Microsoft Intune: Week of March 2, 2026 (Service release 2602)
Microsoft announcement
App management
Newly available protected apps for Intune
The following protected apps are now available for Microsoft Intune:
- Jump by Accio Inc.
- Mijn InPlanning by Intus Workforce Solutions (Android)
For more information about protected apps, see Microsoft Intune protected apps.
Device configuration
Apple declarative device management (DDM) supports assignment filters
You can use assignment filters in policy assignments for DDM-based configurations, like software updates.
Note
This feature is rolling out slowly and should be available for all customers by late March 2026.
To learn more about filters, see Use assignment filters to assign your apps, policies, and profiles in Microsoft Intune.
Applies to:
- iOS/iPadOS
- macOS
New settings in the Windows settings catalog
There are new settings in the Windows settings catalog. To see and configure these settings in Intune, create a Windows settings catalog profile (Devices > Configuration profiles > Create profile > Windows 10 and later > Settings catalog).
The new policies include:
Microsoft Edge:
Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates: When Enabled or not configured, users with Microsoft Entra ID profiles see an informational page about new Edge for Business features after major browser updates. When Disabled, the informational page isn't shown to users.
This policy:
- Applies only to Microsoft Entra ID profiles. It doesn't apply to Microsoft account (MSA) profiles.
- Is available starting in Microsoft Edge version 144, which allows you to configure the setting before any version 145 changes.
Enable Silent Printing: When Enabled, Microsoft Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder. When Disabled or not configured, silent printing is disabled. The print preview window stays open, and the user must choose the print settings as usual.
Microsoft Edge > Content settings:
Allow precise geolocation on these sites: When Enabled, enter a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission. When Disabled or not configured, the default geolocation setting applies to all sites (if configured) or the user's personal setting is used.
For information about valid URL patterns and examples, see Filter formats for URL list-based policies. Wildcards (*) are supported.
Block geolocation on these sites: When Enabled, enter a list of URL patterns for sites that are blocked from requesting or accessing the user's geolocation. These sites can't prompt the user for location permissions. When Disabled or not configured, the default geolocation setting applies to all sites (if configured) or the user's personal browser setting is used.
For information about valid URL patterns and examples, see Filter formats for URL list-based policies. Wildcards (*) are supported.
Windows Backup and Restore:
Enable Windows Restore: Choose to enable Windows Restore. When enabled, the restore process for a device can be initiated:
- At the time of device enrollment during the out-of-box experience (OOBE), or
- The first time a user signs in with their Microsoft Entra ID account after the device finishes enrolling.
It allows a user to restore their backed‑up Windows settings and Microsoft Store apps from the cloud to a new or reset device. It restores the user experience settings and configuration preferences. It's not a full system image. To learn more, see Windows Backup for Organizations overview.
Your options:
- Windows Restore Not Configured
- Windows Restore Enabled
This policy:
- Was previously for Windows Insiders and is now generally available (GA).
- Uses the WindowsBackupAndRestore CSP.
Applies to:
- Windows
To learn more about the settings catalog, see Use the Intune settings catalog to configure settings.
New updates to the Apple settings catalog
The Settings Catalog lists all the settings you can configure in a device policy, and all in one place. For more information about configuring Settings Catalog profiles in Intune, see Create a policy using settings catalog.
There are new settings in the Settings Catalog. To see these settings, in the Microsoft Intune admin center, go to Devices > Manage devices > Configuration > Create > New policy > iOS/iPadOS or macOS for platform > Settings catalog for profile type.
iOS/iPadOS
AirPlay:
- Device Name
macOS
AirPlay:
- Device Name
Microsoft Defender:
- The Microsoft Defender category is updated with new settings. Learn more about available macOS Defender settings at Microsoft Defender - Policies.
Applies to:
- iOS/iPadOS
- macOS
Device enrollment
New setting controls MDM enrollment during account registration on Windows (preview)
A new setting that affects the Microsoft Entra account registration experience on Windows is available in the Microsoft Intune admin center. The setting, Disable MDM enrollment when adding work or school account on Windows, controls whether devices enroll in MDM during the account registration flow. The default setting is set to No, which allows MDM enrollment. No action is required unless you want to change the default enrollment behavior. This Microsoft Entra setting is in preview. For more information, see Enable MDM automatic enrollment for Windows.
Device management
Multi-administrator approval support for device compliance and device configuration policies
Multi-administrator approval now supports device configuration policies created through the settings catalog and device compliance policies. When you turn on this feature, any changes you make, including creating, editing, or deleting a policy, must be approved by a second administrator before they take effect. This dual-authorization process helps protect your organization from unauthorized or accidental changes to role-based access control.
For more information, see Use Access policies to require Multi Admin Approval.
Device security
Intune ending support for legacy Apple MDM software update policies
With the release of iOS 26, iPadOS 26, and macOS 26, Apple has deprecated legacy mobile device management (MDM) software update commands and payloads. As a result, Microsoft Intune will soon end support for creating legacy iOS/iPadOS and macOS software update policies. To continue managing Apple software updates in Intune, configure update policies using Apple's declarative device management (DDM) model. DDM provides a more modern and reliable approach to managing software updates, with improved device autonomy and reporting.
For guidance on moving to DDM‑based software updates, see the Intune Customer Success blog: Move to declarative device management for Apple software updates.
Applies to:
- iOS/iPadOS
- macOS
Autopatch update readiness
Autopatch update readiness provides a unified experience for tracking and remediating Windows update issues across Intune-enrolled devices and Windows Autopatch group-enrolled devices. With a single dashboard, admins can view all managed devices, including enrollment status and policy assignments, to better understand update readiness across their environment.
Key capabilities include:
- Device update journey: View granular update states for each device to quickly identify where updates are blocked and why.
- Centralized alerting: See actionable alerts for update failures, policy conflicts, and readiness gaps in one place, with integrated remediation guidance.
- Update readiness checker: Proactively evaluate devices for deployment risks and flag devices as At Risk based on signals such as disk space, appraiser data, and setup conditions.
- Repair devices with OS reinstall: Remediate upgrade‑blocked devices by triggering an OS reinstall for common issues like insufficient disk space or app compatibility problems, with supporting alerts and reporting.
For more information, see Autopatch update readiness.
Applies to:
- Windows
Monitor and troubleshoot
Updates to operators in device query for multiple devices
Device query for multiple devices now includes expanded operator support, clearer query validation, and improved results to make building and interpreting queries easier.
- New join types supported
You can now use the following join types when querying across entities:leftsemirightsemileftantirightanti
- Updated join behavior
Joins that useon Device.DeviceIdare no longer supported. Queries should instead:- Use
on Device, or - Omit the on clause entirely when joining on the device entity.
- Use
- Updated device references in operators
Using Device by itself is no longer supported in operators such asdistinct,summarize, ororder by. Queries must reference a specific device property. - Improved query results
Queries that involve a device—either by querying a device directly or by joining a device with another entity—now return the device as a clickable link in the results, allowing you to quickly navigate to device details. - Clearer error messages
Some query error messages have been updated to provide clearer, more descriptive guidance when queries are invalid.
For previous months, see the What's new archive.
Source
Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/intune/whats-new/#week-of-march-2-2026-service-release-2602
Change history
- 2026-08-25 · Updated · BodyContent
- 2026-07-23 · Updated · BodyContent
- 2026-07-20 · Updated · BodyContent
- 2026-07-15 · Created · All