Table of Contents
Introduction
Welcome back! It is properly hot in Sweden right now, the kind of summer where you get as close to the water as you can and stay there. Lake, sea, pool, I am working my way through all three, so I hope you are finding your own bit of shade and daylight between deployments. This edition covers a slightly longer span, from mid June into early July, and it turned out to be a big one for licensing and servicing.
Some highlights:
Intune Suite capabilities are moving into Microsoft 365 E5.
As of 1 July, Endpoint Privilege Management and Enterprise App Management are included in E5, and the June service release also brought the Vulnerability Remediation Agent into public preview, EAM app auto-updates to GA, and a redesigned Apple ADE enrollment experience. If you are on E5, it is worth checking what you now have without buying anything extra. https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune-%E2%80%93-june/4491983
Windows 11 version 26H2 is available for early validation.
It ships as a small enablement package over 24H2 and 25H2, with general availability expected in the second half of the year. Now is a good time to test in the Experimental channel and line up your rings. One thing to plan around while you are there: the final phase of Kerberos RC4 hardening begins with the July security update, leaving Enforcement mode as the only supported behavior. https://techcommunity.microsoft.com/blog/windows-itpro-blog/get-ready-for-windows-11-version-26h2/4529367
Context-based redirections for Windows 365 and Azure Virtual Desktop are in public preview.
You can now condition clipboard, drive, USB and printer redirection on Conditional Access signals such as device compliance and network location, instead of a single blanket setting. https://techcommunity.microsoft.com/blog/windows-itpro-blog/adaptive-data-protection-with-context-based-redirections-in-windows-365-now-in-p/4521366
Hope you have a good week.
/Daniel
Intune updates from the community
Intune Multi Admin Approval: the x-msft-approval-justification error https://patchmypc.com/blog/intune-multi-admin-approval-the-x-msft-approval-justification-error/ Rudy Ooms
If you run any app-based Graph automation, read this first. Multi Admin Approval now reaches app-based Graph actions, and Intune app updates started failing with the x-msft-approval-justification error. Rudy walks through exactly what changed and how to handle it before it stalls your pipelines.
Microsoft Intune June 2026: app auto-updates, privilege controls, and enrollment improvements https://4sysops.com/archives/microsoft-intune-june-2026-app-auto-updates-privilege-controls-and-enrollment-improvements/ 4sysops
EPM: The End of Local Admin (three-part series) https://msendpointmgr.com/2026/06/15/epm-part-1-the-end-of-local-admin-how-intune-endpoint-privilege-management-solves-a-problem-it-has-lived-with-for-decades/ Mattias Melkersen Kalvåg and Simon Skotheimsvik
The Ultimate Intune Troubleshooting Guide https://jannikreinhard.com/2026/06/23/intune-troubleshooting-guide/ Jannik Reinhard
Monitor Intune devices with old BIOS versions using Device Query https://www.systanddeploy.com/2026/06/monitor-intune-devices-with-old-bios.html Damien Van Robaeys
Resetting Forced Edge PWAs: a quick guide for IT admins https://sastu-insights.com/posts/Resetting-Forced-Edge-PWAs-Quick-Guide-for-IT-Admins Sascha Stumpler
Web-based enrollment for personally owned Android work profiles https://www.nickydewestelinck.be/2026/06/22/simplifying-android-enrollment-web-based-enrollment-for-personally-owned-work-profiles-in-intune/ Nicky De Westelinck
Configuring Remote Help in Microsoft Intune: a step by step guide https://nickydewestelinck.be/2026/06/29/configuring-remote-help-in-microsoft-intune-a-step-by-step-guide/ Nicky De Westelinck
You can now automatically update your Enterprise App Catalog applications https://blog.hametbenoit.info/2026/07/03/intune-you-can-now-automatically-update-your-enterprise-app-catalog-applications/ Benoit Hamet
ConfigMgr updates from the community
How to set a default Windows 11 wallpaper without locking it down https://configmgrninja.com/how-to-set-a-default-windows-11-wallpaper-without-locking-it-down/ Joshua Arldt
Windows updates from the community
Getting Ready for Windows 11 version 26H2: upgrade paths, Autopatch, pilot to production https://blog.thomasmarcussen.com/windows-11-26h2-upgrade-autopatch-pilot-to-production/ Thomas Marcussen
Turning off account notifications in Start and multi-app kiosk mode https://petervanderwoude.nl/post/turning-off-account-notifications-in-start-and-multi-app-kiosk-mode/ Peter van der Woude
Other updates from the community
Using context-based redirections for Windows 365 https://dominiekverham.com/using-context-based-redirections-for-windows-365/ Dominiek Verham
Controlling AI agents on your endpoints with Defender for Endpoint https://jannikreinhard.com/2026/06/26/defender-ai-agent-runtime-protection/ Jannik Reinhard
First looks at Windows 365’s gallery image with Developer Configuration (preview) https://niallbrady.com/2026/07/03/first-looks-at-windows-365s-gallery-image-with-developer-configuration-preview/ Niall Brady
Seen on X (Twitter)
Janic Verboon shared EAM-AutoUpdater, a free PowerShell tool that automatically deploys new app versions from the Intune Enterprise App Catalog and migrates assignments, metadata and supersedence. Good timing given Enterprise App Management is now reaching E5. @JanicVerboon https://github.com/JanicVerboon/EAM-AutoUpdater
Rudy Ooms spotted that Endpoint Privilege Management is gaining system-level network configuration support, which would let standard users change settings like IP address, gateway and DNS without holding local admin rights. One to keep an eye on as it rolls out. @Mister_MDM
Trond Eirik Haavarstein flagged MDM certificate renewal failures that leave affected devices with zero usable MDM certificates, showing up as RenewStatus 3. It quietly breaks Intune management, so it is worth checking if you are seeing renewal errors in your estate. @xenappblog