August is bringing a fresh wave of Windows 365 updates, and this batch touches four areas that matter to IT admins: authentication, connection resilience, data protection, and monitoring. Microsoft announced these features across the weeks of August 3 and August 10, 2026, with an additional Admin Insights expansion from late July.
Let’s break down each update, what it does, why it matters, and what your team should do about it.
1. macOS Preview: In-Session Passwordless Authentication
What’s New
In-session passwordless authentication is now in preview for the Windows App on macOS. This feature allows users to complete WebAuthn challenges inside their Cloud PC session using passkeys stored on the macOS device or connected hardware security keys — things like Touch ID-backed passkeys in iCloud Keychain, or physical FIDO2 security keys connected via USB or NFC.
Here’s how it works: when a website or application running inside the Cloud PC session triggers a WebAuthn authentication challenge, that challenge is redirected to the local macOS device. The user completes the authentication using their local passkey or hardware key, and the result is passed back into the Cloud PC session. The credential never leaves the local device.
This extends the existing in-session passwordless authentication capability that was already available on Windows clients. macOS joins the party in preview, with general availability expected later.
Why It Matters
For organizations with Mac users accessing Windows 365 Cloud PCs, this closes a meaningful security gap. Previously, Mac users had to rely on passwords or less secure authentication methods for in-session challenges — things like accessing internal portals or approving transactions inside the Cloud PC. With passkey support, those same users can now use phish-resistant credentials they already have on their Mac.
Key benefits:
- Phish-resistant authentication inside Cloud PCs — protects against adversary-in-the-middle attacks
- Reduced password reliance for in-session authentication scenarios
- Better user experience — Mac users use the same passkeys they already use for Microsoft 365 and other services
- Simplified policy — admins can enforce passwordless authentication at both the connection and in-session levels
Requirements
- Windows App for macOS at the preview version that supports in-session passkey redirection
- macOS device with platform passkeys (iCloud Keychain, enterprise passkeys) or connected FIDO2 security keys
- Microsoft Entra ID tenant configured for passwordless authentication methods (FIDO2 security keys, passkeys)
- Conditional Access policies that permit passwordless authentication
- Windows 365 environment integrated with Entra ID
What IT Admins Should Do
- Identify Mac users accessing Windows 365 Cloud PCs in your environment
- Verify Entra ID passwordless configuration — ensure FIDO2 security keys and passkeys are enabled as authentication methods
- Join or opt into the Windows App preview for macOS if you want early access
- Test with pilot users — verify WebAuthn challenges redirect properly and passkey completion works as expected
- Update user documentation — let Mac users know they can now use passkeys inside their Cloud PC sessions
2. Modern Auto-Reconnect Begins Rollout
What’s New
Windows 365 has started rolling out Modern Auto-Reconnect, a new connection recovery experience that leverages RDP Multipath to maintain Cloud PC connectivity during temporary network interruptions.
Traditional reconnection behavior works like this: when a network drops, the RDP session disconnects, and the client attempts repeated reconnects until the network returns or the user gives up. Modern Auto-Reconnect changes this by using RDP Multipath’s multiple transport paths to maintain connection continuity. When one path degrades, the system can switch to an alternative path — or hold the session state — and restore connectivity more quickly when the network recovers.
The result: instead of a visible disconnect followed by a reconnect sequence, users experience a brief hiccup and their session picks up where it left off. Open apps, in-progress work, and session state are preserved.
This feature is rolling out in phases, so it won’t be available on all eligible Cloud PCs immediately.
Why It Matters
Network interruptions are one of the most common sources of Cloud PC support tickets. Users on unstable Wi-Fi, mobile hotspots, or branch office networks frequently experience brief drops that trigger full disconnect-reconnect cycles. Modern Auto-Reconnect significantly reduces the user-visible impact of these events.
Key benefits:
- Faster recovery after temporary network interruptions
- Reduced user-visible disruptions during connectivity changes (network switches, Wi-Fi transitions, brief drops)
- Preservation of open applications and in-progress work — no lost context
- More seamless experience when switching between networks or recovering from brief connectivity drops
- Lower support burden — fewer “Cloud PC keeps disconnecting” tickets
Requirements
- Windows App or Remote Desktop client version that supports RDP Multipath and Modern Auto-Reconnect (auto-updates should be enabled)
- Network connectivity to Windows 365 endpoints over required ports and protocols
- No middleboxes (firewalls, proxies) that block RDP Multipath or aggressively terminate long-lived sessions
- Feature enabled in your region/tenant as part of the phased rollout (no per-tenant configuration toggle)
What IT Admins Should Do
- Ensure Windows App auto-updates are enabled on user devices so they get the latest client version
- Review firewall and proxy configurations to make sure RDP Multipath traffic isn’t being blocked
- Monitor connection health using Cloud PC monitoring in Intune — watch for improvements in connection failure rates as the rollout progresses
- Update support documentation — let help desk staff know that reconnection behavior is changing and what to expect
- Don’t expect immediate availability — this is a phased rollout, so some users will get it before others
3. Screen Capture Protection for Web Connections
What’s New
Screen Capture Protection is now available when accessing Windows 365 Cloud PCs from supported web browsers. Previously, this protection was limited to native client connections (Windows App on Windows, macOS, iOS/iPadOS). Now, when a user connects to their Cloud PC through a browser, screen capture attempts are blocked or result in a blank/black area instead of showing the Cloud PC content.
This extends data loss prevention to the browser access path — which is often used by contractors, BYOD scenarios, and users on devices where installing the native Windows App isn’t possible or desirable.
Why It Matters
Browser-based access is a double-edged sword. It’s convenient and requires no client installation, but it also means Cloud PC content is displayed in a less controlled environment. Without Screen Capture Protection, a user on an unmanaged device could capture screenshots of sensitive information displayed in their Cloud PC session using standard OS-level screenshot tools.
With this update, organizations can now enforce consistent screen capture protection across both native client and web browser connection paths.
Key benefits:
- Consistent data protection across all connection types — native client and web
- Reduced exfiltration risk via screenshots from unmanaged or semi-managed endpoints
- Compliance alignment for regulated environments (financial, healthcare, government) where screen recording must be prevented
- Coverage for BYOD and contractor scenarios where browser access is most common
Requirements
- Screen Capture Protection must be enabled via the appropriate policy in Intune / Windows 365 settings
- Supported modern browser (Edge, Chrome, etc.) that honors the protection mechanism
- For stronger guarantees, pair with other controls (clipboard redirection restrictions, drive redirection restrictions, copy/paste policies)
What IT Admins Should Do
- Review your current Screen Capture Protection policy — if it’s already enabled for native clients, verify whether it now applies to web connections or if additional configuration is needed
- Identify users who access Cloud PCs via browser — contractors, BYOD users, users on non-managed devices
- Test browser-based access with Screen Capture Protection enabled — verify that screenshots are blocked and that legitimate use cases (screen sharing for support, etc.) have alternatives
- Update security documentation — note that Screen Capture Protection now covers web connections
- Combine with other data protection controls — for comprehensive protection, ensure clipboard, drive, and printer redirection policies are also configured appropriately
4. Admin Insights Expands to Monitor Cloud PCs Connection Health Tab
What’s New
Admin Insights for Windows 365, which was already available on the Cloud PC Overview page in the Microsoft Intune admin center, has now expanded to the Monitor Cloud PCs page > Connection health tab. The experience surfaces outlier cards that help administrators quickly identify Cloud PCs with elevated latency or connection failure rates.
Instead of manually scanning graphs and tables, admins now see card-based insights directly on the Connection health tab. These cards highlight anomalies — Cloud PCs or groups with unusually high latency, elevated connection failure rates, or other outlier conditions — so admins can investigate and address issues proactively.
This is a Public Preview feature.
Why It Matters
As Cloud PC environments scale, identifying problems before they become incidents gets harder. Admin Insights addresses this by automatically surfacing the signals that matter. Instead of an admin having to periodically check connection health dashboards and look for anomalies, the system proactively highlights outliers.
Key benefits:
- Proactive issue detection — outlier cards highlight problems before users report them
- Contextual insights in the right place — cards appear directly on the Connection health tab where admins are already working
- Faster troubleshooting — cards summarize outlier conditions so admins can focus on problematic locations, networks, or configurations
- Scalability — up to 15 cards can be generated automatically based on predefined thresholds
- Reduced noise — when everything is normal, admins see a “You’re all caught up” message instead of empty dashboards
Requirements
- Windows 365 (Enterprise) with access to the Microsoft Intune admin center
- Cloud PC monitoring (preview) must be available in your tenant — this provides the Connection health tab
- Appropriate Intune/Windows 365 admin roles (Cloud PC administrator, Intune admin)
- Data considerations: connection data has up to a 15-minute delay with ~2-minute granularity; health data up to a 30-minute delay
What IT Admins Should Do
- Navigate to Monitor Cloud PCs > Connection health tab in the Intune admin center and look for the new Admin Insights cards
- Review the outlier cards — identify any Cloud PCs or groups with elevated latency or connection failure rates
- Investigate flagged outliers — drill into the metrics to understand root causes (network issues, regional problems, device-specific issues)
- Establish a monitoring routine — check Admin Insights cards as part of your daily or weekly Cloud PC health review
- Provide feedback — since this is Public Preview, use the feedback channel in the Intune admin center to report issues or suggest improvements
The Bigger Picture
These four updates reflect Microsoft’s continued investment in three key areas of the Windows 365 platform:
Security: Passwordless authentication on macOS and Screen Capture Protection for web connections both extend security controls to previously uncovered scenarios. The pattern is clear — Microsoft wants every access path to Cloud PCs, regardless of client or platform, to support the same level of data protection and authentication security.
Resilience: Modern Auto-Reconnect builds on the RDP Multipath foundation to make Cloud PC sessions more resilient to the reality of imperfect networks. Instead of treating network drops as exceptions, the system now handles them gracefully — maintaining session state and recovering quickly.
Observability: The Admin Insights expansion to the Connection health tab continues Microsoft’s push to make Cloud PC monitoring more proactive and less manual. As environments scale, automated outlier detection becomes essential — you can’t have humans staring at dashboards all day.
For IT admins, the action items are straightforward: enable auto-updates for Windows App, verify your passwordless authentication configuration in Entra ID, review your Screen Capture Protection policies to include web connections, and start checking the new Admin Insights cards on the Connection health tab.
These features are rolling out now, so expect to see them in your tenant over the coming weeks.
For more information, see the Windows 365 What’s New documentation, Admin Insights for Windows 365, Screen Capture Protection, and RDP Multipath.
Follow @kkaminski on X for daily Windows 365 updates and analysis.