Microsoft Intune’s Service Release 2607 continues to deliver incremental updates beyond the initial July 27 release date. Five new settings catalog entries have been added to the Windows device configuration profile, covering Azure Virtual Desktop session management, Microsoft Store package removal, Get Started app control, OneDrive governance, and — perhaps most notably — a new policy to disable the Model Context Protocol (MCP) for GitHub Copilot in Visual Studio.
These additions reflect Microsoft’s ongoing push to make the Intune settings catalog the central configuration hub for Windows endpoints, while also addressing emerging governance challenges around AI tooling and cloud storage.
Here’s a detailed breakdown of each new setting, what it does, and why IT administrators should care.
New Windows App (Azure Virtual Desktop) Settings in the Windows Settings Catalog
Intune now exposes five new Windows App (Azure Virtual Desktop) settings directly in the Windows settings catalog. These settings give administrators policy-level control over the Windows App client experience on managed Windows devices — something that previously required manual configuration or Group Policy.
The new settings:
- Turn off automatic updates for Windows App — controls whether the Windows App client automatically checks for and installs updates. Disable this if you want to control update timing through your own processes.
- Automatically log off users after inactive interval — signs users out of Windows App after a defined period of inactivity. This is a session security control that prevents idle AVD sessions from remaining accessible.
- Skip First Run Experience (FRE) — skips the Windows App onboarding wizard so users go straight to their resources. Reduces friction in standardized deployments.
- Admin Release Ring Policy — sets the update release ring (channel) that Windows App follows. Lets you phase Windows App updates the same way you’d phase Windows feature updates.
- Automatically create Windows App shortcuts to desktop — creates desktop shortcuts for published Windows App resources. Useful for task-worker environments where users need immediate access to specific AVD resources.
Why this matters:
For organizations running Azure Virtual Desktop, these settings close a gap between Intune’s device management and the AVD client experience. Previously, configuring the Windows App client required either Group Policy, custom scripts, or accepting default behaviors. Bringing these into the Intune settings catalog means:
- Session security — Auto logoff after inactivity limits walk-away risk on shared and BYOD endpoints. In regulated environments, this supports session management controls required by frameworks like ISO 27001 and SOC 2.
- Update governance — Release ring control lets you pilot new Windows App versions with a test group before broad deployment, reducing the risk of client-side compatibility issues.
- User experience standardization — Skipping FRE and auto-creating shortcuts reduces support tickets and eliminates the variability of user-driven first-run configuration.
Practical use cases:
- High-security AVD environments — enforce short idle timeouts (15-30 minutes) for finance, HR, or admin desktops
- Task-worker deployments — auto-create desktop shortcuts and skip FRE for call center or kiosk scenarios where users need immediate, no-friction access
- Phased Windows App rollouts — use release rings to validate new AVD client versions before pushing to production users
Applies to: Windows
New Option for Remove Default Microsoft Store Packages Setting
The existing Remove Default Microsoft Store packages setting in the ApplicationManagement area now has a new subsetting: Specify additional package family names to remove.
What it does:
This subsetting lets you provide a custom list of package family names (PFNs) to remove from Windows devices, in addition to the built-in default set of Microsoft Store packages that Intune already removes. Previously, you could only remove the default set — there was no way to extend the list with organization-specific packages.
Why this matters:
- Attack surface reduction — Every preinstalled Store app is a potential update channel, a potential vulnerability, and a potential path for users to access consumer services. Extending the removal list lets you strip additional bloatware, consumer apps, or previously-deployed apps that are no longer approved.
- Data leakage prevention — Removing apps that sync to consumer Microsoft accounts (Xbox, consumer OneDrive, consumer Outlook) reduces the chance of corporate data flowing into personal cloud services.
- Compliance and standardization — Doing this via Intune policy rather than custom PowerShell scripts or image modification makes it repeatable, reportable, and auditable — key requirements for regulated environments.
Practical use cases:
- Regulated environments — strip consumer messaging, gaming, and social apps from endpoints handling PII, HIPAA data, or export-controlled information
- Privileged workstations — remove all non-essential Store apps from admin or developer workstations to reduce lateral movement paths
- Kiosk and shared devices — deliver a locked-down experience with only approved Store apps available
Applies to: Windows
New Setting to Disable the Get Started App
The new Disable Get Started setting in the Experience policy CSP prevents the Windows Get Started app from being available to users.
What it does:
The Get Started app (sometimes called Tips or Get Help) is the Windows onboarding experience that surfaces Microsoft recommendations, feature highlights, and setup guidance to users. It often includes prompts to sign in with personal Microsoft accounts, enable consumer features, or explore Microsoft services that may conflict with corporate policies.
This new Intune setting lets administrators suppress the app entirely across managed Windows devices.
Why this matters:
- Eliminates conflicting guidance — The Get Started app frequently prompts users to sign in with personal accounts, enable consumer OneDrive, or explore features that corporate IT hasn’t approved. Disabling it ensures users follow corporate onboarding flows instead.
- Reduces support tickets — Users who follow Get Started prompts often end up in configurations that conflict with Intune policies, generating support tickets when settings don’t match expectations.
- Cleaner VDI experience — On AVD and shared devices, the Get Started app adds noise without value. Disabling it creates a more focused experience for task workers.
Practical use cases:
- Corporate identity environments — prevent prompts to use personal Microsoft accounts on company-managed machines
- VDI and shared workspaces — remove non-essential UX elements for task workers who don’t need onboarding guidance
- Education and exam labs — avoid suggestions that could lead students into features or networks not approved for their environment
Applies to: Windows
New OneDrive Settings in the Windows Settings Catalog
Seven new OneDrive settings have been added to the Windows settings catalog, giving administrators significantly more control over OneDrive configuration on managed Windows devices. These settings address several long-standing gaps in OneDrive governance, particularly around offline data access and hybrid SharePoint authentication.
The new settings:
Set a custom name for the OneDrive folder
Lets administrators specify a custom name for the local OneDrive sync folder instead of the default “OneDrive –
- Multi-tenant organizations where users may have OneDrive folders from different tenants — a custom name like “Corporate-OneDrive” eliminates ambiguity
- Script and automation consistency — compliance scripts, backup tools, and monitoring systems that rely on a known folder path can work reliably across all devices
- Data classification clarity — a clearly labeled folder helps users distinguish corporate storage from personal locations
Enable OIDC authentication for on-prem SharePoint sync
Enables OpenID Connect (OIDC)-based authentication for the OneDrive sync client when connecting to on-premises SharePoint Server. This brings modern token-based authentication to hybrid SharePoint scenarios, replacing legacy authentication methods.
- Modern auth alignment — OIDC brings the same token-based, conditional access-aware authentication model that SharePoint Online uses to on-prem SharePoint
- Passwordless readiness — modern auth is a prerequisite for passkey and passwordless strategies, reducing reliance on password-based access to on-prem content
- Unified governance — apply consistent identity and access management whether content lives in SharePoint Online or on-premises
Specify the Application ID URI for Entra application for OIDC
Companion setting to the OIDC authentication above — specifies the Application ID URI for your Microsoft Entra application used for OIDC when it differs from your SharePoint Server URL. This handles cases where the Entra app registration uses a different URI than the SharePoint endpoint.
Prevent users from enabling offline mode in OneDrive on the web
Blocks users from turning on offline mode for OneDrive on the web. This is one of the most security-significant OneDrive settings in this release.
Why offline mode control matters:
- Data residency on endpoints — Offline sync determines whether sensitive files are cached locally. Restricting it reduces the volume of data on lost or stolen devices, even if they’re encrypted.
- BYOD and contractor devices — On lightly managed endpoints, blocking offline mode allows only browser-based access, preventing uncontrolled local copies of corporate files.
- Regulatory compliance — Some data protection regimes care deeply about where data physically resides. Tight offline controls make it easier to demonstrate that sensitive libraries aren’t persistently cached on endpoints.
- Incident response — Less local caching simplifies containment when a device is compromised; there’s less data to recover and fewer copies to track.
Prevent offline mode for shared libraries from other organizations
Extends the offline mode block to libraries and folders shared from other organizations. This is important for B2B collaboration scenarios where external organizations share content with your users — you may want to allow access but prevent that content from being cached locally.
Hard-delete folder shortcut contents when unmounted
When a OneDrive folder shortcut is unmounted, this setting permanently deletes the local contents instead of moving them to the Recycle Bin. This ensures clean de-provisioning with no orphaned data left on the device.
Hard-delete folder shortcut contents when user loses permissions
Permanently deletes the contents of a folder shortcut when the user loses access permissions to that folder. This is critical for:
- Automated offboarding — when an employee departs and their project access is revoked, this ensures no cached data from shared folders remains on their device
- Project rotation — when users move between projects, old project data is cleanly removed rather than lingering in the Recycle Bin
Practical use cases for the OneDrive settings:
- Highly sensitive libraries (M&A, health records, defense projects) — block offline sync entirely; require access via AVD or browser only
- Shared or kiosk devices — prevent OneDrive from caching user data between sessions
- Multi-tenant organizations — use custom folder names to distinguish between tenant OneDrive instances
- Hybrid SharePoint — enable OIDC for modern auth on on-prem SharePoint while maintaining conditional access policies
- Offboarding automation — hard-delete settings ensure clean removal of access when users depart or change roles
Applies to: Windows
Updated Visual Studio Administrative Templates: Disable MCP for GitHub Copilot
The Visual Studio administrative templates have been refreshed to version 1.0.184.40051, adding a new policy setting: Disable Model Context Protocol (MCP) (DisableMCP) for GitHub Copilot in Visual Studio.
What is MCP and why does disabling it matter?
The Model Context Protocol (MCP) is a mechanism that allows GitHub Copilot in Visual Studio to connect to external tools, data sources, and services. Through MCP integrations, Copilot can fetch information from internal APIs, query databases, read documentation, and interact with various developer tooling — extending its capabilities beyond simple code completion to acting as an AI-powered integration layer across the development environment.
While MCP enables powerful workflows, it also introduces significant security and governance considerations:
- Data exfiltration risk — MCP integrations can expose internal systems and data to AI tooling. A Copilot instance connected to an internal API could pull sensitive data into its context window, potentially leaking source code, secrets, or architectural details.
- Supply chain concerns — Developer workstations are high-value targets. MCP-enabled Copilot acts as a “super-integrator” of internal tools. A misconfigured or overly permissive MCP integration could inadvertently create a channel for sensitive data to flow through.
- Unvetted integrations — Without the disable policy, individual developers may connect Copilot to internal systems that haven’t gone through security review, creating shadow integrations that bypass normal governance processes.
What the Disable MCP setting does:
When enabled via Intune policy, this setting centrally blocks all MCP integrations for GitHub Copilot in Visual Studio across managed devices. Core Copilot functionality (code suggestions based on editor context) remains available — only the external tool connections are disabled.
Why this is the most critical security control in this update:
For organizations in regulated industries — healthcare, defense, finance — being able to demonstrate that AI tools cannot directly integrate with protected data systems without explicit approval is becoming an important control under emerging AI risk frameworks. This setting provides that control.
Practical use cases:
- Secure development environments — Enable GitHub Copilot for developer productivity but force MCP = disabled on:
- Payment systems teams handling PCI data
- Healthcare teams handling PHI
- Defense teams handling classified or export-controlled code
- Any environment where AI-to-internal-systems integration hasn’t been formally assessed
- Staged AI adoption — Phase 1: Copilot with MCP disabled (no external integrations). Phase 2+: After risk assessment and data protection reviews, selectively allow MCP for vetted tools via separate governance processes.
- Third-party and vendor developer machines — If vendors use your Visual Studio templates via Intune, MCP disabled ensures their Copilot instance cannot automatically tap into your internal systems without a formal integration path.
Applies to: Windows
How to Operationalize These New Settings
For Windows endpoint teams:
- Review your AVD configuration — the new Windows App settings let you replace manual GPOs or scripts with Intune-native policy. Migrate existing AVD client configurations to Intune settings catalog profiles.
- Update your Microsoft Store app removal baselines — identify additional PFNs for consumer apps you want to strip, and add them to the new subsetting.
- Evaluate the Get Started app — if you’re already using custom onboarding, disabling Get Started eliminates conflicting guidance.
- Audit OneDrive offline mode — identify which libraries are currently syncing offline and determine whether blocking offline mode is appropriate for your data sensitivity tiers.
- Plan for MCP governance — if your developers use Visual Studio with GitHub Copilot, the Disable MCP setting should be evaluated immediately. Even if you don’t disable it today, understanding the integration surface is critical for AI risk management.
For security teams:
- OneDrive offline mode controls are a key lever for data residency and endpoint data protection. Define tiered policies: highly sensitive libraries block offline entirely; standard libraries allow offline on compliant, encrypted devices.
- MCP disablement should be part of your AI governance framework. Even organizations that allow Copilot should understand what MCP integrations exist and whether they’ve been security-reviewed.
- Session controls for AVD (auto logoff) support session management controls required by ISO 27001, SOC 2, and similar frameworks.
For development governance:
- The MCP setting is the first Intune-native policy control specifically targeting AI toolchain integration. As AI-assisted development becomes standard, expect more such controls. Establish your governance baseline now.
Summary
These five new settings catalog entries, added to Service Release 2607, demonstrate Intune’s continued expansion as a comprehensive configuration platform for Windows endpoints. The additions span three key themes:
- Session and client management — Windows App AVD settings bring client-side governance into Intune’s policy engine
- Data governance and protection — OneDrive offline mode controls, hard-delete policies, and Store package removal extend endpoint data protection
- AI toolchain governance — the MCP disablement setting for GitHub Copilot represents an early but important step toward managing AI-assisted development risks through endpoint policy
For IT administrators, the priority actions are clear: evaluate the OneDrive offline mode controls against your data protection requirements, assess whether MCP should be disabled in your development environments, and begin migrating AVD client configurations from GPO to Intune-native policy.
Follow Kevin on X at https://x.com/kkaminski for more Intune and endpoint management content.