In der vergangenen Woche wurden 15 Neuerungen in Microsoft Intune eingeführt, die Windows und Android und Apple-Geräte betreffen. Daneben gibt es eine neue Funktion in der Public Preview. Diese Updates stärken die Sicherheitslage und verbessern die Benutzererfahrung in Unternehmen. #MicrosoftIntune #Windows #Android #AppleGeräte #PublicPreview #Geräteverwaltung #ITManagement #KaffeeUndCode
Windows:
- New settings available in the Windows settings catalog: Microsoft Intune now includes new settings in the Windows settings catalog for Windows devices. You can configure options for camera behavior, Keyboard Filter controls (for Windows Insider devices), and Windows Subsystem for Linux (WSL).
- New Microsoft Edge settings in the Windows settings catalog: The Microsoft Edge administrative templates were refreshed to Microsoft Edge 149 (version 149.0.4022.21), which adds the latest Microsoft Edge 148 and 149 policy settings to the Windows settings catalog. The new settings are: For the full list of policies, see the Microsoft Edge policies reference.
- New Windows App (Azure Virtual Desktop) settings in the Windows settings catalog: There are new Windows App settings in the Windows settings catalog. To see and configure them in Intune, create a Windows settings catalog profile (Devices > Manage devices > Configuration > Create > New policy > Windows 10 and later > Settings catalog). The new settings are:
- New option for the Remove Default Microsoft Store packages setting: The existing Remove Default Microsoft Store packages setting in the ApplicationManagement area has a new subsetting, Specify additional package family names to remove. It lets you provide a custom list of package family names (PFNs) to remove, in addition to the built-in default set of Microsoft Store packages.
- New setting to disable the Get Started app: The new Disable Get Started setting prevents the Windows Get Started app from being available to users.
For more information, see the Experience policy CSP. - New OneDrive settings in the Windows settings catalog: There are new OneDrive settings in the Windows settings catalog:
- Updated Visual Studio administrative templates in the Windows settings catalog: The Visual Studio administrative templates were refreshed to version 1.0.184.40051, which adds the latest Visual Studio policy settings to the Windows settings catalog. The new setting is:
- Collect Windows registry data with the properties catalog: Microsoft Intune now lets you collect Windows registry data through the properties catalog. When you create a device inventory policy, you can define specific registry keys and values to collect from enrolled Windows devices, including a single value, all values directly under a key, or the same value across subkeys under HKEY_LOCAL_MACHINE.
- Improved on-demand device sync for Windows devices: Microsoft Intune now supports a more comprehensive on-demand sync for Windows devices. When you select the Sync device action in the Microsoft Intune admin center, Intune initiates a full synchronization across key workloads, including configuration policies, apps, and scripts, so devices reflect your latest changes faster.
- Controlled Configuration for Microsoft Defender antivirus settings (Public Preview): In preview, Microsoft Intune now supports Controlled Configuration for Microsoft Defender antivirus settings. When you enable it, the Defender antivirus settings delivered by Intune or Microsoft Defender for Endpoint security settings management become authoritative and override configurations from other channels, such as Group Policy, Configuration Manager, and local scripts.
- Regional support for Microsoft Store apps: Microsoft Intune now supports regional selection for Microsoft Store apps. When you add a Microsoft Store app, you can choose the region (market) whose Store catalog to search and deploy from.
Android:
- Samsung Knox E-FOTA firmware update management for Android Enterprise devices: Microsoft Intune now integrates with Samsung Knox E-FOTA (Firmware Over-The-Air), so you can manage firmware updates for corporate-owned Samsung devices directly in the Microsoft Intune admin center. Control which firmware version each device receives, deploy updates without user interaction, and schedule downloads and installations to reduce downtime.
- Dedicated RBAC permission for zero-touch enrollment: Microsoft Intune now provides a dedicated role-based access control (RBAC) permission for Google zero-touch enrollment portal access. Previously, the zero-touch enrollment iframe in the Microsoft Intune admin center required the Update app sync permission, which also grants rights to manage Managed Google Play app sync.
iOS/macOS:
- Skip Setup Assistant screens for tvOS and visionOS enrollment: Microsoft Intune now supports hiding or showing new Setup Assistant screens during automated device enrollment (ADE) for tvOS and visionOS devices. When you configure an enrollment profile, you can choose which screens, such as Apple ID, Diagnostics Data, and Location Services, appear during setup.
- Custom compliance settings for macOS: Microsoft Intune now supports custom compliance settings for macOS. As an admin, you can define compliance checks using scripts and JSON rules, similar to existing support for Windows and Linux.
Public Preview & Beta:
- Controlled Configuration for Microsoft Defender antivirus settings (Public Preview): In preview, Microsoft Intune now supports Controlled Configuration for Microsoft Defender antivirus settings. When you enable it, the Defender antivirus settings delivered by Intune or Microsoft Defender for Endpoint security settings management become authoritative and override configurations from other channels, such as Group Policy, Configuration Manager, and local scripts.
Fazit:
Die aktuellen Updates von Microsoft Intune verbessern die Effizienz und Sicherheit der Geräte- und Anwendungsverwaltung, insbesondere für Windows und Android und Apple-Geräte. IT-Administratoren können nun ihre Aufgaben effektiver und sicherer durchführen, was zu einer verbesserten Benutzererfahrung führt. #MicrosoftIntune #Windows #Android #AppleGeräte #PublicPreview #Geräteverwaltung #ITManagement #KaffeeUndCode
Academy
Weiterlernen in der Kaffeeundcode Academy
Wenn du diese Themen systematisch vertiefen willst, schau dir den ersten Academy-Kurs zur PSADT-Softwarepaketierung an. Im Fokus stehen .msi, .exe, Silent Switches, Detection, Logs und ein belastbarer Troubleshooting-Workflow.
# #iOS # Administration # AndroidEnterprise # AppleManagement # EndpointManagement # Geräteverwaltung # IntuneUpdate # macOS # MicrosoftIntune # SamsungKnox # Security # Sicherheit
Vorheriger BeitragSektion 06: Autopilot Profiles – User-driven vs. Self-deploying vs. Pre-provisioning
Nächster BeitragMicrosoft Enterprise News – Update 03.08.2026