Microsoft Intune: Week of June 29, 2026 (Service release 2606)
Microsoft announcement
App management
Available macOS PKG apps update automatically when you upload a new version
For available macOS PKG apps, updates now deploy to devices automatically when the same app policy was updated with a new app version, so users no longer need to select Install or Reinstall in Company Portal to get the latest version. When you edit an existing available app policy with a newer version of the app that uses the same bundle ID, Intune deploys the update to the device automatically.
Automatic updates apply when both of the following are true:
- You upload an updated version of the app to Intune.
- The user already installed the app on the device.
This behavior requires the Microsoft Intune management agent for macOS version 2606.013 or later.
For more information, see Add an unmanaged macOS PKG app to Microsoft Intune.
Applies to:
- macOS
Newly available protected app for Intune
ChatGPT is now available as a protected app for Microsoft Intune.
For more information about protected apps, see Microsoft Intune protected apps.
Enterprise App Management support for GCC High and DoD
Microsoft Intune now extends Enterprise App Management (EAM) to the GCC High (GCCH) and DoD cloud environments. Government organizations can use the EAM enterprise catalog to discover, deploy, and keep prepackaged Microsoft and third-party apps up to date without manual repackaging. A secure cross-cloud integration model maintains the compliance boundaries and authentication requirements expected for government tenants.
For more information, see Microsoft Intune Enterprise Application Management.
Applies to:
- Windows
Auto-update for Enterprise App Management applications
Microsoft Intune now supports automatic updates for Enterprise App Management (EAM) applications. When you enable auto-update for an EAM app with a required assignment, Intune detects when a newer version is available in the EAM catalog and automatically updates the app on targeted devices. This eliminates manual packaging and supersedence workflows, reduces update maintenance at scale, and helps keep devices secure with timely updates.
For more information, see Microsoft Intune Enterprise Application Management.
Applies to:
- Windows
Device configuration
New Android Enterprise settings in the Intune settings catalog
The settings catalog lists all the settings you can configure in a device policy, and all in one place. The following new Android Enterprise settings are available in the Microsoft Intune settings catalog (Devices > Manage devices > Configuration > Create > New policy > Android Enterprise for platform > Settings catalog for profile type).
Applications
| Setting | Description | Applies to |
|---|---|---|
| Block apps from exposing app functions | This setting controls whether managed apps can expose app functions — programmatic actions that other apps and on-device assistants or AI agents can invoke inside the app. If True, apps on fully managed devices and apps in the work profile on corporate-owned devices are blocked from exposing app functions. If False (default OS behavior), apps are allowed to expose app functions. | COBO, COSU, COPE |
| Block widgets from work profile apps | If True, allows users to access widgets exposed by apps in the work profile on the device's home screen. If False, prevents access to these widgets. By default, the OS might allow widget access. | COPE |
Connectivity
| Setting | Description | Applies to |
|---|---|---|
| Allow selection of a preferential network service | If True, the device gives priority to the specified network service over other available options, such as an enterprise slice on 5G networks. If False, the device connects using its default network selection process. | COBO, COSU, COPE |
| Block airplane mode | If True, the device is prevented from enabling airplane mode. If False, the device follows the default airplane mode behavior of the OS. | COBO, COSU, COPE |
| Block cellular 2G | If True, the device prevents cellular 2G functionality, restricting user access to the setting. If False (default), the device follows the default cellular 2G behavior of the OS. Supported on Android 14 and later. | COBO, COSU, COPE |
| Block configuring cell broadcasts | If True, the device is prevented from receiving cell broadcast messages, such as emergency alerts. If False (default), Intune doesn't change or update this setting, and the OS might allow the reception of cell broadcast messages. | COBO, COSU, COPE |
| Block configuring mobile networks | True prevents users from configuring or modifying mobile network settings on the device. If False (default), Intune doesn't change or update this setting and the OS might allow users to adjust mobile network settings. | COBO, COSU, COPE |
| Block configuring VPN | If True, users can't add, edit, or remove VPN configurations on the device. If False or not configured, the device follows the default VPN configuration behavior of the OS. | COBO, COSU, COPE |
| Block network reset | If True, the device won't reset network settings even if a reset is attempted. If False (default), the device follows the default network reset behavior of the OS. | COBO, COSU, COPE |
| Block outgoing calls | If True, users are prevented from making outgoing calls on the device. If False (default), Intune doesn't change or update this setting, and the OS might allow outgoing calls. | COBO, COSU, COPE |
| Block SMS | If True, the device is prevented from sending or receiving SMS messages, restricting text communication. If False (default), the device follows the default SMS behavior of the OS. | COBO, COSU, COPE |
| Block ultra wideband | If True, the device prevents ultra wideband functionality, restricting user access to the setting. If False (default), the device follows the default ultra wideband behavior of the OS. Supported on Android 14 and later. | COBO, COSU, COPE |
| Select minimum Wi-Fi security level | Select the minimum Wi-Fi security level required for the device to connect to Wi-Fi networks. Options are Open network security, Personal network security, Enterprise network security, and Enterprise 192-bit network security. The default is Open network security, which allows the device to connect to all types of Wi-Fi networks. Supported on Android 13 and later. | COBO, COSU, COPE |
General
| Setting | Description | Applies to |
|---|---|---|
| Block printing | If True, the device is prevented from printing documents. If False (default), the device follows the default printing behavior of the OS. | COBO, COSU, COPE |
| Block setting user icon | If True, users are prevented from changing their user icon or profile image on the device. If False (default), Intune doesn't change or update this setting, and the OS might allow users to modify their user icon. | COBO, COSU, COPE |
| Block setting wallpaper | If True, users are prevented from changing the wallpaper on the device. If False (default), Intune doesn't change or update this setting, and the OS might allow users to change the wallpaper. | COBO, COSU, COPE |
| Block users from adding eSIM profiles | If True, users can't add eSIM profiles to the device. If False (default), users can add eSIM profiles based on the default behavior of the OS. | COBO, COSU, COPE |
Platform key:
- COBO — Android Enterprise corporate-owned fully managed
- COSU — Android Enterprise corporate-owned dedicated devices
- COPE — Android Enterprise corporate-owned devices with a work profile (at work profile level)
For a list of all settings you can currently configure, see Android Enterprise device settings list in the Intune settings catalog.
Applies to:
- Android Enterprise
Support for WPA3-Personal in iOS/iPadOS Wi-Fi profiles
Intune supports WPA3-Personal as a security-type option when configuring Wi-Fi device configuration profiles for iOS/iPadOS. Admins can now select WPA3-Personal alongside existing options such as WPA2-Personal.
This feature:
- Allows managed iOS/iPadOS devices to connect to networks that require the stronger WPA3 protocol.
- Brings iOS/iPadOS in line with the latest Wi-Fi Alliance security standards and helps organizations meet evolving network-security requirements.
Support for WPA3 on Windows, Android, and macOS platforms and for WPA3-Enterprise will be available in a future release (no ETA).
To learn more about the settings you can currently configure, see Add Wi-Fi settings to Apple devices in Microsoft Intune.
Applies to:
- iOS/iPadOS
New supported OEMConfig apps for Android Enterprise
The following OEMConfig apps are available in Intune for Android Enterprise:
- FCNT | com.fcnt.arrowsconfig
- FCNT | com.fcnt.arrowsconfig_test
For more information about OEMConfig, see Use and manage Android Enterprise devices with OEMConfig in Microsoft Intune.
Applies to:
- Android Enterprise
Device management
Advanced Intune capabilities are being added to Microsoft 365 E3 and E5
Microsoft is adding several Intune Suite capabilities to Microsoft 365 E3 and Microsoft 365 E5 to enable more organizations to use advanced endpoint management and security without a separate add-on.
The following capabilities are added to Microsoft Enterprise Mobility + Security E3 (EMS E3), which is included with Microsoft 365 E3:
- Remote Help
- Advanced Analytics
- Intune Plan 2, which includes Microsoft Tunnel for mobile application management (MAM), specialty device management, and firmware over-the-air (FOTA) updates for supported devices
Microsoft 365 E5 includes all Microsoft 365 E3 capabilities, plus:
- Endpoint Privilege Management
- Enterprise Application Management
- Microsoft Cloud PKI
These capabilities are gradually rolling out. Eligible tenants are automatically provisioned, and no action is required. Before the change takes effect in your tenant, Microsoft posts a notification in the Microsoft 365 admin center 30 days in advance.
This update applies to commercial Microsoft 365 E3 and E5. There are no changes to the Education (EDU) or frontline worker (FLW) plans at this time. For Government plans, Intune Suite packaging is planned to align with the equivalent enterprise plans, subject to compliance and regulatory requirements. For the capabilities currently supported in GCC High and DoD, see Supported Intune features in GCC High and DoD.
For more information, see Microsoft Intune advanced capabilities and the blog post Microsoft 365 adds advanced Microsoft Intune solutions at scale.
Intune support for Trustd Mobile as a mobile threat defense partner
You can now use Trustd Mobile as a mobile threat defense partner (MTD) for enrolled devices that run the following platforms:
- Android 9.0 and later
- iOS/iPadOS 15.0 and later
To learn more about this support, see Use Trustd Mobile with Microsoft Intune.
Remote Help support for RemoteApp in Azure Virtual Desktop
Remote Help supports RemoteApp in Azure Virtual Desktop (AVD), enabling help desk agents to securely view and control apps running within RemoteApp sessions. For more information, see Launch Remote Help.
Device security
Microsoft Tunnel adds support for Red Hat Enterprise Linux 9.7
Microsoft Tunnel Gateway now supports Red Hat Enterprise Linux (RHEL) 9.7 as a Linux server distribution.
- This support requires the use of Podman 5.8.2 as its default container engine. Customers upgrading from environments using Podman v3 containers should recreate containers and reinstall Microsoft Tunnel, as those containers aren't compatible with newer Podman versions.
- Like other RHEL 9.x versions, RHEL 9.7 doesn't automatically load the ip_tables module into the Linux kernel. When you use this version, plan to manually load ip_tables before you install Tunnel.
For the full list of supported distributions and their container requirements, see Prerequisites for the Microsoft Tunnel in Intune.
Updated security baseline for Microsoft 365 Apps for Enterprise
An updated security baseline for Microsoft 365 Apps for Enterprise is now available in Microsoft Intune. This baseline aligns with the most recent Microsoft 365 Apps security guidance and includes updated policy recommendations to help protect against evolving threats.
This release is version v2512, which skips the previously published version found in the Security Compliance Toolkit (v2412). Review the new baseline carefully before you adopt it.
The following three settings aren't available in this baseline release and are expected to be added in a future update. The parent setting to these three, (VBA Macro Notification Settings set to Disable all except digitally signed macros) is still included in the v2512 release:
- Require macros to be signed by a trusted publisher: Pending availability in the Settings Catalog.
- Block certificates originating from the current user store only: Pending availability in the Settings Catalog.
- Require Extended Key Usage (EKU) for code signing: Pending availability in the Settings Catalog.
Existing profiles don't automatically upgrade. To use the latest version, create a new baseline profile or update an existing profile to the latest version.
To view the full list of settings and their default values, see Microsoft 365 Apps for Enterprise security baseline version 2512. For a detailed breakdown of setting changes, see the blog post Security baseline for M365 Apps for enterprise v2512.
Applies to:
- Windows
New Microsoft Defender Antivirus settings for Linux Server devices
The existing endpoint security Antivirus policy for the Microsoft Defender Antivirus profile on Linux Server now includes new settings you can configure and deploy to your managed Linux devices:
- Offline security intelligence update - Manage how Microsoft Defender Antivirus keeps its security intelligence current on Linux Server devices, including updates while the device is offline.
- Scheduled scan - Manage when Microsoft Defender Antivirus runs scheduled scans on Linux devices.
These settings:
- Are added to the existing endpoint security Antivirus policy for the Microsoft Defender Antivirus profile on Linux. No new profile is required. By default, they're set to Not configured.
- Are supported for Linux Server devices enrolled with Intune, and for Linux devices managed through the Microsoft Defender for Endpoint security settings management scenario, which supports devices that are managed by Defender for Endpoint but not enrolled with Intune.
For details about the available Defender settings, see Set preferences for Microsoft Defender for Endpoint on Linux in the Microsoft Defender for Endpoint documentation.
Applies to:
- Linux
New setting added to the Windows security baseline version 25H2
The Intune security baseline for Windows, version 25H2, is updated to include one new setting, Disable Internet Explorer 11 Launch Via COM Automation, with a baseline default of Enabled.
This setting was excluded from the version 25H2 baseline at its initial release due to a known issue, which is now resolved. When enabled, the setting prevents Internet Explorer 11 from being launched through COM automation, which reduces the attack surface on managed devices.
This change is an update to an existing baseline version, not a new baseline version. The new setting isn't visible in a baseline profile's properties until you edit and save the profile:
Pre-existing baseline profiles: To add the new setting to a profile you created before this update, select and then Edit the profile, and then Save it. When you open the profile for editing, the new setting appears with its baseline default configuration. You can reconfigure the setting before you save, or save with no changes to apply the baseline default. After you save, Intune deploys the setting to the assigned groups at the next device check-in. If you don't edit and save the profile, the setting doesn't take effect.
New baseline profiles: When you create a profile that uses the Windows security baseline version 25H2, or update an existing profile to version 25H2, that profile includes the new setting along with all the previously available settings.
To view the setting and its baseline default, see Windows MDM baseline settings.
Applies to:
- Windows 11
Source
Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/intune/whats-new/#week-of-june-29-2026-service-release-2606
Change history
- 2026-08-25 · Updated · BodyContent
- 2026-07-23 · Updated · BodyContent
- 2026-07-15 · Created · All