Intune Newsletter – 24th July 2026

Hopefully you didn’t miss this too much last week, I was away enjoying a relaxing break in Madeira with my family, but we have content from the last 2 weeks here so you haven’t missed anything


Community Content

We start this week with the next 2 parts of the excellent Intune Agents series from Gerry Hampson with part 4 looking at the Vulnerability Remediation agent

http://gerryhampsoncm.blogspot.com/2026/07/my-first-look-at-intune-agents-part4.html

And part 5 looking at obtaining agents from the marketplace in the Microsoft Security Store

http://gerryhampsoncm.blogspot.com/2026/07/my-first-look-at-agents-part5-security.html


This remediation from Jorge Suarez will help keep your VS Code extensions managed

https://jorgeasaur.us/manage-vs-code-extensions-with-intune-remediations


We also have two posts from Michael Meier starting with a quick notice about a Microsoft rename (that’s unusual), but worth checking in case it hits your filters

Windows 365 Frontline was renamed to Windows 365 Flex

Michael also looks at how AVD Hybrid unlocks VDI on all hypervisors

AVD Hybrid allows for VDI on any Hypervisor


For those of you with SCUs to use, Michael Frank looks at the CA Agent now included in Security Copilot

https://michaelsendpoint.com/entra/SecurityCopilot/CAAgent.html


Niall Brady looks at the new Windows 365 Reserve option available now (a very useful one for everyone)

First looks at Windows 365 Reserve


Learn how to use Cloud PKI and Cert Based Authentication here with Nicky De Westelinck 

Goodbye Passwords: Certificate-Based Authentication on Windows with Cloud PKI in Microsoft Intune

Nicky also looks at certificate based authentication for your Android devices

Beyond Passwords: Certificate-Based Authentication for Android Enterprise


Some very important news for anyone in the EU, you can now configure the settings to automatically accept SSO permissions which will make things so much better for your users.  Many people covering this one, starting with Jóhannes Geir Kristjánsson, setting it via Remediation

Automatically Accept SSO Permissions


Joey Verlinden also has a script here to set the required registry key

The long awaited DMA-SSO Admin Controls!


Jan Bakker covers the requirements and some further background here

Admin control for SSO prompts in Windows; finally, an off switch!


If you want to know exactly what’s happening, we have a great deep dive here from Rudy Ooms

AutoAcceptSsoPermission: The Continue to Sign In Prompt Fix


Joery Van den Bosch also looks at how this helps different user personas and also includes a remediation to deploy it

Admin control for SSO prompts in Windows – How to configure this in Intune


The final SSO post comes from Mads Johansen with the easier solution, Settings Catalog

https://evil365.com/intune/Microsoft-EU-SSOHassle/


There is nothing worse than sitting down at a new device and finding the @ is on the wrong key, or the £ is missing altogether.  Fortunately, this remediation from Alex Durrant will help you configure regional settings on your devices

Intune: setting regional settings using proactive remediations


We have a new web based tool from Simon Hartmann Eriksen to quickly inspect MSI packages within the browser

Web tool: MSIinfo.com


We have a new tool from Mark Orr as well, this one to quickly assign Access Packages to your users

https://medium.com/@markhunterorr/access-packages-on-demand-assignment-from-powershell-3fdcfacd803e


If you are managing macOS devices, the lack of naming templates may be causing you issues.  Fortunately Tobias Eriksson has a solution for you here

How To Setup a Device Naming Template for macOS in Intune


On the subject of macOS, Anthon N has created a very useful onboarding toolkit available here

https://github.com/SuperDOS/macos-otk


If you’re managing Windows Kiosk devices, this remediation from Dustin Gullett will be an absolute lifesaver

https://getrubix.com/blog/find-blocked-kiosk-apps-at-scale-with-intune-remediations


If you have E5 licensing and are considering testing EAM, have a look at this post from Jannik Reinhard

Enterprise App Management Auto-Update: Now Generally Available


If you are using Windows 365 Link devices and need to do a bare metal recovery, try this guide from Dieter Kempeneers

How to Perform a Windows 365 Link Bare-Metal Recovery


Video Content

Now for the video content starting with two from Chander Mani Pandey, the first assists with troubleshooting, showing where to find the last device check-in time

The second video runs through the Enterprise App Management functionality now available with your E5 licenses


If you are receiving a lot of sign-in requests for your account which are not from you, this video from Dean Ellerby is well worth watching


Learn all about the new Device View in Intune here with Steve Weiner

Also learn how to enable EAM Auto updates in this video from Steve


If you’ve ever attempted Platform SSO on macOS, it’s not as easy as it looks (if you were at Experts Live UK, you know that better than others), fortunately Saurabh Sarkar has created a full in-depth video walkthrough here


Microsoft Content

Onto the Microsoft content we go, starting with the official announcement for the SSO management from Justin Ploegert

https://techcommunity.microsoft.com/t5/windows-it-pro-blog/now-available-admin-control-for-sso-prompts-in-windows/ba-p/4534613


Find AI tools on your macOS devices using MDE by following this guide from Vytas Boyev

https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/hunting-local-ai-tools-on-macos-with-microsoft-defender-for/ba-p/4536965


Chris Morrissey explains all of the Windows updates servicing options here

https://techcommunity.microsoft.com/t5/windows-it-pro-blog/understanding-windows-monthly-updates-servicing-explained/ba-p/4532290


That’s all for this week, have a great weekend!

Leave a Comment