Intune in July: macOS custom compliance and Defender settings that finally win
Custom compliance comes to macOS, a preview stops Group Policy overriding your Defender settings, and Store app search goes regional.
On this page
Custom compliance for macOS
Custom compliance has been available for Windows and Linux: a script reports values and a JSON file defines the rules. It now comes to macOS. If you've been unable to express a Mac compliance requirement with the built-in settings, such as a specific agent running or a configuration file present, you now can.
The pattern is the same on every platform: a script reports values as JSON, and a rules file states what's compliant.
Controlled configuration for Defender Antivirus (preview)
Defender Antivirus settings can come from Intune, Defender for Endpoint, Group Policy, Configuration Manager or local scripts, and conflicts are a classic headache. The new controlled configuration preview lets Intune or Defender for Endpoint settings take precedence over Group Policy, Configuration Manager and local scripts. For co-managed estates mid-migration, that's very welcome.
Samsung Knox E-FOTA
Intune can now manage firmware updates for corporate-owned Samsung devices with Knox E-FOTA, across dedicated, fully managed and work profile corporate-owned devices.
Regional Microsoft Store search
When adding Microsoft Store apps, you can now choose a market catalogue rather than only searching the US catalogue. Useful when an app is only published in certain regions.
What to do this month
- Mac fleets: list compliance requirements the built-in settings can't express, and pilot custom compliance
- Co-managed fleets: test controlled configuration in a pilot to end Defender setting conflicts
- Samsung corporate devices: decide whether to manage firmware updates with E-FOTA
- Check your Store app search uses the right market catalogue