Microsoft Intune: Week of April 27, 2026 (Service release 2604)
Microsoft announcement
Advanced capabilities
Expanded support for Endpoint Privilege Management support approved elevation requests
Intune's Endpoint Privilege Management (EPM) now supports support approved elevation requests from all users of a device. This update expands the utility of support approved file elevations and helps to improve scenarios that involve shared devices.
Previously, file elevation requests that require support approval were supported from only a device's primary user or the user who enrolled the device.
For more information about this type of elevation request, see Support approved file elevations for Endpoint Privilege Management.
Device configuration
Configure credential manager permissions for Android Enterprise devices
You can now control which applications act as system-level credential providers on managed Android Enterprise devices running Android 14 and higher. Credential providers are responsible for password autofill and passkey storage.
To configure credential manager permissions, go to Apps > Android > Configuration > Managed Devices and choose Android Enterprise as the platform type.
By default, Android blocks third-party credential providers on managed devices. This configuration setting lets you:
- Allow specific apps (such as Microsoft Authenticator or a third-party password manager) to act as credential providers
- Enable passkey-based sign-in across managed Android Enterprise devices
- Maintain control over which credential sources are trusted on corporate devices
A known limitation is that Google Password Manager can't act as a credential provider on corporate-owned work profile or personally owned work profile devices. It is blocked on the end user's device. Use a different credential app as a workaround.
For more information, see Add app configuration policies for managed Android Enterprise devices.
Applies to:
- Android fully managed devices (COBO)
- Android dedicated devices (COSU)
- Android corporate-owned devices with a work profile (COPE)
- Android personally owned devices with a work profile (BYOD) using Android Management API (AM API)
Block location setting for Android Enterprise can keep Location services enabled
On Android Enterprise devices, you can use the General > Block location in the settings catalog to disable the location services on the device and prevent users from turning it on.
This setting is now called Location and has three options you can configure:
- Device default - Intune doesn't change or update this setting. By default, the OS allows end users to turn location services on or off.
- Location enabled - Requires location services to be on and prevents end users from turning them off.
- Location disabled - Requires location services to be off and prevents end users from turning them on.
For a list of all the settings you can configure, see Android Intune settings catalog settings list.
Applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) running Android 10 and earlier
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Device enrollment
Access management for Apple services
You can now use Apple access management settings in Apple Business Manager and Apple School Manager to configure service access for Apple accounts on organization-owned devices. These controls let you choose what devices users can sign in to and which apps and services are available to them. For more information, see Configure service access for Apple accounts.
Applies to:
- iOS/iPadOS
- macOS
Microsoft Intune supports userless ADE for visionOS and tvOS devices
Microsoft Intune has added support for userless Apple automated device enrollment (ADE) for visionOS and tvOS devices, enabling you to enroll and manage Apple Vision Pro and Apple TV through Apple Business Manager or Apple School Manager. This capability supports ADE without user affinity and includes custom configuration uploads for settings, default enrollment restrictions, and device actions. The feature is available with Microsoft Intune Plan 2 as part of the Microsoft 365 Suite.
Enrolled visionOS and tvOS devices appear alongside iOS and iPadOS devices in the Intune admin center within Apple mobile and can be filtered. Support requires tvOS 26 and later or visionOS 26 and later. We recommend that you keep these devices up to date to receive the latest security fixes.
For more information, see:
- Overview of Apple ADE for Apple mobile
- Use the Intune settings catalog to configure settings
- Device actions
Applies to:
- tvOS 26 and later
- visionOS 26 and later
Device management
Support for Ubuntu 26.04 LTS
Microsoft Intune now supports Ubuntu 26.04 LTS. Support for Ubuntu 22.04 LTS ends in August 2026. Devices already enrolled on Ubuntu 22.04 remain enrolled, but you should notify users to upgrade to a supported Ubuntu version. You can identify devices running Ubuntu 22.04 in the Intune admin center by going to Devices > All devices, filtering by Linux, and adding the OS version column. For more information, see Enroll Linux desktop devices in Microsoft Intune.
Preview the new device page in the Intune admin center (preview)
In the Intune admin center, when you go to Devices > All Devices and select a device, you can see device-specific info, like device properties.
This page is redesigned and is available for you to preview. To enable the new experience:
- In the Microsoft Intune admin center, go to Devices > All Devices.
- Move the Preview new device view toggle to On.
The new experience is only available when you go to Devices > All Devices and select a device. If you open a device page from a different part of the Intune admin center, like from a report, the original page view is shown, even with the toggle enabled.
When turned on, you see the new full page layout that gives you a single view of the device. Use this view to:
- Track device activity
- Access tools and reports
- Manage device information
The single device page has the following tabs:
- Device action status: Shows requested, in‑progress, and recently completed device actions. You can search, sort, and filter this list. You can quickly see what actions are running or have completed without leaving the device view.
- Tools and reports: This tab was previously called Overview. It shows monitoring reports, like compliance and device configuration status, tools, like remediations. These features were previously accessed in other parts of the Intune admin center.
- Properties: Contains admin‑modifiable device properties with visible scope tags and a dedicated editing view.
- Device details: This tab was previously called Hardware. It provides physical device information and key Intune and Microsoft Entra management details.
Other features:
Device actions are grouped, ordered, and labeled consistently across platforms and device types, and only shows relevant and permitted actions. Destructive actions are separated and require confirmation, reducing unintentional actions.
The updated layout uses a standard structure across device types and platforms, while adapting to platform‑specific capabilities.
Improved labeling, hierarchy, and formatting make device information easier to scan and understand. The Essentials section elevates important device information and is accessible from any tab.
All existing device management capabilities remain available. This update focuses on making them easier to find and use.
New remote actions to suspend and restore Managed Home Screen on Android devices
Intune has two new remote actions that allow admins to temporarily suspend and restore Managed Home Screen (MHS) on Android devices. These actions let users exit MHS and access the device's default launcher for a defined period, without removing policies or requiring a PIN.
When the specified duration expires, or when the restore managed home screen action is triggered, MHS automatically re-locks the device into the kiosk experience. This helps maintain security while reducing disruption during troubleshooting or short-term use outside of MHS.
To learn more, see:
Applies to:
- Android Enterprise corporate-owned Fully Managed (COBO)
- Android Enterprise corporate-owned Dedicated (COSU)
Updated minimum version for Intune Management Extension on Windows
Windows devices managed by Intune need to run Intune Management Extension version 1.58.103.0 or later. Devices on earlier versions no longer receive configurations or updates that depend on the Intune Management Extension, including Win32 app deployments, PowerShell scripts, remediations, and platform scripts.
The Intune Management Extension updates automatically, so most managed devices should already have a compatible version. Verify that your devices can sync with Intune to receive updates.
Applies to:
- Windows 10/11
Device security
Autopatch update risk visibility report
The Autopatch update risk visibility report extends the security update status dashboard with granular insight into patch compliance and risk across your managed devices. It classifies devices as Current, Exposed, or Critical and highlights policies contributing to risk, so you can identify and remediate issues faster.
For more information, see Protect your estate: Reassess your Windows update policies.
Applies to:
- Windows
Updated security baseline for Microsoft Edge v139
Microsoft Edge version 139 security baseline is now available in Microsoft Intune. This baseline reflects current Microsoft security recommendations for the Microsoft Edge browser and is the latest available Edge security baseline in Intune.
The Edge v139 security baseline includes new settings, updated default values, and retired settings.
Existing security baseline profiles don't automatically update to the new version. To use this baseline, Intune admins can create a new baseline profile or update an existing profile to the latest version.
We recommend carefully reviewing the settings in the new baseline before moving from a previous baseline version, especially if existing profiles include customizations.
For a detailed breakdown of setting changes, see the blog post Security baseline for Microsoft Edge version 139.
To view the default configuration of settings in the updated baseline, see Microsoft Edge security baseline settings reference.
Intune apps
Direct Android line-of-business app management
You can now manage Android line-of-business (LOB) apps directly in Microsoft Intune without publishing them to Managed Google Play on Android Enterprise corporate-owned fully managed (COBO) and dedicated (COSU) devices.
With direct LOB app management, admins can upload APK files directly to Intune and deploy required apps to supported Android Enterprise enrollment types using a native Intune workflow.
Direct LOB app management enables you to:
- Deploy in-house LOB APKs to fully managed and dedicated devices without publishing them to Managed Google Play
- Manage the app lifecycle directly from Intune
- Create app configuration policies for directly deployed LOB apps, giving you the same configuration flexibility you have for Managed Google Play apps
For more information, see Add an Android line-of-business app to Microsoft Intune.
Applies to:
- Android Enterprise
Newly available protected apps for Intune
The following protected apps are now available for Microsoft Intune:
- Harvey AI by Harvey AI Corporation (iOS)
- Continia Expense App by Continia Software A/S
For more information about protected apps, see Microsoft Intune protected apps.
Tenant administration
Change Review Agent suggestions available inline in Multi Admin Approval (preview)
The Change Review Agent now provides risk-based recommendations directly in the Multi Admin Approval experience for Windows PowerShell scripts. On the My requests and All requests tabs, a new Agent Response column displays when a suggestion is available. You can then select the suggestion to open and complete the Change Review Agent's approval workflow for that request without leaving the Multi Admin Approval node.
Change Review Agent suggestions continue to be available in the agent's primary experience as well.
For more information, see Change Review Agent suggestions in Multi Admin Approval.
Source
Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/intune/whats-new/#week-of-april-27-2026-service-release-2604
Change history
- 2026-07-20 · Updated · BodyContent
- 2026-07-15 · Created · All