Intune

Winsage
August 6, 2026
Microsoft has announced that support for Windows 10 Enterprise LTSC 2021 will end on January 12, 2027, coinciding with the release of a final security update. Organizations can enroll in the Extended Security Updates (ESU) program to maintain security updates beyond this date, which will cost per device in Year 1, with prices doubling each subsequent year until the program ends on January 8, 2030. ESU sales will start on September 1, 2026, and licenses are cumulative. The ESU program does not cover Windows 10 IoT Enterprise LTSC, which is supported until January 13, 2032. Organizations using Microsoft’s cloud-based update services can receive a 25 percent discount on the Year 1 price. As of July, 16.9 percent of monitored devices were still running Windows 10, with migration to Windows 11 stalling due to compatibility issues and hardware requirements.
Winsage
August 4, 2026
Microsoft has begun silently installing the "OneDrive Photos" app on Windows PCs, including enterprise systems managed via Microsoft Intune, without prior notification. IT professionals have expressed significant frustration over this unexpected addition, noting that the app is incompatible with Entra accounts and cannot be removed without uninstalling OneDrive entirely. The app functions as a web-based gallery feature, indexing and displaying photos stored on local machines, but its necessity is questioned due to the existing Microsoft Photos app. OneDrive Photos is linked to the OneDrive sync client, making it impossible to uninstall independently. Users have reported that the app appears in Windows Search results with an 'Uninstall' option but does not show up in the Installed apps page, leading to confusion. A script has been developed to remove the shortcut, but it often reappears due to its connection with the OneDrive sync client. Discussions with Microsoft suggest that the rollout may have been unintended, with an apology expected soon.
Winsage
August 1, 2026
Microsoft announced enhancements for Windows 11 aimed at optimizing performance and resource utilization, potentially reconsidering the minimum system requirements. A new tool for IT administrators was introduced in the July Intune update (Service Release 2607), which includes native support for Registry Inventory. This feature allows administrators to assess system configurations more accurately, aiding in troubleshooting, compliance, and security. The Registry Inventory feature operates through Intune's Properties catalog, enabling administrators to monitor specific registry keys. Detailed reports are generated for each configured entry, providing information on registry key paths, value names, types, and data. The data collected is accessible from the Device inventory page, and the initial release supports common collection patterns for HKEYLOCALMACHINE (HKLM) registry paths. Registry Inventory is included with Microsoft Intune Plan 1. Other enhancements in the Intune update include management capabilities for Samsung firmware updates.
Winsage
July 29, 2026
Microsoft's July Intune update includes enhancements for IT administrators, such as real-time monitoring of Windows device sync progress, custom compliance settings for macOS, and improved firmware update management for Samsung devices. The Intune admin center now allows real-time monitoring of sync progress for Windows devices, enabling simultaneous updates across various management aspects. Custom compliance settings for macOS enable organizations to define specific compliance requirements beyond Apple's standard checks, allowing for a unified compliance management experience across Windows, Linux, and macOS. The update also enhances Samsung Galaxy firmware management through Samsung Knox E-FOTA, allowing administrators to control firmware version deployment and update schedules. Additionally, the update clarifies that newer Windows Autopilot methods allow provisioning of Windows 11 devices without prior registration.
Winsage
July 19, 2026
Microsoft has introduced point-in-time restore for Windows 11 users, enhancing the traditional System Restore. This new recovery tool allows users to recover their PCs from software issues, problematic drivers, or faulty updates, even when Windows won’t boot. It uses the Volume Shadow Copy Service (VSS) to automatically generate restore points every 24 hours, which include both system and user files, unlike System Restore. Point-in-time restore manages storage by deleting restore points after 72 hours and integrates seamlessly into Windows Settings, being activated by default for volumes over 200GB. Users with smaller volumes must activate it manually. It also incorporates Reserved Storage to ensure restore points do not consume regular disk space. The feature is available on Windows 11 Home and Pro editions with the installation of the optional Preview Update KB5095093. Users can access point-in-time restore through Windows Settings under System > Recovery, and initiate recovery via the Windows Recovery Environment (Windows RE).
Winsage
July 18, 2026
Microsoft held its OEM Secure Boot Office Hours event on July 15, where engineers collaborated with OEM representatives from companies like Acer, Asus, Cisco, Dell, and HP. IT administrators were able to ask live questions about the Secure Boot 2023 rollout. The discussion thread became a detailed technical record, especially following the expiration of the first certificates three weeks prior. Concerns raised by IT admins included BitLocker recovery loops, stuck confidence ratings, and unhelpful Intune error codes. Key facts include: - Devices offline for long periods will still receive the 2023 certificates upon reconnecting to Windows Update. - Devices with existing 2023 certificates in firmware will switch to the new boot manager after the latest Windows patches are installed. - A new script, Detect-SecureBootCertUpdateStatus.ps1, is available in Windows for checking certificate status. - BIOS updates may reset a device’s confidence rating to unrated, which is normal and does not indicate certificate failure. - Admins should edit the AvailableUpdates registry key, not the AvailableUpdatesPolicy, which is managed by Intune and Group Policy. - A licensing bug affecting AvailableUpdatesPolicy on devices upgraded from Pro to Enterprise was resolved by Microsoft in 2026. - BitLocker recovery is not typically linked to the certificate update process but may relate to firmware or PCR issues. - Dell and HP provided guidance on which BIOS versions include the 2023 certificates for their newer models. - Older HP EliteBook 840 G5 units require a manual update package for the new certificates. - Eligible devices can still receive the 2023 certificates in the future, and Surface devices released from 2024 onward come pre-equipped with them. - Microsoft confirmed that devices running 2011 certificates will not lose the ability to receive the 2023 chain. - The Microsoft Corporation KEK CA 2011 and Microsoft UEFI CA 2011 certificates have expired, with the Microsoft Windows Production PCA 2011 set to expire on October 19, 2026.
Search