Intune Newsletter – 25th September 2026

Happy Friday, it’s time for your favourite Intune news!  Quite an international feel this week, you may notice from a few of the more strange URLs that I’ve been looking at blogs in different languages as well, but have linked the UK translation to save you precious clicks!

I’m always looking for new people to follow so please let me know if I’m missing anyone!


Community Content

We start this week with a look at the different types of (Windows) application available within Intune and where to use which from Mark Oldham

https://medium.com/@m.oldham/microsoft-intune-app-deployment-guide-store-lob-and-win32-apps-explained-1691af0bdc8b


If you have ever wanted compliance to be just that bit quicker, it’s coming soon.  Learn about the new Client driven compliance here from Laurent Gébeau

https://www-toutwindows-com.translate.goog/blogtoutwindows/intune-client-driven-compliance-evaluation-mise-a-jour-rapide-de-la-conformite-intune/?_x_tr_sl=fr&_x_tr_tl=en&_x_tr_hl=en-GB


You may have noticed the wipe options have recently changed in the new device view.  Find out which method is best for your org in this post from James Vincent

Which Windows device wipe/reset method is right for you?


A new preview release which appeared in my tenant today, deployment plans so you can stagger your policy and app deployments like you do with Autopatch.  Jonathan Fievet takes a closer look here

https://leblogmodernworkplace-fr.translate.goog/deployment-plans-dans-microsoft-intune-le-rollout-progressif-enfin-natif/?_x_tr_sl=fr&_x_tr_tl=en&_x_tr_hl=en-GB


Mathias Borowicz also looks at the wave deployments here

https://zerotruststories.com/how-to-use-native-wave-deployment-in-intune/


Next, Dustin Gullett looks at the new Entra token protection for browsers and how to use it to protect your admin portals

https://zerototrust.tech/microsoft-entra-token-protection-for-browsers-same-key-wrong-car/


This post from Arno van Dijk looks at what Autopilot Device Prep Device Association adds to your deployment strategy

https://www.xplorethecloud.nl/l/windows-autopilot-device-preparation-explained-what-device-association-really-adds-to-the-oobe-experience/


If you are finding you are hitting 401 walls in Graph when using your unlicensed admin account, this post from Roy Klooster should help you out

https://rksolutions.nl/posts/thought-global-reader-could-read-everything-intune-says-401/


By now I’m sure you all know how I feel about browser extensions!  If you want to track them in your tenant and have defender licensing, try this post from Jeffrey Appel

How to track browser extension installations with Microsoft Defender


When dealing with kiosks, the order of configuration is critical, you don’t want a config to hit before the app has arrived.  If this sounds familiar, try this post from Peter van der Woude

Making sure the multi-app kiosk configuration is applied after the installation of the applications


With the imminent retirement of SMS and Voice MFA, check how you are impacted and what happens to your SSPR config here with Rahul Jindal

https://rahuljindalmyit.blogspot.com/2026/09/microsoft-entra-sms-and-voice.html


Learn how to use Windows point in time restore in this post from Driek Desmet

Windows 11 Point in Time Restore with Intune: Configuration and Recovery Strategy


For those of you managing surface devices, see how DFCI can work for you, but with the right config in this post from Mr T-Bone

DFCI on Surface: Intune Reaches Below Windows, and One Checkbox Combo Can Cost You an SSD


Delve into the murky world of app control for business here with Andrew Blumhardt 

App Control for Business: Looking Beyond the Surface


If you want more control over how Edge updates (and informs your users), try this guide from Kevin Malinoski

Your Edge Updates Have No Deadline (….and how to set one with Intune)


Video Content

Onto this weeks video content, starting with a look at hybrid joined devices, how they work, how to join your devices and why they are a perfect stepping stone from Jonathan Edwards


For those who prefer a video, Mark Oldham has a video run-through to follow the blog post earlier covering apps in Intune


Learn how to grab Bitlocker keys with PowerShell in this video from Liam Robinson


This video from Steve Weiner covers how to opt out of passkeys in Entra with the end of SMS and Voice MFA


Microsoft Content

Now for this weeks Microsoft content starting with an excellent addition to Windows 365 Reserve where you can allow users to provision machines themselves.  Learn more here from Logan Silliman

https://techcommunity.microsoft.com/t5/windows-it-pro-blog/general-availability-user-initiated-provisioning-for-windows-365/ba-p/4557248


Users can now select which desktop apps can access the camera and microphone rather than a catch-all as covered here by Rohit Kurup

https://techcommunity.microsoft.com/t5/windows-it-pro-blog/giving-you-more-control-over-camera-microphone-and-location/ba-p/4559374


Find out what the release of Apple OS 27 brings to Intune in this post from the Intune Support Team

https://techcommunity.microsoft.com/blog/IntuneCustomerSuccess/microsoft-intune-and-apple-os-27-new-settings-support-and-platform-changes/4559764


That’s all for this week, have an amazing weekend

Leave a Comment