Microsoft Intune: Week of August 25, 2026 (Service release 2608)
Microsoft announcement
Advanced capabilities (formerly "Microsoft Intune Suite")
Unattended Remote Help sessions for Windows devices
Microsoft Intune now supports unattended Remote Help sessions on physical Windows devices. Authorized helpdesk agents can sign in to a remote device with their own credentials without requiring the user to be present or take action. Helpers can view and control the device to troubleshoot issues and complete support tasks remotely.
For more information, see Planning for Remote Help.
Applies to:
- Windows
App management
Newly available protected apps for Intune
The following protected apps are now available for Microsoft Intune:
- Notion by Notion Labs
- Superhuman Mail by Superhuman Labs
- Calven by Calven Pty Limited
- Heijmans by Heijmans
- Notability by Ginger Labs, Inc. (iOS)
- Ben for Intune by Thanks Ben Ltd
- SDP - On Premises | Intune by Zoho Corporation
For more information about protected apps, see Microsoft Intune protected apps.
Declarative Device Management for Apple volume purchase program apps
Microsoft Intune now supports Apple Declarative Device Management (DDM) for required volume purchase program (VPP) apps on devices running iOS/iPadOS 17.2 and later and macOS 26 and later. By changing the management type to DDM when you upload a new VPP token, you can deploy and configure apps using Apple's policy-based model, which improves delivery efficiency, provides real-time app status, and adds new per-app settings such as automatic app updates.
Applies to:
- iOS/iPadOS
- macOS
Device configuration
Configure screen timeout for corporate Android devices
Microsoft Intune now supports a Screen timeout setting in the Android Enterprise settings catalog, letting you specify how many seconds pass before the screen turns off. Configure it under Devices > Manage devices > Configuration > Create > New policy > Android Enterprise > Settings catalog. The value must stay at or below Time to lock screen and applies to fully managed and dedicated devices on Android 9 and later, and corporate-owned work profile devices on Android 15 and later.
Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Separate device and work profile passwords on Android Enterprise devices
Microsoft Intune now supports the Block one lock for device and work profile setting in the Android Enterprise settings catalog, letting you require separate locks for the device and work profile instead of a shared one. Set it to True after configuring a work profile password requirement. The default, False, allows a common lock. The setting supports Android 9 and later.
Applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE)
Limit how long an Android work profile can stay off
Microsoft Intune now supports the Number of days work profile is allowed to be switched off setting in the Android Enterprise settings catalog, so you can limit how long a work profile stays turned off. Enter the maximum number of days, with a minimum of three, or enter 0 to disable the restriction. There's no documented upper limit, giving you flexibility for your organization's needs.
Applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE)
Remove eSIMs during a device wipe with a settings catalog policy
Microsoft Intune now supports the Remove all eSIMs during a device wipe setting in the Android Enterprise settings catalog. Set it to True to request removal of all eSIMs when a corporate-owned device is wiped while the policy applies. The default, False, doesn't request removal, although the operating system might still remove eSIMs when required. The setting supports Android 15 and later.
Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
New updates to the Apple settings catalog
Microsoft Intune now supports new Settings Catalog options for testing on the OS 27 betas, covering Declarative Device Management areas such as App Settings, Web Content Filter, and Siri Settings for iOS/iPadOS and macOS. Configure them under Devices > Manage devices > Configuration > Create > New policy > iOS/iPadOS or macOS > Settings catalog. This lets you test upcoming Apple management controls ahead of general availability.
For more information, see Create a policy using settings catalog.
Applies to:
- iOS/iPadOS
- macOS
Keep Android device screens on while charging
Microsoft Intune now includes a settings catalog option for keeping fully managed and dedicated Android device screens on while charging. Select one or more modes - AC, USB, or Wireless - to control when the screen stays on. AC and USB support Android 6.0 and later; wireless charging requires Android 8.1 and later. No modes are selected by default.
Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
New policy settings for Windows
Microsoft Intune now includes new Windows settings catalog options across several administrative template refreshes. Highlights include Turn on Protected Mode controls for Internet Explorer security zones, new Microsoft Edge policies from the Edge 150 template refresh, and a Disconnect if a Remote Desktop Services session when no smart card is present option for interactive logon. The Microsoft Office templates also gained new settings. Create a Windows settings catalog profile to configure them.
Applies to:
- Windows
Device enrollment
Skip new Apple Setup Assistant panes during enrollment
Microsoft Intune now includes Apple OS 27 Setup Assistant skip keys for Liquid Glass and Accessibility Appearance in Automated Device Enrollment profiles. You can hide these panes to reduce setup interactions and provide a more consistent enrollment experience on supported iPhone, iPad, and Mac devices.
Applies to:
- iOS/iPadOS
- macOS
Device management
New single device page in the Intune admin center
The new single device page is turned on by default for all customers. You can use the Preview new device view toggle to turn it off and return to the original device page.
In the Intune admin center, when you go to Devices > All devices and select a device, you can see device-specific information, including device properties, device activity, tools, and reports.
Where to find common device information and actions in the new single device view:
- Change the management name, primary user, or device category: Go to Devices > All devices > select a device > Properties > Edit.
- View hardware and operating system information: Go to Devices > All devices > select a device > Device details. The Device details tab was previously called Hardware.
- Perform device actions: Go to Devices > All devices and select a device. Some actions are organized in the Remote actions, Secure, and Remove data menus on the device command bar. The available actions depend on the device platform, management type, ownership, permissions, and supported capabilities.
- View the status of device actions: Go to Devices > All devices > select a device > Device action status.
- View the status of Remediations: Go to Devices > All devices > select a device > Tools > Remediations.
- View scope tags: Go to Devices > All devices > select a device > Properties.
Return to the original device page:
If you prefer to use the original device page, you can turn off the new experience:
- In the Intune admin center, go to Devices > All devices.
- Move the Preview new device view toggle to Off.
Applies to:
- Android
- iOS/iPadOS
- macOS
- Windows
Operating system version property in assignment filters is generally available
The operatingSystemVersion property in assignment filters is now generally available for managed devices and managed apps. Use this property to create filter rules that scope your app and policy assignments to devices running a specific OS version or build range. For example, create an assignment filter that pilots a configuration on a newer build before rolling it out broadly or excludes devices that haven't yet updated.
You can build rules using the rule editor or the rule syntax text box, with the same operators available for other filter properties. Existing assignments continue to work without changes.
For more information, see:
- Use assignment filters to assign apps, policies, and profiles
- App and device properties, operators, and rule editing when creating assignment filters
Collect enhanced diagnostic logs from supervised Apple devices
Microsoft Intune now supports Apple's Enhanced Logging device action on supported supervised devices running a compatible OS release. Administrators can start an AppleCare diagnostic-log collection session using an AppleCare-provided token and monitor device-reported status through Declarative Device Management, reducing the need to coordinate manual log collection with the device user.
Applies to:
- iOS/iPadOS
- macOS
Note
The following eSIM features are rolling out and might not be available to all tenants yet.
View expanded SIM inventory for corporate-owned Android devices
Microsoft Intune now surfaces expanded SIM inventory for corporate-owned Android Enterprise devices, including EIDs, multiple ICCIDs, and activation state. View these details under Devices > All devices > select a device > Hardware, and use the reported ICCID to identify the correct eSIM for a removal action. EID reporting requires Android 13 and later; full inventory requires Android 15 and later.
Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Activate an eSIM on a corporate-owned Android device
Microsoft Intune now supports single-device eSIM activation for corporate-owned Android Enterprise devices running Android 15 and later. Turn on Preview new device view, select the device, then select Activate eSIM and enter the carrier activation code. Intune sends the request without first blocking it based on reported eSIM slot capacity and surfaces errors returned by Google. Personally owned work profile devices aren't supported.
Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Remove an individual eSIM from a corporate-owned Android device
Microsoft Intune now lets you remove a single eSIM from a corporate-owned Android Enterprise device without wiping it. Turn on Preview new device view, select the device, copy the eSIM's ICCID from device inventory, then select Remove eSIM and enter the ICCID. The action supports fully managed and dedicated devices on Android 15 and later, and work profile devices on Android 17 and later.
Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Choose whether to remove eSIMs when wiping one corporate-owned Android device
Microsoft Intune now lets you choose whether to preserve or remove eSIMs when wiping one corporate-owned Android Enterprise device. Turn on Preview new device view, select the device, then select Wipe. By default, the wipe preserves eSIMs; select the eSIM removal option only when you want the wipe to remove them. Personally owned work profile devices aren't supported.
Applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Enterprise corporate-owned devices with a work profile (COPE)
Device inventory for personally owned devices on Android Enterprise
Microsoft Intune now supports device inventory for personally owned Android Enterprise devices with a work profile managed by Android Management API. View these devices from the device's Inventory page alongside corporate-owned devices in Resource Explorer, and query them with Multi-Device Query. Inventory data is a subset of corporate-owned data; properties such as IMEI, ICCID, and MAC address aren't available. This gives you more consistent analytics across mixed corporate and BYOD environments.
Applies to:
- Android Enterprise personally owned devices with a work profile using Android Management API
Device security
Audit mode for the Microsoft Defender Antivirus template for Linux
The Microsoft Defender Antivirus template for Linux, which is part of Intune's Endpoint Security Antivirus policy, now includes a new Audit value for the Enforcement level setting. When you set Enforcement level to Audit, the antivirus engine detects threats in real time but doesn't automatically remediate them. Malware detections are reported as alerts in the Microsoft Defender portal through real-time scanning, without quarantining the malicious files. Audit mode gives you visibility into the threat landscape before you turn on full protection.
The Microsoft Defender Antivirus template for Linux is supported for devices managed by Intune, and for devices managed only by Defender through the Microsoft Defender for Endpoint security settings management scenario (MDE attach).
Applies to:
- Linux
Windows 365 for Agents security baseline
Microsoft Intune now includes a security baseline for Windows 365 for Agents Cloud PCs. Administrators can deploy and customize recommended, device-scoped settings for Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint to establish a consistent security posture for agentic workloads.
For more information, see Manage security baseline profiles in Microsoft Intune and What is Windows 365 for Agents?.
Applies to:
- Windows 365 for Agents Cloud PCs running Windows 11 and later
Memory scan setting for Microsoft Defender Antivirus on Linux
Microsoft Intune now supports a memory scan setting in the Microsoft Defender Antivirus template for Linux endpoint security antivirus policies. You can manage memory scan behavior on Linux devices managed through Microsoft Defender for Endpoint security settings management, giving you finer control over how Defender inspects memory on your Linux endpoints.
Applies to:
- Linux
Source
Public Microsoft post (not observed by a tenant):
https://learn.microsoft.com/en-us/intune/whats-new/#week-of-august-25-2026-service-release-2608
Change history
- 2026-08-25 · Created · All