Skip to content

What’s new in Microsoft Intune – August

At scale, endpoint management becomes a different job. A two-minute task on one device can become months of work across thousands of devices. Organizations can’t add headcount every time the device estate grows. They need repeatable processes that give IT admins’ time back.


This month’s updates support the device lifecycle, from provisioning devices with trusted identity before they ever reach enrollment, to unattended remote access and preparing Apple device settings.


Establish trust during provisioning, before enrollment


Windows Autopilot device association is now generally available. Device association is a Windows Autopilot device preparation capability that can help admins associate devices to their tenant before enrollment in Microsoft Intune and establish trust earlier in the onboarding flow. This step adds an extra layer of onboarding security by verifying device identity before enrollment with cryptographic keys and TPM attestation, helping ensure that only trusted devices gain access to organizational resources.


For teams deploying devices with Autopilot device preparation, we’ve added a streamlined path from first boot to a productive, managed Windows device. Device association enables device-based device preparation policies, out-of-box experience customization, and support for renaming devices before enrollment. This capability is rolling out with support for the upcoming Windows update and will become available as the required OS update is released to devices. For more detail read the customer success blog on Autopilot device preparation.


Resolve device issues on your schedule


Microsoft Intune Remote Help unattended access with remote sign-in gives IT teams the flexibility to support Windows devices whenever assistance is needed, even when the device is idle and no user is signed in. With remote sign-in, help desk agents can securely access a physical Windows device using their own credentials, so a user does not have to be present to accept the remote help connection. This makes it easier to provide support during scheduled maintenance, after-hours operations, and across distributed branch office environments.


Access is scoped through a dedicated role-based access control (RBAC) permission, so unattended support can be reserved for admins authorized for their designated device set. This lets IT teams run maintenance at optimal times and resolve issues sooner, with Intune still enforcing access and audit controls throughout every session. For more details, read guidance on unattended support with remote sign-in.


Figure 1, Administrators can start an unattended control session from the same place in the Intune admin center used for attended support today.

Stay in control of apps and help resolve AppleCare cases faster


In anticipation of Apple releasing its new OSes in the coming months, we’ve added new capabilities to ensure you’re prepared, especially as AI adoption accelerates across your digital estate. Although the new release will have many additional features to configure, we want to highlight two of them.


The first is the App Settings configuration, a native way for admins to manage apps and binaries, including AI apps, on managed Mac devices running macOS 27 and later. That matters for organizations that want to prevent specific apps from running on their devices. Before this, blocking an app meant standing up and maintaining complex open-source tooling. When managing only a few hundred devices, that’s a workaround. But workarounds do not scale. And every new app widens the gap until it becomes a system nobody wants to own or manage. Admins can now stay in control of allowed and denied apps and binaries with a single policy in the Intune admin center.


The second is the new enhanced logging device actions option to minimize a lot of the manual work needed for collecting logs on AppleCare support cases. Admins can put a device into an enhanced logging state to ensure its log files go directly to the AppleCare case. The old path meant asking the user to trigger log collection, then uploading the files by hand. Now it’s streamlined into a device action, reducing interruptions for users. For more details on Apple’s announcement, see WWDC26 app management updates.



Intune: Myth vs. Reality


Myth: Organizations need a dedicated third-party endpoint management tool to deploy and run Microsoft Defender for Endpoint at scale.


Reality: Built-in integration between Microsoft Intune and Defender for Endpoint helps organizations make the most of their existing Microsoft investments, reduce tool sprawl, and avoid managing and reconciling separate endpoint security and management systems.


Onboarding, configuration, and ongoing security management are available through Intune as native, first-party capabilities. From the Intune admin center, admins can deploy Defender onboarding policies, apply protection using Microsoft-recommended security baselines or targeted endpoint security policies, and manage security settings at scale.


The built-in integration between Intune and Defender for Endpoint connects threat detection with device compliance and access. When appropriate policies are configured, Defender for Endpoint risk signals can inform compliance in Intune, and Conditional Access can prevent at-risk devices from accessing company resources without manual intervention.


Still have questions about switching from a third-party solution? Watch Microsoft MVP Jonathan Edwards’ video, 99% of IT Teams still get Microsoft Defender & Microsoft Intune Wrong, where he addresses the common concerns and explains the benefits of running Defender alongside Intune.


How: Follow the new Defender and Intune Technical User Manual for a clear, sequenced path from setup to full integration.


 



Native Defender for Endpoint integration is one more example of the same theme running through this month’s blog. Fewer tools to manage. Fewer manual steps. More of IT’s time going toward the work that actually needs judgment. That’s what scaling with Intune looks like in practice. Tell us in the comments which capability you’ll put to work first.




Stay up to date! Bookmark the Microsoft Intune Blog and follow us on LinkedIn  or @MSIntune and @IntuneSuppTeam on X to continue the conversation.

Microsoft Tech Community originally posted this article on 27 August 2026 at 7:06 PM.

Leave a Reply