Microsoft Intune: Week of June 15, 2026
Microsoft announcement
App management
Managed Win32 app content now requires HTTPS delivery
Intune now requires HTTPS delivery for managed Win32 app content. This change primarily affects organizations that use Microsoft Connected Cache and haven't configured their cache nodes for HTTPS delivery. Clients that previously pulled content from Connected Cache can still download Intune Win32 apps, but those requests bypass the cache nodes and fall back to the content delivery network (CDN). This behavior can increase internet traffic and bandwidth usage.
For more information, see the blog post How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education.
For setup and validation guidance, see:
Device enrollment
Enrollment time grouping for new Apple ADE enrollment policies generally available
Enrollment time grouping is now generally available for Apple automated device enrollment (ADE) on iOS/iPadOS and macOS. With enrollment time grouping, you can identify a device's Microsoft Entra security group during enrollment, so policies, apps, and settings can be applied earlier in the setup process.
Enrollment time grouping is supported in new Apple ADE enrollment policies. For requirements and setup details, see Set up enrollment time grouping.
With the enrollment time grouping availability to iOS/iPadOS and macOS, we're also making the new Apple enrollment policies experience avaialble. Please check our previous blog post to learn more. (https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-iosipados-visionos-tvos-and-macos-ade-enrollment-policies-experience/4393531)
Device management
Android Enterprise personally owned devices with a work profile uses Android Management API (AMAPI)
When users enroll their personally owned Android devices in Intune, a work profile is created with a separate partition on the device for the user's work account. These devices are referred to as personally owned devices with a work profile.
As part of the Intune move to the Android Management API (opens Android's web site), there are some updates for personally owned devices that enroll in Intune:
- Web based enrollment for an improved enrollment flow and experience - Users don't have to install an app to enroll in Intune. Web enrollment is tenant wide.
- New implementation for how Intune delivers policies - Modern update on how Intune delivers and monitors policies on Android personally owned devices with a work profile. This change also aligns with how Intune manages policies on corporate owned devices with a work profile, fully managed, and dedicated devices. You can scale your migration to targeted groups.
To use these features, opt in through the Microsoft Intune admin center:
- Web based enrollment: Devices > Device Onboarding > Enrollment > Android> Personally owned devices with a work profile > Use web enrollment for all users enrolling into Android personally-owned work profile management
- Policy: Devices > Manage devices > Configuration > Create > New policy > Android Enterprise > Move to Android Management API
To learn more, see:
- New policy implementation and web enrollment for Android personally owned work profile blog
- Use Android Management API for personally owned devices with work profiles
Applies to:
- Android Enterprise personally owned devices with a work profile
Improvements to the new Intune single device page (preview)
In the Intune admin center, the Devices > All Devices > select a device page is redesigned and available for you to preview. This feature was available in the 2604 service release.
After the initial 2604 release, we made the following improvements:
After you select one of the following device actions, you can temporarily view passcodes and PINs in the Device action status table:
- Reset passcode
- Recover passcode
- Remote Lock
- Rotate BitLocker Keys
Updates to Device actions:
- Device actions work as expected when multi admin approval policies are enabled.
- Device actions for supervised iOS devices are available when the action is supported.
- Admins can enable and disable Lost mode.
Updates to navigation:
- Tools and reports have been moved to the left navigation menu.
- The monitor tab is now the default landing tab.
In the Essentials section:
- The Copy button and the User and Compliance links are available.
- Supervised iOS devices show a badge to help identify these devices.
When preview is disabled, the feedback pane shows the correct text.
Comanagement information is available.
Admins can remove the primary user from an Azure domain joined device.
Device security
Microsoft Windows 11 STIG SCAP Benchmark audit baseline
Intune now includes a STIG audit baseline that assesses Windows devices against the recommended configurations defined in the Security Technical Implementation Guides (STIGs) published by the Defense Information Systems Agency (DISA). The initial baseline audits against the Microsoft Windows 11 STIG SCAP Benchmark Version 2, Release 7 (benchmark date: January 5, 2026).
Unlike other Intune security baselines that configure and enforce settings, the STIG audit baseline is audit-only. It evaluates the current state of a device's configuration and generates detailed audit reports without changing any configured settings, helping organizations demonstrate compliance with DoD security recommendations. Audit results have a documented mapping to NIST XCCDF result categories for formal DISA compliance reporting, and Graph API support enables programmatic data retrieval and cross-tenant assessment aggregation.
The STIG audit baseline is available for US Government Community Cloud High (GCC High) tenants and requires Advanced Analytics licensing.
For more information, see Use STIG audit baselines to assess Windows device compliance.
Applies to:
- Windows 10
- Windows 11
Source
Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/intune/whats-new/#week-of-june-15-2026
Change history
- 2026-08-25 · Updated · BodyContent
- 2026-07-23 · Updated · BodyContent
- 2026-07-15 · Created · All