Microsoft Intune’s Service Release 2608 (week of August 25, 2026) is one of the most substantial updates of the year — with major upgrades across support automation, Apple management, Android device lifecycle, and Linux security. Whether you run a small fleet or a global enterprise estate, there’s something here worth planning around.
Here’s the full breakdown of what’s new, what it means, and why IT administrators should care.
Advanced capabilities: Unattended Remote Help for Windows
What it does: Intune now supports unattended Remote Help sessions on physical Windows devices. Authorized helpdesk agents can sign in to a remote device with their own credentials — no user present, no user action required. Helpers can view and control the device to troubleshoot and complete support tasks remotely.
Why it matters: This is a game-changer for after-hours support, kiosk and shared devices, and any break/fix scenario where the user isn’t available to approve a session. It reduces time-to-resolution and removes the dependency on user availability — a huge win for frontline and remote workforces.
Practical use cases:
- After-hours maintenance and patching support on unattended machines
- Kiosk and shared-device troubleshooting without interrupting the next shift
- Helpdesk escalation paths where the user has already left for the day
Applies to: Windows
App management
Newly available protected apps for Intune
Seven new protected apps joined the Intune catalog:
- Notion by Notion Labs
- Superhuman Mail by Superhuman Labs
- Calven by Calven Pty Limited
- Heijmans by Heijmans
- Notability by Ginger Labs, Inc. (iOS)
- Ben for Intune by Thanks Ben Ltd
- SDP - On Premises | Intune by Zoho Corporation
For organizations standardizing on app protection policies (APP), each new protected app expands the list of productivity tools you can manage without full device enrollment — particularly relevant for BYOD strategies.
Declarative Device Management for Apple VPP apps
What it does: Intune now supports Apple Declarative Device Management (DDM) for required volume purchase program (VPP) apps on iOS/iPadOS 17.2+ and macOS 26+. When you upload a new VPP token, you can change the management type to DDM and deploy apps using Apple’s policy-based model.
Why it matters: DDM improves delivery efficiency, provides real-time app status, and adds new per-app settings such as automatic app updates. For large iPhone/iPad fleets, DDM reduces sync churn and makes app deployment and update behavior far more predictable.
Applies to: iOS/iPadOS, macOS
Device configuration
The Android Enterprise settings catalog got a significant expansion this release:
Configure screen timeout for corporate Android devices
A new Screen timeout setting lets you specify how many seconds pass before the screen turns off. The value must stay at or below the Time to lock screen setting. Applies to fully managed and dedicated devices on Android 9+, and corporate-owned work profile devices on Android 15+.
Separate device and work profile passwords
The new Block one lock for device and work profile setting lets you require separate locks for the device and work profile instead of a shared one. Set it to True after configuring a work profile password requirement. Supports Android 9+ on COPE devices — useful for organizations that want a hard separation between personal and corporate access.
Limit how long an Android work profile can stay off
The new Number of days work profile is allowed to be switched off setting caps how long users can keep their work profile disabled. Minimum of three days, or enter 0 to disable the restriction entirely. This is a compliance-friendly control for COPE fleets — if the work profile is off, the device isn’t receiving policy, so limiting that window matters.
Remove eSIMs during a device wipe
The Remove all eSIMs during a device wipe setting requests removal of all eSIMs when a corporate-owned device is wiped while the policy applies. Supports Android 15+. Combined with the new per-device eSIM removal options below, this gives admins granular control over connectivity on device lifecycle events.
Keep Android device screens on while charging
A new settings catalog option keeps fully managed and dedicated device screens on while charging. Select one or more modes — AC, USB, or Wireless. AC and USB support Android 6.0+; wireless charging requires Android 8.1+. No modes are selected by default. Useful for kiosk and signage deployments.
New updates to the Apple settings catalog
New Settings Catalog options for testing on the OS 27 betas cover DDM areas including App Settings, Web Content Filter, and Siri Settings for iOS/iPadOS and macOS. This lets you test upcoming Apple management controls ahead of general availability.
New policy settings for Windows
New Windows settings catalog options arrived across several administrative template refreshes:
- Turn on Protected Mode controls for Internet Explorer security zones
- New Microsoft Edge policies from the Edge 150 template refresh
- Disconnect if a Remote Desktop Services session when no smart card is present for interactive logon
- New Microsoft Office template settings
Applies to: Windows
Device enrollment
Skip new Apple Setup Assistant panes during enrollment
Intune now includes Apple OS 27 Setup Assistant skip keys for Liquid Glass and Accessibility Appearance in Automated Device Enrollment (ADE) profiles. Hide these panes to reduce setup interactions and deliver a more consistent enrollment experience on supported iPhone, iPad, and Mac devices.
Applies to: iOS/iPadOS, macOS
Device management
New single device page is now the default
The redesigned single device page in the Intune admin center is now on by default for all customers. When you select a device under Devices > All devices, you get a consolidated view with device properties, activity, tools, and reports.
Key navigation updates:
- Properties tab — change management name, primary user, device category, and scope tags
- Device details tab (formerly Hardware) — hardware and OS information
- Remote actions, Secure, and Remove data menus — device actions on the command bar
- Device action status — track the status of device actions
- Tools > Remediations — view remediation status
Prefer the old view? Move the Preview new device view toggle to Off to return to the original page. Note: Intune has signaled the legacy page will be fully replaced in the September (2609) release, so plan to standardize on the new view now.
Applies to: Android, iOS/iPadOS, macOS, Windows
Operating system version property in assignment filters is generally available
The operatingSystemVersion property in assignment filters is now GA for managed devices and managed apps. Create filter rules that scope app and policy assignments to devices running a specific OS version or build range.
Why it matters: This makes staged rollouts dramatically cleaner. Pilot a configuration on a newer build before broad rollout, or exclude devices that haven’t updated yet. Build rules with the rule editor or rule syntax — same operators as other filter properties — and existing assignments keep working unchanged.
Collect enhanced diagnostic logs from supervised Apple devices
Intune now supports Apple’s Enhanced Logging device action on supported supervised devices. Administrators can start an AppleCare diagnostic-log collection session using an AppleCare-provided token and monitor device-reported status through DDM — reducing the need to coordinate manual log collection with the device user. Richer logs shorten mean time to root cause for stubborn iOS/iPadOS/macOS management failures.
Applies to: iOS/iPadOS, macOS
Expanded eSIM lifecycle management for corporate Android devices
This release delivers a full eSIM management toolkit for corporate-owned Android Enterprise devices:
- Expanded SIM inventory — view EIDs, multiple ICCIDs, and activation state under Hardware. Use the reported ICCID to identify the correct eSIM for removal. EID reporting requires Android 13+; full inventory requires Android 15+.
- Activate an eSIM — single-device eSIM activation on Android 15+ devices. Turn on Preview new device view, select the device, choose Activate eSIM, and enter the carrier activation code.
- Remove an individual eSIM — remove a single eSIM without wiping the device. Copy the ICCID from inventory, select Remove eSIM, and enter the ICCID. Supports fully managed and dedicated devices on Android 15+, and work profile devices on Android 17+.
- Choose eSIM behavior on wipe — when wiping a single device, choose whether to preserve or remove eSIMs. The default preserves them.
Why it matters: Mobile connectivity can now be provisioned, inventoried, and deprovisioned at scale without touching a carrier portal — essential for corporate-liable fleets, field workers, and device refresh cycles.
Applies to: COBO, COSU, COPE
Device inventory for personally owned Android Enterprise devices
Intune now supports device inventory for personally owned Android Enterprise devices with a work profile managed by Android Management API (AMAPI). View these devices from the device’s Inventory page alongside corporate-owned devices in Resource Explorer, and query them with Multi-Device Query.
Inventory data is a subset of corporate-owned data — properties such as IMEI, ICCID, and MAC address aren’t available — but this still delivers more consistent analytics across mixed corporate and BYOD environments without forcing full device ownership. A meaningful step for BYOD programs balancing compliance visibility with user privacy.
Device security
Audit mode for Microsoft Defender Antivirus on Linux
The Defender Antivirus template for Linux now includes an Audit value for the Enforcement level setting. In audit mode, the antivirus engine detects threats in real time but doesn’t automatically remediate them — malware detections surface as alerts in the Microsoft Defender portal without quarantining files.
Why it matters: Audit mode gives you visibility into the Linux threat landscape before you turn on full protection. It’s ideal for safely validating policy impact across servers and developer workstations before enforcing blocking actions. Supported for Intune-managed devices and for devices managed only by Defender via security settings management (MDE attach).
Applies to: Linux
Windows 365 for Agents security baseline
A new security baseline for Windows 365 for Agents Cloud PCs lets administrators deploy and customize recommended, device-scoped settings for Windows 11, Microsoft Edge, and Microsoft Defender for Endpoint. As agentic workloads become a growing part of enterprise estates, having a secure-by-default starting point for these Cloud PCs reduces configuration drift and accelerates safe deployment.
Applies to: Windows 365 for Agents Cloud PCs running Windows 11+
Memory scan setting for Defender Antivirus on Linux
A new memory scan setting in the Defender Antivirus template for Linux gives finer control over how Defender inspects memory on Linux endpoints managed through Microsoft Defender for Endpoint security settings management.
Applies to: Linux
The big picture
Service Release 2608 tells a clear story about where Intune is heading:
- Support without friction — Unattended Remote Help and the new single device page attack the two biggest support pain points: user availability and navigation overhead.
- Apple management maturity — DDM for VPP apps, enhanced diagnostic logging, and OS 27 beta settings show Apple’s declarative model becoming the default management path.
- Android lifecycle control — The eSIM toolkit and new settings catalog entries turn Intune into a true full-lifecycle manager for Android fleets, from activation to wipe.
- Platform parity — Linux keeps getting real investment: audit mode, memory scan controls, and the Defender template expansion close the gap with Windows and macOS.
- AI-era security — The Windows 365 for Agents baseline reflects the new reality that agentic workloads need guardrails from day one.
What should you do now?
- Turn on the new device page and get your helpdesk trained before the legacy view is retired in 2609.
- Test assignment filters with
operatingSystemVersion— it’s GA, and it makes staged rollouts far cleaner. - Review the new Android eSIM capabilities if you manage corporate-liable Android fleets — this is a major workflow improvement.
- Evaluate Defender audit mode on Linux before enforcing full protection.
- Check the Windows 365 for Agents baseline if agentic Cloud PC workloads are on your roadmap.
Follow me at https://x.com/kkaminsk for ongoing Intune and endpoint management coverage — and check back here regularly as we continue tracking every Intune service release.
This article is based on Microsoft’s official What’s new in Microsoft Intune documentation. Feature availability may vary by tenant due to gradual rollout.