Endpoint Mgmt Weekly — September 25, 2026

Here’s what caught my attention this week.

Intune is adding a more structured way to stage app and policy rollouts, Rudy Ooms dug into a change that can make app inventory updates much faster, Microsoft has published its Apple OS 27 management notes, there’s a Windows domain trust issue to check for, and a reminder that Windows 11 24H2 Pro is nearing end of support.

Intune now has deployment plans for staged rollouts

Intune deployment plans are a new way to roll out apps and configuration policies in stages instead of pushing a change to the whole assigned population at once. The new Deployments experience lets admins organize releases across rings, control rollout timing, and integrate with Multiple Admin Approval.

For larger fleets, this gives you a built-in way to manage a phased rollout rather than stitching the process together with separate assignments and groups. It currently applies to Windows, Win32 and Enterprise App Catalog apps, Settings Catalog policies, and Endpoint security policies.

What’s new in Microsoft Intune — deployment plans

Intune app inventory may now refresh in minutes after an install

Rudy Ooms has a good technical breakdown of a change he observed in the Device Inventory Agent: an application change can trigger a targeted App Inventory collection instead of waiting for the normal four-hour cycle.

In his test, Firefox was detected, validated, collected, and uploaded in about five minutes. The agent watches for app changes, checks that the change is real, and uploads the delta rather than repeatedly running a full inventory. The behavior he captured is ahead of the public documentation, and the agent uses flighting, so I wouldn’t treat five minutes as a guaranteed refresh time across every tenant or device.

Intune App Inventory: From 4 Hours to About 5 Minutes — Rudy Ooms

Some domain-joined devices may lose their secure channel after the September update

Microsoft added a known issue for some Credential Guard-protected machine accounts that can lose their secure channel with an on-premises Active Directory domain after the September 8 update or later updates. Users may see a trust relationship failure when signing in with domain credentials, although cached offline sign-in may still work.

The trigger is Machine Identity Isolation: the updates cause Windows to honor existing or policy-provisioned enforcement settings. Microsoft says the feature is supported only when devices connect to domain controllers at Windows Server 2025 Domain Functional Level or higher.

September 22, 2026 Windows 11 preview update — known issues and workaround

Windows 11 24H2 Pro reaches end of support next month

Windows 11 24H2 Pro reaches end of updates on October 13, 2026. After that, it will stop receiving security and preview updates, fixes, and technical support. Enterprise and Education editions remain supported until October 12, 2027.

The September 22 preview update is also the final non-security preview for 24H2.

September 22, 2026 Windows 11 preview update — lifecycle notice

Microsoft has published its Apple OS 27 Intune notes

Microsoft’s latest Intune update covers support and management changes for Apple’s new OS 27 releases. Intune includes new Setup Assistant skip keys for the Liquid Glass and Accessibility Appearance panes in Automated Device Enrollment.

The update also calls out Settings Catalog options for testing on OS 27 betas, including Declarative Device Management areas such as App Settings, Web Content Filter, and Siri Settings.

Microsoft Intune and Apple OS 27: New settings, support, and platform changes

That’s it for this week.

Do you have a suggestion for this newsletter? Let me know in the comments.