Endpoint Mgmt Weekly — October 2, 2026

Here’s what caught my attention this week.

Configuration Manager 2609 is available, Windows 11 26H2 has reached general availability, and Intune is making some changes to app delivery that are worth understanding. Rudy Ooms also has a couple of good technical write-ups on what’s happening under the hood.

Configuration Manager 2609 is available, but check your prerequisites first

Configuration Manager 2609 is available as an in-console update for sites running version 2503 or later. There are a few things to check before you start planning the upgrade.

SQL Server 2016 is no longer supported, and the prerequisite check will block the upgrade if your site database is still running on it. Windows Server 2012 and 2012 R2 are also no longer supported as ConfigMgr client operating systems. One other thing to watch: ODBC Driver 18.7.1.1 can block site configuration on ConfigMgr 2603 and earlier, so don’t install that driver before upgrading those environments to 2609.

There are other changes too, including updates to Cloud Management Gateway deployments and the removal of Asset Intelligence reports.

What’s new in Configuration Manager 2609 — Microsoft Learn

Windows 11 26H2 is generally available, with an AVD issue to watch

Windows 11 26H2 reached general availability on September 29. The rollout is phased, and eligible 24H2 and 25H2 devices can receive it through Windows Update when users have enabled the option to get the latest updates as soon as they’re available.

There’s already a known issue worth watching if you run Azure Virtual Desktop with FSLogix. Some devices can land on a black screen or fail to load the desktop after sign-in, with existing user profiles appearing to be affected more often. Microsoft has published a Known Issue Rollback for managed environments.

Windows 11 26H2 release health — Microsoft Learn

Intune is speeding up Win32 app delivery

Intune is now using push notifications for administrator-initiated and service-side changes to Win32 apps, allowing managed devices to check for changes sooner rather than waiting for their normal polling interval.

There’s a related improvement after Windows enrollment: the Intune Management Extension now checks app assignments immediately after the Enrollment Status Page completes. Required apps that didn’t install during ESP can start sooner instead of potentially waiting for the next regular check-in.

Rudy Ooms dug into both behaviors, including how the push notification reaches the IME and how the post-ESP check is triggered.

What’s new in Microsoft Intune — Microsoft Learn

Faster Win32 App Delivery in Intune with Push Notifications — Rudy Ooms

Faster Required App Delivery After Autopilot — Rudy Ooms

Intune Settings Catalog now supports Windows 11 26H2

Microsoft has announced day-zero support for validated Windows policy settings in the Intune Settings Catalog for Windows 11 26H2. If you’re testing the new release, you can use the catalog to configure supported settings without waiting for a later Intune update.

As always, I’d still validate the specific settings you depend on in a pilot before assuming every policy behaves exactly as expected on the new OS.

Microsoft Intune Settings Catalog updated to support Windows 11 26H2 — Microsoft

Rudy Ooms breaks down client-driven compliance evaluation

Microsoft recently introduced client-driven compliance evaluation for Windows devices. Instead of waiting for a scheduled check, supported devices can detect changes to compliance signals such as BitLocker, firewall, antivirus, Secure Boot, and Defender status, then request a reevaluation.

Rudy’s new write-up digs into how this works on the client side. It’s useful context for anyone trying to understand why a compliance state updates when it does, especially when compliance feeds into access decisions.

Inside Intune Client-Driven Compliance Evaluation for Windows Devices — Rudy Ooms

That’s it for this week.

Do you have a suggestion for this newsletter? Let me know in the comments.