azureblog.co.uk
← cd ~/posts

Intune in September: deployment rings, faster compliance and stricter automation

Five recent Intune changes that affect how you roll out, how quickly devices become compliant, and whether your automation keeps working.

2 min read✓ checked 6 Oct 2026Intune · Windows · What's new
On this page
  1. Deployment plans: proper rings, built in
  2. Client-driven compliance evaluation (preview)
  3. Multi Admin Approval now covers Graph automation
  4. Windows 11 26H2 security baseline
  5. iOS/iPadOS 18 is now the minimum
  6. Checklist

Deployment plans: proper rings, built in

The new Deployments experience lets you stage a rollout across multiple rings with controlled timing, instead of assigning straight to everyone or juggling pilot groups by hand. It works with , Enterprise App Catalog apps, Settings Catalog policies and endpoint security policies, and integrates with Multiple Admin Approval.

For anything risky, such as a new security baseline or a firewall policy change, this should become the default way you deploy.

  1. IT devices, day 1
  2. Pilot users, day 3
  3. 25% of devices, day 7
  4. Everyone, day 14
A typical ring plan for a security baseline.

Client-driven compliance evaluation (preview)

Compliance on Windows has traditionally waited for the next check-in. Now supported Windows devices notice when a compliance signal changes, such as the firewall, antivirus, BitLocker, Defender status, OS build, real-time protection or Secure Boot, and ask Intune to re-evaluate straight away.

The practical benefit is speed. When a user fixes the problem that blocked them, they get access back faster. When a device falls out of compliance, catches it sooner.

Scheduled check-in

  • Device re-evaluates on its next check-in
  • Delay between fixing a setting and getting access

Client-driven (preview)

  • Device notices a signal change
  • Asks Intune to re-evaluate straight away
  • Firewall, antivirus, BitLocker, Secure Boot…
Scheduled versus client-driven compliance.

Multi Admin Approval now covers Graph automation

Multi Admin Approval (MAA) used to apply only to changes made in the admin center. It now applies to calls too. If you have MAA access policies protecting a resource, scripts and apps that change it without going through approval now get an HTTP 403 error.

  • Check which automation touches MAA-protected resources, such as app deployments or scripts.
  • Update those scripts to follow the MAA approval workflow.
  • If you can't change an app yet, use the new Exclusions tab in the access policy to exempt it. Treat that as temporary.
ScriptMicrosoft GraphMulti Admin ApprovalChange protected appassignment1Is this resource protected?2Yes; no approval header3HTTP 4034Fix: follow the approvalworkflow, or exclude the apptemporarily
An automation call against a protected resource.

Windows 11 26H2 security baseline

A new security baseline for Windows 11, version 26H2, is available. Existing baseline profiles don't update automatically. Create a new profile or update the version on an existing one, and compare the setting changes first. Deployment plans are a sensible way to roll it out.

iOS/iPadOS 18 is now the minimum

Intune now requires iOS/iPadOS 18 or later for standard device management, Company Portal and app protection policies. Check your device inventory for older devices before users run into problems.

Checklist

  • Plan a deployment plan for the next baseline or major policy change
  • Pilot client-driven compliance on a few Windows devices
  • Find scripts and apps that change MAA-protected resources
  • Create a new 26H2 baseline profile and compare settings
  • Report on iOS devices below version 18
You've reached the end of Intune for Windows, start to finishBack to the path →