‹ Back to list
Stay InformedCC00183

Microsoft Intune: Week of July 27, 2026 (Service release 2607)

Services: Microsoft Intune· Published: 2026-07-27· MS modified: 2026-07-27· View source ↗
What's new

Microsoft announcement

Device configuration

Samsung Knox E-FOTA firmware update management for Android Enterprise devices

Microsoft Intune now integrates with Samsung Knox E-FOTA (Firmware Over-The-Air), so you can manage firmware updates for corporate-owned Samsung devices directly in the Microsoft Intune admin center. Control which firmware version each device receives, deploy updates without user interaction, and schedule downloads and installations to reduce downtime.

For more information, see Samsung Knox E-FOTA integration with Microsoft Intune.

Applies to:

  • Android Enterprise corporate-owned dedicated (COSU)
  • Android Enterprise corporate-owned fully managed (COBO)
  • Android Enterprise corporate-owned with a work profile (COPE)

New settings available in the Windows settings catalog

Microsoft Intune now includes new settings in the Windows settings catalog for Windows devices. You can configure options for camera behavior, Keyboard Filter controls (for Windows Insider devices), and Windows Subsystem for Linux (WSL). To find them, go to Devices > Manage devices > Configuration > Create > New policy > Windows 10 and later > Settings catalog.

Applies to:

  • Windows 11
  • Windows 10

New Microsoft Edge settings in the Windows settings catalog

The Microsoft Edge administrative templates were refreshed to Microsoft Edge 149 (version 149.0.4022.21), which adds the latest Microsoft Edge 148 and 149 policy settings to the Windows settings catalog. The new settings are:

For the full list of policies, see the Microsoft Edge policies reference.

Applies to:

  • Windows

New Windows App (Azure Virtual Desktop) settings in the Windows settings catalog

There are new Windows App settings in the Windows settings catalog. To see and configure them in Intune, create a Windows settings catalog profile (Devices > Manage devices > Configuration > Create > New policy > Windows 10 and later > Settings catalog). The new settings are:

  • Turn off automatic updates for Windows App – controls whether Windows App automatically checks for and installs updates.
  • Automatically log off users after inactive interval – signs users out of Windows App after a set period of inactivity.
  • Skip First Run Experience (FRE) – skips the first-run experience so users go straight to their resources.
  • Admin Release Ring Policy – sets the update release ring (channel) that Windows App follows.
  • Automatically create Windows App shortcuts to desktop – creates desktop shortcuts for published Windows App resources. For more information, see Configure updates for Windows App.

Applies to:

  • Windows

New option for the Remove Default Microsoft Store packages setting

The existing Remove Default Microsoft Store packages setting in the ApplicationManagement area has a new subsetting, Specify additional package family names to remove. It lets you provide a custom list of package family names (PFNs) to remove, in addition to the built-in default set of Microsoft Store packages. For more information, see the ApplicationManagement policy CSP.

Applies to:

  • Windows

New setting to disable the Get Started app

The new Disable Get Started setting prevents the Windows Get Started app from being available to users. For more information, see the Experience policy CSP.

Applies to:

  • Windows

New OneDrive settings in the Windows settings catalog

There are new OneDrive settings in the Windows settings catalog:

  • Set a custom name for the OneDrive folder – sets a custom name for the synced OneDrive folder on the user's device.
  • Enable OpenID Connect (OIDC) authentication for syncing content from an on-prem SharePoint Server using the OneDrive sync app – lets the OneDrive sync app authenticate to an on-premises SharePoint Server using OpenID Connect when the server supports it.
  • Specify the Application ID URI for your Entra application for OIDC – specifies the Application ID URI for your Microsoft Entra application used for OIDC when it differs from your SharePoint Server URL.
  • Prevent users at your organization from enabling offline mode in OneDrive on the web – blocks users from turning on offline mode for OneDrive on the web.
  • Prevent users at your organization from enabling offline mode in OneDrive on the web for libraries and folders that are shared from other organizations – blocks offline mode for libraries and folders shared from other organizations.
  • Hard-delete the contents of a folder shortcut when unmounted – permanently deletes the contents of a folder shortcut when it is unmounted instead of moving them to the Recycle Bin.
  • Hard-delete contents of a folder shortcut when a user loses permissions to the folder – permanently deletes the contents of a folder shortcut when the user loses permissions to that folder. For more information, see Use Group Policy to control OneDrive sync app settings.

Applies to:

  • Windows

Updated Visual Studio administrative templates in the Windows settings catalog

The Visual Studio administrative templates were refreshed to version 1.0.184.40051, which adds the latest Visual Studio policy settings to the Windows settings catalog. The new setting is:

Applies to:

  • Windows

Device enrollment

Skip Setup Assistant screens for tvOS and visionOS enrollment

Microsoft Intune now supports hiding or showing new Setup Assistant screens during automated device enrollment (ADE) for tvOS and visionOS devices. When you configure an enrollment profile, you can choose which screens, such as Apple ID, Diagnostics Data, and Location Services, appear during setup. By default, these screens are shown.

For more information, see Set up ADE for tvOS and Set up ADE for visionOS.

Applies to:

  • tvOS
  • visionOS

Dedicated RBAC permission for zero-touch enrollment

Microsoft Intune now provides a dedicated role-based access control (RBAC) permission for Google zero-touch enrollment portal access. Previously, the zero-touch enrollment iframe in the Microsoft Intune admin center required the Update app sync permission, which also grants rights to manage Managed Google Play app sync. With the dedicated permission, you can grant zero-touch enrollment portal access independently from app management permissions.

For more information, see Enroll by using Google Zero Touch.

Applies to:

  • Android Enterprise

Device management

Collect Windows registry data with the properties catalog

Microsoft Intune now lets you collect Windows registry data through the properties catalog. When you create a device inventory policy, you can define specific registry keys and values to collect from enrolled Windows devices, including a single value, all values directly under a key, or the same value across subkeys under HKEY_LOCAL_MACHINE. This gives you richer device state visibility and advanced querying without custom scripts.

For more information, see Use the Intune properties catalog to get device hardware properties.

Applies to:

  • Windows

Improved on-demand device sync for Windows devices

Microsoft Intune now supports a more comprehensive on-demand sync for Windows devices. When you select the Sync device action in the Microsoft Intune admin center, Intune initiates a full synchronization across key workloads, including configuration policies, apps, and scripts, so devices reflect your latest changes faster. This capability is especially useful during troubleshooting, incident response, and high-priority rollouts.

For more information, see Device action: sync.

Applies to:

  • Windows

Device security

Custom compliance settings for macOS

Microsoft Intune now supports custom compliance settings for macOS. As an admin, you can define compliance checks using scripts and JSON rules, similar to existing support for Windows and Linux. This capability lets you evaluate device configuration, security posture, and other custom attributes not covered by built-in settings. Results appear alongside standard compliance reporting in the Intune admin center.

For more information, see Custom compliance settings in Microsoft Intune.

Applies to:

  • macOS

Controlled Configuration for Microsoft Defender antivirus settings (preview)

In preview, Microsoft Intune now supports Controlled Configuration for Microsoft Defender antivirus settings. When you enable it, the Defender antivirus settings delivered by Intune or Microsoft Defender for Endpoint security settings management become authoritative and override configurations from other channels, such as Group Policy, Configuration Manager, and local scripts. Extending Tamper Protection, this capability locks settings to your defined values for consistent and predictable device states.

For more information, see Controlled configuration for Microsoft Defender settings.

Applies to:

  • Windows

Intune apps

Regional support for Microsoft Store apps

Microsoft Intune now supports regional selection for Microsoft Store apps. When you add a Microsoft Store app, you can choose the region (market) whose Store catalog to search and deploy from. Previously, Intune searched only the United States catalog. Now you can deploy apps published for specific markets, such as Japan or Spain, that aren't available in the US catalog.

For more information, see Add Microsoft Store apps to Microsoft Intune.

Applies to:

  • Windows

Source

Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/intune/whats-new/#week-of-july-27-2026-service-release-2607

Change history