Intune in September: deployment rings, faster compliance and stricter automation
Five recent Intune changes that affect how you roll out, how quickly devices become compliant, and whether your automation keeps working.
On this page
Deployment plans: proper rings, built in
The new Deployments experience lets you stage a rollout across multiple rings with controlled timing, instead of assigning straight to everyone or juggling pilot groups by hand. It works with Win32 apps, Enterprise App Catalog apps, Settings Catalog policies and endpoint security policies, and integrates with Multiple Admin Approval.
For anything risky, such as a new security baseline or a firewall policy change, this should become the default way you deploy.
- IT devices, day 1
- Pilot users, day 3
- 25% of devices, day 7
- Everyone, day 14
Client-driven compliance evaluation (preview)
Compliance on Windows has traditionally waited for the next check-in. Now supported Windows devices notice when a compliance signal changes, such as the firewall, antivirus, BitLocker, Defender status, OS build, real-time protection or Secure Boot, and ask Intune to re-evaluate straight away.
The practical benefit is speed. When a user fixes the problem that blocked them, they get access back faster. When a device falls out of compliance, Conditional Access catches it sooner.
Scheduled check-in
- Device re-evaluates on its next check-in
- Delay between fixing a setting and getting access
Client-driven (preview)
- Device notices a signal change
- Asks Intune to re-evaluate straight away
- Firewall, antivirus, BitLocker, Secure Boot…
Multi Admin Approval now covers Graph automation
Multi Admin Approval (MAA) used to apply only to changes made in the admin center. It now applies to Microsoft Graph calls too. If you have MAA access policies protecting a resource, scripts and apps that change it without going through approval now get an HTTP 403 error.
- Check which automation touches MAA-protected resources, such as app deployments or scripts.
- Update those scripts to follow the MAA approval workflow.
- If you can't change an app yet, use the new Exclusions tab in the access policy to exempt it. Treat that as temporary.
Windows 11 26H2 security baseline
A new security baseline for Windows 11, version 26H2, is available. Existing baseline profiles don't update automatically. Create a new profile or update the version on an existing one, and compare the setting changes first. Deployment plans are a sensible way to roll it out.
iOS/iPadOS 18 is now the minimum
Intune now requires iOS/iPadOS 18 or later for standard device management, Company Portal and app protection policies. Check your device inventory for older devices before users run into problems.
Checklist
- Plan a deployment plan for the next baseline or major policy change
- Pilot client-driven compliance on a few Windows devices
- Find scripts and apps that change MAA-protected resources
- Create a new 26H2 baseline profile and compare settings
- Report on iOS devices below version 18