Intune Newsletter – 4th September 2026

September has arrived and with it comes both the conference season and a LOT of rain.  Congratulations to the new Intune MVPs this week, especially Nicky De Westelinck and Mads Johansen who you will have seen in here a lot (Nicky even has a post this week)


Community Content

With the end-of-life of the Dev Boxes in Azure, Microsoft announced a developer special Windows 365 image at Build 2026.  This post from Aresh Sarkari looks at what it includes and also has a useful script to quickly provision a machine!

Windows 365 Cloud PC for Developers – Developer Configuration Image + PowerShell Provisioning


Michael Frank continues diving into the world of security copilot, this time looking at the new vulnerability agent, what it brings and how to use it

https://michaelsendpoint.com/intune/SecurityCopilot/VulnerabilityAgent.html


We have the third part of the excellent series from Michael Meier looking at automating your custom VM images.  This part looks at a limitation on editing your templates after deployment and how to work around it with DevOps pipelines

Using Azure Image Builder to build your custom VM Images – Part 3


On the subject of AVD, you will want a secure landing zone in place before you start building anything.  This comprehensive guide from Dieter Kempeneers is a great starting point

https://kempeneers.eu/2026/08/31/building-a-secure-azure-landing-zone-for-avd-and-windows-365/


If you are also managing Entra environments, you probably know the pain of managing custom extensions.  Luckily for you, Sebastian F. Markdanner has a new application to help you

https://www.chanceofsecurity.com/post/introducing-entra-extensions-manager


Now point in time restore is GA on Windows, learn how to manage it and use it here from Peter van der Woude

Configuring Point-in-time restore in Windows


Newly minted MVP Nicky De Westelinck looks at all of the new goodies available for Android Enterprise in the 2608 Intune release

What’s New for Android Enterprise in Microsoft Intune 2608: August 2026 Highlights


You have until November to remove any MemberOf rule within Entra dynamic groups before they simply stop working.  Use this script from Tobias Eriksson to rapidly fix them

How to Find and Bulk-Replace Every MemberOf-Rule in Entra ID (Before the November 2026 retirement)


You can now use token protection to protect your key web apps (Intune, Entra etc.)  Learn how to implement these to further increase your security in this post from Jan Mulder

How to use token Protection for web apps in Windows 11


If you are switching to Device Prep with Device Association, you probably want things to run a bit quicker than the backwards and forwards with CSV files.  Rudy Ooms has created a new script to run during OOBE and sort it all for you here

Windows Autopilot Device Association: somebody has to be the OEM


If you are worried about AI running on your devices, check out this guide from Jannik Reinhard to get you underway

Detect and Block Shadow AI with Intune: OpenClaw in Practice


If you have been having issues with Company Portal on your Apple devices, check out this post from Jeroen Burgerhout

https://www.burgerhout.org/p/getting-company-portal-back-after-the-new-ade-policy-quietly-drops-it


Next, this post from Mecken Swyter is great for taking your Windows compliance to a whole new level

https://meckenswyter.com/intune/custom-compliance-policies-intune


Video Content

Now for this weeks video content starting with two videos from Chander Mani Pandey looking at the new Autopilot Device Association functionality.  The first video runs through how to bind a device to your tenant.

Chander’s second video looks at how to pre-associate devices to the tenant


A quick but very useful video from Mark Oldham showing how to block personal devices from enrolling into your Intune tenant.


Microsoft Content

Onto the Microsoft content, starting with a guide on how to plan your GPO to Intune migration from Per Larsen

https://techcommunity.microsoft.com/blog/IntuneCustomerSuccess/from-gpo-to-microsoft-intune-a-practical-guide-to-cloud-first-policy-management/4551946


You will soon have VBS backed kernel-level protection on your Windows devices as covered here by Peter Waxman

https://techcommunity.microsoft.com/t5/windows-it-pro-blog/expanding-memory-integrity-protection-across-windows-devices/ba-p/4551984


The all important Windows news you can use is here for August from Chris Morrissey

https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-news-you-can-use-august-2026/4552394


That’s all for this week, have an amazing weekend

Leave a Comment