Intune will move Windows health attestation compliance evaluation from Device Health Attestation to Microsoft Azure Attestation at the end of Q1 2027. Windows 11 devices with BitLocker, Secure Boot or Code Integrity settings fall out of compliance if they cannot reach their tenant’s intunemaape*.attest.azure.net host, and TLS inspection on that traffic breaks attestation even when port 443 is open.
Conditional Access
Block Device Code Flow in Conditional Access
Device code phishing uses the real microsoft.com/devicelogin page. MFA succeeds, the attacker gets the tokens. Block Authentication flows > Device code in Conditional Access, report-only first.
Entra memberOf Rules Freeze November 3
Entra memberOf does not error on November 3. Dynamic groups, admin units, and entitlement policies just stop updating and keep last week’s members. Export the rules now.
Intune Shared Devices Done Right: Identity Patterns for Frontline Workers
Most frontline device pilots stall at identity. Microsoft just published a practical guide to the assigned vs. shared device decision — and it has real consequences for Conditional Access, auditability, and shift-based workflows. Here’s the checklist that keeps your rollout from derailing.
