If Autopilot device preparation is already your main path, you still rename with a script. Windows Autopilot device association in the Aug 27 preview CU (KB5120998) adds a name template during OOBE. The tax is a DeviceLink CSV, one device at a time, on physical TPM hardware.
Intune
Intune Device Page Becomes Default in September
The Intune device page you have been clicking through retires in the September 2609 release. Legacy view is gone. Flip the preview toggle this week and retake the helpdesk screenshots.
Edge for Business adds Cisco, Tanium, and Clever security connectors
Cisco Secure Access, Tanium, and Clever MFA TrustPass are now GA as Edge for Business connectors. If you already run any of the three, here is the config-and-verify path.
Intune Suite Capabilities Now Included in M365 E3/E5 — What MSPs Should Enable First
As of July 1, Microsoft folded EPM, Cloud PKI, and Advanced Analytics into M365 E5 (select pieces into E3). If you manage E5/E3 clients, they now own tooling they were paying extra for — here’s the enable-first order and a per-tenant checklist.
Intune Shared Devices Done Right: Identity Patterns for Frontline Workers
Most frontline device pilots stall at identity. Microsoft just published a practical guide to the assigned vs. shared device decision — and it has real consequences for Conditional Access, auditability, and shift-based workflows. Here’s the checklist that keeps your rollout from derailing.
Intune Field Notes: MDOP Migration Deadlines and macOS Platform SSO Gotchas
Two Intune signals deserve client action this quarter: MDOP is now out of extended support, and Microsoft’s Platform SSO field notes show where Mac rollouts can break. MSPs should inventory legacy MDOP dependencies, prioritize MBAM replacement, and pilot Platform SSO before pushing it broadly.
Copilot Cowork Is GA — What MSPs Need to Watch Before Turning Agents Loose
Copilot Cowork is GA, but MSPs should treat it as an operations change, not just another Copilot feature. The work now is permissions, billing controls, agent identity, audit trails, and deciding which client workflows are safe enough for long-running agents.
Deploying Claude Desktop Behind Entra ID: The No-Backend Architecture MSPs Need
Claude Desktop ships with a shared API key in a local config file — no per-user identity, no MFA, no audit trail. For MSPs with regulated clients, that’s a non-starter. Microsoft just published an architecture that routes Claude Desktop through Entra ID and Azure API Management with zero custom backend code. Per-user identity, Conditional Access, auditable, and the config can be pushed via Intune. If your clients are asking for sanctioned AI desktop tools alongside their existing M365 stack, this closes a real governance gap.
Intune Log Analysis Accelerated with GitHub Copilot
GitHub Copilot CLI can analyze exported Intune diagnostics. Dataverse MCP gives agents named tools that can create records. MSPs need one auditable policy for AI access before useful troubleshooting turns into shadow IT.
Stop Grepping Intune Logs: Use GitHub Copilot CLI for Faster Endpoint Troubleshooting
If your helpdesk still opens an Intune diagnostics bundle and starts grepping through files by hand, Stefan Röll has a useful shortcut: run GitHub Copilot CLI in the extracted log folder and ask it to build the first pass. The important part is the boundary. This is not a native Intune integration, and it is not autopilot for remediation. It is a faster way to turn a dense bundle into a timeline, likely root cause, and RCA draft that an admin still has to verify.
