Intune deployment plans arrive in preview: the payload is still yours

Intune health attestation moves to Azure Attestation: the proxy check to run now

This is the way: Windows Autopilot device preparation

Windows 11 26H2 Is an Enablement Package — 24H2 Home/Pro End October 13

I’d Run Omarchy Everywhere if Intune Would Manage It

Intune deployment plans arrive in preview: the payload is still yours

Intune health attestation moves to Azure Attestation: the proxy check to run now

Intune deployment plans arrive in preview: the payload is still yours
Posted in

Intune deployment plans arrive in preview: the payload is still yours

Intune deployment plans are in public preview: a reusable set of rings, then a deployment that walks one app or policy through them. Worth piloting.

The part admins will trip over is that the deployment does not own the payload. Direct payload edits take precedence, include assignments accumulate as rings activate, and pausing or canceling a rollout leaves the assignments the earlier rings already added. Pause and cancel stop future rings, they do not take back what already landed.

Before your first pilot: pull the payload assignments next to your rings and remove any overlap, check that whoever launches the deployment has Read and Assign on the payload category (plan permissions are separate), and remember Multi Admin Approval now gates create, resume, cancel and delete.

Windows only for now, four payload types, Required install intent only for Win32 and catalog apps.

Intune health attestation moves to Azure Attestation: the proxy check to run now
Posted in

Intune health attestation moves to Azure Attestation: the proxy check to run now

Intune will move Windows health attestation compliance evaluation from Device Health Attestation to Microsoft Azure Attestation at the end of Q1 2027. Windows 11 devices with BitLocker, Secure Boot or Code Integrity settings fall out of compliance if they cannot reach their tenant’s intunemaape*.attest.azure.net host, and TLS inspection on that traffic breaks attestation even when port 443 is open.

This is the way: Windows Autopilot device preparation
Posted in

This is the way: Windows Autopilot device preparation

Microsoft has not retired classic Windows Autopilot, and nothing in the documentation behind this post carries an end-of-life date for it. What the September Intune Customer Success post did say is that device preparation is now the recommended path for user-driven Entra join and that future engineering investment goes there. That is a direction, not a deadline, and it matters because the transition costs money before any deadline appears: every new Windows 11 device provisioned the old way is another one to migrate later, Windows 10 and hybrid-joined fleets have no device preparation path at all, and pre-association only converts devices at their next natural reset. Start with the population that qualifies rather than the whole estate.

Windows 11 26H2 Is an Enablement Package — 24H2 Home/Pro End October 13
Posted in

Windows 11 26H2 Is an Enablement Package — 24H2 Home/Pro End October 13

Windows 11 26H2 (Build 26300.9278) is in Release Preview as an enablement package on the 24H2/25H2 servicing branch. Do not treat it as the October 13 fix. 24H2 Home, Pro, Pro Education, and Pro for Workstations lose updates that day. Enterprise 24H2 lasts until October 12, 2027. 25H2 is already GA if you cannot wait for 26H2.

I’d Run Omarchy Everywhere if Intune Would Manage It
Posted in

I’d Run Omarchy Everywhere if Intune Would Manage It

I have been running Omarchy on my own laptop and it is the most fun I have had with a computer in years. Arch, Hyprland, agents wired in. Then I held it up against the Intune Linux support matrix: Ubuntu 24.04 or 26.04 LTS, RHEL 9 or 10, GNOME documented as required, x86/64, Edge plus the Intune app. My machine is LUKS-encrypted with Secure Boot and a TPM, and Intune still rejects it at the platform and package layer. Here is what Intune actually does on Linux, and what I evaluated as a way around it.

Windows Autopilot device association can retire the rename script
Posted in

Windows Autopilot device association can retire the rename script

If Autopilot device preparation is already your main path, you still rename with a script. Windows Autopilot device association in the Aug 27 preview CU (KB5120998) adds a name template during OOBE. The tax is a DeviceLink CSV, one device at a time, on physical TPM hardware.