The defaults already decided: Windows Autopatch quality update policy
Posted in

The defaults already decided: Windows Autopatch quality update policy

Windows Autopatch quality update policies now cover .NET Framework and quick machine recovery alongside monthly Windows quality updates, and the approvals already sitting on your tenant are worth a read before the rollout finishes on October 15.

Start with the default that is not the same for every category: a newly created policy auto-approves monthly security updates and holds non-security and out-of-band releases for review. Any policy someone created and assigned without opening Settings is already approving on your behalf.

Two mechanics decide whether that matters. Quick machine recovery is manual by default and the approval method cannot be changed in an existing policy, so decide it while you are creating the policy. And pausing a release revokes the approval for new devices without pulling the update off devices that already installed it.

Intune deployment plans arrive in preview: the payload is still yours
Posted in

Intune deployment plans arrive in preview: the payload is still yours

Intune deployment plans are in public preview: a reusable set of rings, then a deployment that walks one app or policy through them. Worth piloting.

The part admins will trip over is that the deployment does not own the payload. Direct payload edits take precedence, include assignments accumulate as rings activate, and pausing or canceling a rollout leaves the assignments the earlier rings already added. Pause and cancel stop future rings, they do not take back what already landed.

Before your first pilot: pull the payload assignments next to your rings and remove any overlap, check that whoever launches the deployment has Read and Assign on the payload category (plan permissions are separate), and remember Multi Admin Approval now gates create, resume, cancel and delete.

Windows only for now, four payload types, Required install intent only for Win32 and catalog apps.

This is the way: Windows Autopilot device preparation
Posted in

This is the way: Windows Autopilot device preparation

Microsoft has not retired classic Windows Autopilot, and nothing in the documentation behind this post carries an end-of-life date for it. What the September Intune Customer Success post did say is that device preparation is now the recommended path for user-driven Entra join and that future engineering investment goes there. That is a direction, not a deadline, and it matters because the transition costs money before any deadline appears: every new Windows 11 device provisioned the old way is another one to migrate later, Windows 10 and hybrid-joined fleets have no device preparation path at all, and pre-association only converts devices at their next natural reset. Start with the population that qualifies rather than the whole estate.

Windows 11 26H2 Is an Enablement Package — 24H2 Home/Pro End October 13
Posted in

Windows 11 26H2 Is an Enablement Package — 24H2 Home/Pro End October 13

Windows 11 26H2 (Build 26300.9278) is in Release Preview as an enablement package on the 24H2/25H2 servicing branch. Do not treat it as the October 13 fix. 24H2 Home, Pro, Pro Education, and Pro for Workstations lose updates that day. Enterprise 24H2 lasts until October 12, 2027. 25H2 is already GA if you cannot wait for 26H2.

Microsoft and NVIDIA Are Turning Windows Into an Agent Runtime
Posted in

Microsoft and NVIDIA Are Turning Windows Into an Agent Runtime

Microsoft and NVIDIA are turning Windows into an orchestration layer for autonomous AI agents. For MSPs, that means your endpoint policies and client billing models need to account for software that acts independently — with its own compute costs, identity boundaries, and security surface. Three Microsoft developments this week make the trajectory clear.

Intune Secures Endpoints Amid AI PC Shift
Posted in

Intune Secures Endpoints Amid AI PC Shift

Assuming Intune alone secures your endpoints is a dangerous architectural flaw. Intune manages configurations, but it cannot replace dedicated endpoint detection and response for advanced threat hunting. Real resilience demands combining Intune with a dedicated EDR platform, not relying on it as a standalone security shield. #Intune #EndpointManagement #CyberSecurity