Microsoft Intune: Week of June 8, 2026 (Service release 2605)
Microsoft announcement
App management
Newly available protected apps for Intune
The following protected apps are now available for Microsoft Intune:
- Caju AI by Caju AI
- eYACHO for Biz 7 Intune by MetaMoJi Corporation (iOS)
- eYACHO Viewer 7 Intune by MetaMoJi Corporation (iOS)
- Harvey AI by Harvey AI (Android)
- Notta for Intune by Notta
- SwiftConnect Mobile by SwiftConnect
For more information about protected apps, see Microsoft Intune protected apps.
APP Multiple Managed Accounts
Microsoft Intune mobile application management now supports Multiple Managed Accounts, letting users add and manage more than one managed account within the same app. App protection policies apply separately to each account, so you can tailor protection based on the account's organization or tenant. This capability helps consultants, acquisition teams, or users with multiple mailboxes stay productive without switching devices.
Currently we support Multiple Managed Accounts in Microsoft Teams on iOS/iPadOS (v8.10.0 or later). Support for additional apps and platforms is coming soon.
Note
This feature is gradually rolling out and may not yet be available in your tenant.
To learn more, see Multiple managed accounts for app protection policies.
Applies to:
- iOS/iPadOS
Device configuration
Custom top bar elements on Managed Home Screen
You have the option to display custom text in the top bar of the Managed Home Screen (MHS). In addition to the existing choices (serial number, device name, tenant name), you can now select Custom and enter a free-text string of up to 63 characters. Custom strings support dynamic variables: {{SerialNumber}}, {{DeviceName}}, and {{TenantName}}. This is useful for kiosk scenarios such as checkout devices, departmental tagging, or any case where staff need a quick visual identifier.
Applies to:
- Android Enterprise dedicated devices (COSU)
- Android Enterprise fully managed devices (COBO)
Managed Home Screen exit lock task mode password now requires a device configuration profile
You can no longer configure the Managed Home Screen exit lock task mode password by using an app configuration policy. To set or update the lock task mode password for Managed Home Screen, create or update a device configuration profile that defines the lock task mode password policy.
For more information, see Configure the Microsoft Managed Home Screen app for Android Enterprise.
Applies to:
- Android Enterprise corporate-owned Fully Managed (COBO)
- Android Enterprise corporate-owned Dedicated (COSU)
New Block Bluetooth sharing setting in the Android Enterprise settings catalog
There's a new Block Bluetooth sharing setting in the settings catalog (Devices > Manage devices > Configuration > Create > New policy > Android Enterprise for platform > Settings catalog for profile type > General). When set to True, the device can't share content over Bluetooth. When set to False, Intune doesn't change or update this setting. By default, the OS has the following behavior:
- Fully managed and dedicated devices allow Bluetooth sharing.
- Corporate-owned devices with a work profile block Bluetooth sharing.
For a list of existing settings you can configure in the settings catalog, see Android Enterprise device settings list in the Intune settings catalog.
Applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE)
- Android Enterprise corporate-owned fully managed (COBO)
- Android Enterprise corporate-owned dedicated devices (COSU)
Use DDM to manage Apple Intelligence settings on devices running 26.4 and later
With the release of 26.4, Apple deprecated several intelligence-related settings in the MDM restrictions payload. To manage these settings, use the DDM configurations released in March 2026 instead.
In the settings catalog, the following Restrictions are now deprecated:
- Allow Apple Intelligence Report
- Allow Assistant
- Allow Assistant User Generated Content
- Allow Assistant While Locked
- Allow Auto Correction
- Allow Continuous Path Keyboard
- Allow Definition Lookup
- Allow Dictation
- Allowed External Intelligence Workspace IDs
- Allow External Intelligence Integrations
- Allow External Intelligence Integrations Sign In
- Allow Genmoji
- Allow Image Playground
- Allow Image Wand
- Allow Keyboard Shortcuts
- Allow Mail Smart Replies
- Allow Mail Summary
- Allow Notes Transcription
- Allow Notes Transcription Summary
- Allow Personalized Handwriting Results
- Allow Predictive Keyboard
- Allow Safari Summary
- Allow Spell Check
- Allow Visual Intelligence Summary
- Allow Writing Tools
- Force Assistant Profanity Filter
- Force On Device Only Dictation
- Force On Device Only Translation
In the device restrictions template, the following settings are deprecated.
Built-in apps:
- Block Siri
- Block Siri while device is locked
- Block Siri for dictation
- Block Siri for translation
- Require Siri profanity filters
- Block user-generated content in Siri
Keyboard and dictionary:
- Block word definition lookup
- Block predictive keyboards
- Block auto-correction
- Block spell check
- Block keyboard shortcuts
- Block dictation
Applies to:
- iOS/iPadOS
- macOS
Silence apps on Managed Home Screen to prevent session PIN bypass
For devices using Managed Home Screen (MHS), you can now silence apps whenever MHS prompts the user for authentication, such as during sign-in or at the session PIN screen. When silenced, apps can't start activities, display notifications, appear in recent apps, or trigger toasts, dialogs, or device ringing. You can configure an allowlist of apps that remain unsilenced during the locked state, ensuring that critical communications like calls aren't interrupted. This feature is opt-in and configurable, allowing your organization to tailor the experience to its operational needs. Once the device is unlocked, all apps automatically return to their normal state.
For more information, see Configure the Microsoft Managed Home Screen app for Android Enterprise.
Applies to:
- Android Enterprise
New Microsoft Edge settings in the Windows settings catalog
There are new Microsoft Edge 148 settings in the Windows settings catalog. To see and configure these settings in Intune, create a Windows settings catalog profile (Devices > Manage devices > Configuration > Create > New policy > Windows 10 and later for platform > Settings catalog for profile type).
The new policies include:
Microsoft Edge > Startup, home page and new tab page > Configure whether the Discover or Work feed tabs are shown on the New Tab Page
This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled. Your options:
EnableBothWorkDiscover: If you set this value or don't configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.EnableOnlyWork: Microsoft Edge shows only the Work feed tab on the new tab page.EnableOnlyDiscover: Microsoft Edge shows only the Discover feed tab on the new tab page.
This policy works with the Set the default New Tab Page feed tab to Work or Discover policy, which controls which feed tab is selected by default when both tabs are available.
Microsoft Edge - Default Settings (users can override) > Set the default New Tab Page feed tab to Work or Discover
This policy sets the default feed tab on the New Tab Page to Work or Discover. Your options:
Work: If you set this value or don't configure this policy, Microsoft Edge sets the default feed tab to Work.Discover: Microsoft Edge sets the default feed tab to Discover.
This policy only takes effect when Configure whether the Discover or Work feed tabs are shown on the New Tab Page is set to
EnableBothWorkDiscoveror is not configured. If only one tab is visible, this policy has no effect.Microsoft Edge > Identity and sign-in > Allow M365 authentication popups in work profiles
This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles. When users are signed in with a work account, some Microsoft 365 sites, like
microsoft.com,cloud.microsoft.com, andvisualstudio.com, might open authentication pop-ups tologin.microsoftonline.com,login.live.com, orlogin.microsoft.com. These pop-ups are required to complete sign-in.Your options:
- If you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.
- If you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups. Users can choose to allow or block them, but they aren't automatically allowed.
This policy only applies to work profiles. In personal profiles, Microsoft 365 authentication pop-ups are always allowed regardless of this policy's configuration.
Microsoft Edge > Automatically open Copilot side pane with contextual insights for links opened from Outlook
This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open web links from Outlook emails sent from the same tenant. Starting in Microsoft Edge version 148, when users open eligible links from Outlook emails sent from the same tenant, Microsoft Edge automatically opens the Copilot side pane with contextual insights. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.
Your options:
- If you enable this policy or don't configure it, the Copilot side pane opens automatically when users open links from Outlook emails sent from the same tenant.
- If you disable this policy, the Copilot side pane doesn't open automatically when users open links from Outlook emails sent from the same tenant.
This feature applies only to links opened from Outlook emails sent from the same tenant and requires Microsoft Copilot to be available for the user in Microsoft Edge. This feature is disabled if the Control Copilot access to page context for Microsoft Entra ID profiles policy or the Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane policy is disabled, regardless of this policy's configuration. Copilot requires access to page content to provide contextual insights.
Microsoft Edge > Enable the extended lifetime option for SharedWorkers
Controls whether Microsoft Edge keeps a SharedWorker running briefly after all tabs using it are closed, allowing background tasks to finish.
Your options:
- If you enable or don't configure this policy, SharedWorkers can use the extended lifetime option.
- If you disable this policy, the extended lifetime option is ignored, even if it is requested by the page.
This policy is temporary and will be removed in a future release.
Microsoft Edge > List of URL patterns for which developer tools are allowed to be opened
This policy controls where developer tools can be used in Microsoft Edge by specifying an allowlist of URL patterns. URL patterns are matched against the URL of every frame on the page being inspected.
Your options:
- If you configure this policy and don't configure the List of URL patterns for which developer tools are blocked policy, developer tools are available only when every frame on the page matches a pattern in this allowlist. If any frame doesn't match, developer tools are blocked for the entire page. For information on the URL format, see Filter formats for URL list-based policies.
- If you configure both this policy and the List of URL patterns for which developer tools are blocked policy, this allowlist takes precedence. URLs that match this allowlist are allowed even if they also match the blocklist. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither are governed by the Control where developer tools can be used policy.
- If you disable or don't configure this policy, developer tools availability is determined by the List of URL patterns for which developer tools are blocked and Control where developer tools can be used policies.
This policy applies to developer tools opened for websites, extensions, and web applications. It supports up to 1,000 entries. Example value:
contoso.com https://ssl.server.com contoso.com/good_path https://server.contoso.com:8080/path .exact.hostname.com file://*Microsoft Edge > List of URL patterns for which developer tools are blocked
This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see Filter formats for URL list-based policies. URL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page.
Your options:
- If you configure this policy and don't configure the List of URL patterns for which developer tools are allowed to be opened policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the Control where developer tools can be used policy.
- If you configure both this policy and the List of URL patterns for which developer tools are allowed to be opened policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the Control where developer tools can be used policy determines availability.
- If you disable or don't configure this policy, developer tools availability is determined by the List of URL patterns for which developer tools are allowed to be opened and Control where developer tools can be used policies.
This policy supports up to 1,000 entries. Example value:
https://contoso.com contoso.com https://ssl.server.com contoso.com/bad_path https://server.contoso.com:8080/path .exact.hostname.com * file://*Microsoft Edge > Maximum number of concurrent connections to the proxy server for WebSocket requests
Specifies the maximum number of simultaneous connections to a proxy server for WebSocket requests. To configure limits for non-WebSocket requests, see the MaxConnectionsPerProxy policy.
If you don't configure this policy, the default value of 32 is used. Some web applications maintain multiple concurrent connections, like long-lived or hanging requests. Setting a value lower than the default may cause networking delays when many such applications are open. Some proxy servers can't handle a high number of concurrent connections per client. In these cases, reducing the value of this policy might improve reliability. The supported range is 6 to 256:
- Values less than 6 are treated as 6.
- Values greater than 256 are treated as 256.
Modify this value only if required by your proxy server configuration or network environment.
Microsoft Edge > Controls the availability of browsing with Copilot in Microsoft Edge
When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically. Browsing with Copilot is available only on domains specified in the Browsing with Copilot Allowed URLs policy and is blocked on domains specified in the Browsing with Copilot Blocked URLs policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.
This feature is available only to users with an active Microsoft 365 Copilot subscription. For more information about configuring browsing with Copilot, see Configure browsing with Copilot.
Your options:
- If you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.
- If you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.
- If you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.
Microsoft Edge > Browsing with Copilot Allowed URLs
Allows you to define a list of URLs where browsing with Copilot is available. Users can't modify this list.
Your options:
- If you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the Browsing with Copilot Blocked URLs policy. For example, you can include
*to allow all sites, and then use the block list to restrict access to specific URLs. You can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list. - If you disable or don't configure this policy, browsing with Copilot is unavailable on all sites, even if the Controls the availability of browsing with Copilot in Microsoft Edge policy is enabled.
Browsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (
*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see Filter formats for URL list-based policies. Example value:https://www.contoso.com [*.]contoso.edu contoso.net login.contoso.us- If you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the Browsing with Copilot Blocked URLs policy. For example, you can include
Microsoft Edge > Browsing with Copilot Blocked URLs
Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list. Use this policy to define exceptions to broader allowlists. For example, you can set Browsing with Copilot Allowed URLs to
*to allow all sites, and then use this policy to block access to specific URLs. This policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.If you don't configure this policy, no exceptions are applied to Browsing with Copilot Allowed URLs. Browsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (
*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored. For information about URL pattern format, see Filter formats for URL list-based policies. Example value:https://www.contoso.com [*.]contoso.edu contoso.net login.contoso.usMicrosoft Edge > Enable the Copilot new tab page
This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business. The Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who don't have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.
Most policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see Configure the Copilot new tab page. This policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy doesn't apply to the Copilot new tab page on personal Microsoft account profiles.
Your options:
- If you enable this policy, the Copilot new tab page is turned on.
- If you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy isn't configured, users can turn it on via user settings.
Microsoft Edge > Manageability > Allow MAM enrollment when managed device has Purview DLP policy configured
Controls whether Microsoft Edge allows Mobile Application Management (MAM) enrollment on managed devices when Microsoft Purview Data Loss Prevention (DLP) is configured.
Your options:
- If you enable this policy, MAM enrollment is allowed even when Purview DLP is detected on the device.
- If you disable or don't configure this policy, MAM enrollment is blocked when Purview DLP is detected on the device.
To learn more about the settings catalog, see Use the Intune settings catalog to configure settings.
Applies to:
- Windows
New Wired Networks device configuration profile for iOS/iPadOS
There's a new 802.1x Wired Networks device configuration profile for iOS/iPadOS devices. The feature supports 802.1x Ethernet access controls, which is ideal for M-series iPads that support native resolution screen extension. It allows iPads to securely connect to hot desk docks and monitors using wired access.
This profile:
- Supports EAP protocols, like TLS, PEAP, and TTLS
- Is similar to the macOS wired network profile experience
This feature helps with secure enterprise deployments for iPads in education, finance, and other regulated industries.
To learn more about wired networks, see Add and use wired networks settings on your devices.
Applies to:
- iOS/iPadOS 17 and newer
Device management
Detect and block Shadow AI using the properties catalog, device query, and a security baseline (preview)
Using Intune, you can detect and block a Local AI Agent, like OpenClaw, on Windows devices enrolled in Intune. Specifically, you can:
- Use a Properties catalog policy to collect the Local AI Agent entity. Admins can use this information to identify devices where OpenClaw is present or active.
- Use Device Query to view devices with a Local AI Agent, like OpenClaw.
- Use the Local AI Agent Baseline - OpenClaw (Preview) to block users from using OpenClaw.
This feature is in preview.
Applies to:
- Windows
Device security
In-place renewal of Cloud PKI issuing certification authorities (CAs)
Microsoft Intune now supports in-place renewal of eligible Cloud PKI issuing certification authorities (CAs). Previously, renewing an issuing CA required creating a new CA and manually updating dependent SCEP certificate profiles, which increased operational overhead and configuration risk. With in-place renewal, certificate issuance continues uninterrupted for scenarios such as Wi-Fi, VPN, and email, without changes to existing SCEP profiles or device assignments.
For more information, see Renew a certification authority in Cloud PKI.
Strict Tunnel Mode for Microsoft Tunnel on Android
Microsoft Tunnel now supports Strict Tunnel Mode on Android Enterprise devices. When Strict Tunnel Mode is enabled, all network traffic is forced through the VPN tunnel. If the VPN connection is unavailable or drops, all network traffic on the device is blocked until the VPN reconnects, preventing apps from accessing the public internet outside of the tunnel.
Strict Tunnel Mode is available when a Microsoft Tunnel VPN profile is configured with Always-on VPN. Admins can configure an app exclusion list to allow specific apps to bypass the tunnel and connect directly to the network, regardless of VPN connection status.
Strict Tunnel Mode requires devices enrolled through Android Management API (AM API). For unenrolled devices using Microsoft Tunnel for Mobile Application Management (MAM), Strict Tunnel Mode is available through the Microsoft Edge app configuration policy.
For more information about Microsoft Tunnel capabilities, see Overview of Microsoft Tunnel.
Applies to:
- Android Enterprise corporate-owned fully managed
- Android Enterprise corporate-owned work profile
- Android Enterprise personally owned work profile
- Android (MAM, unenrolled devices)
Grant enhanced security permissions to a Mobile Threat Defense app on Android
A new Mobile Threat Defense role category is available on the Mobile Threat Defense connector configuration page in the Microsoft Intune admin center. The Grant MTD role permissions to <MTD partner name> on enrolled Android COBO and COPE devices toggle lets you grant enhanced security permissions to one Mobile Threat Defense partner app, such as Microsoft Defender for Endpoint or a supported third-party partner, on enrolled Android Enterprise corporate-owned fully managed (COBO) and Android Enterprise corporate-owned work profile (COPE) devices.
When you turn on this toggle, the selected MTD app receives the following exemptions on targeted devices:
- Suspension — The app is prevented from being suspended.
- Hibernation — The app is prevented from entering hibernation.
- Power restrictions — The app is exempt from power-related restrictions such as app standby, and can start foreground services from the background.
- User controls — Users can't clear app data or force-stop the app.
These exemptions help the MTD app maintain continuous threat protection without interruption from system or user actions. Only one MTD partner can hold these permissions per tenant.
For Microsoft Defender for Endpoint, a second toggle is also available: Automatically launch Microsoft Defender for Endpoint during setup on Android COBO and COPE devices. When enabled, the Defender for Endpoint app automatically launches during device setup, allowing it to complete its initial configuration without requiring the user to manually open it.
For more information, see Mobile Threat Defense role.
Applies to:
- Android Enterprise corporate-owned fully managed
- Android Enterprise corporate-owned work profile
Vulnerability Remediation Agent now uses Microsoft Entra agentic identity (preview)
This feature is rolling out to tenants gradually and may take several weeks to become available in your environment.
The Vulnerability Remediation Agent is now available to all customers in preview. Previously, the agent was available only to a select group of customers in a limited preview.
The Vulnerability Remediation Agent now uses Microsoft Entra agentic identity instead of a human user identity. When you set up a new agent instance, the setup process automatically provisions an agentic identity in your tenant's Entra directory. The agent runs under the permissions delegated to this agentic user, providing a more secure and scalable identity model.
What this means for existing agents: If you already have a Vulnerability Remediation Agent instance that uses a human user identity, your agent continues to work as-is for now. Human user identity support expires 90 days after this release, after which you must transition to an agentic identity. A banner on the agent page notifies you when agentic identity is available for your agent. For transition steps and details, see Transition existing agents to agentic identity.
What's new for agentic identity:
- New agent instances are provisioned with an agentic identity during setup.
- After setup, you must delegate the required permissions to the agentic user in the Microsoft Entra and Microsoft Defender admin centers.
- Use the Run Readiness Check button to verify that all required permissions are in place before running the agent.
For more information, see Agent identity.
Source
Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/intune/whats-new/#week-of-june-8-2026-service-release-2605
Change history
- 2026-08-25 · Updated · BodyContent
- 2026-07-23 · Updated · BodyContent
- 2026-07-15 · Created · All