Endpoint Mgmt Weekly — September 18, 2026

A few things caught my attention this week.

Microsoft had to push another out-of-band Windows update, Autopilot Device Preparation is getting a much stronger recommendation from Microsoft, and there’s an interesting Defender compliance issue showing up in the wild.

There’s also a new ConfigMgr update worth knowing about.

Microsoft had to ship an out-of-band Windows update

The September 8 Windows update caused enough problems that Microsoft released an out-of-band update on September 14.

KB5129195 for Windows 11 24H2/25H2 addresses several issues from the September update, including Remote Desktop Services instability. The 26H1 release uses KB5129194. Microsoft also addressed the Hyper-V/Plan9 folder-sharing problem that affected things such as WSL and Claude Cowork.

The USB Audio Class 1.0 problem is a little more complicated. The OOB update fixes the multichannel/3D audio symptom, but Microsoft still lists the broader issue as only partially resolved.

KB5129195 — Microsoft Support

Windows 11 release health — Microsoft Learn

Autopilot Device Preparation is now Microsoft’s recommended path for user-driven deployments

Microsoft published a fairly significant change to its Autopilot guidance this week: Windows Autopilot device preparation is now the recommended solution for eligible user-driven scenarios.

Microsoft is not telling everyone to rip out their existing Autopilot deployment. The two models can coexist, and Microsoft specifically calls out scenarios that should remain on classic Autopilot for now, including pre-provisioning, self-deploying mode, hybrid Entra join, and Autopilot into co-management.

The interesting part for me is the migration guidance. Microsoft is recommending that organizations move eligible populations in controlled waves rather than trying to recreate every existing Autopilot object one-for-one. Device preparation brings the deployment configuration, OOBE settings, applications, scripts, naming and enrollment-time grouping into a different model.

Moving from Windows Autopilot to Windows Autopilot device preparation — Microsoft

Intune is moving Windows Health Attestation to Azure Attestation

Microsoft also published a plan to move Windows Health Attestation compliance evaluation from the existing Device Health Attestation service to Microsoft Azure Attestation. The change is service-side and is expected to roll out by the end of Q1 2027.

This one has an actual action attached to it. If your firewall or proxy rules restrict outbound access, Windows 11 devices using Intune compliance checks for things like BitLocker, Secure Boot or Code Integrity will need to be able to reach the new Azure Attestation endpoints.

Network endpoints for Microsoft Intune — Microsoft Learn

Defender’s false compliance problem looks to be getting fixed

Rudy Ooms has a good follow-up on the Defender/Windows Security Center issue that could make healthy devices appear noncompliant in Intune.

The problem was particularly nasty because Defender could actually be running normally while Windows Security Center reported the wrong state. Intune could then use that bad signal for antivirus compliance, potentially leading Conditional Access to block the user.

Rudy dug into the startup race and tested Defender platform version 4.18.26080.4. Microsoft has now released that platform version through the Current Channel (Broad), with the Update Catalog showing September 17 as the release date. There are already reports from admins that affected devices are returning to compliant after receiving .4.

Defender is On. Intune Says Noncompliant — Rudy Ooms

Microsoft Update Catalog — Defender platform updates

Configuration Manager got another security update

Microsoft released KB39398030 for Configuration Manager this week. It addresses security issues involving scripts, the SMS Provider, the Message Processing Engine and Discovery Data Record processing.

The update applies to Configuration Manager 2603, 2509 and 2503 through the applicable servicing paths.

KB39398030 — Microsoft Learn

A practical Defender deployment write-up

Allester Padovani published a useful walkthrough of using Intune deployment rings for Microsoft Defender updates.

Given the Defender compliance problem we’ve been dealing with recently, I thought the timing was pretty good. The article walks through separating test, pilot and production deployment of Defender updates rather than allowing every endpoint to consume a new platform version at once.

Deploy Microsoft Defender Updates in Deployment Rings — Endpoint Tech Blog

That’s it for this week.

Do you have a suggestion for this newsletter? Let me know in the comments.