Here’s what caught my attention this week.
There’s a new Windows 11 security baseline in Intune, more control over Windows App updates, and a ConfigMgr 2609 warning worth checking before your next upgrade. I also found a couple of useful pieces on Windows LAPS and a less obvious cause of Edge settings coming back.
The Windows 11 26H2 security baseline is available in Intune
Microsoft has released the Windows 11, version 26H2 security baseline for Intune. It includes new settings, updated defaults, and revised recommendations.
One thing to keep in mind: existing baseline profiles don’t automatically move to the new version. You’ll need to create a new profile or update an existing one. Review the differences before applying it, particularly if you’ve customized settings in your current baseline.
Read the Microsoft Intune announcement
You can now manage more of the Windows App experience
Peter van der Woude covered new administrative controls for the Windows App on Windows devices. Admins can manage its update behavior, first-run experience, logoff behavior, and shortcut creation.
The update controls are particularly useful. You can configure an admin release ring and disable automatic updates, giving you more say over how new versions are tested and rolled out instead of leaving every device on its own schedule.
ConfigMgr 2609 warns about automatic client approval
Configuration Manager 2609 adds a prerequisite warning if your hierarchy is configured to automatically approve all computers. The warning won’t block the upgrade, but Microsoft plans to remove that approval option in a future release because it can allow untrusted computers to become approved clients without administrator review.
Check your hierarchy settings before your next upgrade. Microsoft recommends manual approval or automatic approval limited to computers in trusted domains.
Microsoft’s ConfigMgr 2609 release notes · Prajwal Desai’s explanation and steps
Windows LAPS: deployment isn’t the finish line
Andy Kemp wrapped up his Windows LAPS series with a look at what happens after deployment. Password rotation and backup are only part of the job. You also need to consider retrieval permissions, how credentials are used, whether rotation succeeds after use, and how failures are detected.
When removed Edge settings keep coming back
Sascha Stumpler investigated Edge settings that kept returning after they were removed. The culprit was the MDMWinsOverGP behavior associated with Windows Autopatch managing Edge or Microsoft 365 Apps updates.
The interesting detail is that the behavior can restore a previously saved registry value when the MDM setting is removed. This can happen even on cloud-only devices where Intune originally wrote that value. If you’re chasing a setting that seems to be tattooed onto a device, check the DeviceManagement event log for event 819 followed by 2210.
How Windows Autopatch Tattooed My Edge Settings Sascha Stumpler
That’s it for this week.
Do you have a suggestion for this newsletter? Let me know in the comments.