Week 39 · 21 Sep – 27 Sep 2026

Updated Mon 28 Sep 2026 13:19
Microsoft Intune3 what's new3changesMicrosoft Defender XDR2 what's new2changesMicrosoft Entra1 what's new1 important1 heads-up2changes

Key signals

Heads-up Heads-up and plan for change 1

How to read this report

Microsoft Intune

What's new, release notes and known issues 3

Device Management · updated 2026-09-21

not compared yet No previous version of this page yet, so these are the 4 entries under its most recent heading - not necessarily new this week.

  • Not compared yet The Deployments page does not currently support sorting options.
    The Deployments page does not currently support sorting options. The list is sorted based on when a ring starts in an active deployment.
  • Not compared yet Search in the Deployments page only searches on deployment name.
    Search in the Deployments page only searches on deployment name.
  • Not compared yet Deployments
    When you create a deployment for a payload protected by a Multi Admin Approval access policy, the deployment doesn't appear in the Deployments list until the approval is complete.
  • Not compared yet To view the Multi Admin Approval status for a Deployment, open the deployment or use Tenant administration:
    To view the Multi Admin Approval status for a Deployment, open the deployment or use Tenant administration: Multi Admin Approval, or Admin tasks.
In developmentIn development
What's new · updated 2026-09-25

not compared yet No previous version of this page yet, so this is the entry under its most recent heading - not necessarily new this week.

  • Microsoft Intune Suite
  • Not compared yet Scope tags support for Endpoint Privilege Management reports
    We're fixing how scope tags work with Endpoint Privilege Management (EPM) reports. With this change, EPM reports will respect the report viewer's assigned scope and display the details for only the users and devices that the report user is scoped to view.
What's new · updated 2026-09-25

not compared yet No previous version of this page yet, so these are the 16 entries under its most recent heading - not necessarily new this week.

  • Week of September 21, 2026 › Device management
  • Not compared yet Stage app and policy rollout with deployment plansWindows
    Microsoft Intune now supports deployment plans, a new way to roll out apps and configuration policies in stages instead of all at once. From the new Deployments experience in the Intune admin center, you can stage a rollout across multiple rings, control rollout timing, and integrate with Multiple Admin Approval to reduce risk when deploying changes to large device fleets. For more information, see Deployment plans and deployments in Microsoft Intune. Applies to: WindowsWin32 and Enterprise app catalog appsSettings catalog and Endpoint security policies
  • Week of September 28, 2026 (Service release 2609) › Advanced capabilities (formerly "Microsoft Intune Suite")
  • Not compared yet Microsoft Cloud PKI support for US Government GCC HighWindowsAndroidiOS/iPadOSmacOS
    Microsoft Cloud PKI is now available for Microsoft Intune tenants in the Microsoft Government Community Cloud High (GCC High) environment. You can create and manage a cloud-based public key infrastructure that automates certificate issuance, renewal, and revocation for Intune-managed devices without deploying an on-premises certification authority, Network Device Enrollment Service, or Intune Certificate Connector for device certificate delivery. Use these certificates for certificate-based authentication to organizational resources such as Wi-Fi, VPN, and applications. Support includes managed Windows, Android, iOS/iPadOS, and macOS devices. Cloud PKI isn't currently supported in the Department of Defense environment. For more information, see Overview of Microsoft Cloud PKI for Microsoft Intune. Applies to: WindowsAndroidiOS/iPadOSmacOS
  • Week of September 28, 2026 (Service release 2609) › App management
  • Not compared yet Faster delivery of Win32 appsWindows
    Microsoft Intune now uses push notifications for admin-initiated and service-side changes to Win32 apps. Managed devices can check in sooner after app changes, reducing delivery and refresh delays compared with waiting for normal polling intervals. This update improves Win32 app deployment responsiveness without requiring a new admin workflow. Applies to: Windows
  • Not compared yet Newly available protected app for IntuneAndroidiOS/iPadOS
    Microsoft Dragon Copilot by Microsoft Corporation is now available as a protected app for Microsoft Intune. You can apply Intune app protection policies to the app on supported Android and iOS/iPadOS devices, helping protect organizational data while clinicians use its AI-assisted documentation capabilities. For more information, see Microsoft Intune protected apps. Applies to: AndroidiOS/iPadOS
  • Not compared yet Require Managed Home Screen authentication for protected app activitiesAndroid
    Microsoft Intune now helps prevent users from bypassing Managed Home Screen (MHS) authentication when they access protected activities in MAM-integrated apps. If MHS requires sign-in or a session PIN, the app redirects the user to MHS before allowing access to protected content. Assign an Intune app protection policy to both the app and the signed-in user; no specific app protection policy setting is required. For more information, see Configure the Microsoft Managed Home Screen app for Android Enterprise. Applies to: Android Enterprise corporate-owned dedicated devices using Managed Home Screen with Microsoft Entra shared device mode
  • Not compared yet Faster Win32 app delivery after Windows enrollmentWindows
    Microsoft Intune Management Extension now checks for Windows app assignments immediately after the Enrollment Status Page (ESP) completes. This reduces the delay before required Win32 apps that weren't installed during ESP begin installing on newly enrolled devices. For more information, see Intune Management Extension for Windows. Applies to: Windows
  • Week of September 28, 2026 (Service release 2609) › Device configuration
  • Not compared yet New Apple settings in the Settings Catalog for iOS/iPadOS and macOSiOS/iPadOSmacOS
    Microsoft Intune now includes new Apple Settings Catalog options for supported iOS/iPadOS and macOS devices. You can configure additional controls for areas such as app settings, Apple Intelligence, network and web-content filtering, and the macOS login window by using the same Settings Catalog policy workflow in the Microsoft Intune admin center. For more information, see Create a policy using settings catalog. Applies to: iOS/iPadOSmacOS
  • Not compared yet Assignment filters for Android Settings Catalog policiesAndroid
    Microsoft Intune now supports assignment filters for Android Enterprise and Android Open Source Project (AOSP) Settings Catalog policies. You can include or exclude specific devices based on device properties, giving you more granular control over policy deployments and helping apply the right settings to the right Android devices. For more information, see Use assignment filters in Microsoft Intune. Applies to: Android EnterpriseAndroid (AOSP)
  • Week of September 28, 2026 (Service release 2609) › Device enrollment
  • Not compared yet Automatically launch Microsoft Defender for Endpoint during Android Enterprise device setupAndroid
    Microsoft Intune now supports automatically opening Microsoft Defender for Endpoint during out-of-box setup for supported corporate-owned Android Enterprise devices. After you configure the Defender for Endpoint connector, turn on Grant MTD role permissions, and assign the Defender app as required, enable the experience from Endpoint security > Defender for Endpoint. Intune opens Defender during enrollment so users can complete its initial configuration as part of device setup. If configuration isn't completed, the Intune setup step remains available so users can open Defender again. For setup-time availability, assign Defender for Endpoint to user groups or all devices before enrollment. Assignment processing for a specific device group might not complete early enough for Defender to be available during setup. Applies to: Android Enterprise corporate-owned fully managed devices (COBO)Android Enterprise corporate-owned devices with a work profile (COPE)
  • Not compared yet Skip the Device Features Tour during Apple enrollmentiOS/iPadOS
    Microsoft Intune now includes the Device features tour Apple OS 27 Setup Assistant skip key in Automated Device Enrollment profiles. You can hide this pane to reduce setup interactions and provide a more streamlined enrollment experience on supported iPhone and iPad devices. For more information, see Set up automated device enrollment for iOS/iPadOS. Applies to: iOS/iPadOS
  • Not compared yet Upgrade an existing Android Enterprise connection to a managed Google domainAndroid
    Microsoft Intune now supports an optional upgrade for tenants that connected Android Enterprise with a Gmail account. You can link the enterprise to a managed Google domain and manage the Google-Intune connection with your Microsoft Entra work account instead. Start at Devices > Enrollment, select Android, and under Prerequisites, select Managed Google Play. For more information, see Connect your Intune account to your managed Google Play account. Applies to: Android Enterprise
  • Week of September 28, 2026 (Service release 2609) › Device management
  • Not compared yet Bulk manage eSIMs on corporate-owned Android Enterprise devicesAndroid
    Microsoft Intune now supports bulk eSIM actions for corporate-owned Android Enterprise devices. From Devices > All devices > Bulk device actions, you can activate eSIMs on up to 100 selected devices running Android 15 or later by using a carrier activation server URL. When you bulk wipe supported devices, Intune preserves eSIM data plans by default. You can select the option to remove eSIMs when the wipe should also remove the data plans. Personally owned Android Enterprise work profile devices aren't supported. Applies to: Android Enterprise corporate-owned fully managed devices (COBO)Android Enterprise corporate-owned dedicated devices (COSU)Android Enterprise corporate-owned devices with a work profile (COPE)
  • Not compared yet Updated minimum supported version for iOS and iPadOSiOS/iPadOS
    Microsoft Intune now requires iOS/iPadOS 18 or later for standard device-management, Company Portal, and app-protection scenarios. Administrators should identify and upgrade affected devices. Userless devices enrolled through Automated Device Enrollment have a separate support statement. Applies to: iOS/iPadOS
  • Not compared yet New single device page becomes the default experience in the Intune admin center
    Microsoft Intune now uses the new single device page as the default experience for all admins, and the previous device page is no longer available. In Devices > All devices, select a device to view details and properties, monitor activity, access tools and reports, and perform supported actions from a consistent layout across platforms. Existing device-management capabilities remain available. For more information, see See device details in Microsoft Intune. Applies to: All platforms
  • Week of September 28, 2026 (Service release 2609) › Device security
  • Not compared yet Configure MDE AI agent runtime protection for WindowsWindows
    Microsoft Intune now includes Microsoft Defender for Endpoint AI agent runtime protection settings in the new endpoint security template for Windows. You can use Audit mode to detect and alert on unsafe AI agent activity without blocking it, or Block mode to stop threats before they execute. These settings support Windows devices managed through Intune or MDE security settings management. For more information, see AI agent runtime protection with Microsoft Defender for Endpoint. Applies to: Windows
  • Not compared yet Onboard MDM compliance partners with new self-service functionality
    Microsoft Intune now supports bring-your-own connector functionality for MDM compliance partners. Partners can build, test, and onboard compliance connectors using Intune documentation, contracts, and validation hooks. As an admin, you can opt in to a partner connector by providing the vendor's information in the Microsoft Intune admin center, speeding partner onboarding and expanding the compliance solutions available to your organization. For more information, see Self-service onboarding for compliance partners. Applies to: All supported platforms
Changed, no previous version to compare with yet (21)

Microsoft Defender XDR

What's new, release notes and known issues 2

Defender for Office 365 · updated 2026-09-21

not compared yet No previous version of this page yet, so this is the entry under its most recent heading - not necessarily new this week.

  • September 2026
  • Not compared yet Expanding user reporting in Teams to include group calls
    Expanding user reporting in Teams to include group calls: Users can report completed or missed group Microsoft Teams calls from the call history as malicious (scam) or nonmalicious (non-scam). Depending on user reported settings, reported calls are sent to the specified reporting mailbox, to Microsoft, or both.
Defender for Endpoint · updated 2026-09-28 · +19 −9 words

Compared with the previous version: 1 changed

  • Linux releases › Linux | September 2026 | 101.26081.0010
  • Changed Enhancements and featuresLinux

    What changed in this entry (removed / added):

    | Feature area | Update summary | | --- | --- | | Device identity | Fixed an issue where cloned Linux virtual machines could retain the source image's machine identifier, causing multiple endpoints to appear with the same Microsoft Defender for Endpoint device identity. identity.Each cloned endpoint is now correctly identified as a unique device. | | Bug fix | Fixed `SIGILL` crashes on systems with processors that don't support SSE4.1. The crashes were caused by bundled open-source libraries. | | General | Reliability and quality improvements. |
    Full text as it is now| Feature area | Update summary | | --- | --- | | Device identity | Fixed an issue where cloned Linux virtual machines could retain the source image's machine identifier, causing multiple endpoints to appear with the same Microsoft Defender for Endpoint device identity.Each cloned endpoint is now correctly identified as a unique device. | | Bug fix | Fixed SIGILL crashes on systems with processors that don't support SSE4.1. | | General | Reliability and quality improvements. |
Show full page diff
Feature area Update summary
Device identityFixed an issue where cloned Linux virtual machines could retain the source image's machine identifier, causing multiple endpoints to appear with the same Microsoft Defender for Endpoint device identity. identity.Each cloned endpoint is now correctly identified as a unique device.
Bug fixFixed `SIGILL` crashes on systems with processors that don't support SSE4.1. The crashes were caused by bundled open-source libraries.
GeneralReliability and quality improvements.
Changed, no previous version to compare with yet (64)

What's new, release notes and known issues 1

Hybrid · updated 2026-09-24

not compared yet No previous version of this page yet, so this is the entry under its most recent heading - not necessarily new this week.

  • Not compared yet Known issue: Synchronization fails after upgrade if miiserver.exe.config was previously modified
    Applies to Microsoft Entra Connect 2.5.190.0Microsoft Entra Connect 2.6.1.0

Important changes 1

Global Secure Access · updated 2026-09-28 · +359 −158 words

Changed in:

What changed
Configure dynamic and AutoReuse TCP port ranges
Expanding ephemeral port range
Private network connectors initiate outbound TCP and UDP connections to configured destinations. Each connection requires an available source port on the connector host.
Private network connectors initiate TCP and UDP connections to designated destination endpoints. These connections require available source ports on the connector host machine. Expanding the ephemeral port range can improve the availability of source ports, particularly when you're managing a high volume of concurrent connections.
For high-volume TCP workloads, configure separate, non-overlapping dynamic and AutoReuse port ranges:
To view the current dynamic port range on a system, use the following netsh commands:
Dynamic TCP range: 49152–65535 (16,384 ports)
netsh int ipv4 show dynamicport tcp
AutoReuse TCP range: 10000–49151 (39,152 ports)
netsh int ipv4 show dynamicport udp
The AutoReuse range improves TCP connection scalability by allowing eligible outbound connections to reuse a local source port when the complete connection tuple—source IP, source port, destination IP, and destination port—remains unique.
netsh int ipv6 show dynamicport tcp
Important
netsh int ipv6 show dynamicport udp
The dynamic and AutoReuse TCP ranges must not overlap.
Here are sample netsh commands to increase the ports:
Before you begin:
netsh int ipv4 set dynamicport tcp start=1025 num=64511
Use Windows Server 2016 or later.
netsh int ipv4 set dynamicport udp start=1025 num=64511
Run the commands from an elevated PowerShell session.
netsh int ipv6 set dynamicport tcp start=1025 num=64511
Confirm that ports 10000–49151 aren't required by applications installed on the connector server.
netsh int ipv6 set dynamicport udp start=1025 num=64511
Review the excluded TCP port ranges:
… 16 more changes: see the page or its history
Minor changes (1) · fewer than 15 words
Changed, no previous version to compare with yet (34)
↑ Top