amp;nbsp;This ensures Cloud PCs are provisioned with the necessary applications from the start and remain up to date without extra effort.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Conclusion and a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;dministrative benefits&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;For IT administrators, the “better together” solution of Windows 365 and Intune means simpler operations and more streamlined management. All endpoints, whether physical or Cloud PC, are handled with a common set of tools and processes, reducing the need for specialized expertise. Admins can provision or deprovision Cloud PCs quickly (no need to image devices or to maintain a complex VDI environment), and the unified policies in Intune ensure configuration drift is minimized. This integrated approach also means fewer vendors and agents to deal with: endpoint security, management, and virtualization all come from Microsoft, which improves reliability and support.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Many organizations are seeking to consolidate their security and endpoint tools to eliminate inefficiencies—and the Windows 365 + Intune combination is well-positioned to meet this need. In summary, Windows 365 and Intune provide a competitive edge: they simplify IT administration, strengthen security across all devices, and empower users—all within one holistic, cloud-first solution.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P aria-level="2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P aria-level="2"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt;or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/windows-365-intune-advanced-endpoint-management-capabilities/ba-p/4503802</guid>
      <dc:creator>tanialima</dc:creator>
      <dc:date>2026-04-02T16:00:00Z</dc:date>
    </item>
    <item>
      <title>What’s new in Microsoft Intune – March</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-march/ba-p/4493136</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In a typical week, IT admins are enrolling devices, deploying apps, enforcing policies, and making a hundred small decisions that keep their organizations running. This month’s updates focus on improving the experience around daily actions, compliance visibility, and management capabilities for Apple devices and mobile apps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;More&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;timely&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;notifications&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 3 Char"&gt;Microsoft Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune sends notifications to devices when changes occur that require devices to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;check in. When those notifications are delayed, whether from devices being offline or in a particular state (network instability, low battery, etc.), the action can be delayed, and devices can miss the check in. Now, on Windows devices, we're complementing the Windows Notification Service (WNS) with the same notification protocol that powers Microsoft Teams to support more timely notification delivery that gives admins the traceability they need for troubleshooting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We're introducing this functionality with Remote Help for Windows to help reduce the likelihood of stalled session starts when devices are online and reachable. We recommend updating firewall rules to include this new endpoint: *&lt;U&gt;.&lt;/U&gt;&lt;/SPAN&gt;&lt;U&gt;&lt;SPAN data-contrast="auto"&gt;trouter.communications.svc.cloud.microsoft&lt;/SPAN&gt;&lt;/U&gt;&lt;SPAN data-contrast="auto"&gt;. Stay informed about our progress by bookmarking the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/intune-management-extension#intune-management-extension-logs" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune Management Extension logs documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help-use?tabs=windows%2Cwindowsnative#provide-help" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Remote Help for Windows documentation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;New controls for role assignment, device setup, and update readiness&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Scope tags are used by Intune to control resources that an administrator can act on in Microsoft Intune. When an admin holds multiple role assignments with different scope tags, those tags can be combined and grant more access than intended. A new de-union setting lets admins keep these scopes discrete and within the boundaries they define. This prevents a role assignment from expanding based on how they overlap with permissions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Before enabling the capability, admins can use the new ‘Permissions assessment report’ to review how changes to roles and permission allocation will affect their IT team’s day-to-day operations, giving them the chance to plan and adjust before implementing changes. To get started configuring permissions behaviors, read our learn page on&amp;nbsp;&lt;A href="https://learn.microsoft.com/intune/intune-service/fundamentals/scope-tags" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ermission behavior across role assignments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Turning to device setup, having to manually authorize each app before it can run can slow down deployment and create gaps that are hard to track. Managed installer policy helps address this by automatically marking apps deployed through Intune as authorized, removing the need to manually whitelist each app. This month, Managed installer policy now applies during Windows Autopilot device preparation, running during out-of-box experience (OOBE) so that Win32, Microsoft Store, and Enterprise App Catalog apps are trusted and available earlier in the setup experience, before the user reaches the desktop.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Beyond a great setup experience, the next job is keeping devices current.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Autopatch update readiness&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;is now generally available to help just that. With four additional experiences that provide visibility of the status across their tenant, device-level details into the quality update process, centralized alerts with remediation guidance, and an Update Readiness Checker, admins gain tools intended to support a more proactive approach to update management. For the full story, the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-update-readiness-brings-insights-to-it/4497611" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows IT Pro Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;has the complete announcement.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;M&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;anagement&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;options&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;further&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;protect&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Apple devices&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;and apps&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune's adoption of&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-ios" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Apple's Declarative Device Management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; (DDM) protocol has moved quickly, from software update reporting and day zero configuration support to our most recent release of assignment filters. This month, DDM extends to line-of-business (LOB) apps on iOS and iPadOS devices. Until now, app install status was only reported once devices check in. With DDM-based LOB apps, devices proactively report installation status back to Intune as it changes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This change represents progress toward broader DDM support within the apps infrastructure, with additional capabilities under consideration for future releases. To dive deeper into these topics, check out the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/manage-apple-devices-at-scale-intune-security-best-practices/4490571" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Tech Takeoff session on&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;iOS management at scale&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and the &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/lob-apps-ios" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;iOS line-of-business app documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;On Mac, admins previously had no MDM-based way to set a password on the recovery OS, leaving Apple Silicon devices with a potential exposure that could be difficult to address. With macOS Recovery lock, admins can now set that password directly, helping prevent users from booting into recovery mode to bypass security controls, and support both on-demand and scheduled password rotation. The March 2026 Tech Takeoff session on &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/manage-apple-devices-at-scale-intune-security-best-practices/4490571" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Apple device security best practices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; covers this in detail. With this improvement, Recovery Lock support in Intune helps organizations progress towards compliance with security baselines such as STIG, preventing users from booting into recovery mode to bypass security controls.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When I think of a month like this, I don't think about any one of those new capabilities in isolation. I think about the IT admins who have greater visibility into whether a device action reached its destination, or the help desk professionals who don't have to wonder whether a policy applied. It's not exactly headline grabbing, but it's exactly this kind of continuous improvement that makes for a strong foundation for our customers. That same idea holds whether we're talking about improvements aimed at supporting more reliable Windows device notifications, tighter permission boundaries, or Apple devices that are protected all the way down to its recovery partition. We'd love to hear what resonated most with you this month, so please leave a comment below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2026 18:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-march/ba-p/4493136</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-03-31T18:00:00Z</dc:date>
    </item>
    <item>
      <title>Secure apps: Where people, data, and AI intersect</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/secure-apps-where-people-data-and-ai-intersect/ba-p/4493201</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At RSAC, Microsoft is highlighting a foundational truth: more and more AI interactions—whether through Copilot, an agent, or an automated workflow—ultimately run through an application on a device.&amp;nbsp;&amp;nbsp;As organizations adopt more AI-driven workflows, the application layer is becoming an increasingly important enforcement point in modern security architecture.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Security teams are working to maintain visibility and control as new categories of software are introduced into the environment. When applications are unknown, outdated, over-privileged, or allowed to run without control, organizations may face increased risk of unauthorized access to sensitive data or systems. Maintaining visibility into the application estate and helping ensure that users primarily interact with approved and trusted applications has therefore become an important part of reducing risk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/solutions/cloud-native-endpoints/cloud-native-endpoints-planning-guide" target="_blank" rel="noopener"&gt;Moving application management into cloud-native workflows&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; can&amp;nbsp;support&amp;nbsp;cross-platform&amp;nbsp;visibility&amp;nbsp;and&amp;nbsp;help organizations&amp;nbsp;streamline&amp;nbsp;how they manage&amp;nbsp;their application estate.&amp;nbsp;This&amp;nbsp;strategy&amp;nbsp;supports&amp;nbsp;organization's&amp;nbsp;ability to&amp;nbsp;respond&amp;nbsp;to vulnerabilities&amp;nbsp;more quickly&amp;nbsp;and apply security policies more consistently across their environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune’s&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; upcoming releases and recent updates strengthen how organizations secure the application layer across discovery, version control, privilege management, execution control, and data protection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Upcoming releases include&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune&amp;nbsp;enhanced app inventory&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, designed to gain visibility into your app estate across devices.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune Enterprise Application Management auto-updates&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;are designed to help reduce&amp;nbsp;the time between new releases and deployment&amp;nbsp;of&amp;nbsp;business-critical apps.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Expanded Endpoint Privilege Management capabilities&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; help to&amp;nbsp;further&amp;nbsp;support&amp;nbsp;least-privilege enforcement with improved approvals and reporting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recent releases strengthen both execution control and data protection through&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;App Control for Business with managed installer&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;expanded app-level protection&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;with Intune Application Protection Policies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and Microsoft Edge for Business work profiles&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;STRONG&gt;Managed installer support now extends to Windows Autopilot device preparation&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, helping ensure applications deployed through trusted provisioning workflows are recognized by execution policies. Additionally, application migration partner motions also help organizations modernize and standardize their app estate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Together, these capabilities help IT and security teams address application-based attack paths and support AI-driven work in a more controlled way, without disrupting productivity. Securing the application layer can benefit from a clearer risk-to-control chain that improves visibility into what’s installed and reduces the time older app versions remain in use. This approach also helps organizations limit unnecessary privileges, support trusted execution, and apply app-level data protection in scenarios when device management isn’t feasible.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The following scenarios demonstrate how Intune can help strengthen application security.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;1. Reduce blind spots across the app estate installed on devices&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A secure application strategy starts with understanding what is running across their device environment. Without reliable application intelligence, it is difficult to accurately assess exposure, prioritize remediation, or enforce policy consistently. Cloud-native endpoint management with Intune enables organizations to view their app estate across Windows, macOS, iOS, and Android devices, helping teams understand their broader application footprint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune enhanced app inventory,&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;generally available&amp;nbsp;starting in&amp;nbsp;May,&amp;nbsp;is&amp;nbsp;designed to provide&amp;nbsp;richer&amp;nbsp;and more current data for managed and user-installed Windows applications on Intune-enrolled devices. As Intune continues to expand app inventory,&amp;nbsp;additional&amp;nbsp;platforms and capabilities&amp;nbsp;are expected to&amp;nbsp;follow.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The improved app inventory experience is intended to help admins:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Help detect unexpected or risky applications more quickly through improved latency&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Target investigations and remediation using added application attributes&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Use fine-grained controls to choose which devices and app attributes are included in inventory&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Access richer and more actionable reporting directly in the device blade&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With clearer visibility into application presence and state, IT and SecOps teams can better target remediation of unauthorized, unmanaged, or unexpected applications—and in turn, scope policies more precisely, investigate incidents faster, and reduce application-based attack paths.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;1 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View from &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Intune &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;app installer &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;showing &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;a list of installed &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;applications, including&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt; version and date.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;2&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Keep applications current &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt; reduce vulnerability exposure&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Keeping applications up to date across devices is an important part of managing application risk. Manual packaging processes often lead to version drift and inconsistent application states, making it harder to remediate vulnerabilities and maintain a predictable security posture.&lt;/SPAN&gt; &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-enterprise-app-management" target="_blank" rel="noopener"&gt;Intune&amp;nbsp;Enterprise&amp;nbsp;Application Management&amp;nbsp;(EAM)&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;helps organizations move away from fragmented workflows to a more unified, cloud-native application lifecycle management approach—bringing deployments, updates, and policy enforcement together.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;EAM auto-updates,&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;generally available&amp;nbsp;starting in July,&amp;nbsp;streamline&amp;nbsp;app&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;packaging&amp;nbsp;and keep&amp;nbsp;applications up to date&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. EAM auto-updates help organizations deploy new application versions faster and shorten the time between updates and deployment. This approach can help reduce version drift and exposure to known vulnerabilities. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;2 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of the Intune admin center showing how to apply auto‑updates for application management.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;While auto-updates help shrink the vulnerability window and attack surface, vulnerability-driven remediation is still required to identify new risks.&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;The Vulnerability Remediation Agent&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;(part of Microsoft Security Copilot), &lt;SPAN data-contrast="auto"&gt;in limited public preview, helps connect vulnerability intelligence with remediation actions. When vulnerable application versions are identified through Common Vulnerabilities and Exposures (CVEs), remediation suggestions can be surfaced in Intune and used to drive targeted remediations, helping IT admins respond more quickly when new vulnerabilities are discovered.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-win32-app-management" target="_blank" rel="noopener"&gt;Script installer support for Enterprise Application Management and Win32&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; provides IT admins with greater customization and control over application installs and uninstalls, without relying solely on command-line logic or repackaging apps. By using script installer, admins can more effectively manage deployment complexities such as dependencies, configuration steps, and cleanup actions, while keeping installation logic easy to update as requirements change.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;3&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Replace standing admin rights with just-in-time elevation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Some applications and support tasks require elevated permissions to complete. When elevation is handled through broad local administrator rights, those permissions can extend beyond the intended task, creating opportunities for unwanted or untrusted processes to run with elevated privileges. These capabilities are intended to help admins manage elevation in complex environments while maintaining least-privilege access.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;By June, a set of expanded &lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-overview" target="_blank" rel="noopener"&gt;Endpoint Privilege Management&amp;nbsp;(EPM) capabilities&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;are expected to be available in Intune, helping organizations move from standing administrator rights toward just-in-time elevation with more controlled and auditable workflows.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recent EPM enhancements help improve how elevations are requested, approved, and reviewed:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Support approvals for non-primary users&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; allows&amp;nbsp;elevation requests on shared devices and helpdesk-managed scenarios without permanently expanding administrator access.&amp;nbsp;Generally&amp;nbsp;available&amp;nbsp;starting in&amp;nbsp;April.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Scope tag support for EPM reporting data&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;allows elevation activity to be segmented across teams and administrative scopes. Generally available starting in June.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;4. Enforce trusted application execution&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Trusted applications can still be weaponized. Even widely deployed software can be exploited to launch unauthorized tools or run malicious code—which is why controlling what’s allowed to run is as important as controlling what gets installed. Deployment and update controls help standardize the application estate, but execution policies determine which applications can run on managed devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;App Control for Business in Intune&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;helps enforce trusted application execution on Windows devices by specifying which applications are allowed to run&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Applications not permitted by these policies can be blocked, helping maintain a more controlled application environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Managed installer support in Intune&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;helps simplify policy management by automatically identifying trusted applications deployed through Intune. Applications installed by Intune are allowed to run without requiring individual rules, helping admins maintain execution policies as the application estate evolves.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The managed installer policy is now also applied during&amp;nbsp;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/autopilot/device-preparation/whats-new" target="_blank" rel="noopener"&gt;Windows Autopilot device preparation&lt;/A&gt;&lt;/STRONG&gt; before apps are installed, generally available starting in April. This update helps ensure that apps delivered during Autopilot device preparation are marked as trusted during provisioning. By aligning trusted deployment workflows with execution policy, organizations can support controlled application environments without introducing friction during device onboarding.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;3 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Intune's admin center via App Control for Business to begin configuring a policy from the managed installer.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security-app-control-policy" target="_blank" rel="noopener"&gt;Read more&lt;/A&gt;about App Control for Business and managed installer to help maintain a more predictable and policy-aligned application environment.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;5&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Protect corporate data &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;at the app level&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Work increasingly takes place on devices that an organization cannot enroll—agency-managed PCs, partner devices, and personal endpoints. In these scenarios, secure access to corporate resources is still required even when device-level controls cannot be applied.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/apps/app-protection-policy-settings-windows" target="_blank" rel="noopener"&gt;Intune Application Protection Policies (APP)&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;enable&amp;nbsp;organizations to protect&amp;nbsp;corporate data&amp;nbsp;at the application layer without requiring device enrollment.&amp;nbsp;APP&amp;nbsp;helps&amp;nbsp;enforce&amp;nbsp;data protection controls—such as restricting copy and paste—to&amp;nbsp;help&amp;nbsp;maintain&amp;nbsp;data boundaries between corporate and personal work.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;New support for&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Edge for Business work profiles on Windows PCs managed by another organization extends APP protection to browser-based work without creating tenant management conflicts. Recent Microsoft Entra sign-in improvements further help guide users into the intended app-protection experience and help prevent unintended device enrollment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/IntuneAPPWindowsPCs" target="_blank" rel="noopener"&gt;Read more&lt;/A&gt;about these&amp;nbsp;enhancements&amp;nbsp;and&amp;nbsp;how&amp;nbsp;Intune applies&amp;nbsp;Zero Trust-aligned&amp;nbsp;principles&amp;nbsp;to&amp;nbsp;the&amp;nbsp;browser&amp;nbsp;on externally managed Windows PCs.&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Securing the application layer across the full lifecycle&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The application layer has long been the center of work, and with the rise of AI, it’s rapidly becoming the center of decision-making as well. As organizations adopt Copilot and agents, it becomes an increasingly important enforcement point—and the place where the next wave of security investments need to land. Securing this layer requires applying consistent controls across visibility, updates, controlled privilege, trusted execution, and app-level data protection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune is designed to help organizations secure the application layer end-to-end, across discovery, deployment, updates, privilege, execution, and data protection. As organizations modernize their app estates, moving them into cloud-native management can provide a foundation for more consistent visibility, streamlined remediation, and stronger security controls across the environment. By applying Zero Trust-aligned principles consistently throughout the application lifecycle, organizations can work to minimize application-related risks while enabling safer and more flexible ways of working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To support these modernization efforts, application migration partners can work to transition existing applications into cloud-native Intune management by automating assessment, packaging conversion, and remediation. Bringing applications into Intune-managed workflows helps organizations identify potential Shadow IT, help strengthen their security posture, manage updates, apply privilege controls and enforce policies more consistently across the environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Here are the next steps to take toward securing the application layer:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Connect with Intune experts at the Microsoft Booth #5744 at RSA Conference, Moscone Center, March 23–26.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=EKRwGZAZDfY" target="_blank" rel="noopener"&gt;Move Windows app packaging and updates into cloud-native management&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://microsoft.github.io/zerotrustassessment/docs/workshop-guidance/devices/RMD_019" target="_blank" rel="noopener"&gt;Learn how to apply Zero Trust principles&amp;nbsp;to data within the applications&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/face-the-future-today-by-moving-your-application-to-cloud-native/4453681" target="_blank" rel="noopener" data-lia-auto-title="Migrate app management to Intune with partner assistance" data-lia-auto-title-active="0"&gt;Migrate app management to Intune with partner assistance&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener" data-lia-auto-title="Learn&amp;nbsp;which&amp;nbsp;Intune&amp;nbsp;advanced&amp;nbsp;solutions&amp;nbsp;will&amp;nbsp;be coming to the M365 E3 and E5 suites" data-lia-auto-title-active="0"&gt;Learn&amp;nbsp;which&amp;nbsp;Intune&amp;nbsp;advanced&amp;nbsp;solutions&amp;nbsp;will&amp;nbsp;be coming to the M365 E3 and E5 suites&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;&amp;nbsp;on X to continue the conversation.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/secure-apps-where-people-data-and-ai-intersect/ba-p/4493201</guid>
      <dc:creator>Talal_Alqinawi</dc:creator>
      <dc:date>2026-03-20T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Announcing three new partners for multi-tenant management with Microsoft Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/announcing-three-new-partners-for-multi-tenant-management-with/ba-p/4501339</link>
      <description>&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;The challenge:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;S&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;caling&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Intune across customer environments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="auto"&gt;Managed service providers (MSPs) of all sizes are under pressure to manage an expanding portfolio of customer environments efficiently, securely, and profitably. Historically, MSPs have had to choose between building custom multi-tenant tooling or relying on third-party platforms that lack deep Microsoft integration. As client expectations rise and competitive pricing pressures intensify, MSPs need solutions that help them deliver more value from the Microsoft 365 investments their customers already have—investments that already include Microsoft Intune—without fragmenting data or security outside Microsoft's ecosystem.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P aria-level="3"&gt;&lt;SPAN data-contrast="auto"&gt;Managing multiple tenants often means duplicating routine processes, reconciling policy inconsistencies, and navigating separate management portals. MSPs need centralized oversight across all tenants without sacrificing security, compliance, or operational efficiency. Microsoft Intune is the answer—and the right partner solutions make it scale.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;The solution: Microsoft Intune, extended by validated partners&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;In &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/addressing-multi-tenant-management-challenges-for-msps-with-microsoft-intune-and/4453682" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;September&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, we announced our collaboration with two leading multi-tenant management providers—inforcer&amp;nbsp;and&amp;nbsp;Nerdio—and the response was remarkable. The program, which we call&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Strong"&gt;#IntuneForMSPs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;, has exceeded our expectations. We heard strong positive feedback from MSPs and enterprises at events around the world and across social media, from organizations that have long needed a better way to manage multiple tenants at scale.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;Today, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;we're&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;excited to announce three&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;additional&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;validated partners joining the&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-charstyle="Strong"&gt;#IntuneForMSPs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;ecosystem. Each has&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;been&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;validated&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt;&amp;nbsp;against&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="Normal (Web)"&gt; Microsoft's product and business requirements, enabling MSPs to scale efficiently, standardize operations, and deliver more secure, Intune-aligned experiences to their customers.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;Momentum in the MSP market&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Over the past year, we've seen strong momentum across the MSP market—through global events, partner sessions, and #IntuneForMSPs meetups. One message has been consistent across all of these conversations:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;MSPs want Intune-aligned solutions that respect Microsoft's security model, tenant boundaries, and licensing investments.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At recent in-person and virtual events, the energy around this shift has been clear. MSPs are actively moving away from traditional RMM-centric approaches toward models where Microsoft Intune serves as the control plane for device management, security, and compliance. That shift is what makes today's announcement particularly meaningful.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Welcoming &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;three&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;new&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;#IntuneForMSPs&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;p&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;artners&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We're pleased to welcome three new validated partners to the #IntuneForMSPs ecosystem. Each offers independent, complementary capabilities built on top of and alongside the Microsoft Intune platform—preserving their unique workflows and features while extending what Intune can do for MSPs at scale. Partners are presented in alphabetical order; the descriptions below were provided by each partner.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We encourage you to learn more about all validated partners at &lt;A class="lia-external-url" href="https://aka.ms/IntuneForMSPs" target="_blank" rel="noopener"&gt;https://aka.ms/IntuneForMSPs&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;AvePoint Confidence Platform: Elements Edition&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;AvePoint is&amp;nbsp;the&amp;nbsp;global leader&amp;nbsp;in data protection, unifying data security, governance, and resilience to provide a trusted foundation for AI. More than 28,000 customers rely on the AvePoint Confidence Platform to secure, govern, and rapidly recover data across multi&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;‑&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;cloud environments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Through AvePoint Confidence Platform: Elements Edition, AvePoint extends Microsoft Intune with secured multi&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;‑&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;tenant automation, lifecycle management, and centralized visibility—enabling partners to scale Intune delivery profitably and consistently across customers. With a single platform for governance, lifecycle control, and recovery, partners reduce operational overhead, prevent sprawl, and accelerate Copilot readiness.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;AvePoint supports a global partner ecosystem of 6,000 MSPs, VARs, and SIs, with solutions available in over 100 cloud marketplaces.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learn more at: &lt;A class="lia-external-url" href="https://www.avepoint.com/lp/microsoft-intune-for-msps" target="_blank" rel="noopener"&gt;avpt.is/intune&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;CyberDrain CIPP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;CyberDrain CIPP provides MSPs with a centralized, multi-tenant management platform for Microsoft 365. It enables partners to securely manage tenants at scale, automate common administrative tasks, enforce standards across environments, and gain deep visibility into tenant security and configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With built-in automation, governance controls, and extensibility, CIPP reduces reliance on custom scripts and manual processes. MSPs can standardize operations, streamline user and tenant management, monitor security posture, and respond quickly to issues across all customers from a single interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;CIPP is supported by one of the largest and most active MSP communities in the Microsoft ecosystem, with thousands of partners contributing feedback, automation ideas, and best practices. As one of the most widely adopted platforms for Microsoft 365 multi-tenant management, CyberDrain CIPP continues to evolve rapidly to meet the needs of modern MSPs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learn more at: &lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://cyberdrain.com/intuneformsps" target="_blank" rel="noopener"&gt;cyberdrain.com/intuneformsps&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&lt;SPAN data-contrast="auto"&gt;SoftwareCentral Tenant Manager&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;SoftwareCentral Tenant Manager helps MSPs run Microsoft Intune across multiple customer tenants with consistency and control. MSP teams can standardize policies, manage applications and devices across environments, monitor configuration drift, and maintain visibility into changes across tenants from a single platform. The platform runs entirely on Microsoft Azure with region-selectable deployment for your data protection requirements.&amp;nbsp;It includes CIS&amp;nbsp;certified&amp;nbsp;security baselines, helping MSPs deliver secure, repeatable Intune services as their customer portfolios grow, even without in-depth Intune knowledge.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Learn more at: &lt;A class="lia-external-url" href="https://tenantmanager.com/intuneformsps/" target="_blank" rel="noopener"&gt;tenantmanager.com/intuneformsps/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;What’s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;n&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ext&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;for #IntuneForMSPs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today's announcement reflects our continued and reinvigorated commitment to the MSP market. Going forward, you can expect:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;More news&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;about the&amp;nbsp;#IntuneForMSPs ecosystem&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Continued monthly meetups&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; and technical sessions for MSPs—open to any MSP interested in learning how Intune can help scale their business&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;MSP-specific guidance and resources&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;to help MSPs grow with Microsoft&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune MVP Jonathan Edwards (also known as the Bearded365Guy) created a video&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-fontsize="11"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;reviewing three of our partner solutions.&amp;nbsp;Watch the video&amp;nbsp;and explore all&amp;nbsp;our&amp;nbsp;validated partners at &lt;A class="lia-external-url" href="https://aka.ms/IntuneForMSPs" target="_blank" rel="noopener"&gt;https://aka.ms/IntuneForMSPs&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;Jonathan Edwards reviews Nerdio, inforcer, and CIPP in one video.&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If&amp;nbsp;you're&amp;nbsp;an MSP modernizing your management approach—or a partner building on Intune—we invite you to explore these&amp;nbsp;new solutions&amp;nbsp;and stay engaged with the #IntuneForMSPs partner program at our resource page&amp;nbsp;aka.ms/IntuneForMSPs&amp;nbsp;and monthly meetups.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI aria-setsize="-1" data-leveltext="%1." data-font="" data-listid="29" data-list-defn-props="{&amp;quot;335552541&amp;quot;:0,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769242&amp;quot;:[65533,0],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;%1.&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;"Jonathan Edwards is a Microsoft Intune MVP. Microsoft's MVP program is an independent recognition program; Jonathan was not compensated by Microsoft for this video."&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; on X to continue the conversation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2026 16:18:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/announcing-three-new-partners-for-multi-tenant-management-with/ba-p/4501339</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2026-03-17T16:18:31Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Intune – February</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-february/ba-p/4488307</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every IT environment has workarounds. Policies are duplicated instead of edited because&amp;nbsp;there's&amp;nbsp;no approval process. Apple software updates are pushed to every device because Declarative Device Management (DDM) policies&amp;nbsp;couldn't&amp;nbsp;filter by ownership type.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Workarounds aren't just inconvenient. They can increase risk. Duplicate policies, broad software updates, and unchecked changes expand the attack surface and undermine Zero Trust principles. This month’s Microsoft Intune updates focus on eliminating those workarounds by giving admins &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;greater control, clearer accountability, and more precise targeting.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Helping to ensure security policies are enforced the way they were intended, without slowing IT teams down.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;Reduce policy risk with greater oversight over compliance and configuration changes&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To provide an extra security measure against any unauthorized or accidental changes, additional &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval" target="_blank" rel="noopener"&gt;multi-administrator approval&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;options are now available&amp;nbsp;for device&amp;nbsp;configuration&amp;nbsp;policies created through the settings catalog and device&amp;nbsp;compliance&amp;nbsp;policies&amp;nbsp;(for more information see&amp;nbsp;&lt;/SPAN&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/device-cleanup-rules" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Compliance settings, and Device cleanup rules&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;). With this control enabled, critical policy changes (creation, alteration, or deletion) will need approval from a second administrator before they can be implemented.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This latest update expands the multi-admin approval capabilities introduced over the past year, which include apps, scripts, device actions like wipe, retire, and delete, RBAC roles, and device categories. The addition of compliance and configuration policies approvals help enable organizations to offer a more comprehensive safety net for their most critical policies. In environments where configuration drift can lead to non-compliance and security risks, this level of oversight is not simply a good practice, but rather a preventive control and governance option integrated into the IT workflow.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Furthermore, since every request, approval, and business justification is documented in the Intune audit logs, this control not only helps prevent potential problems but also documents them. &lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;Find and fix issues faster with updates for multiple device queries&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Zero Trust decisions depend on accurate, actionable data, and IT admins need precise queries to identify compliance gaps or missing configurations across their fleet.&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-advanced-analytics" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Advanced Analytics&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; now includes the operator details in multiple device query (MDQ) results, (including join types such as new leftanti and rightsemi operators). This assists in finding the specific settings of missing devices and helps you run fleet-wide queries more accurately, especially if you are managing thousands of devices of all OS types.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Additionally, Advanced Analytics device join syntax in MDQ results are now clickable for faster navigation to device details and improved error messaging. A good example to illustrate this improvement is a query to retrieve all devices with ARM processors, ordered alphabetically. The column for the Device field in the results is now clickable when the Device entity is joined. In addition, admins can now join the results on the Device field without using custom Device syntax.&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Device query results showing x64 CPU data joined on Device. &lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more detail, please refer to the Microsoft Learn page on&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/advanced-analytics/device-query-multiple-devices" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;device query for multiple devices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;.&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="none"&gt;Target Apple updates precisely—without overreaching&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When managing Apple devices, targeting matters; not every policy needs to reach every device. But until now, Declarative Device Management (DDM) policies did not account for assignment filters. Admins couldn't target devices by OS version or differentiate between company-owned and personally owned devices.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;A common challenge for admins is enforcing software updates on company-owned devices while avoiding personal devices. The enhancements included in this month’s Intune release help resolve this challenge. Now admins can use DDM-based policies with &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/filters" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;assignment filters&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; in the same way they do for MDM-based policies. For instance, if an organization wants to target devices running iOS 17 or later with software updates, they can use an operating system version filter. To target Automated Device Enrollment (ADE) supervised devices while ignoring personal devices, they can use an enrollment profile name filter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;This capability is becoming more important as Apple has expanded Declarative Device Management across iOS, iPadOS, macOS, Vision OS, and Apple TV. Intune keeps pace with that shift by doing what it has always done: giving admins a consistent way to apply policies across every platform they manage.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-contrast="none"&gt;Fewer workarounds, stronger Zero Trust across every platform&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The capabilities rolling out in our February release all have something in common: multi-admin approval, multi-device queries, and assignment filters for Declarative Device Management collectively eliminate the need for workarounds.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;I know that workarounds are part of every IT environment. However, with each workaround there may be concessions: more access, more policies created without proper scrutiny, or updates not intended for particular devices. While this month’s new capabilities will not eliminate all workarounds, they are a step toward managing devices the way Zero Trust requires: precisely, reliably, and with built-in least privilege. &lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 19:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-february/ba-p/4488307</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-02-26T19:00:00Z</dc:date>
    </item>
    <item>
      <title>Protect browser-based work on agency-managed Windows PCs</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/protect-browser-based-work-on-agency-managed-windows-pcs/ba-p/4496538</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;From SaaS apps and internal web portals to AI-powered tools, the browser is now a major workspace for many employees and contractors alike. This shift has introduced new opportunities for organizations to enable an extended workforce. At the same time, it creates new data protection complexities for IT administrators.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Securing corporate data has traditionally relied on full device management. However, when work occurs on a Windows PC that your organization doesn't own—such as a device already enrolled and managed by a contractor’s home agency—full device enrollment isn't a viable option. Organizations need a flexible way to reduce these data blind spots without taking over the device itself.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To address this, Microsoft continues to expand data protection capabilities across Microsoft Edge for Business, Microsoft Entra, Microsoft Intune, and Microsoft Purview. Recent profile and sign-in updates with Edge for Business and Entra now help organizations to secure browser-based work on Windows PCs managed by another organization. And these updates work alongside inline data loss prevention with Purview and prescriptive deployment guidance from Intune to help administrators apply protections consistently rather than configuring policies in isolation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Support&amp;nbsp;and protection&amp;nbsp;for&amp;nbsp;agency-managed Windows&amp;nbsp;PCs&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Edge for Business now extends Intune app protection policies (APP) to the Edge for Business work profile on Windows PCs managed by another organization. This new capability,&amp;nbsp;currently in&amp;nbsp;public&amp;nbsp;preview,&amp;nbsp;helps&amp;nbsp;organizations to&amp;nbsp;protect&amp;nbsp;work&amp;nbsp;contractors&amp;nbsp;do&amp;nbsp;in the&amp;nbsp;browser,&amp;nbsp;while respecting existing device ownership and management boundaries.&amp;nbsp;This protects corporate data&amp;nbsp;without&amp;nbsp;requiring full device enrollment or creating conflicts with another tenant’s management.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;div data-video-id="https://youtu.be/Ng2w_aBGgUw/1771962075551" data-video-remote-vid="https://youtu.be/Ng2w_aBGgUw/1771962075551" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FNg2w_aBGgUw%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DNg2w_aBGgUw&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FNg2w_aBGgUw%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1 &lt;SPAN data-teams="true"&gt;Demo showing Intune app protection policies in action within an Edge for Business work profile on a Windows PC managed by another organization.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Key capabilities include:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Browser-level protection&amp;nbsp;through the Edge work profile:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Intune APP policies can be applied directly to Edge for Business user profiles, helping to create a protected boundary for work data. Contractors can securely access corporate resources in an Edge for Business profile without enrolling the device or altering existing management.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:1080,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Tenant-scoped controls within Edge for Business&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Organizations can&amp;nbsp;help&amp;nbsp;protect corporate data within the browser by redirecting downloads to OneDrive for Business, restricting copy and paste, and enforcing data boundaries inside the managed Edge for Business profile.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559685&amp;quot;:360,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/DeployEdge/microsoft-edge-cross-tenant-support-using-intune-mam?branch=pr-en-us-6771" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;How to get started with&amp;nbsp;agency-managed device&amp;nbsp;support&amp;nbsp;in&amp;nbsp;Edge&amp;nbsp;for Business&amp;nbsp;and apply&amp;nbsp;APP.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Simplified&amp;nbsp;onboarding&amp;nbsp;for&amp;nbsp;APP&amp;nbsp;policies&amp;nbsp;on&amp;nbsp;Windows&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recent Entra improvements to the Edge on Windows sign-in flow enable admins to configure the enrollment screen to create a more predictable setup and enrollment experience. These new sign-in updates help route users into Intune application protection polices, while reducing accidental full device enrollment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure 2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;Microsoft Entra updated sign-in experience pop-up window.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These Entra updates include: &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Modernized&amp;nbsp;Entra registration&amp;nbsp;page&amp;nbsp;for the&amp;nbsp;user:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;An updated&amp;nbsp;account registration&amp;nbsp;flow&amp;nbsp;provides&amp;nbsp;clearer guidance during sign-in, helping users understand when they are registering an account versus&amp;nbsp;enrolling&amp;nbsp;a device.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Prevention of unintended device enrollment:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Administrators can enable the “Disable MDM enrollment when adding work or school account” setting to block the prompt for devince enrollment during the account registration flow. Users are directed into the intended app-protection experience without unnecessary prompts or management conflicts.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/windows-enroll" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Read more about&amp;nbsp;how to apply&amp;nbsp;the&amp;nbsp;updated&amp;nbsp;Entra&amp;nbsp;sign-in flow.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Apply&amp;nbsp;data&amp;nbsp;security&amp;nbsp;across&amp;nbsp;browser-based work&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Purview Data Loss Prevention (DLP) helps protect sensitive corporate data during browser-based work&amp;nbsp;on Windows PCs&amp;nbsp;that are managed by another organization or not enrolled at all. Purview DLP is built directly into Edge for Business and applies to the user’s work profile,&amp;nbsp;so&amp;nbsp;organizations&amp;nbsp;can&amp;nbsp;detect and control sensitive actions without requiring device onboarding into Purview or taking ownership of the device.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure 3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;Purview DLP: Displays&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;pop-up message to indicate&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;organizationa&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;l protection for a file download.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With Purview DLP in Edge for Business, organizations can:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Apply inline DLP protection in the browser:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Support detection&amp;nbsp;and control&amp;nbsp;for&amp;nbsp;sensitive actions, such as uploads, downloads, copy/paste, printing,&amp;nbsp;and&amp;nbsp;across cloud apps&amp;nbsp;accessed in the browser.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Extend coverage to unmanaged cloud apps:&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Apply DLP policies&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="none"&gt;to enrolled apps and extend protection to unenrolled&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;cloud apps, helping prevent oversharing or unintended data movement during browser activity.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG style="color: rgb(30, 30, 30);"&gt;&lt;SPAN data-contrast="auto"&gt;Reduce data leakage without limiting productivity: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;Detect and prevent risky actions involving sensitive data without blocking site access or disrupting normal workflows.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/purview/dlp-browser-dlp-learn" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn more:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Apply&amp;nbsp;Purview&amp;nbsp;Data Loss Prevention in Edge for Business&amp;nbsp;to protect sensitive data during browser-based work.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5&gt;&lt;SPAN data-contrast="none"&gt;Guidance&amp;nbsp;to help&amp;nbsp;secure&amp;nbsp;corporate data&amp;nbsp;in the browser&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft&amp;nbsp;published&amp;nbsp;“&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/mamedge-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Secure&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Your Corporate Data in Intune with Microsoft Edge for Business&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;”&amp;nbsp;to provide&amp;nbsp;guidance&amp;nbsp;on&amp;nbsp;how administrators can&amp;nbsp;operationalize browser-based protections across platforms.&amp;nbsp;This&amp;nbsp;guidance&amp;nbsp;provides step-by-step configuration paths that align identity, app protection, browser configuration, and device controls into a single, structured deployment model rather than isolated policy setup.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The guide covers:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Three-level security framework&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Basic, Enhanced, and High protection tiers mapped to common industry standards such as NIST and DISA STIG,&amp;nbsp;enabling&amp;nbsp;organizations to align browser security posture with risk tolerance and user roles.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cross-platform policy mapping&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Clear guidance on when to use app protection policies, app configuration policies, settings catalog controls, and conditional access across Windows, macOS, iOS, and Android without creating policy conflicts&amp;nbsp;or double-applying browser policies.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt; &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Sequenced configuration paths&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Ordered implementation steps that show how identity enforcement, app protection, browser configuration, and device-level controls work together to form a cohesive&amp;nbsp;secure&amp;nbsp;enterprise&amp;nbsp;browser&amp;nbsp;strategy.&lt;/SPAN&gt;&lt;SPAN style="color: rgb(30, 30, 30);" data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/mamedge-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Learn&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ore:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Read more on how&amp;nbsp;to get&amp;nbsp;started with&amp;nbsp;Intune’s&amp;nbsp;configuration guidance&amp;nbsp;to&amp;nbsp;protect browser-based&amp;nbsp;work and align identity, app protection, and browser controls.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H5 aria-level="3"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;Apply&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;additional&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;protections for a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;more&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;consistent sign-in flow&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;today&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Organizations do not need to treat browser-based work as an exception to endpoint protection. By combining identity routing in Entra, app-level boundaries through Intune, workspace separation in Edge for Business, and inline data governance with Purview, organizations can apply consistent controls even on Windows PCs they don’t own or manage. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;With this approach, protection&amp;nbsp;moves from the device to the work context itself.&amp;nbsp;Administrators&amp;nbsp;can&amp;nbsp;secure corporate data where work happens,&amp;nbsp;while preserving productivity and respecting existing device ownership and management boundaries.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 19:41:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/protect-browser-based-work-on-agency-managed-windows-pcs/ba-p/4496538</guid>
      <dc:creator>LiMiller</dc:creator>
      <dc:date>2026-02-24T19:41:58Z</dc:date>
    </item>
    <item>
      <title>What's New in Microsoft Intune – January 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-january-2026/ba-p/4476487</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;When trees lose their leaves, you see the structure beneath. The branches you couldn’t see. The shape that was always there.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;January is like that for IT admins. You get a fresh view of your endpoint management landscape, such as where elevation can get sharper, where application deployment process can be improved, and where admin tasks could be made more efficient.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The same is true for Intune. January isn’t just about celebrating what we’ve accomplished in the past year, but it’s also about looking forward to what new challenges we will face and new ways we can help IT admins be more productive. In this blog post, I’ll highlight the recent capabilities that I’m personally excited about.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Accelerate deployment with Power&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;S&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;hell&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;script&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;installers for Win&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;32 apps&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;Today, many organizations customize app deployments outside Intune using PowerShell scripts to handle prerequisite checks, post-install steps, dependencies, and registry updates. Previously, each time the script changed, the entire app binary needed to be repackaged and re-uploaded.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;That friction&amp;nbsp;often&amp;nbsp;can&amp;nbsp;add hours to deployment cycles and&amp;nbsp;kept&amp;nbsp;critical work outside the admin center.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;This month, that changes that. When creating a Win32 app in Intune, admins can now upload a PowerShell script that acts as the app installer, rather than specifying a command line. The script runs natively. Intune packages it with app content and runs it in the same context as the installer. Installation results show in the admin center as 'success' or 'failure' based on return codes, providing visibility into what happened.&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;So, what does this mean? It means app deployment gets faster, customization gets easier, and teams in highly regulated industries like finance and healthcare can use the script to enforce compliance steps as part of the app installation process. It means system requirements can be checked before anything else runs, and app-specific settings can be configured after the app is installed. It means admins gain even more control.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;Endpoint Privilege Management gets sharper&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;When users need elevated privilege, we are introducing a new Endpoint Privilege Management (EPM) capability to elevate users in a way that preserves their current profile. For example, profile paths, environment variables, and personalized settings.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;This matters for installers and tools that depend on the active user’s profile. Before,&amp;nbsp;&amp;nbsp;&lt;BR /&gt;EPM isolated virtual accounts. Now, the user’s identity is maintained throughout elevation, meaning your audit trails stay cleaner and compliance records are more accurate.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;In addition, the ability to enforce scope tags for elevation scenarios safeguards admins can only view elevation requests for which they have permission. This is critical for compartmentalizing data in regulated environments. Together with 'Elevate as current user,' this enables organizations to easily oversee who is allowed to perform elevated actions, while avoiding the disclosure of excessive context. These two capabilities integrate seamlessly out of the box, with no configuration required.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;Admin tasks&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;capability&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;bring&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;&amp;nbsp;your work togethe&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Heading 2 Char"&gt;r&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The new year brings clarity. Admins manage privilege elevation, device offboarding, security alerts, and policy approvals. Admin tasks, now generally available (GA) in Microsoft Intune, brings that work into a single, prioritized queue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin tasks centralizes these workflows to help admins focus on high-impact actions that need their attention now. It is under Tenant Administration, where admins can search, filter, and sort across requests, tasks, and approvals. Currently, admin tasks includes Endpoint Privilege Management (EPM) requests, Multi Admin Approval (MAA) tasks, Microsoft Defender for Endpoint (MDE) security tasks, and the Device Offboarding Agent (part of Microsoft Security Copilot) for tasks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;EPM elevation requests help admins quickly approve or deny elevation needs and create reusable rules. Microsoft Defender for Endpoint security tasks enables admins to review recommended remediation actions, take corrective action on security issues, and monitor task status through a consistent Intune workflow. The Device Offboarding Agent helps detect unused or outdated devices that may no longer be needed or may pose a security risk, surfacing these findings as actionable tasks within admin tasks. Multi Admin Approval requests, such as scripts, device wipes, and role changes, are reviewed and approved with this same view. Each approval or rejection is recorded to support audit and compliance requirements. Learn more by taking a deeper dive in this blog on&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/IntuneAdminTasksBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;admin tasks in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Apple enrollment keeps evolving with new &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;certificate support&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The technical foundation for enrollment of Apple devices just got stronger. We're rolling out support for the Automated Certificate Management Environment (ACME) protocol for new iOS, iPadOS, and macOS enrollments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;So, what’s the difference? ACME provides better protection than the previous SCEP approach against unauthorized certificate issuance. It includes improved validation mechanisms and automated processes that reduce errors in certificate management. Now, when new Apple devices enroll, they receive an ACME certificate instead of a SCEP certificate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;There's no change to your enrollment experience or Intune admin center doesn’t change. Its infrastructure works better in the background. This applies to Apple Device Enrollment, Apple Configurator enrollment, and automated device enrollment (ADE) methods. We also added 12 new Setup Assistant screens you can control during ADE. Want to skip the App Store screen? Hide camera settings? Now you can. This gives you more flexibility in how your end-users experience onboarding.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;What's&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; ahead&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;January always feels like a restart. New year, fresh roadmap, the engineering teams recharged and looking at what's next. When I talk with the team building these capabilities, the energy is real. They're already thinking about solving more challenges&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;IT admins face. The momentum is here with the team at Microsoft Intune.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Stay up to date with Intune, please bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/MicrosoftIntuneBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/showcase/microsoft-intune/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; on X.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 17:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-january-2026/ba-p/4476487</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-02-05T17:00:00Z</dc:date>
    </item>
    <item>
      <title>Admin tasks in Microsoft Intune: Centralized control today, AI-ready for tomorrow</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/admin-tasks-in-microsoft-intune-centralized-control-today-ai/ba-p/4489448</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IT admins make daily, quiet decisions that determine whether an organization stays secure, compliant, and productive. They review privilege requests, security remediation actions, and high-impact configuration changes across multiple consoles. Given the growing breadth of their daily responsibilities, scattered decision points could lead to slower response times, increased risks, and make audit readiness harder to maintain.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Intune already consolidates endpoint management into one place. And now with the general availability (GA) of admin tasks it aggregates high-impact approvals and remediation workflows, into a single, prioritized queue, giving admins a unified view of what needs action right now.&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Introduced at Microsoft &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-at-ignite/4471043" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Ign&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;i&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;te&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, admin tasks&amp;nbsp;brings&amp;nbsp;together three essential decision points:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-support-approved#manage-pending-elevation-requests" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Endpoint Privilege Managemen&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;t&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(EPM)&amp;nbsp;elevation requests,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/atp-manage-vulnerabilities" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Defe&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;n&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;der&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;for Endpoint&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(MDE)&amp;nbsp;security tasks, and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval#approve-requests" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Multi&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Approval&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(MAA)&amp;nbsp;requests.&amp;nbsp;And now,&amp;nbsp;admin tasks&amp;nbsp;also&amp;nbsp;incorporates&amp;nbsp;actions from&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/agents/device-offboarding-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device O&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ff&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;boarding Agent&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;(part of&amp;nbsp;Microsoft&amp;nbsp;Security Copilot),&amp;nbsp;currently in&amp;nbsp;public preview, extending centralized decision-making to device lifecycle cleanup.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-contrast="auto"&gt;As organizations adopt&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust principles&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;and&amp;nbsp;prepare for&amp;nbsp;AI-assisted operations, IT teams need more automation without sacrificing oversight. As Intune expands automated and AI-assisted capabilities, admin tasks&amp;nbsp;adds&amp;nbsp;an&amp;nbsp;oversight layer that&amp;nbsp;helps&amp;nbsp;ensure AI-driven recommendations&amp;nbsp;remain&amp;nbsp;under administrator control.&amp;nbsp;Over time,&amp;nbsp;additional&amp;nbsp;task types will&amp;nbsp;continually&amp;nbsp;be integrated,&amp;nbsp;consolidating&amp;nbsp;even more&amp;nbsp;high-impact&amp;nbsp;operational decision points into a single experience.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-contrast="auto"&gt;“Admin tasks in Intune is a centralized, prioritized task view that cuts through the noise. The simplified processes boost our team’s ability to respond quickly and confidently to critical requests.” –Michael Meier, IT Workplace Design, Krones AG&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-contrast="auto"&gt;Admin tasks&amp;nbsp;is&amp;nbsp;available in the Intune admin center under Tenant administration. The following sections outline what admins can access today.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;H4 data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Four ways to streamline IT operations&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;dmin&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;asks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;OL style="padding-left: 0; margin-left: 0;"&gt;
&lt;LI style="font-weight: bold;" data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-endpoint-privilege-management" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Endpoint Privilege Managem&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;nt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;elevation&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;requests&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;SPAN data-contrast="auto"&gt;EPM&amp;nbsp;enables&amp;nbsp;standard users to run approved applications with elevated privileges without&amp;nbsp;granting&amp;nbsp;permanent local admin rights.&amp;nbsp;In admin tasks, elevation requests appear in the same prioritized queue as other high-impact actions, so&amp;nbsp;admins can review and approve&amp;nbsp;requests&amp;nbsp;from a single view.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Approve or deny elevation requests, create reusable rules based on file details, or add files to reusable settings.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-ccp-border-top="0px none " data-ccp-padding-top="0px" data-ccp-border-bottom="2px solid #000000" data-ccp-padding-bottom="1.3333333333333333px"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335572079&amp;quot;:12,&amp;quot;335572080&amp;quot;:1,&amp;quot;335572081&amp;quot;:4278190080,&amp;quot;469789806&amp;quot;:&amp;quot;single&amp;quot;}"&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&lt;SPAN data-contrast="auto"&gt;What&amp;nbsp;EPM&amp;nbsp;enables:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Flexible&amp;nbsp;elevation&amp;nbsp;models:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Supports automatic, user-confirmed, and support-approved&amp;nbsp;workflows.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Granular controls:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Defines&amp;nbsp;elevation rules&amp;nbsp;based on publisher, file hash, or&amp;nbsp;command-line&amp;nbsp;arguments.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Audit and compliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Logs&amp;nbsp;elevation&amp;nbsp;activity&amp;nbsp;for visibility,&amp;nbsp;reporting, and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Improved user experience:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Helps standard&amp;nbsp;users stay productive,&amp;nbsp;while reducing help desk tickets and security&amp;nbsp;exposure.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Contextual risk analysis*&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;With&amp;nbsp;EPM&amp;nbsp;and Security Copilot,&amp;nbsp;it&amp;nbsp;enables&amp;nbsp;admin tasks&amp;nbsp;to&amp;nbsp;surface contextual risk&amp;nbsp;signals&amp;nbsp;to help inform elevation approval decisions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="auto"&gt;*&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Note&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&amp;nbsp;This capability requires Microsoft Security Copilot,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/copilot/security/get-started-security-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;get started here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;Security&amp;nbsp;Copilot will be included for&amp;nbsp;Microsoft 365 E5 customers,&amp;nbsp;roll&amp;nbsp;out&amp;nbsp;began&amp;nbsp;for&amp;nbsp;existing Security Copilot&amp;nbsp;users&amp;nbsp;and&amp;nbsp;is&amp;nbsp;continuing&amp;nbsp;in the upcoming months,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;l&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;earn more here.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;EPM is&amp;nbsp;also&amp;nbsp;coming to&amp;nbsp;M365 E5;&amp;nbsp;learn&amp;nbsp;more about the Intune capabilities coming to both the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;E3 and E5 bundle here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;g&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;ranular controls for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;levation requests in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Intune&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Endpoint Privilege Management&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;within admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;OL style="padding-left: 0; margin-left: 0;" start="2"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/atp-manage-vulnerabilities" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;D&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;efender for Endpoint&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ecurity tasks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;MDE requests for remediation generate security tasks that surface in the Intune admin center, when threats or configuration issues are detected on devices. Admins can track and complete security remediation work from the same queue used for other critical IT decisions.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Mark tasks as complete or reject them, and review&amp;nbsp;impacted&amp;nbsp;device lists.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;What&amp;nbsp;MDE security&amp;nbsp;task in Intune&amp;nbsp;enables:&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Unified&amp;nbsp;task management:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;View&amp;nbsp;and&amp;nbsp;act on&amp;nbsp;security&amp;nbsp;tasks&amp;nbsp;from Defender in&amp;nbsp;a single&amp;nbsp;queue.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Recommended&amp;nbsp;endpoint security profiles:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Supports&amp;nbsp;new configurations for&amp;nbsp;Endpoint Detection and Response (EDR)&amp;nbsp;and&amp;nbsp;Antivirus exclusions on Linux devices.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Audit and compliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Logs&amp;nbsp;all&amp;nbsp;task&amp;nbsp;activities&amp;nbsp;for visibility,&amp;nbsp;reporting, and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Integrated security settings management&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Manage&amp;nbsp;antivirus&amp;nbsp;and EDR settings&amp;nbsp;directly&amp;nbsp;through&amp;nbsp;Defender for Endpoint&amp;nbsp;security&amp;nbsp;settings&amp;nbsp;management&amp;nbsp;in Intune&amp;nbsp;using&amp;nbsp;security&amp;nbsp;tasks&amp;nbsp;recommendations.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Microsoft&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Defender for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;E&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;ndpoint&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;security tasks&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;surfaced&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;OL style="padding-left: 0; margin-left: 0;" start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/agents/device-offboarding-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device Offboarding&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Admin&amp;nbsp;tasks now&amp;nbsp;incorporates&amp;nbsp;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Device Offboarding Agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;tasks.&amp;nbsp;Admins can review and act on&amp;nbsp;the&amp;nbsp;cleanup&amp;nbsp;of&amp;nbsp;stale&amp;nbsp;devices&amp;nbsp;using&amp;nbsp;the same flow used for other high-impact tasks.&amp;nbsp;The preview supports Intune&amp;nbsp;managed devices running Windows, iOS/iPadOS, macOS, Android, and Linux, and allows admins to disable Microsoft Entra ID objects with&amp;nbsp;guided&amp;nbsp;remediation.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Download a CSV list of affected devices.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What&amp;nbsp;the&amp;nbsp;Device Offboarding Agent&amp;nbsp;enables*:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Routine reviews:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Pre-packaged tasks reduce manual investigation and help make cleanup repeatable.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Automated identification&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&amp;nbsp;Detects&amp;nbsp;unused or outdated devices&amp;nbsp;using automated signals&amp;nbsp;across Intune and Microsoft Entra&amp;nbsp;to help reduce the attack surface.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Offboarding&amp;nbsp;insights:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Provides actionable recommendations and details requiring approval before offboarding.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;*&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Note&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;The Device&amp;nbsp;Offboarding Agent requires&amp;nbsp;Microsoft&amp;nbsp;Security Copilot,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/copilot/security/get-started-security-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;get started here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. Security Copilot will be included for all Microsoft 365 E5 customers,&amp;nbsp;roll out began for existing Security Copilot users and&amp;nbsp;is&amp;nbsp;continuing&amp;nbsp;in the upcoming months, &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;learn more here.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;View of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;potential devices&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;identified&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;for&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;removal&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;the&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;Device Offboarding Agent&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;within&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;OL style="padding-left: 0; margin-left: 0;" start="4"&gt;
&lt;LI style="font-weight: bold;"&gt;&lt;STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Multi&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Admin Approval&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;requests&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Multi&amp;nbsp;Admin Approval requires a second administrator to approve&amp;nbsp;high-impact&amp;nbsp;actions,&amp;nbsp;such as scripts, remote actions, role changes, and device wipes before they are executed.&amp;nbsp;MAA requests now appear in admin tasks,&amp;nbsp;ensuring&amp;nbsp;sensitive configuration changes follow&amp;nbsp;a consistent, centralized review process.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Key actions to take in admin tasks&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;: &lt;/STRONG&gt;Approve or reject a request, complete a change, and add requester and approver notes for audit and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;What&amp;nbsp;MAA&amp;nbsp;enables&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Alignment with access policies:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Applies to protected&amp;nbsp;configurations&amp;nbsp;that&amp;nbsp;require approvals, such as&amp;nbsp;scripts,&amp;nbsp;roles,&amp;nbsp;settings,&amp;nbsp;and&amp;nbsp;remote actions.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Audit and compliance:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Logs&amp;nbsp;all&amp;nbsp;approval, rejection,&amp;nbsp;and completion&amp;nbsp;of&amp;nbsp;activity&amp;nbsp;for visibility,&amp;nbsp;reporting, and compliance.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Protection against compromised accounts:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;Helps ensure&amp;nbsp;sensitive changes—such as script executions, device wipes, or&amp;nbsp;role&amp;nbsp;permission&amp;nbsp;updates—cannot be performed by a single administrator.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:2,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:300}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Contextual risk analysis*:&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/agents/change-review-agent" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Change Review Agent&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;(part of Microsoft&amp;nbsp;Security Copilot)&amp;nbsp;analyzes&amp;nbsp;MAA script requests&amp;nbsp;in context&amp;nbsp;providing&amp;nbsp;detailed insights&amp;nbsp;on potential impact and clear recommendations.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="auto"&gt;*&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Note&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;:&amp;nbsp;The Change Review Agent&amp;nbsp;requires&amp;nbsp;Microsoft&amp;nbsp;Security Copilot,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/copilot/security/get-started-security-copilot" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;get started here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. Security Copilot will be included for all Microsoft 365 E5 customers, roll out began for existing Security Copilot users and&amp;nbsp;is&amp;nbsp;continuing&amp;nbsp;in the upcoming months, &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;learn more here.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Figure &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;4&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;: View of Multi Admin&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;Approval&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;script requests&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;&amp;nbsp;displayed within admin tasks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="caption"&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559739&amp;quot;:0}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:200,&amp;quot;335559740&amp;quot;:240}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;S&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;implify&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;decisions&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;and prepare for AI-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;assisted&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;workflows&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;today&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Admin tasks in Intune&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;offers&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;a single, prioritized view to act quickly on what matters most—while building the secure foundation organization&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;need for agentic automation. As Intune continues t&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;o expand its AI&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;-&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;driven capabilities, this centralized model&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;gives&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;IT more&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;control&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;deeper&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;insights&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;across the&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;&amp;nbsp;platform.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Explore&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/admin-tasks" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;admin tasks in&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Microsoft&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;today and see how the expanded&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft 3&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;6&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;5 E3&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;E5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;value helps organizations&amp;nbsp;scale securely and confidently.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;FOOTER&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-ccp-props="{}"&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/FOOTER&gt;</description>
      <pubDate>Tue, 03 Feb 2026 17:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/admin-tasks-in-microsoft-intune-centralized-control-today-ai/ba-p/4489448</guid>
      <dc:creator>LiMiller</dc:creator>
      <dc:date>2026-02-03T17:00:00Z</dc:date>
    </item>
    <item>
      <title>What's in store for Intune at Microsoft Technical Takeoff 2026</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-in-store-for-intune-at-microsoft-technical-takeoff-2026/ba-p/4489457</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;It’s&amp;nbsp;almost time&amp;nbsp;for Microsoft Technical Takeoff, our month‑long digital skilling event designed to help IT admins and technical decision-makers go deeper with Windows, Microsoft Intune, and Windows 365. Every Monday in March,&amp;nbsp;you’ll&amp;nbsp;get fresh technical content, hands‑on guidance, and direct engagement with the engineering teams who build the products you use every day.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;This year’s event brings together technical deep dives, Ask Microsoft Anything (AMA) sessions, and feedback‑gathering sessions—all streamed live on the Microsoft Tech Community.&amp;nbsp;Expect deep, scenario‑driven guidance spanning security, automation, cloud management, and cross‑platform device administration.&amp;nbsp;You’ll&amp;nbsp;also be able to engage directly with the product engineering teams with&amp;nbsp;live Q&amp;amp;A&amp;nbsp;during the sessions.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Start your Technical Takeoff experience right&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="auto"&gt;As&amp;nbsp;you explore the full agenda,&amp;nbsp;make sure you&amp;nbsp;tune in to&amp;nbsp;our annual kickoff panel,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windowsevents/lets-talk-windows-intune-2026-edition/4490524" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Let’s Talk Windows &amp;amp; Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;Monday, March 2 at 7:00&amp;nbsp;AM&amp;nbsp;PT.&amp;nbsp;Engineering leaders&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/users/sangee_visweswaran/1808723" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Sangeetha Visweswaran&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/users/john_cable/586135" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;John Cable&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/users/bhavyachopra/313719" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Bhavya Chopra&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;will&amp;nbsp;share what they’re learning from IT admins around the world, as well as&amp;nbsp;what’s shaping the future of device management, security, and cloud‑powered productivity.&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Explore&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;essions at Technical Takeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You&amp;nbsp;can bookmark and watch the full event at&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/TechnicalTakeoff" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://aka.ms/TechnicalTakeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;All the sessions are also listed&amp;nbsp;day-by-day&amp;nbsp;below.&amp;nbsp;From each session page, you can:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;“Add to Calendar” to save the date.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Click&amp;nbsp;“Attend”&amp;nbsp;to&amp;nbsp;hold your spot and&amp;nbsp;receive reminders.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Post your&amp;nbsp;Q&amp;amp;A&amp;nbsp;questions early for the engineering team. (Of course, you can also&amp;nbsp;post questions live as you learn!)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Tune in&amp;nbsp;live or watch on demand afterward.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;🔐 Zero Trust&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;and s&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ecurity&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/zero-trust-in-action-securing-endpoints-with-intune/4490569" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Zero Trust in Action: Securing&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;e&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ndpoints with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 9:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/least-privilege-on-windows-with-endpoint-privilege-management/4490591" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Least privilege on Windows with Intune Endpoint Privilege Management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 10:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;📦 Provisioning&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;and&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;device&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;anagement&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ama-migrating-from-windows-autopilot-to-windows-autopilot-device-prep/4490581" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AMA: Migrating from Windows Autopilot to Windows Autopilot Device Prep&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 9:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/one-platform-many-industries-smart-android-management-with-intune/4490570" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;One platform, many industries: smart Android management with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 11:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/intune-playbook-for-ios-management-at-scale/4490574" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune playbook for iOS management at scale&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 11:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/why-smarter-windows-management-starts-with-intune/4490586" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Why&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;marter Windows Management&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;s&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;tarts with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 7:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/manage-apple-devices-at-scale-intune-security-best-practices/4490571" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Manage Apple devices at scale: Intune security best practices&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 9:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/intune-timing-demystified-what-really-happens-behind-the-scenes/4490580" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Intune timing demystified: what really happens behind the scenes&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16&amp;nbsp;–&amp;nbsp;11:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windowsevents/deploy-manage-windows-365-microsoft-intune/4490510" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Deploy and manage Windows 365 with Microsoft Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 23 – 8:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;🤖 Automation&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;&amp;nbsp;and AI&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ai-powered-admin-emerging-trends-in-endpoint-management/4490567" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AI‑powered admin: Emerging trends in endpoint management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 2 – 9:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ai-roundup-intune-agents-for-outcome-oriented-innovation/4490578" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AI roundup: Intune agents for outcome-oriented innovation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 8:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/ama-getting-the-most-from-security-copilot-in-intune/4490590" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;AMA: Getting the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;ost from Security Copilot in Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 9:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;📊 Apps,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;d&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;ata&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;, and r&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;eporting&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/feedback-wanted-app-management-in-the-enterprise/4490584" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Feedback wanted:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;a&lt;/SPAN&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;pp management in the enterprise&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 8:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/making-the-most-of-your-intune-data/4490577" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Making the most of your Intune data&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 9 – 9:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windowsevents/real-time-reporting-with-windows-autopatch-update-readiness/4490526" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Real-time reporting with Windows Autopatch update readiness&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 7:30 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/click-less-manage-more-simplify-app-deployment-with-intune/4490573" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Click less, manage more: simplify app deployment with Intune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 16 – 10:00 AM PT&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H5&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;🎥&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 3"&gt;All things endpoint management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H5&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-technical-takeoff/unpacking-endpoint-management-live-from-tech-takeoff-2026/4490583" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Unpacking Endpoint Management: Live from Tech Takeoff 2026&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;March 23&amp;nbsp;–&amp;nbsp;9:00 AM PT&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:80,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;See&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;y&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;ou on Mondays in March!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Whether&amp;nbsp;you’re&amp;nbsp;modernizing your endpoint estate, strengthening security, or looking for practical configuration guidance, Microsoft Technical Takeoff is your chance to get actionable insights straight from engineering.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Can’t attend live? No problem. All sessions are recorded and available on demand shortly after they air. You can also post your Q&amp;amp;A questions in advance or anytime during the week of the session. In addition, although sessions will feature AI-generated captions during the live broadcast, we will update those with human-generated, human-verified captions (and transcripts) by the end of each week.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We hope to see you at Microsoft Technical Takeoff! Grab your seat, customize your agenda, and get answers directly from the experts behind Windows and Intune.&amp;nbsp;Visit&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/TechnicalTakeoff" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://aka.ms/TechnicalTakeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;to get started&amp;nbsp;and see our sister&amp;nbsp;guide to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://aka.ms/WindowsAtTechTakeoff" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows and Windows 365 at Tech Takeoff&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:259}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;FOOTER&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Stay up to date! Bookmark the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Intune Blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and follow us on &lt;/SPAN&gt;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;LinkedIn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; or &lt;/SPAN&gt;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@MSIntune&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt; and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;@IntuneSuppTeam&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;on X to continue the conversation.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559739&amp;quot;:0,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;/FOOTER&gt;</description>
      <pubDate>Mon, 02 Feb 2026 17:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-in-store-for-intune-at-microsoft-technical-takeoff-2026/ba-p/4489457</guid>
      <dc:creator>Rachelle_Blanchard</dc:creator>
      <dc:date>2026-02-02T17:00:00Z</dc:date>
    </item>
    <item>
      <title>Save the date: Intune Tech Community Live – January 26</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/save-the-date-intune-tech-community-live-january-26/ba-p/4486086</link>
      <description>&lt;ARTICLE&gt;&lt;HEADER&gt;
&lt;P&gt;Level up your endpoint management skills at &lt;STRONG&gt;Tech Community Live: Intune Edition&lt;/STRONG&gt;. &lt;BR /&gt;&lt;BR /&gt;IT professionals:&amp;nbsp;mark your calendars for Monday, January 26, 2026. If you manage endpoints with Microsoft Intune, this is your chance to connect directly with the experts and get answers to your toughest questions.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/HEADER&gt;
&lt;SECTION&gt;
&lt;P&gt;This isn’t your typical webinar. It’s an interactive event packed with four Ask Microsoft Anything (AMA) sessions, where you can bring your toughest questions and get real answers from the experts. Here’s what’s on the agenda (all times in PST):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;8:00 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-secure-your-endpoints-with-policy-and-microsoft-defender/4485786" target="_blank" rel="noopener"&gt; Secure your endpoints with policy and Microsoft Defender &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;9:00 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-manage-apps-like-a-pro-with-microsoft-intune/4485787" target="_blank" rel="noopener"&gt; Manage apps like a pro with Microsoft Intune &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;10:00 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-best-practices-for-applying-zero-trust-principles-using-intune/4485788" target="_blank" rel="noopener"&gt; Best practices for applying Zero Trust using Intune &lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;10:30 AM – &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-copilotagentic-centered-endpoint-management/4485789" target="_blank" rel="noopener"&gt; Copilot and agentic-centered endpoint management &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/SECTION&gt;
&lt;SECTION&gt;
&lt;H2&gt;Why Tech Community Live?&lt;/H2&gt;
&lt;P&gt;Endpoint management is evolving fast—and so are the challenges. This event gives you &lt;STRONG&gt;direct access to the Microsoft engineering teams&lt;/STRONG&gt; creating new features and capabilities in Intune. It’s your chance to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Get answers to real-world questions straight from the experts.&lt;/LI&gt;
&lt;LI&gt;Learn best practices you can apply immediately.&lt;/LI&gt;
&lt;LI&gt;Influence the future by sharing your feedback with the people who build the product.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Whether you’re looking to strengthen compliance, streamline app deployment, or embrace Zero Trust strategies, you’ll walk away with actionable insights to keep your organization secure and efficient.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;SECTION&gt;
&lt;H2&gt;How to join the fun&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Browse the session topics above.&lt;/LI&gt;
&lt;LI&gt;Hit &lt;STRONG&gt;Add to calendar&lt;/STRONG&gt; on the session pages to save them, well, to your calendar.&lt;/LI&gt;
&lt;LI&gt;Sign in to the Tech Community (top right corner of the site) then click &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive event reminders.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Post your questions in the Comments section at the bottom of each session page early and often. We’ll be ready to tackle them live! Don’t miss this opportunity to learn from Microsoft experts and elevate your Intune skills. &lt;STRONG&gt;See you there!&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Community matters. Let your network know they get the Intune answers and insights they need on January 26 on the Microsoft Tech Community.&lt;/P&gt;
&lt;!-- Image placeholder: replace src with the final hosted image URL --&gt;
&lt;FIGURE&gt;&lt;/FIGURE&gt;
&lt;img /&gt;&lt;/SECTION&gt;
&lt;HR /&gt;&lt;FOOTER&gt;
&lt;P&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and &lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;
&lt;/FOOTER&gt;&lt;/ARTICLE&gt;</description>
      <pubDate>Fri, 30 Jan 2026 17:35:10 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/save-the-date-intune-tech-community-live-january-26/ba-p/4486086</guid>
      <dc:creator>Rachelle_Blanchard</dc:creator>
      <dc:date>2026-01-30T17:35:10Z</dc:date>
    </item>
    <item>
      <title>What's new in Microsoft Intune: December 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-december-2025/ba-p/4476486</link>
      <description>&lt;P&gt;Following Microsoft Ignite 2025, I caught up with colleagues and Intune MVPs who made the trip to San Francisco. There was a lot to talk about, but one conversation stood out: When I asked what surprised them most about this year for Microsoft Intune, the answer wasn't a single capability. It was witnessing busy IT admin work disappear by automating work that used to consume hours of admin time.&lt;/P&gt;
&lt;P&gt;Microsoft &lt;A href="https://learn.microsoft.com/en-us/intune/agents/" target="_blank" rel="noopener"&gt;Security Copilot agents in Intune&lt;/A&gt; exemplify that shift, but the introduction of additional agents doesn’t address other IT challenges. Throughout 2025, the Intune engineering team has shipped capabilities for cross-platform support, security, and more that has helped to remove many areas of friction from day-to-day operations. For a more complete story about what was delivered and what’s coming soon, watch the on-demand &lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK341?source=sessions" target="_blank" rel="noopener"&gt;Microsoft Ignite presentation&lt;/A&gt; or read the &lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-at-ignite/4471043" target="_blank" rel="noopener"&gt;What’s new in Microsoft Intune at Ignite&lt;/A&gt; blog.&lt;/P&gt;
&lt;P&gt;Today, I'll focus on several recent capabilities worth examining in detail from November and December.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Empowering IT by automating and enhancing workflows&lt;/H2&gt;
&lt;P&gt;For many of the customers I spoke with this year, context-switching drains productivity. Switching between multiple console nodes to manage security tasks, elevation requests, and admin approvals increases friction and the chance of missing something.&lt;/P&gt;
&lt;P&gt;The new Admin tasks node&lt;STRONG&gt; &lt;/STRONG&gt;under Tenant Administration in the Intune admin center consolidates this workflow into a single view. Now in public preview, this centralized location surfaces Endpoint Privilege Management (EPM) file elevation requests, Defender for Endpoint security tasks, and &lt;BR /&gt;Multi-Admin Approval requests in one place. Administrators can search, filter, and sort across all task types without jumping between console areas. The centralized view reduces time spent hunting for what needs attention and creates a more reliable review process.&lt;/P&gt;
&lt;P&gt;This helps centralize admin tasks, but visibility without boundaries can create noise. Until now, administrators with permission to review Endpoint Privilege Management elevation requests could see every request across the organization, regardless of their assigned scope. Scope tag enforcement adds role-based access control to this highly valued capability, aligning EPM with Zero Trust by ensuring admins only access the elevation requests required for their role. This reduces unnecessary visibility into devices and users outside their remit and lowers the risk of accidental or inappropriate actions.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Enhancing visibility and control across platforms&lt;/H2&gt;
&lt;P&gt;November's updates deliver improvements across three areas: app management, privacy controls, and policy targeting. These areas give IT administrators even more granular control for diverse device fleets running iOS, macOS, and Android.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Android: User experience and app management options&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Intune has introduced new capabilities to Managed Home Screen for IT to enhance the end user experience on frontline Android devices: Offline mode and App access without sign-in offers users greater flexibility to access critical applications, while improved volume controls now allow more granular adjustments for call, ring, notifications, alarms, and media.&lt;/P&gt;
&lt;P&gt;Additionally, if customizing your managed Google Play app catalog becomes too time consuming, you can use the new “Reset to Basic” mode. This reverts to the default "all approved apps visible" experience instantly, without support tickets or manual collection rebuilds. Taken together, these changes move Android app management away from low-level device plumbing and toward intentional experience design. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Android: Data protection and privacy controls&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Beneath the user-facing improvements, the November Intune release tightens Android data protection. This is critical for AI features that may not have been part of the original security model. The Intune Settings Catalog now provides access to Android controls, which include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;“Block assist content sharing with privileged apps", a setting that helps mitigate the emerging risk of AI assistants and screen readers from capturing work profile screenshots and app details. This stops AI services like Circle to Search from ingesting corporate context into external learning datasets while still allowing personal AI features to function.&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Work-profile privacy settings that block Bluetooth contact sharing and prevent work contacts from appearing in personal caller ID Control data flows.&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI&gt;New work profile password options (expiration, reuse history, and device wipe on failure).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Android: Policy targeting and security enforcement&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;To help ensure your most sensitive controls reach only the devices that need them, IT can now use Device Management Type as an assignment filter property in Intune for precision policy targeting. Instead of over-applying rules to all Android devices, you can now differentiate between corporate and personal devices across Android Enterprise and AOSP.&lt;/P&gt;
&lt;P&gt;This precision extends into real-time security enforcement. When Microsoft Defender for Endpoint detects a rooted Android device, Microsoft Tunnel immediately blocks VPN access, dropping active connections until the device is remediated. Because Defender's detection works natively within Intune, your existing compliance policies are automatically enforced through Tunnel (across both MDM-managed and MAM scenarios) without manual reconfiguration.&lt;STRONG&gt; &lt;/STRONG&gt;Learn more in the following blog on&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/native-root-detection-support-for-microsoft-defender-on-android/4461576" target="_blank" rel="noopener"&gt;native root detection support for Microsoft Defender on Android&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;iOS and macOS: Enrollment experience design&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;First impressions during enrollment shape user expectations and IT confidence alike.&lt;/P&gt;
&lt;P&gt;When an employee unboxes a new device enrolled through your organization, those initial screens become an opportunity to empower users and position IT as an enabler. Finding the right balance has sometimes meant accepting trade-offs. IT admins could streamline the flow, or show every configuration option, but rarely both.&lt;/P&gt;
&lt;P&gt;Setup Assistant customization for iOS/iPadOS and macOS automated device enrollment, now generally available, delivers both of these benefits. Administrators can now hide or show specific Setup Assistant screens, enabling fine-grained control over the enrollment experience while preserving flexibility. Want to show App Store and camera configuration on some devices but hide privacy settings on others based on policy? You can do that now. The result is enrollment tailored to your actual requirements, not constrained by platform defaults.&lt;STRONG&gt; &lt;/STRONG&gt;For detailed configuration guidance, see&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-ios" target="_blank" rel="noopener"&gt;Set up automated device enrollment for iOS/iPadOS&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-macos" target="_blank" rel="noopener"&gt;Set up automated device enrollment for macOS&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;In summary, whether Android users require precise privacy controls or iOS users benefit from a customized enrollment experience, the November Intune release emphasizes that effective, cross-platform management involves respecting each device platform's uniqueness and working to optimize for them.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Improving end-user onboarding experiences&lt;/H2&gt;
&lt;P&gt;Providing employees with immediate access to devices equipped with necessary applications can enhance employee satisfaction, optimize security measures, and increase overall productivity. Upon logging into a Cloud PC environment, end-users encounter pre-installed applications, enabling them to begin working efficiently without delay.&lt;/P&gt;
&lt;P&gt;Windows Autopilot device preparation in automatic mode is now available in public preview for Windows 365 Enterprise, Windows 365 Frontline dedicated mode, and Windows 365 Cloud Apps.&amp;nbsp;IT administrators now can include device preparation policies as part of their Cloud PC provisioning process.&lt;/P&gt;
&lt;P&gt;This capability streamlines the Cloud PC provisioning process, improves the end-user experience, and eliminates the need for custom images, while providing visibility into installation progress with both the CPC report and the Autopilot device prep deployment report. This ensures the device is set up with critical apps and scripts when the end-user logs in on day one.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Looking forward to 2026&lt;/H2&gt;
&lt;P&gt;Cloud-native endpoint management on a trusted platform is the foundation for how organizations will support AI safely across endpoints. The investments throughout 2025 focused on reducing friction at critical points, rather than painting with a broad brush, across every aspect of endpoint management, and showed what's possible when management infrastructure is built for modern threats and modern work.&lt;/P&gt;
&lt;P&gt;Whether it's automating tedious admin tasks, respecting platform-specific security needs, or accelerating device readiness, a cloud-powered, AI-driven approach helps move IT from firefighting to strategy. In 2026, we will continue to innovate with this focus and share more updates on &lt;A href="https://aka.ms/IntuneM365Blog" target="_blank" rel="noopener"&gt;Intune's advanced capabilities coming to Microsoft 365 E3 and Microsoft 365 E5&lt;/A&gt;, which will expand access to the solutions of the Microsoft Intune Suite to more customers. See you in 2026!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 19:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-december-2025/ba-p/4476486</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2025-12-11T19:00:00Z</dc:date>
    </item>
    <item>
      <title>Microsoft 365 adds advanced Microsoft Intune solutions at scale</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/ba-p/4474272</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: &lt;EM&gt;New capabilities will begin to roll out CY26 Q3. Customers will receive a 30‑day notice in Message Center before the update becomes available in their tenant.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;In the last three years, Microsoft launched multiple endpoint management solutions with advanced capabilities that enable IT professionals to unify mission critical endpoint management functionality in one cost-effective plan with the &lt;STRONG&gt;Microsoft Intune Suite&lt;/STRONG&gt;. These capabilities are essential to accelerate every organization’s journey towards Zero Trust security, improving end user productivity, and empowering IT and security professionals to improve total cost of ownership (TCO).&lt;/P&gt;
&lt;P&gt;Today, IT teams face new challenges, as device inventories grow larger, more diverse, and are much more widely distributed and dynamic than just a few years ago. At the same time, they are still expected to keep systems protected, compliant, and operational with limited budgets. To meet evolving security needs and growing demands, organizations need &lt;STRONG&gt;more advanced security and management tools&lt;/STRONG&gt; capable of transforming IT operations in ways that can safeguard against AI-enhanced attack vectors and new risks while preserving productivity on every endpoint.&lt;/P&gt;
&lt;P&gt;To help organizations make this transition, Microsoft is bringing powerful capabilities of the &lt;STRONG&gt;Microsoft Intune Suite&lt;/STRONG&gt; to &lt;STRONG&gt;Microsoft 365 E3 and Microsoft 365 E5&lt;/STRONG&gt;. By expanding these offerings, more customers can confidently embrace transformation and stay secure in the age of AI.&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM class="lia-align-left"&gt;“Intune Suite makes managing 10,000 or 40,000 devices effortless through automation and unification. The capacity to scale effortlessly while simplifying processes has led to more efficient updates and quicker incorporation of new assets.” –Roman Kleyn, Head of Workplace Design, Krones AG&lt;SUP&gt;&lt;A href="#community--1-_note1" target="_self"&gt;i&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Unifying Endpoint Management: Key capabilities driving customer choice&lt;/H2&gt;
&lt;P&gt;Microsoft Intune empowers IT to solve issues faster, get proactive with data and secure diverse devices with Intune Remote Help, Intune Advanced Analytics, Microsoft Tunnel for Mobile Application Management, specialty device management and firmware updates. These capabilities will be added to Microsoft Enterprise Mobility and Security E3 (EMS E3) which also extends this value to Microsoft 365 E3. Furthermore, to unify advanced security and device management, Intune Endpoint Privilege Management, Intune Enterprise Application Management and Microsoft Cloud PKI will be added to Microsoft 365 E5.&lt;/P&gt;
&lt;P&gt;These changes, alongside the &lt;A href="https://www.microsoft.com/en-us/security/blog/2025/11/18/agents-built-into-your-workflow-get-security-copilot-with-microsoft-365-e5/" target="_blank" rel="noopener"&gt;Microsoft Security Copilot&lt;/A&gt; and &lt;A href="https://aka.ms/M365-PIBlog" target="_blank" rel="noopener"&gt;Microsoft 365&lt;/A&gt; updates, will fundamentally expand the availability of Intune integrated, cloud powered capabilities. This expansion will provide seamless access to advanced management and security features as well as agentic, automated workflow capabilities within Microsoft’s most comprehensive commercial products. It will empower IT to help &lt;STRONG&gt;safeguard productivity&lt;/STRONG&gt; and &lt;STRONG&gt;strengthen their Zero Trust posture&lt;/STRONG&gt; by minimizing risk, maintaining compliance, and ensuring seamless, secure digital employee experiences. Ultimately, this change will enable proactive issue prevention, more secure work, and efficient ways to&amp;nbsp;&lt;STRONG&gt;scale &lt;/STRONG&gt;&lt;STRONG&gt;operations&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;With the rollout of &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/copilot/copilot-intune-overview" target="_blank" rel="noopener"&gt;Microsoft Security Copilot in Intune&lt;/A&gt;, we’ve helped organizations enter a new era where AI is increasingly incorporated into their IT operations. Last month at Microsoft Ignite 2025, we announced a significant step that goes even further, putting AI at the core of endpoint management. With the launch of a &lt;A href="https://aka.ms/IntuneAtIgnite2025" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;new wave of Security Copilot agents in Intune&lt;/STRONG&gt;&lt;/A&gt; and more ways to explore Intune data, IT can ask important questions, take action on the answers, and simplify complex tasks with intelligence and automation.&lt;/P&gt;
&lt;P&gt;Here’s a closer look at why organizations are choosing Intune and Security Copilot as their endpoint management solution.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Enhanced security simplifies implementation of Zero Trust principles &lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;In 2025, 79% of ransomware attacks involved remote management tools on endpoints, highlighting the critical need for Zero Trust controls and least-privilege access on every device.&lt;SUP&gt;&lt;A href="#community--1-_note2" target="_self"&gt;ii&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-endpoint-privilege-management" target="_blank" rel="noopener"&gt;Endpoint Privilege Management&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;enables organizations to adopt a least privilege approach, mitigating&lt;STRONG&gt; &lt;/STRONG&gt;systemic risks of local admin privileges by providing elevated access only to approved apps or services. Just-in-time elevation helps to maintain productivity without compromising security.
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Copilot&lt;/STRONG&gt; in Intune offers assistance by providing valuable insights based on Microsoft Defender threat intelligence that assesses an app’s risk before IT approves an elevation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/microsoft-tunnel-mam" target="_blank" rel="noopener"&gt;Microsoft Tunnel for Mobile Application Management&lt;/A&gt; supports Zero Trust principles by providing secure per-app VPN connectivity access to company resources without requiring enrollment, protects corporate data and respects employee privacy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;AI-powered insights and remote assistance powers productivity &lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;“Remote Help closed the gap that we had for remote management. Now we have an enterprise-compatible solution with audit logs, allowing us to see what’s happened, who is connected to whom, etc. These are true benefits from an enterprise solution,” – Michael Meier, Senior System Administrator, Krones AG&lt;SUP&gt;&lt;A href="#community--1-_note3" target="_self"&gt;iii&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-advanced-analytics" target="_blank" rel="noopener"&gt;Advanced Analytics&lt;/A&gt; offers AI-powered anomaly detection to proactively identify device health and other forms of digital friction and gives IT visibility into areas of focus to keep operations running smoothly and ensure device compliance.
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;
&lt;P&gt;Copilot in Intune assists admins of all experience levels in performing complex tasks such as writing KQL queries through the simple use of natural language.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-remote-help" target="_blank" rel="noopener"&gt;Remote Help&lt;/A&gt; allows IT teams to safely and remotely support and fix issues more quickly. All interactions are fully auditable and use strong authentication, trusted connections, role-based access control, and device compliance checks.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Streamlined app deployment and automated certificate lifecycle management helps maintain compliance and protection at scale &lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;“Cloud PKI within the Intune Suite allows you to go cloud native in terms of certificate deployment, which means you can provision PKIs with just a few clicks — that’s a blessing for all the IT administrators. With this built-in service, Microsoft hosts everything for you to manage certificates.” Niklas Tinner, Founder/Solution Architect, Oceanleaf GmbH&lt;SUP&gt;&lt;A href="#community--1-_note4" target="_self"&gt;iv&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-intune-enterprise-application-management" target="_blank" rel="noopener"&gt;Enterprise Application Management&lt;/A&gt;&lt;STRONG&gt; &lt;/STRONG&gt;streamlines app deployment and updates, reduces IT overhead, and improves the digital user experience with a curated catalog of 1000+ of prepackaged applications.
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;
&lt;P&gt;The&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/microsoft-security-copilot-in-intune---pt-2-vulnerability-remediation-agent-in-l/4424824" target="_blank" rel="noopener"&gt;Vulnerability Remediation Agent&lt;/A&gt; helps reduce the effort of discovering and prioritizing breach or work disruption risks, giving IT insight on what patches to prioritize.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;S&gt; &lt;/S&gt;&lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-cloud-PKI" target="_blank" rel="noopener"&gt;Microsoft Cloud PKI&lt;/A&gt; allows IT to streamline the management of the complete certificate lifecycle and reduce the dependency on on-premises infrastructure. It also helps prevent phishing and mitigate other risks with certificate based authentication to Wi-Fi and VPN services.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;A unified IT ecosystem for long term value&lt;/H2&gt;
&lt;P&gt;Including Intune’s advanced capabilities directly into Microsoft 365 is the latest step in our larger vision to create a unified, strategic foundation that enables companies to manage and secure their endpoints. Intune and Security Copilot are built to work seamlessly within Microsoft 365, Windows 11, Windows 365, Entra, Purview and Defender.&lt;/P&gt;
&lt;P style="display: block; background: linear-gradient(to right,#0078d7 6px,transparent 6px),#f3f3f3; padding: 18px 22px; margin-left: 2.2rem; max-width: 940px; box-sizing: border-box; font-family: 'Segoe UI', Roboto, Arial, sans-serif; color: #111; line-height: 1.55; white-space: pre-line; font-size: 15px;"&gt;&lt;EM&gt;“One New Zealand saved $800K by modernizing with Windows 365 and Microsoft Intune, cutting provisioning-related tickets by 80%. Devices that once took four to six hours to provision are now ready in 30 minutes. User assignments take less than 15 seconds, and onboarding time for call center staff dropped almost 95%.&lt;SUP&gt;&lt;A href="#community--1-_note5" target="_self"&gt;v&lt;/A&gt;&lt;/SUP&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In addition to Intune’s upcoming changes within Microsoft 365, the recently announced Windows resiliency and security capabilities will be added to &lt;STRONG&gt;Windows Enterprise E3&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Resiliency Initiative recovery tools now include &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/scalable-windows-resiliency-with-new-recovery-tools/4470659" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;quick machine recovery&lt;/STRONG&gt;&lt;/A&gt; (QMR) with enterprise-level controls, point-in-time restore, and cloud rebuild for Windows 11. Through Intune, QMR enables fast restoration of apps, settings, and files, as well as Windows Backup and OneDrive.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Windows Autopatch now includes &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-autopatch-%E2%80%94-elevate-your-update-experience-for-modern-work/4468111" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;update readiness&lt;/STRONG&gt;&lt;/A&gt;, in preview, giving IT teams real-time visibility into device compliance and risks through a pre-built Intune dashboard. Administrators can quickly identify, diagnose, and remediate updates, telemetry and policy issues directly within Autopatch.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;What does this mean for your organization?&lt;/H2&gt;
&lt;P&gt;Microsoft is committed to delivering a unified management and security foundation on a trusted, cloud platform that elevates how organizations operate and defend at scale. Aligning this with AI-powered and agentic automation enables stronger Zero Trust controls to help safeguard productivity, minimizes risks, and improves agility for IT teams and end users.&lt;/P&gt;
&lt;P&gt;When you’re ready to learn more, &lt;STRONG&gt;connect with your Microsoft account team&lt;/STRONG&gt; to discuss adoption roadmaps and discover how a comprehensive, AI-ready portfolio can help you solve even the most complex IT challenges.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;FAQ&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;1. Which Intune related capabilities are included in each plan? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Here is a summary of the Microsoft 365 plan changes related to Microsoft Intune:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 835px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft 365 plans&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Included capabilities&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft Enterprise Mobility and Security E3 (EMS E3)&lt;/P&gt;
&lt;P&gt;(&lt;EM&gt;included in Microsoft 365 E3&lt;/EM&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help" target="_blank" rel="noopener"&gt;Remote Help&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/analytics/advanced-endpoint-analytics" target="_blank" rel="noopener"&gt;Advanced Analytics&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune Plan 2&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft 365 E5&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;All Microsoft 365 E3&lt;/STRONG&gt; features plus:&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-overview" target="_blank" rel="noopener"&gt;Endpoint Privilege Management &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/microsoft-cloud-pki-overview" target="_blank" rel="noopener"&gt;Cloud PKI &lt;/A&gt;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Intune &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/apps/apps-enterprise-app-management" target="_blank" rel="noopener"&gt;Enterprise App Management &lt;/A&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Microsoft 365 E5&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Microsoft Security Copilot&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Enterprise E3 &amp;nbsp;&lt;/P&gt;
&lt;P&gt;(&lt;EM&gt;included in Microsoft 365 E3&lt;/EM&gt;)&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Quick Machine Recovery (QMR)&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cloud rebuild for Windows 11&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Point-in-time restore for desktop&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Post-quantum security APIs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Autopatch update readiness&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;Windows Enterprise per-device license&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Basic resiliency features (QMR, point in time restore)&lt;/P&gt;
&lt;P&gt;·&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Software Assurance&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2. What is included in Intune Plan 2?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Intune Plan 2 capabilities planned to be included in Microsoft Enterprise Mobility and Security E3 include:&lt;STRONG&gt; &lt;/STRONG&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/microsoft-tunnel-mam" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Tunnel for Mobile Application Management&lt;/STRONG&gt;&lt;/A&gt; (MAM) for secure per-app VPN connectivity access to company resources without requiring full device enrollment. &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/specialty-devices-with-intune" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Specialty device management&lt;/STRONG&gt;&lt;/A&gt; covers the protection for devices such as AR/VR headsets, smart screens, and certain meeting room systems for specialized business needs. &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/zebra-lifeguard-ota-integration" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Firmware over the air&lt;/STRONG&gt;&lt;/A&gt; (FOTA) updates for supported Zebra devices.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3. When do these changes take effect? &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;For the 2026 planned product additions to Microsoft 365, a Microsoft 365 admin center notification will be posted for administrators of eligible organizations 30 days in advance of the effective change.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;4. Do I need to change my plan to use the Intune Suite capabilities or any of its add-ons? &amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;No action is necessary. All eligible tenants with Microsoft Enterprise Mobility and Security E3 and Microsoft 365 E5 will automatically be provisioned with the Intune Suite capabilities based on the table above. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P style="margin-top: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-size: 14px; font-weight: 400; color: #333333;"&gt;&lt;SUP&gt;i &lt;A href="https://www.microsoft.com/en/customers/story/19747-krones-ag-microsoft-intune?msockid=32d43ffd627f670a251d295f63b166f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Success with Intune Suite streamlines Krones AG global operations | Microsoft Customer Stories&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="endnote text"&gt;ii &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Digital Defense Report 2025 – Safeguarding Trust in the AI Era&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="endnote text"&gt;iii &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en/customers/story/19747-krones-ag-microsoft-intune?msockid=32d43ffd627f670a251d295f63b166f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Success with Intune Suite streamlines Krones AG global operations | Microsoft Customer Stories&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;iv &lt;A href="https://www.microsoft.com/en-us/security/business/endpoint-management/microsoft-cloud-PKI?msockid=32d43ffd627f670a251d295f63b166f6" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Microsoft Cloud PKI—Certificate Management | Microsoft Security&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/SUP&gt;&lt;SUP&gt;v &lt;A href="https://www.microsoft.com/en/customers/story/25487-one-new-zealand-microsoft-365-frontline-worker#customers-share-modal-dialog" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;One New Zealand saves $800,000 by modernizing with Windows 365 and Microsoft Intune | Microsoft Customer Stories&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SUP&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 23:05:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/ba-p/4474272</guid>
      <dc:creator>Talal_Alqinawi</dc:creator>
      <dc:date>2025-12-16T23:05:27Z</dc:date>
    </item>
    <item>
      <title>Essential Intune reading list: MVP community content for 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/essential-intune-reading-list-mvp-community-content-for-2025/ba-p/4471897</link>
      <description>&lt;P&gt;As we head into the holiday season, I wanted to take a moment to celebrate something truly special: the incredible contributions from our Microsoft Intune MVP community this year. Last year, I released our &lt;A href="https://www.linkedin.com/feed/update/urn:li:activity:7274431599616626688/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;first Holiday Reading post&lt;/STRONG&gt;&lt;/A&gt;, which got a lot of traction, and I was asked to do it again this year — so I guess we are starting a new tradition!&lt;/P&gt;
&lt;P&gt;Whether you're a security-focused admin exploring Zero Trust architecture, a Windows specialist diving into the latest policy enforcement mechanisms, a Mac admin navigating the evolving Apple ecosystem, or an automation advocate building the next great community tool, there's something here for you.&lt;/P&gt;
&lt;P&gt;This collection represents the spirit of our community, packed with real-world lessons, practical insights, and suggested solutions from experts in the field. While this is a select set of collected content, I strongly recommend checking out all of the content created by our MVPs — you can find a list of our &lt;A href="https://mvp.microsoft.com/en-US/search?target=Profile&amp;amp;program=MVP"&gt;active Intune MVPs&lt;/A&gt; here (make sure to set the filter for Microsoft Intune under Technology).&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Introduction to Intune&lt;/H2&gt;
&lt;P&gt;Know someone who needs to get up to speed on Intune quickly? Share these resources:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://andrewstaylor.com/2025/08/20/getting-started-with-intune-some-things-to-watch/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Getting started with Intune&lt;/STRONG&gt;&lt;/A&gt; – Important hints and tips for Intune beginners — settings you won't want to overlook &lt;EM&gt;(Andrew Taylor)&lt;/EM&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=EKDWOGXpFKU" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;12 reasons why Intune&lt;/STRONG&gt;&lt;/A&gt; – A comprehensive podcast covering Zero Trust-ready, BYOD-friendly endpoint management &lt;EM&gt;(Sucheta Gawade)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Security &amp;amp; compliance&lt;/H2&gt;
&lt;P&gt;A stronger security posture is at the top of almost every organization’s wish list. Read and watch what MVPs are recommending:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://youtu.be/EJrCy4XrtAo?si=69o2y9fb_jvVD4OF" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cloud PKI essentials&lt;/STRONG&gt;&lt;/A&gt; – A deep dive into what Cloud PKI is, deployment approaches, and where organizations stand today with certificate distribution &lt;EM&gt;(Shady Khorshed)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=nWixi8ODMG4&amp;amp;list=PLhLCvUkszoFol8WFcxwQQZomqd8LBKQ9d" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Device-centric Zero Trust with Intune + Defender&lt;/STRONG&gt;&lt;/A&gt; – Learn how to implement a complete Zero Trust strategy using Intune and Microsoft Defender for Endpoint &lt;EM&gt;(Sucheta Gawade)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/pulse/windows-patching-common-mistake-intune-admins-do-mirochnitchenko-dvllf/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows patching best practices&lt;/STRONG&gt;&lt;/A&gt; – Common mistakes Intune admins make and how to patch Windows correctly &lt;EM&gt;(Pavel Mirochnitchenko)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.oceanleaf.ch/advanced-conditional-access/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Advanced conditional access scenarios&lt;/STRONG&gt;&lt;/A&gt; – Real-world field experience and best practices for complex conditional access setups &lt;EM&gt;(Niklas Tinner)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.vansurksum.com/2025/10/20/balancing-control-and-convenience-preventing-edge-password-sync-on-unmanaged-devices/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Edge password sync security&lt;/STRONG&gt;&lt;/A&gt; – How to manage Edge password sync on unmanaged devices when using Microsoft Password Manager &lt;EM&gt;(Kenneth van Surksum)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.nielskok.tech/intune/automate-applocker-configuration-for-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;AppLocker automation&lt;/STRONG&gt;&lt;/A&gt; – Automate your AppLocker configuration directly in Intune with scripts &lt;EM&gt;(Niels Kok)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.burgerhout.org/navigating-nis2-quality-marks-with-microsoft-security-from-qm10-to-qm30/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;NIS2 compliance with Microsoft 365&lt;/STRONG&gt;&lt;/A&gt; – Comprehensive guide to reaching NIS2 compliance using Intune and Azure &lt;EM&gt;(Jeroen Burgerhout)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://smbtothecloud.com/configure-mam-for-ios-android-with-one-script/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Mobile Application Management (MAM)&lt;/STRONG&gt;&lt;/A&gt; – Step-by-step setup for iOS and Android MAM with automation scripts &lt;EM&gt;(Gannon Novak)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Windows &amp;amp; Windows 365&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Master the latest Windows capabilities&lt;/STRONG&gt; with this guidance from our top experts:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/09/09/windows11-kiosk-windows-app/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 11 kiosk multi-app mode&lt;/STRONG&gt;&lt;/A&gt; – Tackle the XML struggle and get your kiosk devices working with Edge and the Windows App &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/08/31/multi-admin-approval/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Multi-admin approval in Intune&lt;/STRONG&gt;&lt;/A&gt; – Set up Intune's multi-admin approval feature with ease, plus insights on the end-user experience &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/08/26/windows-backup-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows Backup for Organizations&lt;/STRONG&gt;&lt;/A&gt; – Introducing Windows Backup with Intune for smooth device upgrades and refreshes &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://techcaching.com/2025/05/08/windows-11-hotpatching-with-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 11 hotpatching&lt;/STRONG&gt;&lt;/A&gt; – A comprehensive deep-dive into applying critical security updates without reboots using Intune &lt;EM&gt;(Sucheta Gawade)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://joostgelijsteen.com/oma-dm-and-intunes-policy-enforcement/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;OMA-DM and policy enforcement&lt;/STRONG&gt;&lt;/A&gt; – Understanding how Intune uses the OMA-DM protocol to manage and enforce policies &lt;EM&gt;(Joost Gelijsteen)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://joostgelijsteen.com/declared-configuration/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Declared configuration&lt;/STRONG&gt;&lt;/A&gt; – The evolution of Windows policy enforcement with MMP-C and declared configuration &lt;EM&gt;(Joost Gelijsteen)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://joostgelijsteen.com/device-query-for-multiple-devices/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Device query for multiple devices&lt;/STRONG&gt;&lt;/A&gt; – Extract device data across your fleet using endpoint analytics &lt;EM&gt;(Joost Gelijsteen)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.burgerhout.org/mastering-windows-shared-pcs-with-microsoft-intune" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows shared PCs configuration&lt;/STRONG&gt;&lt;/A&gt; – Master Windows shared PCs with Intune and understand how it differs from kiosk mode &lt;EM&gt;(Jeroen Burgerhout)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://patchmypc.com/blog/administrator-protection-windows-11-25h2/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Administrator protection in Windows 11 25H2&lt;/STRONG&gt;&lt;/A&gt; – Explore the new isolated privilege model replacing traditional admin elevation &lt;EM&gt;(Rudy Ooms)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://patchmypc.com/blog/windows-finally-translates-entra-group-and-role-sids-to-real-names/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Entra group SID translation&lt;/STRONG&gt;&lt;/A&gt; – Finally! Translate Entra group SIDs into readable names on your devices &lt;EM&gt;(Rudy Ooms)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://patchmypc.com/blog/intune-policy-delivery-debugging-the-8-hour-sync-myth/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune policy delivery&lt;/STRONG&gt;&lt;/A&gt; – Debunking the 8-hour sync myth and understanding how policy delivery really works &lt;EM&gt;(Rudy Ooms)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.oceanleaf.ch/windows-365-link-experience/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Windows 365 Link experience&lt;/STRONG&gt;&lt;/A&gt; – Best practice configurations and everything you need to know about Windows 365 Link &lt;EM&gt;(Niklas Tinner)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.joeyverlinden.com/entra-id-joined-kiosk-or-autologon-device-on-a-budget/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Entra ID joined kiosk devices&lt;/STRONG&gt;&lt;/A&gt; – Deploy fully functional, self-deploying kiosk devices on modern Windows endpoints &lt;EM&gt;(Joey Verlinden)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ccmexec.com/2025/11/application-control-for-business-and-the-story-of-the-unsigned-wix-dlls/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;App&lt;/STRONG&gt;&lt;STRONG&gt; Control for Business&lt;/STRONG&gt;&lt;/A&gt; – Solving unsigned WIX .dll issues with App Control for Business &lt;EM&gt;(Jörgen Nilsson)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;macOS &amp;amp; Apple ecosystem&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Apple device management is evolving fast&lt;/STRONG&gt;. The Intune community helps keep you up to date:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/2025/07/28/macos-laps-intune/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;macOS LAPS configuration&lt;/STRONG&gt;&lt;/A&gt; – Complete guide to setting up Local Administrator Password Solution for macOS with Intune &lt;EM&gt;(Joery Van den Bosch)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://youtu.be/EKfTjysk_jw?si=Z2138B6xQ7ndTxl4" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;JUMP-IN: macOS MDM migration tool&lt;/STRONG&gt;&lt;/A&gt; – Discover this all-in-one macOS MDM migration tool and learn how it's revolutionizing transitions &lt;EM&gt;(Shady Khorshed)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intuneirl.com/macos-ios-26-for-enterprise-ddm-deployment-and-the-intel-mac-sunset/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;macOS 26 &amp;amp; iOS 26 for enterprises&lt;/STRONG&gt;&lt;/A&gt; – Apple's biggest shift in enterprise device management in years — key changes and deadlines for IT admins &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intuneirl.com/mac-admins-your-migration-glow-up-just-dropped/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;macOS migration glow-up&lt;/STRONG&gt;&lt;/A&gt; – Step-by-step process for switching macOS MDM using the new ABM update &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.burgerhout.org/introduction-to-macos-management-in-intune-beginner-friendly/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Introduction to macOS management&lt;/STRONG&gt;&lt;/A&gt; – Beginner-friendly guide to managing macOS with Intune &lt;EM&gt;(Jeroen Burgerhout)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.xplorethecloud.nl/l/ios-app-protection-policy-new-features/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;iOS app protection policy features&lt;/STRONG&gt;&lt;/A&gt; – New features in app protection policies for iOS and what they mean for your setup &lt;EM&gt;(Arno Van Dijk)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Updates, patching &amp;amp; device management&lt;/H2&gt;
&lt;P&gt;Get tips to keep your devices running smoothly and securely:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/pulse/install-update-drivers-microsoft-intune-my-script-ii-mirochnitchenko-mjskf" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Driver management in Intune&lt;/STRONG&gt;&lt;/A&gt; – Compare script-based driver updates vs. Intune's Driver Update Management solution &lt;EM&gt;(Pavel Mirochnitchenko)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.xplorethecloud.nl/l/blog-series-intune-suite-part-1-enterprise-app-management/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Enterprise App Management&lt;/STRONG&gt;&lt;/A&gt; – Explore the Intune Suite's features for simplified app deployment and maintenance &lt;EM&gt;(Arno Van Dijk)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.xplorethecloud.nl/l/remove-default-windows-store-packages/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Remove Default Windows Store packages&lt;/STRONG&gt;&lt;/A&gt; – Control Windows 11 built-in apps using the Settings Catalog without scripts &lt;EM&gt;(Arno Van Dijk)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intunebrew.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;IntuneBrew&lt;/STRONG&gt;&lt;/A&gt; – Application and patch management for macOS apps made easy &lt;EM&gt;(Ugur Koc)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Community tools &amp;amp; automation&lt;/H2&gt;
&lt;P&gt;Supercharge your Intune management with these community-created solutions:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intuneassistant.cloud" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Assistant&lt;/STRONG&gt;&lt;/A&gt; – Empower yourself with unparalleled efficiency in Intune management through advanced visualization and analysis &lt;EM&gt;(Sander Rozemuller)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/AllwaysHyPe/IntuneStack" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;IntuneStack&lt;/STRONG&gt;&lt;/A&gt; – Manage Intune policy as code with GitHub Actions, OIDC authentication, and ring-based deployments &lt;EM&gt;(Hailey Phillips)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/Intune-Log-Reader-for-Windows" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Log Reader for Windows&lt;/STRONG&gt;&lt;/A&gt; – Real-time analysis and monitoring of Microsoft Intune Management Extension logs on Windows &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/Intune-Log-Reader" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Log Reader for macOS&lt;/STRONG&gt;&lt;/A&gt; – Real-time analysis and monitoring of Microsoft Intune MDM logs on macOS &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/ABM-API-Client" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;ABM API Client&lt;/STRONG&gt;&lt;/A&gt; – Native macOS client for Apple Business Manager and Apple School Manager APIs with an intuitive GUI &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/pathaksomesh06/Fleetly" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Fleetly&lt;/STRONG&gt;&lt;/A&gt; – iOS app for IT administrators to manage and monitor Intune-enrolled devices on the go &lt;EM&gt;(Somesh Pathak)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.tenuvault.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;TenuVault&lt;/STRONG&gt;&lt;/A&gt; – Backup and restore for Intune with full automation &lt;EM&gt;(Ugur Koc)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intunedocumentation.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Intune Documentation Generator&lt;/STRONG&gt;&lt;/A&gt; – Generate PDF reports of all your Intune configurations in minutes &lt;EM&gt;(Ugur Koc)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.joeyverlinden.com/envoy-lightweight-user-environment-manager/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Envoy Lightweight UEM&lt;/STRONG&gt;&lt;/A&gt; – PowerShell-based User Environment Manager designed for Intune-managed Windows machines &lt;EM&gt;(Joey Verlinden)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://openintunebaseline.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;OpenIntuneBaseline&lt;/STRONG&gt;&lt;/A&gt; – Community-supported security baseline for Intune with real-world best practices &lt;EM&gt;(James Robinson)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.intuneqlinks.net/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;IntuneQLinks&lt;/STRONG&gt;&lt;/A&gt; – Comprehensive catalog of community articles, blogs, videos, and diagrams — your go-to resource library &lt;EM&gt;(Andy Jones)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/srozemuller/azavd" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Azure Virtual Desktop PowerShell module&lt;/STRONG&gt;&lt;/A&gt; – Streamline Azure Virtual Desktop management with this powerful community tool &lt;EM&gt;(Sander Rozemuller)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dailychecks.euctoolbox.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Daily Checks&lt;/STRONG&gt;&lt;/A&gt; – Get a daily digest of what's happening in your tenant via email with this free service &lt;EM&gt;(Andrew Taylor)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Community groups &amp;amp; resources&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/groups/13067571/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Microsoft Intune - Android and iOS Admins LinkedIn Group&lt;/STRONG&gt;&lt;/A&gt; – A focused community for mobile device management with Intune &lt;EM&gt;(Andy Jones)&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Community Events&lt;/H2&gt;
&lt;P&gt;Participate in the Intune community in person at these upcoming events&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Workplace Ninjas US 2025 – Dallas, Texas, USA – Dec 9–10, 2025 &lt;BR /&gt;Event page: &lt;A href="https://workplaceninjas.us/" target="_blank" rel="noopener"&gt;https://workplaceninjas.us&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Experts Live Denmark 2026 – Copenhagen, Denmark – February 24–25, 2026 &lt;BR /&gt;Event page: &lt;A href="https://cloudway.com/calendar-event/experts-live-denmark/" target="_blank" rel="noopener"&gt;https://cloudway.com/calendar-event/experts-live-denmark&lt;/A&gt;/&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Modern Endpoint Management Summit 2026 EMEA Edition (MEM Summit Paris) – Paris, France – April 22–24, 2026 &lt;BR /&gt;Event page: &lt;A href="https://sessionize.com/MEMSummit2026/" target="_blank" rel="noopener"&gt;https://sessionize.com/MEMSummit2026/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Workplace Ninjas Norway 2026 – Oslo, Norway-May 27, 2026 &lt;BR /&gt;Event page: &lt;A href="https://wpninjas.no/" target="_blank" rel="noopener"&gt;https://wpninjas.no/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Workplace Ninja Summit 2026 – Baden, Switzerland – TBD &lt;BR /&gt;Event page: &lt;A href="https://summit.wpninjas.global/" target="_blank" rel="noopener"&gt;https://summit.wpninjas.global/&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Intune Community Resources&lt;/H2&gt;
&lt;P&gt;Get trusted Intune tips and strategies from these blogs, videos, and podcasts from industry experts.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/andrew-taylor-41707916/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Andrew Taylor&lt;/STRONG&gt;&lt;/A&gt; Newsletter and blogs - &lt;A href="https://andrewstaylor.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://andrewstaylor.com/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/lewis-barry/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Lewis Barry&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://conditionalaccess.uk/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://conditionalaccess.uk/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MsEndpointmgr- &lt;A href="https://www.youtube.com/channel/UC3Kii1MYmVNmla5VgWIGqwA" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;(33) MSEndpointMgr - Jungling the Cloud - YouTube&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/peterwoude/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Peter van der Woude&lt;/STRONG&gt;&lt;/A&gt; – All about Microsoft Intune - &lt;A href="https://petervanderwoude.nl/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://petervanderwoude.nl/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/simonskotheimsvik/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Simon Skotheimsvik&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://skotheimsvik.no/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://skotheimsvik.no/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/niklas-tinner/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Niklas Tinner&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://www.oceanleaf.ch/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.oceanleaf.ch/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/asquaredozen/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Adam Gross&lt;/STRONG&gt;&lt;/A&gt; Intune Training -&amp;nbsp;&lt;A href="https://www.youtube.com/@IntuneTraining" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.youtube.com/@IntuneTraining&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/jonathanjedwards/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Jonathan Edwards&lt;/STRONG&gt;&lt;/A&gt; M365 Training - &lt;A href="https://www.youtube.com/@bearded365guy" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.youtube.com/@bearded365guy&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.linkedin.com/in/stevew25/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Steven Weiner&lt;/STRONG&gt;&lt;/A&gt; - &lt;A href="https://www.getrubix.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.getrubix.com/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://creators.spotify.com/pod/show/wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Workplace Ninjas Netherlands Podcast&lt;/STRONG&gt;&lt;/A&gt; - &lt;STRONG&gt;&lt;A class="lia-external-url" href="https://creators.spotify.com/pod/show/wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://creators.spotify.com/pod/show/wpninjasnl&lt;/STRONG&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/@wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Workplace Ninja User Group Netherlands Video&lt;/STRONG&gt;&lt;/A&gt; - &lt;STRONG&gt;&lt;A href="https://www.youtube.com/@wpninjasnl" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.youtube.com/@wpninjasnl&lt;/STRONG&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.meetup.com/workplace-ninja-user-group-india/events/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Workplace Ninja User Group India&lt;/STRONG&gt;&lt;/A&gt; &lt;STRONG&gt;- &lt;A class="lia-external-url" href="https://www.meetup.com/workplace-ninja-user-group-india/events/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.meetup.com/workplace-ninja-user-group-india/events/&lt;/STRONG&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Microsoft Cloud and Client Management Community Belgium -&amp;nbsp;&lt;A href="https://www.linkedin.com/company/mc2mcbe/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://www.linkedin.com/company/mc2mcbe/&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;A special thanks to our contributors&lt;/H2&gt;
&lt;P&gt;A heartfelt thank you to all the MVPs who contributed to this year's roundup:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://intunestuff.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Joery Van den Bosch&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://de.linkedin.com/in/shadykhorshed" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Shady Khorshed&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://techcaching.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://andrewstaylor.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Andrew Taylor&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.nielskok.tech/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Niels Kok&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.joeyverlinden.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Joey Verlinden&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.oceanleaf.ch/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Niklas Tinner&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.linkedin.com/in/pavelmiro/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Pavel Mirochnitchenko&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.vansurksum.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Kenneth van Surksum&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.linkedin.com/in/haileypc/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Hailey Phillips&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.burgerhout.org/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Jeroen Burgerhout&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://intuneirl.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Somesh Pathak&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.petervanderwoude.nl/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Peter van der Woude&lt;/STRONG&gt;&lt;/A&gt; | &lt;STRONG&gt;&lt;A href="https://www.xplorethecloud.nl/" target="_blank"&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Arno van Dijk&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/STRONG&gt;| &lt;A href="https://smbtothecloud.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Gannon Novak&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://www.intuneqlinks.net/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Andy Jones&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://rozemuller.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Sander Rozemuller&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://scloud.work/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Florian Salzmann&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://openintunebaseline.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;James Robinson&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://call4cloud.nl/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Rudy Ooms&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://joostgelijsteen.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Joost Gelijsteen&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://ugurkoc.de/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Ugur Koc&lt;/STRONG&gt;&lt;/A&gt; | &lt;A href="https://ccmexec.com/" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Jörgen Nilsson&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Your expertise, generosity, and passion for sharing knowledge continue to elevate the entire Intune community. Thank you for everything you do. Wishing you a wonderful holiday season and a successful 2026! Stay secure, stay innovative, and be well.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Disclaimer: This content has been created and curated by the community. Readers are encouraged to independently verify technical details and evaluate resources for their specific environments.&lt;/EM&gt;&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2025 20:04:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/essential-intune-reading-list-mvp-community-content-for-2025/ba-p/4471897</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2025-12-04T20:04:15Z</dc:date>
    </item>
    <item>
      <title>What's new in Microsoft Intune at Ignite</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-at-ignite/ba-p/4471043</link>
      <description>&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Welcome to Microsoft Ignite, where the future of IT is being reimagined. Today we’re unveiling how Microsoft Intune is transforming endpoint management by putting AI at its core, with assistive chat-based and agentic experiences to help you streamline operations, unify cross-service insights, and enable scalable action, tailored to your organization's needs. With Security Copilot chat embedded across Intune, you gain expert assistance to help guide you through daily operations while new AI agents help scale your team to tackle your most time-consuming tasks.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;These AI experiences will be available for even more IT professionals with &lt;/SPAN&gt;&lt;A href="https://aka.ms/SCP-Ignite25" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;the announcement&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; that Security Copilot is being included in Microsoft 365 E5. We're entering a new era in how IT teams manage, secure, and scale operations for their organizations.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Alongside these AI-powered innovations, we're also announcing foundational platform improvements that help IT teams act with confidence — centralizing critical tasks, reducing rollout risk, and strengthening recovery and update control for a more resilient environment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Streamline operations with agentic AI&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;A new wave of Security Copilot agents in Intune is here to help make complex tasks easier and security stronger. From transforming requirements into policies, to identifying devices for removal, to assessing changes before they impact productivity — these agents help deliver smarter decisions, better compliance, and reduced risk through intelligence and automation.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Every change that IT admins make matters. From app deployments to policy updates, even small adjustments can ripple across your environment impacting productivity or security. The new &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Change Review Agent&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;uses advanced AI to analyze each change in context, checking for risks, conflicts, and compliance. It provides detailed insights and clear recommendations, so you can move forward with confidence knowing your decision is informed. Initially the Change Review Agent will handle Multi-Admin Approval script requests, and we will continue to add more types of change requests over time.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;The Change Review Agent provides detailed insights into the request, its purpose, history, and potential impacts.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Configuring Intune policies is a job where every choice can shape your organization's security, productivity, and compliance. The&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; &lt;STRONG&gt;Policy Configuration Agent&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt; is here to help. By using natural language input, it translates your organization’s requirements into clear, actionable configurations and provides guidance on settings. IT admins can now create and validate policies easily —&lt;/SPAN&gt; &lt;SPAN data-contrast="none"&gt;making security and productivity goals easier to achieve.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;For organizations operating under strict compliance frameworks such as PCI, HIPAA, DISA STIG, or other industry-specific mandates, regulatory compliance is critical. The Policy Configuration Agent is designed to complement your existing compliance efforts. It checks for alignment with these standards and continuously audits your environment to support ongoing monitoring. The agent adds expertise and efficiency — helping flag deviations before they become risks so IT teams can continue to maintain a secure, compliant posture with greater agility and scalability. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;The Policy Configuration Agent reviews a document and recommends steps to fulfill unmatched requirements in Intune.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Unused or outdated devices aren’t just clutter — they’re a security risk. Every unmanaged endpoint increases the chance of vulnerabilities and compliance gaps. The &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Device Offboarding Agent&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt; takes the guesswork out of cleanup by scanning your entire digital estate to identify devices that no longer belong. It offers an efficient, straightforward way to offboard those devices from your organization, helping maintain the hygiene of the digital estate and helping reduce the attack surface.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;The Device Offboarding Agent provides a summary including reasoning for removing devices and recommended actions to offboard them.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;All three agents are currently rolling out to preview and can be found under “Agents” on the left side of the Intune portal once rolled out.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;To make the agents easily accessible and teams get started more quickly, we are excited to announce that Security Copilot will be available to all Microsoft 365 E5 customers.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Rollout starts today for existing Security Copilot customers with Microsoft 365 E5 and will continue in the upcoming months for all Microsoft 365 E5 customers. Customers will receive 30 day advanced notice before activation. Learn more: &lt;/SPAN&gt;&lt;A href="https://aka.ms/SCP-Ignite25" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;https://aka.ms/SCP-Ignite25&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Explore data with assistive AI&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;Copilot is there to assist you in your daily IT work — delivering guidance when and where you need it. You can use everyday language with Copilot chat to gain deep insights and get actionable recommendations, making it even easier to manage your environments. Copilot chat enables you to quickly access and manage all your endpoints including Windows 365 Cloud PCs.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="none"&gt;When you need to dive deeper into your data and take action on it, Copilot is there to help. The explorer experience allows you to interact with data using natural language queries and view customized data sets. There's even more flexibility in the data queries you can explore, and we are consistently broadening the range of data available for Copilot to reason over, which now includes your &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Autopilot&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;, &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;Endpoint Privilege Management&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;(EPM), and &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&lt;STRONG&gt;Advanced Analytics&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;data&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Build the foundation for secure AI deployments&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Every action and rollout must be secure, compliant, and predictable. Intune is building that foundation with two capabilities that keep IT in control today and prepare for agentic workflows tomorrow.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IT admins face a flood of requests across multiple portals. Soon, those requests won’t just come from people — they’ll come from agents recommending actions. That’s why we’re introducing &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;admin tasks&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;,&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; a centralized view for high-priority items, so admins can act quickly on what matters most. Today, that includes critical approvals like elevation requests, multi-admin approvals, and security tasks. Expected in the first quarter of calendar year 2026, agent-driven approval needs will appear here too, keeping control firmly in IT’s hands.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Admin tasks is a consolidated list helping IT admins focus on what matters most from a centralized place.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Changes to the environment should start small, &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;validate&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; stability and &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;impact&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;, and then scale with confidence. Intune introduces &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;deployments&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;, a controlled, phased approach to rollouts. This capability brings ring-based&lt;STRONG&gt; &lt;/STRONG&gt;deployments&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;—&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;already proven in &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Windows Autopatch&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;—&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;into application workloads, helping IT apply changes safely across the fleet. &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Looking ahead, deployments&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; will play a critical role in rolling out AI-driven experiences, ensuring every change is &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;rolled out in &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;phases&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;, minimizing ri&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;sks&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; and downtime&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;. Deployments &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;is&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; now in limited private preview.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Discover improved operational recovery and resilience&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Recovering a Windows device boot failure used to mean hands-on, one-at-a-time fixes. Intune introduces a new feature, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;recovery&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, for remote management of the Windows Recovery Environment (WinRE) at scale. IT admins can respond to mass outages or tailor recovery with custom scripts, all without being physically present. IT admins gain fleet-wide visibility into which devices are in WinRE and their recovery readiness, making it possible to act quickly and confidently. Security is included, with actions authenticated and authorized using hardware-bound recovery certificates. Recovery is in limited, private preview.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Keeping devices secure and up to date often means balancing update schedules with the end user experience and mission-critical operations. Intune introduces &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;maintenance windows&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; for cloud-managed devices, giving IT precise control over when updates — including OS, drivers, and firmware — can run. This capability helps minimize disruption and improve patch compliance while delivering the agility and security of a cloud-based management platform, without the complexity and cost of on-prem infrastructure. Maintenance windows is expected to roll out to preview in the first quarter of calendar year 2026.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Windows Autopatch introduces proactive &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;update readiness&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; capabilities that help IT teams identify blockers before deployment begins. With tenant-wide inventory views, admins can see their Windows fleet update posture across OS, drivers, and firmware. Readiness checkups surface “at risk” devices early, highlighting issues like connectivity gaps, safeguard holds, or hotpatch prerequisites. These capabilities reduce surprises and accelerate compliance. Update readiness is now available in preview as part of Windows Autopatch. &lt;/SPAN&gt;&lt;A href="https://aka.ms/ManageWindowsUpdateIgniteBlog2025" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Read the blog&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; for more information.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Endpoint Privilege Management empowers IT administrators to enable users to run elevated applications under the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;current user's identity&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, improving the user experience by preserving personal data and settings. Support for elevation requests from &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;non-primary device users&lt;/STRONG&gt; &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;has been added, ensuring users utilizing shared devices can leverage the value of EPM and elevate critical applications. The new &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;EPM readiness dashboard&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;offers comprehensive oversight of rollouts and provides rule recommendations. Additionally, expected to roll out in the first quarter of calendar year 2026, IT administrators will be able to create elevation rules that allow users to change certain network configuration settings, supporting productivity without compromising security.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We’re also excited to announce several previewed capabilities are now generally available. &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Installer script support for Enterprise App Catalog apps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; gives IT admins the flexibility to include PowerShell scripts when deploying apps through Intune — ideal for handling prerequisites, custom parameters, or post-install steps at scale. Support for Win32 apps is expected in the first quarter of calendar year 2026. &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/configure-authorized-apps-deployed-with-a-managed-installer?utm_source=chatgpt.com" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;App Control for Business with Managed Installer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; allows IT admins to designate the Intune Management Extension as a managed installer so apps deployed through Intune are recognized as trusted when your policy allows managed installers — helping reduce the risk of unapproved or malicious code. Finally, &lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/configuration/windows-backup/?utm_source=chatgpt.com&amp;amp;tabs=intune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Backup for Organizations&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;, configurable through Intune, enables IT to back up and restore user settings and Microsoft Store app lists during enrollment or recovery, helping minimize downtime and helping users return to a known-good state fast.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Learn how Intune is driving impact for customers&lt;/H2&gt;
&lt;img /&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Intune delivers impact at enterprise scale: at PepsiCo, unified endpoint management helped &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;cut device build time by 50%&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt; and drove a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;99% drop in sign-in time for shift workers&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, reducing costs while boosting reliability across a global fleet. Read &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en/customers/story/25526-pepsico-microsoft-intune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;the full story&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;As organizations modernize on Intune, they’re also positioned to harness emerging AI-powered capabilities like Copilot in Intune to surface risk insights faster, guide troubleshooting, and automate routine work. LTI Mindtree integrated Microsoft Security Copilot with Microsoft Intune, Defender XDR, Threat Intelligence, and Sentinel to automate and enhance threat detection and response. Chandan Pani, Chief Information Security Officer says “Microsoft Security Copilot is our true AI partner in cyber defense. It provides AI-enabled automated incident response, integrated threat intelligence, and advanced threat analysis. With adaptive detection engineering, it improves future responses and generates more accurate detection rules.” Read &lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en/customers/story/19319-lti-mindtree-microsoft-intune" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;the full story&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; to learn more.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Join us at Ignite&lt;IMG /&gt;&lt;/H2&gt;
&lt;img /&gt;
&lt;P&gt;Whether you’re in person or online, there are great sessions you can attend:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Online and in-person:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK341?source=sessions" target="_blank" rel="noopener"&gt; BRK 341 What's new in Intune: empower IT, protect endpoints &amp;amp; optimize with AI &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK340?source=sessions" target="_blank" rel="noopener"&gt; BRK 340 Demystify Zero Trust with Intune: cloud-connected, secure, and AI-ready end &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK242?source=sessions" target="_blank" rel="noopener"&gt; BRK 242 Top Essentials for an Integrated, AI-Ready Security Foundation &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Hands-on lab (in-person only):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/LAB542?source=sessions" target="_blank" rel="noopener"&gt; LAB 542 Microsoft Zero Trust Workshop Lab: Securing Identities and Devices with Intune &amp;amp; Entra &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Additional sessions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;That’s not all — check out these hybrid sessions covering Security, Copilot, Windows, and more!&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK238?source=sessions" target="_blank" rel="noopener"&gt; Transform security and IT with Security Copilot agents &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK242?source=sessions" target="_blank" rel="noopener"&gt; Top Essentials for an Integrated, AI-Ready Security Foundation &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK244?source=sessions" target="_blank" rel="noopener"&gt; Security Copilot: Protect at the speed and scale of AI &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK258?source=sessions" target="_blank" rel="noopener"&gt; Inside Windows Security, from client to cloud &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK344?source=sessions" target="_blank" rel="noopener"&gt; Agents at Work: Windows Powers the Era of Intelligent Productivity &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK345?source=sessions" target="_blank" rel="noopener"&gt; Resilient by design: How Windows has evolved with new recovery tools &lt;/A&gt;&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK346?source=sessions" target="_blank" rel="noopener"&gt; Secure &amp;amp; Manage the Most Productive, Intelligent OS: Windows 11 &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;For more information on announcements, read the blogs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://aka.ms/SCP-Ignite25" target="_blank" rel="noopener"&gt; Learn more about Security Copilot being included in Microsoft 365 E5&lt;/A&gt;.&lt;/LI&gt;
&lt;LI style="line-height: 1.7; margin-bottom: 12px;"&gt;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fblogs.windows.com%2Fwindowsexperience%2F%3Fp%3D180032&amp;amp;data=05%7C02%7Ckaitlin.sechrest%40microsoft.com%7C71daaf334a864bad7ff708de11a34e44%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638967590731809090%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=YomzXcxegn0CkxPUOQgejdFRKXfCApsAetnwIGIRVyU%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt; Read about all the latest updates for Windows. &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt; Microsoft Intune Blog &lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt; LinkedIn &lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt; @MSIntune &lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Nov 2025 19:43:34 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-at-ignite/ba-p/4471043</guid>
      <dc:creator>Jason_Roszak</dc:creator>
      <dc:date>2025-11-26T19:43:34Z</dc:date>
    </item>
    <item>
      <title>What’s New in Microsoft Intune: October 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-october-2025/ba-p/4464595</link>
      <description>&lt;P&gt;Last week, someone asked me what keeps me up at night when it comes to endpoint management. The answer surprised them; it was not the sophisticated threats or latest vulnerabilities we read about in headlines. What concerns me most is the friction between security and productivity, that invisible tax we've all paid for years when security can get in the way of getting work done. October marks &lt;A href="https://www.microsoft.com/en-us/security/blog/2025/10/01/cybersecurity-awareness-month-security-starts-with-you/?msockid=213d829269416b630d7f94b868e96a21" target="_blank" rel="noopener"&gt;Cybersecurity Awareness Month&lt;/A&gt;, and this year's theme, "Security Starts with You," resonates deeply with the work our team has been doing. The features landing in Microsoft Intune this month reflect a fundamental shift in how we think about security — not as a barrier, but as an enabler. From enrollment-time grouping that helps IT teams surface issues faster to new Endpoint Privilege Management (EPM) capabilities that make IT professionals' lives easier.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Faster reporting with new enrollment time grouping reports&lt;/H2&gt;
&lt;P&gt;There's no single reason why a device might not end up in the right group during provisioning — and that's exactly what makes it so hard to troubleshoot. For teams managing hundreds or thousands of devices, these blind spots add up fast. That’s why I’m glad the enrollment time grouping failures report is now generally available in the Microsoft Intune admin center. This helps eliminate blind spots and gives IT teams visibility to address issues proactively. The new capability surfaces failures across Windows Autopilot device preparation provisioning, Android Enterprise fully managed devices, Android corporate-owned work profile devices, and Android Enterprise dedicated devices.&lt;/P&gt;
&lt;P&gt;Administrators can now navigate enrollment time grouping failures in the admin center to gain more visibility of devices that didn't become members of their specified static device groups during enrollment. The enrollment time grouping failures report is available in the admin center under &lt;STRONG&gt;**Devices**&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;**Monitor**&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;**Enrollment time grouping failures**&lt;/STRONG&gt;. Now updated information is displayed within 20 minutes, helping device configuration removal when a device is not part of the required group.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Identity-aware privilege management&lt;/H2&gt;
&lt;P&gt;The new elevate as current user capability in EPM gives IT admins finer control over how elevation works. When creating rules, you can now specify whether an elevated process runs under the user’s own account or the EPM default virtual account.&lt;/P&gt;
&lt;P&gt;Why does this matter? Because some applications, especially during runtime, fail when they lose awareness of the user’s profile, environment variables, or registry settings. Processes such as user customization, accessing profile information, or obtaining a server license require that the system maintains the context of the user with elevated privileges. With this new mode, those processes keep the user’s identity, so they work as expected, while still maintaining full audit trails.&lt;/P&gt;
&lt;P&gt;Zero Trust principles favor virtual account elevation, which strips user context from tokens entirely. When applications need user profile paths or settings to function correctly, the elevate as current user capability gives you that flexibility while maintaining control through scoped rules and audit trails. Configure these elevation options based on your specific application requirements — learn more in the &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-elevation-settings" target="_blank" rel="noopener"&gt;elevation settings documentation&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Improving security posture visibility with new EPM Overview dashboard&lt;/H2&gt;
&lt;P&gt;Greenfield organizations moving to standard user accounts for the first time needed a better way to identify deployment targets, gauge health, and measure impact. The new EPM Overview Dashboard provides a centralized view in Intune showing readiness for migrating local admin accounts to standard users, including managed versus unmanaged elevation activity and trends.&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1: Screenshot of the new EPM Overview Dashboard&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;This new dashboard (shown above) answers three critical questions. It identifies which users are experiencing friction, shows what changes improve user experience based on actual elevation patterns, and enables adjustments without manual data entry. Enterprise IT security teams gain faster policy refinement, improved security posture through removal of persistent admin rights, and reduced helpdesk load by identifying candidates for auto-approval rules.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Updated network endpoints for Azure Front Door&lt;/H2&gt;
&lt;P&gt;Behind every feature you use in Microsoft Intune runs an infrastructure designed for security, reliability, and performance. As part of Microsoft's ongoing &lt;A href="https://www.microsoft.com/en-us/trust-center/security/secure-future-initiative?msockid=213d829269416b630d7f94b868e96a21" target="_blank" rel="noopener"&gt;Secure Future Initiative&lt;/A&gt;, network service endpoints for Microsoft Intune are adopting new IP addresses defined by Azure Front Door. This change affects customers using a firewall allowlist that allows outbound traffic based on IP addresses or Azure service tags.&lt;/P&gt;
&lt;P&gt;This improvement supports better alignment with modern security practices and makes it easier over time for organizations using multiple Microsoft products to manage and maintain their firewall configurations. It's the kind of behind-the-scenes work that doesn't make headlines but reinforces the secure foundation upon which everything else depends. If you're managing third-party firewalls or proxy configurations, now is the time to review your allowlists and ensure these endpoints are included. Detailed information about all IP addresses that should be allowed for use by Intune client and host services is available in the Network endpoints for Microsoft Intune documentation under Intune core service &lt;A href="https://review.learn.microsoft.com/en-us/intune/intune-service/fundamentals/intune-endpoints?branch=main&amp;amp;branchFallbackFrom=pr-en-us-18410&amp;amp;tabs=north-america#intune-core-service" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Windows Autopilot delivers secure-by-default device provisioning&lt;/H2&gt;
&lt;P&gt;A quick update on an item we shared in &lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune-august-2025/4445612" target="_blank" rel="noopener"&gt;August&lt;/A&gt;: the ability for the Enrollment Status Page to install Windows security updates during out-of-box experience (OOBE) is now scheduled for January 2026. While the setting is visible in your profiles, updates to Windows are not yet available during OOBE. This extra time allows the team to ensure a reliable, seamless experience for every device.&lt;/P&gt;
&lt;P&gt;Administrators continue to have complete authority over when updates are installed, using the enrollment status page (ESP) to manage configurations. This applies to both Intune-managed devices and Windows Autopilot scenarios, ensuring the core benefit remains consistent. Please read the &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/windows-enrollment-status?source=docs%22%20\l%20%22install-windows-monthly-security-update-releases" target="_blank" rel="noopener"&gt;Intune documentation&lt;/A&gt; for more details, requirements, and limitations.&lt;/P&gt;
&lt;P&gt;This aligns with the "Security starts with you" theme Microsoft has been emphasizing for Cybersecurity month. Devices that are patched from the moment users first ‘sign in’ reduce the window of vulnerability that comes with delayed updates.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Looking ahead&lt;/H2&gt;
&lt;P&gt;In summary, October's updates reflect what IT teams have been working toward — security that empowers rather than restricts. When the tools supporting security work this seamlessly, "Security starts with you" becomes more than a theme, it becomes the foundation every device is built on. I encourage you to explore these capabilities in your own environment and share your experiences. The &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune" target="_blank" rel="noopener"&gt;Microsoft Intune community&lt;/A&gt; thrives on feedback from IT professionals solving real-world challenges, and your insights help shape where we invest next.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 18:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-october-2025/ba-p/4464595</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2025-10-30T18:00:00Z</dc:date>
    </item>
    <item>
      <title>Your guide to Intune at Microsoft Ignite 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/your-guide-to-intune-at-microsoft-ignite-2025/ba-p/4464594</link>
      <description>&lt;img /&gt;
&lt;P&gt;The Microsoft Intune team is gearing up for Microsoft Ignite, happening November 17-21 in San Francisco! Whether you'll be joining in person or online, this guide is the best place to learn all about the sessions and experiences where you can connect with the Intune team, learn about the latest innovations, and boost your skills. &lt;A href="https://register.ignite.microsoft.com/" target="_blank" rel="noopener"&gt;Don't forget to register today&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Attendees will have opportunities to learn about a range of product innovations and scenarios, from streamlining endpoint management to simplifying operations and improving security. Discover how Security Copilot can help safeguard your organization and streamline productivity — ensuring you stay informed and prepared for the future of secure endpoint solutions.&lt;/P&gt;
&lt;P&gt;We’ll continue to add times and dates here as soon as the schedule is released and the session builder tool is up and running for you to personalize your agenda.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Don’t forget to bookmark this post at &lt;/STRONG&gt;&lt;A href="https://aka.ms/IntuneAtIgnite" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;https://aka.ms/IntuneAtIgnite&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt; for quick and easy reference!&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Featured sessions&lt;/H2&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK341?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;What's new in Intune: empower IT, protect endpoints &amp;amp; optimize with AI&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Wednesday November 19th, 2:45pm-3:30pm PST&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Discover what’s new in Microsoft Intune — from exploring deeper data with Copilot, simplifying workflows and cloud native deployments, to scaling with agents. Learn about the latest innovation across platforms to build resilient, secure, and productive environments, to stay ahead of rapidly evolving threats, app updates and device compliance. Empower IT, protect endpoints, and optimize with AI to get there.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK340?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Demystify Zero Trust with Intune: cloud-connected, secure, and AI-ready endpoints&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thursday November 20th, 11:00am-11:45am PST&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;Managing endpoints in the cloud is a fundamental piece of the Zero Trust puzzle and of delivering the optimal AI experience for business. In this session, we’ll demystify what that means in practice. See how Microsoft Intune brings Zero Trust to life by connecting device and app management, compliance, and threat protection. We’ll show how cloud-native management establishes a stronger security foundation and enables safe, scalable adoption of AI. Strengthen endpoint protection across Windows, macOS, iOS, and Android—helping IT teams stay ahead of threats while empowering employees to work productively and securely from anywhere.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Microsoft Intune sessions at a glance&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK341?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;What's new in Intune: empower IT, protect endpoints &amp;amp; optimize with AI &lt;/STRONG&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK340?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Demystify Zero Trust with Intune: cloud-connected, secure, and AI-ready endpoints&lt;/STRONG&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/LAB542?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Zero Trust Lab: Securing Identities and Devices with Intune &amp;amp; Entra &lt;/STRONG&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Related sessions&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK238?source=sessions" target="_blank" rel="noopener"&gt;Transform security and IT with Security Copilot agents &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK242?source=sessions" target="_blank" rel="noopener"&gt;Top Essentials for an Integrated, AI-Ready Security Foundation &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK244?source=sessions" target="_blank" rel="noopener"&gt;Security Copilot: Protect at the speed and scale of AI &lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK258?source=sessions" target="_blank" rel="noopener"&gt;Inside Windows Security, from client to cloud&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK344?source=sessions" target="_blank" rel="noopener"&gt;Agents at Work: Windows Powers the Era of Intelligent Productivity&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK345?source=sessions" target="_blank" rel="noopener"&gt;Resilient by design: How Windows has evolved with new recovery tools&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK346?source=sessions" target="_blank" rel="noopener"&gt;Secure &amp;amp; Manage the Most Productive, Intelligent OS: Windows 11&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Dive deep into latest product updates&lt;/H2&gt;
&lt;P&gt;Last year, our Intune sessions at Ignite generated incredible buzz. One breakout alone drew several thousand attendees — earning a spot as one of the top attended sessions of the entire week!&lt;/P&gt;
&lt;img&gt;Last year, thousands of attendees learned how Intune and AI could help analyze large volumes of data to optimize endpoint performance and take action to mitigate risks.&lt;/img&gt;
&lt;P&gt;Join this year’s in-depth breakout sessions to find out how Intune is evolving to help you tackle complex endpoint management challenges and use innovative solutions to protect against threats at the speed and scale of AI.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK341?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;What's new in Intune: empower IT, protect endpoints &amp;amp; optimize with AI &lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Wednesday November 19th, 2:45pm-3:30pm PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Discover what’s new in Microsoft Intune — from exploring deeper data with Copilot, simplifying workflows and cloud native deployments, to scaling with agents. Learn about the latest innovations across platforms to build resilient, secure, and productive environments, to stay ahead of rapidly evolving threats, app updates, and device compliance. Empower IT, protect endpoints, optimize with AI to get there.&lt;/P&gt;
&lt;P&gt;Speakers: Jason Roszak, Eugenie Burrage&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK340?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Demystify Zero Trust with Intune: cloud-connected, secure, and AI-ready endpoints &lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thursday November 20th, 11:00am-11:45am PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Managing endpoints in the cloud is a fundamental piece of the Zero Trust puzzle and of delivering the optimal AI experience for business. In this session, we’ll demystify what that means in practice. See how Microsoft Intune brings Zero Trust to life by connecting device and app management, compliance, and threat protection. We’ll show how cloud-native management establishes a stronger security foundation and enables safe, scalable adoption of AI. Strengthen endpoint protection across Windows, macOS, iOS, and Android — helping IT teams stay ahead of threats while empowering employees to work productively and securely from anywhere.&lt;/P&gt;
&lt;P&gt;Speaker: Lior Bela, Sangeetha Visweswaren&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK344?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Agents at Work: Windows Powers the Era of Intelligent Productivity&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Tuesday November 18th, 2:30pm-3:15pm PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The future of work is here. See how Windows combines security, adaptability, cloud, and AI to empower organizations and people to create, decide, and grow.&lt;/P&gt;
&lt;P&gt;Speakers: Stefan Kinnestrand, Navjot Virk&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK258?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Inside Windows Security, from client to cloud&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thursday November 20th, 8:30am-9:15am PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The latest innovations across Windows — from client to cloud — are designed to improve your security posture and protect users, devices and data. Join this session to learn about the newest security releases and capabilities across Windows 11 and Windows 365, including features like administrator protection, token protection, protecting against malware, hotpatching, and more. We will also discuss how Cloud PC devices like Windows 365 Link are changing the game in Windows endpoints.&lt;/P&gt;
&lt;P&gt;Speakers: Katharine Holdsworth, Pratik Shah&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK238?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Transform security and IT with Security Copilot agents&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thursday November 20th, 8:30am-9:15am PST &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Automate tasks, strengthen defense, and accelerate response with Security Copilot agents — built by Microsoft, partners, or tailored by you for the unique challenges of your environment.&lt;/P&gt;
&lt;P&gt;Speakers: Sarat Subramaniam, Lizzie Heinze&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK242?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Top Essentials for an Integrated, AI-Ready Security Foundation&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thursday November 20th, 4:45pm-5:30pm PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;To stay ahead, organizations need a secure, identity-based foundation for your digital landscape. Learn what Microsoft Entra and Intune bring across the M365 stack to help you reach a Zero Trust security posture with more compliance and control in the era of AI. We’ll dive into top scenarios that bring to life what you need to maximize your Microsoft investment.&lt;/P&gt;
&lt;P&gt;Speakers: Joseph Dadzie, Mayaan Bar-Niv&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK244?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Security Copilot: Protect at the speed and scale of AI&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Wednesday November 19th, 1:30pm-2:15pm PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Security teams face relentless pressure, complexity, and fewer resources. With generative AI, we have the opportunity to change the game. Join Microsoft product leaders to see what’s new in Security Copilot and how it’s transforming security and IT work.&lt;/P&gt;
&lt;P&gt;Speaker: Dorothy Li, Dilip Radhakrishnan&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Upskill with hands-on experiences&lt;/H2&gt;
&lt;P&gt;Demos and hands-on labs are exclusively available to in-person attendees, offering a direct experience with the newest endpoint management and security features from Intune.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ignite.microsoft.com/en-US/sessions/BRK244?source=sessions" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Zero Trust Lab: Securing Identities and Devices with Intune &amp;amp; Entra&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Wednesday November 19th, 2:00pm-3:15pm PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Repeat: Thursday November 20th, 2:45pm-4:00pm PST&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Discover the enhanced Microsoft Zero Trust Workshop — now covering all six technical pillars. Explore how Intune and Entra secure identities and devices, with new implementation indicators and cross-pillar guidance. Build a tailored roadmap, track progress, and leverage the latest integrations to accelerate adoption and boost your security posture.&lt;/P&gt;
&lt;P&gt;Instructors: John Callaghan, Terrell Headen&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;And so much more!&lt;/H2&gt;
&lt;P&gt;Security is a core focus at Microsoft Ignite this year, with the Security Forum on November 17, deep dive technical sessions, theater talks, and hands-on labs designed for security leaders and practitioners. &lt;STRONG&gt;Join us in San Francisco, November 17–21, or online, November 18–20&lt;/STRONG&gt;, to learn why endpoint security and management are critical in today’s hybrid environments. At Ignite, endpoint management sessions and labs will help you secure devices, automate management, and integrate with AI-powered security tools.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Security Forum — Make day 0 count (November 17)&lt;/STRONG&gt; &lt;BR /&gt;Kick off with an immersive, in person pre-day focused on strategic security discussions and real-world guidance from Microsoft leaders and industry experts. If you’ll be there in person, make sure to select Security Forum during registration: &lt;A href="https://register.ignite.microsoft.com/" target="_blank" rel="noopener"&gt;Microsoft Ignite&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Join an Intune Product Roundtable at Ignite!&lt;/H2&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Don’t miss your chance to connect directly with the Intune product team and peers at our customer roundtables! These small-group sessions are your opportunity to:&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Share feedback and real-world experiences with the Intune team&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Dive deep into topics like AI-powered endpoint management, integrated security, Windows and Mac management, and more&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1.5; margin-bottom: 12px;"&gt;Influence the future direction of Intune by engaging with Product managers, engineers, and fellow IT leaders&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Ready to join?&lt;/H2&gt;
&lt;P&gt;Space is limited, if interested complete please &lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fforms.cloud.microsoft%2FPages%2FResponsePage.aspx%3Fid%3Dv4j5cvGGr0GRqy180BHbR-CgKDND-kxBpIXGfzsTQ89UMDkxQ0RTOUFVUFBMMklBTTI4V1NWS05NVS4u&amp;amp;data=05%7C02%7Cv-benohashi%40microsoft.com%7C82677ed7d8114e74acc208de1736077f%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638973717984680384%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=poCuBIvW6f8%2FNhm70Ff0dF81p2E2J%2BIPI6y%2BfVE74lo%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;this form&lt;/A&gt;. We look forward to hearing your insights and partnering to shape the future of endpoint management.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Windows Ignite Reception at the Levi's flagship store&lt;/H2&gt;
&lt;P&gt;Join us to celebrate 40 years of Windows at the Levi's® corporate headquarters in San Francisco. Wednesday, November 19th; 6:30-8:30 pm PST.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://msevents.microsoft.com/event?id=2732452856" target="_blank" rel="noopener"&gt;Register to attend&lt;/A&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Get a head start&lt;/H2&gt;
&lt;P&gt;Got questions that can’t wait until Ignite? &lt;A href="https://techcommunity.microsoft.com/event/techcommunitylive/tech-community-live-intune-edition/4453031" target="_blank" rel="noopener"&gt;Watch our latest Tech Community Live on demand&lt;/A&gt; to learn more about Microsoft Intune Suite, Copilot in Intune, Security, and cross-platform management.&lt;/P&gt;
&lt;P&gt;And be sure to &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-intune-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;bookmark the Microsoft Intune blog&lt;/A&gt; for news and announcements starting day one of Microsoft Ignite. We can’t wait to connect with you before, during, and after this year’s big event!&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2025 17:30:16 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/your-guide-to-intune-at-microsoft-ignite-2025/ba-p/4464594</guid>
      <dc:creator>Talal_Alqinawi</dc:creator>
      <dc:date>2025-11-07T17:30:16Z</dc:date>
    </item>
    <item>
      <title>10 ways Microsoft Intune supports a smooth upgrade to Windows 11</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/10-ways-microsoft-intune-supports-a-smooth-upgrade-to-windows-11/ba-p/4461797</link>
      <description>&lt;P&gt;&lt;EM&gt;Upgrade to Windows 11 with confidence — 10 Intune tips from Microsoft engineers, MVPs, and guides.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Windows 10 reached end of support on &lt;A href="https://aka.ms/Win10EOS-1014" target="_blank" rel="noopener"&gt;October 14, 2025&lt;/A&gt; for most editions. After this date, devices no longer receive new features, quality updates, security fixes, or support.&lt;/P&gt;
&lt;P&gt;Organizations that need more time can enroll eligible devices in the &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/when-to-use-windows-10-extended-security-updates/4102628" target="_blank" rel="noopener"&gt;Windows 10 Extended Security Updates (ESU) program&lt;/A&gt;, which provides critical security updates — but no new features or non-security fixes — for up to three additional years (through October 2028).&lt;/P&gt;
&lt;P&gt;For organizations planning or completing their migration to Windows 11, Intune plays a key role in managing upgrades smoothly. The following ten tips — drawn from Microsoft engineers and MVPs — offer practical guidance to help IT teams align stakeholders, validate readiness, and structure upgrade strategies.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;From readiness to rollout:&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Check out these 10 tips with Intune to streamline your Windows 11 migration&lt;/STRONG&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 1: Get leadership buy-in with a clear business case for Windows 11&lt;/H2&gt;
&lt;P&gt;Modernization starts with alignment at the top. MVP &lt;STRONG&gt;James Robinson&lt;/STRONG&gt;, with over 20 years of IT experience, explains why moving to Windows 11 can deliver benefits such as smoother device management, stronger security, and simplified hardware procurement. It’s also an opportunity to shift from legacy tools to cloud-native endpoint management with &lt;A href="https://learn.microsoft.com/en-us/mem/intune/fundamentals/what-is-intune" target="_blank" rel="noopener"&gt;Intune&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://skiptotheendpoint.co.uk/windows-10-is-dead-migrate-to-11-immediately/" target="_blank" rel="noopener"&gt;&lt;EM&gt;Explore James’s full perspective&lt;/EM&gt;&lt;/A&gt; on framing your business case.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 2: Prepare your foundation — verify hardware, policy, and enrollment readiness&lt;/H2&gt;
&lt;P&gt;Begin your Windows 11 migration by checking that every device is &lt;A href="https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment" target="_blank" rel="noopener"&gt;enrolled in Intune&lt;/A&gt;. Once enrolled, use &lt;A href="https://learn.microsoft.com/en-us/mem/analytics/overview" target="_blank" rel="noopener"&gt;Endpoint analytics&lt;/A&gt; to validate that devices meet Windows 11 requirements. Key considerations include licensing, hardware compatibility, and enrollment — all critical for reducing risk and supporting a smoother upgrade.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-11-cloud-native-migration-with-microsoft-intune/4434495" target="_blank" rel="noopener"&gt;&lt;EM&gt;Microsoft engineer Steven Hosking&lt;/EM&gt;&lt;/A&gt; outlines five steps to migrate Windows 10 domain-joined and co-managed devices to Windows 11.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 3: Free up disk space with Intune Remediations and Storage Sense&lt;/H2&gt;
&lt;P&gt;Low free disk space is a common cause of upgrade failures, especially on devices with smaller SSDs. Use &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remediations" target="_blank" rel="noopener"&gt;Remediations&lt;/A&gt; in Intune to deploy PowerShell scripts that check available storage, clean up locations like Recycle Bin and Downloads, and proactively notify users.&lt;/P&gt;
&lt;P&gt;For ongoing maintenance, pair this with &lt;A href="https://learn.microsoft.com/en-us/windows/configuration/storage/storage-sense?tabs=intune" target="_blank" rel="noopener"&gt;Storage Sense&lt;/A&gt;, a built-in Windows feature that automatically clears temporary and Recycle Bin files. While Storage Sense handles routine cleanup, custom Intune Remediations address additional scenarios — such as large user folders or legacy files — that Storage Sense doesn’t cover. Together, they provide a proactive, centrally managed way to keep devices upgrade ready.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://aka.ms/IntuneRemediationTipsFS" target="_blank" rel="noopener"&gt;&lt;EM&gt;Follow MVP Florian Salzmann’s&lt;/EM&gt;&lt;/A&gt; step-by-step guide to create and deploy Remediation scripts in Intune.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 4: Manage OS updates automatically with Windows Autopatch&lt;/H2&gt;
&lt;P&gt;Simplify your Windows 11 rollout with &lt;A href="https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/manage/windows-autopatch-manage-autopatch-groups" target="_blank" rel="noopener"&gt;Windows Autopatch&lt;/A&gt;. Start by reviewing Windows 11 readiness reports in Intune to confirm which devices meet upgrade requirements. Next, use Autopatch Groups to organize pilot and production rings. Autopatch supports multi-phase feature update deployments for these groups to stagger rollout timing and reduce risk. Throughout deployment, track progress and resolve upgrade blocks leveraging the feature update reports in Autopatch. This structured approach provides clear visibility and helps upgrades progress smoothly at scale.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/upgrade-to-windows-11-with-windows-autopatch-groups/4434497" target="_blank" rel="noopener"&gt;&lt;EM&gt;Check out the 4 steps to success&lt;/EM&gt;&lt;/A&gt; in the playbook from Microsoft engineer, Akash Malhotra.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 5: Run targeted, version-specific rollouts with feature update policies&lt;/H2&gt;
&lt;P&gt;When you need to manage Windows 11 upgrades outside of Autopatch—such as in highly customized environments—use feature update policies in Intune for direct control. These policies let you to deploy a specific Windows 11 version to selected device groups, keeping those devices on that current version until you decide to upgrade. This approach aligns to honor Microsoft safeguard holds to help prevent known issues.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/windows-10-feature-updates#upgrade-devices-to-windows-11" target="_blank" rel="noopener"&gt;&lt;EM&gt;Learn how to configure feature update policies&lt;/EM&gt;&lt;/A&gt; for Windows devices in Intune.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 6. Modernize provisioning with Intune and Windows Autopilot&lt;/H2&gt;
&lt;P&gt;Upgrading to Windows 11 is an ideal time to rethink your approach to provisioning. MVP Andrew Taylor recommends using hardware refresh cycles to switch from Microsoft Configuration Manager or on-premises methods to cloud-based provisioning with Intune and &lt;A href="https://learn.microsoft.com/en-us/autopilot/overview" target="_blank" rel="noopener"&gt;Windows Autopilot&lt;/A&gt;. This helps build a solid foundation for modern provisioning, enabling phased deployment and streamlining lifecycle management.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://andrewstaylor.com/2024/05/19/planning-your-intune-autopilot-migration/" target="_blank" rel="noopener"&gt;&lt;EM&gt;Read Andrew’s&lt;/EM&gt;&lt;/A&gt; post on planning an Intune Autopilot migration.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 7: Preserve user settings and app lists with Windows Backup for Organizations&lt;/H2&gt;
&lt;P&gt;Use Windows Backup for Organizations to capture user settings, personalization, and a list of installed Microsoft Store apps from Windows 10 before migration. These preferences can be restored during device enrollment when the user signs in to Windows 11 with the same Entra ID. This helps employees return to familiar configurations and quickly reinstall apps from their list — helping to reduce post-upgrade friction and improving user satisfaction.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/windows-backup-restore" target="_blank" rel="noopener"&gt;&lt;EM&gt;Learn how to configure Windows Backup for Organizations&lt;/EM&gt;&lt;/A&gt; in Intune and explore best practices.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 8: Bridge hardware delays with Windows 365 Reserve&lt;/H2&gt;
&lt;P&gt;When hardware refresh cycles don’t align with your timeline, Windows 365 Reserve — now in limited public preview — can enhance business continuity. By provisioning secure temporary Cloud PCs, you can keep your workforce productive while you plan upgrade waves at your own pace. Because these Cloud PCs are managed with Intune, you apply more consistent security policies and app deployment across physical and virtual endpoints during the transition.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhancing-business-continuity-windows-365-reserve-is-now-in-limited-public-previ/4441669" target="_blank" rel="noopener"&gt;&lt;EM&gt;Explore more about the limited public preview&lt;/EM&gt;&lt;/A&gt; and get practical guidance to plan upgrade waves.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 9: Treat your upgrade as a security milestone&lt;/H2&gt;
&lt;P&gt;A Windows 11 migration is an opportunity to strengthen and modernize endpoint security. MVP Simon Hartmann shares practical insights from enterprise deployments with Intune, illustrating how aligning upgrades with stronger security measures and future-ready policies can help reduce risk, streamline management, and improve compliance readiness.&lt;/P&gt;
&lt;P&gt;Use this stage to apply security baselines and enable features such as &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/protect/endpoint-security-app-control-policy" target="_blank" rel="noopener"&gt;App Control for Business&lt;/A&gt;. This baseline helps to ensure only trusted applications run and reviews device-level protections such as BitLocker, Microsoft Defender for Endpoint, and Secure Boot.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://aka.ms/IntuneSimonH" target="_blank" rel="noopener"&gt;&lt;EM&gt;Explore Simon’s tips&lt;/EM&gt;&lt;/A&gt; to set the stage for a more secure, future-ready upgrade with Intune.&lt;/EM&gt;&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Tip 10: Maintain your new Windows 11 security posture with faster patching&lt;/H2&gt;
&lt;P&gt;After upgrading, keeping devices secure means minimizing the window between patch release and protection. Hotpatch updates — available for Windows 11 Enterprise, version 24H2 — apply &lt;A href="https://learn.microsoft.com/en-us/windows/deployment/update/release-cycle#monthly-security-update-release" target="_blank" rel="noopener"&gt;Monthly B release security updates&lt;/A&gt; without waiting for a reboot. This helps organizations reduce exposure gaps and maintain compliance with minimal disruption. In the Intune admin center, you can configure Hotpatch as part of a Windows quality update policy for eligible devices, so updates take effect promptly.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates" target="_blank" rel="noopener"&gt;&lt;EM&gt;Learn how to configure Hotpatch&lt;/EM&gt;&lt;/A&gt; and apply quality-update policies in Intune.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What’s new Intune:&lt;/STRONG&gt; &lt;A href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;What's new in Microsoft Intune - Microsoft Intune | Microsoft Learn&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;__________________________________________________________________________________________________________________________________________________________________&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the&amp;nbsp;&lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftechcommunity.microsoft.com%2Fcategory%2Fmicrosoftintune%2Fblog%2Fmicrosoftintuneblog&amp;amp;data=05%7C02%7Cv-benohashi%40microsoft.com%7C25015886c41a42fe107b08de10c63528%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C638966640658746542%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=NFYsOeCT4eu6VD5frE0%2BW9Q09hXBQ7qdE3KZHe82%2F68%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Microsoft Intune Blog | Microsoft Community Hub&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;BR /&gt;&lt;STRONG&gt;_________________________________________________________________________________________________________________________________________________________________________________________&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2025 20:46:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/10-ways-microsoft-intune-supports-a-smooth-upgrade-to-windows-11/ba-p/4461797</guid>
      <dc:creator>LiMiller</dc:creator>
      <dc:date>2025-10-22T20:46:49Z</dc:date>
    </item>
    <item>
      <title>Intune partner portal adds Intel vPro integration</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/intune-partner-portal-adds-intel-vpro-integration/ba-p/4461760</link>
      <description>&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Hardware-level management meets cloud-native simplicity: Intel vPro now in Intune Partner portal&lt;/H2&gt;
&lt;P&gt;IT pros regularly tell us about the challenges of managing devices that go offline, crash, or become unresponsive. In a world where company devices are spread across work sites, you can’t always send a technician to help, or wait for a device to be shipped, fixed, and returned.&lt;/P&gt;
&lt;P&gt;We're excited to announce the arrival of Intel vPro® Fleet Services to the Microsoft Intune Partner portal, bringing hardware-level remote management to your Intune workflows.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;A brief history&lt;/H2&gt;
&lt;P&gt;Last year, we welcomed the Dell Management Portal to this growing ecosystem of OEM integrations, joining the HP Connect Portal announced in spring of 2023 and the Surface Management Portal.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Announcing Intel vPro integration in the Intune admin center&lt;/H2&gt;
&lt;P&gt;Intel vPro® Fleet Services can be accessed through the Intune admin center, streamlining access to these hardware-level device management capabilities for Intel vPro®-enabled devices (8th Gen Intel Core processors and newer):&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;STRONG&gt;Hardware-level access.&lt;/STRONG&gt; Manage devices even when they're powered off or the operating system has crashed — capabilities that traditional software-only management can't deliver.&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;STRONG&gt;Secure authentication.&lt;/STRONG&gt; Leverage your existing Microsoft Entra ID credentials and conditional access policies for all hardware management operations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;&lt;STRONG&gt;Out-of-band management.&lt;/STRONG&gt; Perform critical operations including:&lt;BR /&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;Remote power-on for maintenance and updates&lt;/LI&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;BIOS-level diagnostics and troubleshooting&lt;/LI&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;System recovery and re-imaging operations&lt;/LI&gt;
&lt;LI style="line-height: 1; margin-bottom: 12px;"&gt;Security compliance monitoring for offline devices&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Get started with Intel vPro Fleet services&lt;/H2&gt;
&lt;P&gt;IT admins can access these enterprise-grade capabilities with existing Intune licensing — no extra fees or infrastructure are required.&lt;/P&gt;
&lt;P&gt;Intel vPro® Fleet Services will appear in the Partner portals tab in the Devices blade of the Intune admin center.&lt;/P&gt;
&lt;img&gt;The Microsoft Intune Partner portals screen&lt;/img&gt;
&lt;P&gt;Selecting Intel vPro® Fleet Services will authenticate using your Microsoft Entra tenant credentials and connect you directly to the Intel vPro® Fleet Services management portal.&lt;/P&gt;
&lt;img&gt;The Intel vPro Fleet Services home screen&lt;/img&gt;
&lt;P&gt;We look forward to sharing more updates on our OEM collaborations in the future.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Let us know what you think&lt;/H2&gt;
&lt;P&gt;We read the comments on posts like this and consolidate your feedback from the &lt;A href="https://aka.ms/FeedbackForIntune" target="_blank" rel="noopener"&gt;Microsoft Intune feedback portal&lt;/A&gt;. Your questions and comments inform and shape our product roadmap, so please continue to share your feedback. Subscribe to this blog for the latest official news, and &lt;A href="https://www.linkedin.com/in/liorbela/" target="_blank" rel="noopener"&gt;follow me on LinkedIn&lt;/A&gt; to get the latest updates as soon as I do.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 21:35:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/intune-partner-portal-adds-intel-vpro-integration/ba-p/4461760</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2025-10-15T21:35:08Z</dc:date>
    </item>
    <item>
      <title>What’s New in Microsoft Intune: September 2025</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-september-2025/ba-p/4457065</link>
      <description>&lt;P&gt;The most resilient IT environments aren't just reactive, they're built with hardware-level contingencies, flexible deployment methods, and automation that works asynchronously. Behind every new capability is our team of Microsoft Intune engineers, who think about the real-world problems IT admins face every day.&lt;/P&gt;
&lt;P&gt;They're the ones building solutions that address questions like, 'What if a device goes offline and you can't reach it?' or 'How can we make a complex app installation less likely to fail?' This month’s updates are the result of that ongoing work — updates that give you early access to offline Intel vPro devices, PowerShell scripts for those fragile app deployments, and day-zero compatibility for Apple’s new operating systems. We’re also excited to share new AI enhancements that can optimize Cloud PC experiences and reduce costs.&lt;/P&gt;
&lt;P&gt;These aren't just new capabilities; they're our way of getting ahead of and solving challenges that impact customers’ business every day.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Hardware-level management adds business resilience&lt;/H2&gt;
&lt;P&gt;When a device won't boot, traditional remote management fails. Companies with Intel vPro devices now have a better option. Microsoft has worked with Intel vPro Fleet Services, bringing hardware-level management directly into the Intune admin center. IT admins can recover and troubleshoot devices even when they're powered off. With &lt;A href="https://learn.microsoft.com/en-us/entra/fundamentals/what-is-entra" target="_blank" rel="noopener"&gt;Microsoft Entra ID&lt;/A&gt; single sign-on, IT teams gain authenticated access without requiring additional infrastructure or licensing.&lt;/P&gt;
&lt;P&gt;After gaining access, IT teams can use Intel Active Management Technology (AMT) to get out-of-band management independent of the primary operating system. Teams can perform BIOS and OS recovery of Intel vPro devices from 2018 or later. This capability can help to build resilience for an Intel-powered fleet of devices. When standard remote access fails, hardware-level management ensures IT teams can still reach and recover critical business devices, helping to restore availability and maximize user productivity.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Comprehensive Apple device management on day zero&lt;/H2&gt;
&lt;P&gt;Apple's iOS/iPadOS and macOS 26 releases bring new capabilities that organizations want to use immediately, but they can sometimes introduce configuration requirements that can't wait. Our Intune team has extensively evaluated existing Intune endpoint management functionality against the changes introduced with Apple’s new operating systems to ensure compatibility. We added new settings introduced in the latest Intune releases and updated our OS version support statement to align with Apple's recommendations, ensuring end users can safely use new capabilities from Apple on day zero. The settings catalog now supports new iOS/iPadOS and macOS settings, including audio accessory configuration, Safari controls, security restrictions, app defaults, and web filtering. For more information on these settings, read our recent blog on &lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/day-zero-support-for-iosipados-and-macos-26/4454161" target="_blank" rel="noopener"&gt;day zero support for iOS/iPadOS and macOS 26&lt;/A&gt;.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Updated Purebred derived credentials experience&lt;/H2&gt;
&lt;P&gt;Companies using Purebred-derived credentials for personal user affinity devices will benefit from Intune Company Portal support for the improved Purebred 3.0 experience available with iOS 26.&lt;SUP&gt;&lt;A href="#community--1-_note1" target="_self"&gt;*&lt;/A&gt;&lt;/SUP&gt; For devices without user affinity, we're maintaining our established support model: the three most recent OS versions receive full support, while older versions within range remain allowed with baseline functionality.&lt;/P&gt;
&lt;P&gt;This approach helps to ensure that Apple device management doesn't create deployment delays. IT admins can confidently update to the latest Apple operating systems knowing that Intune capabilities will work as expected from day one.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;Installer script support that delivers control for application deployment&lt;/H2&gt;
&lt;P&gt;Application deployment has traditionally been limited to command-line configurations, which can restrict customization and preparation work that complex installations often require. IT admins need the flexibility to configure environments, validate prerequisites, and perform post-installation tasks within a single deployment workflow.&lt;/P&gt;
&lt;P&gt;Intune now supports PowerShell installer scripts for Enterprise Application Management (EAM) catalog apps, giving IT admins the option to use the command-line approach with flexible scripting capabilities.&lt;SUP&gt;&lt;A href="#community--1-_note2" target="_self"&gt;**&lt;/A&gt;&lt;/SUP&gt; Admins can upload PowerShell scripts for installation and uninstallation processes, with Intune executing these scripts using the same privileges and context specified by the app installer.&lt;/P&gt;
&lt;P&gt;This capability enables IT teams to configure user environments before installation, validate that installation requirements are met, prepare the operating system for specific applications, and perform cleanup or configuration tasks after installation completes. These scripts can report success and failure through standard exit codes while maintaining the same deployment reporting that administrators expect.&lt;/P&gt;
&lt;P&gt;With installer script support, administrators can build sophisticated deployment workflows and ensure applications are installed correctly across diverse environments. If you are not yet managing applications in Intune, &lt;A href="https://aka.ms/intuneapppackaging" target="_blank" rel="noopener"&gt;read our blog&lt;/A&gt; on this exciting app packaging partner offer.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 26px; color: #333333;"&gt;AI-powered insights optimize Cloud PC experiences&lt;/H2&gt;
&lt;P&gt;Copilot in Intune now can reason over data about Windows 365 Cloud PCs, enabling administrators to gain insights into connectivity trends, optimize license usage, identify and resolve performance issues, and detect deployment gaps in Cloud PCs through AI-powered analysis and recommendations.&lt;/P&gt;
&lt;P&gt;This represents an evolution of endpoint management cloud-first scenarios where traditional device metrics sometimes can’t tell the complete story. By bringing AI-powered insights to Cloud PC management, organizations can ensure their virtual desktop investments deliver maximum value while maintaining optimal user experiences. For a deep dive into the specific Copilot in Intune capabilities, check out this &lt;A href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/extending-copilot-in-intune-to-manage-windows-365-cloud-pcs/4453398" target="_blank" rel="noopener"&gt;blog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;From hardware-level recovery capabilities to cloud-based AI insights, this month's updates are all about making endpoint management more resilient, easier to update and deploy, and empowering IT admins to make more informed decisions more quickly and cost-effectively. And as always, we look forward to your feedback—let us know what you think in the comments below.&lt;/P&gt;
&lt;P style="margin-top: 10px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-size: 10px; font-style: italic; font-weight: 400; color: #333333;"&gt;&lt;a id="community--1-_note1" class="lia-anchor"&gt;&lt;/a&gt;&lt;SUP&gt;*&lt;/SUP&gt;If your company is planning to upgrade to the latest version of Purebred, the IT admin should update to Company Portal version 5.2509.0 to ensure compatibility.&lt;/P&gt;
&lt;P style="margin-top: 10px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-size: 10px; font-style: italic; font-weight: 400; color: #333333;"&gt;&lt;a id="community--1-_note2" class="lia-anchor"&gt;&lt;/a&gt;&lt;SUP&gt;**&lt;/SUP&gt;EAM catalog app script support is not yet available in Government Community Cloud High (GCCH) environments.&lt;/P&gt;
&lt;HR /&gt;
&lt;P style="font-size: 14px;"&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/bg-p/MicrosoftEndpointManagerBlog" target="_blank" rel="noopener"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt; or &lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; on X to continue the conversation.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 18:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-september-2025/ba-p/4457065</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2025-09-29T18:00:00Z</dc:date>
    </item>
  </channel>
</rss>

