top of page

Intune & ConfigMgr News Roundup: What IT Admins Need to Know Right Now

Writer: Christopher Hazlitt
Christopher Hazlitt
May 8
5 min read

📰 A lot has been happening across the Microsoft endpoint management landscape in the past few weeks. From Intune's May 2026 service updates and hotpatch going on by default, to ConfigMgr's annual release cadence becoming official and the M365 licensing shake-up that bundles enterprise-grade Intune features into E3 and E5 — there is plenty for IT admins to digest. Here is your roundup.

⚡ Hotpatch Now On By Default — Starting May 2026

⚡ This is one of the biggest quality-of-life changes for Windows Autopatch admins this year. Starting with the May 2026 Windows security update, hotpatch updates are enabled by default for all eligible devices managed through Windows Autopatch.

Hotpatch installs security updates without requiring a device restart, which means faster protection and less disruption for end users. Previously, admins had to explicitly opt in — now it is the default behaviour.

  • Eligible devices: Windows 11 version 24H2 and later, enrolled in Windows Autopatch.

  • Opt-out option: A tenant-level setting is available in the Intune admin centre to disable hotpatch across all eligible devices. This became available from April 1, 2026.

  • Policy override: Quality update policies configured per device group will override the tenant-level setting, giving you granular control where needed.

  • If your organization is not ready, opt out now via the Intune admin centre before the May update begins rolling out.

Action required: If your change management process requires restart windows or pre-approved update schedules, review whether the default hotpatch enablement aligns with your patching policies before May's update drops.

🤖 Change Review Agent Arrives in Multi Admin Approval

🤖 Microsoft has added AI-powered risk assessment directly into the Multi Admin Approval workflow. The new Change Review Agent analyses pending approval requests for Windows PowerShell scripts and surfaces risk-based recommendations without admins having to leave the Multi Admin Approval node.

A new Agent Response column now appears on the My Requests and All Requests tabs, indicating when an AI suggestion is available. Admins can click through to review and complete the approval workflow directly from there. This is a meaningful step toward reducing the manual overhead of change governance in larger environments.

🥽 Android XR Device Management Now Supported

🥽 Intune now supports management of Android XR devices using Android Enterprise dedicated and fully managed enrollment modes. As mixed reality and XR headsets begin appearing in enterprise environments — think frontline worker scenarios, logistics, healthcare — this brings them under the same Intune policy framework as your phones and tablets.

🍎 macOS Recovery Lock Password Management

🍎 For organizations managing company-owned macOS devices, Intune now supports configuring a recovery OS password that prevents users from booting into recovery mode, reinstalling macOS, or bypassing remote management.

  • Admins can set a recovery lock password via configuration policy.

  • The Recovery Lock device action allows manual password rotation for a specific device.

  • The recovery lock password is viewable in the per-setting status report under Passwords and Keys — requires the Remote tasks/View macOS recovery lock password permission.

⚠️ Intune Data Warehouse Beta Connector Being Retired — Act Now

⚠️ If your organization uses Power BI reports built on the Intune Data Warehouse (beta) connector, this affects you. Microsoft began transitioning tenants away from the beta connector starting April 20, 2026, rolling out gradually over two weeks.

  • Reports created after November 2025 already use the v2 connector — no action needed.

  • Reports created before November 2025 may still rely on the beta connector and must be updated to Intune connector v2 or the OData Feed connector.

  • After the transition completes, data access through the beta connector will be permanently unavailable.

🔐 Android Play Integrity API Changes — October 2026 Deadline

🔐 Google has updated the definition of Strong Integrity for Android 13 and above devices, now requiring hardware-backed security signals and a security update within the past 12 months. Intune will enforce this change by October 31, 2026.

Devices running Android 13 or above without a recent security update will no longer meet the Strong Integrity standard. If you have app protection or compliance policies targeting these devices, review your fleet now to identify devices at risk of falling out of compliance after the October deadline.

💰 Intune Capabilities Coming to M365 E3 and E5 — July 2026 Pricing Update

💰 Microsoft announced in December 2025 that several Intune Suite capabilities are being bundled into core Microsoft 365 licences, effective alongside a global pricing update on July 1, 2026.

  • M365 E3 gains: Intune Remote Help, Intune Advanced Analytics, improved device diagnostics and troubleshooting capabilities.

  • M365 E5 gains: Everything in E3, plus Endpoint Privilege Management, Enterprise Application Management, and Microsoft Cloud PKI.

  • If you are paying for any of these as standalone add-ons today, review your licensing before July to avoid paying for duplicate capability.

  • Price increases are coming alongside these additions — now is the time to audit what you are actually using and eliminate shelfware.

This is one of the largest expansions of native endpoint management ever bundled into M365. If you are on E5 and not yet using Endpoint Privilege Management or Cloud PKI, you will soon be paying for them whether you use them or not — make a plan to evaluate and deploy.

📅 ConfigMgr Annual Release Cadence Now Official

📅 Microsoft has officially confirmed that Configuration Manager will move to an annual release cadence starting with version 2609 in September 2026. Subsequent releases will align with the Windows H2 security and stability update cycle.

  • Hotfix rollups will only be provided when 'absolutely necessary' — critical security or functionality problems. All other fixes will be bundled into the annual release.

  • The 18-month support lifecycle per version is unchanged.

  • All future innovation and investment is going into Intune. ConfigMgr's focus going forward is security, stability, and on-premises reliability.

  • Microsoft has also encouraged admins who still manage Windows Updates via SCCM to evaluate Intune's update management capabilities, which offer more granular policy control without the need to build and push update packages manually.

ConfigMgr is not being retired — but the writing is on the wall that cloud-native management via Intune is where Microsoft is putting its chips. If you have not started evaluating co-management, now is the time.

📱 Intune MAM SDK Enforcement — iOS Apps Must Be Updated

📱 Since January 19, 2026, Intune has been enforcing updated MAM SDK versions for iOS wrapped apps, iOS SDK-integrated apps, and the Intune Company Portal for Android. Apps not on the required versions are blocked from launching for users with MAM policies applied.

  • Apps built with Xcode 16: must be on Intune App SDK v20.8.0 or Intune App Wrapping Tool v20.8.1 or later.

  • Apps built with Xcode 26: must be on Intune App SDK v21.1.0 or later.

  • Android apps update automatically once one Microsoft app with the updated SDK is on the device and the Company Portal is updated — but iOS requires explicit action.

📌 The Bottom Line

It has been a busy period for endpoint management. The hotpatch default change and the M365 licensing bundle are the two biggest items requiring proactive review in most environments. The ConfigMgr annual cadence confirmation and the multiple October 2026 deadlines — Android Play Integrity enforcement and the Software Center compliance token expiry — mean admins have a clear set of items to track between now and the end of the year.

Stay tuned — ConfigMgr 2609 lands in September and will be the first major test of the new annual release model. Expect a full breakdown here when it drops.

Tags: Microsoft Intune | Configuration Manager | SCCM | Windows Autopatch | Hotpatch | Co-Management | M365 Licensing | Android XR | macOS Management | MAM SDK | Endpoint Management | IT Admin | Enterprise IT | May 2026

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating*
bottom of page