Modern Workplace consulting · Microsoft cloud architectureAdelaide, Australia
Service release 2608

What’s new in Microsoft Intune — August 2026

Unattended remote sign-in, Windows Autopilot device association and expanded macOS configuration are the headline changes. Here is what they mean for an enterprise rollout.

The August 2026 Intune service release is less about adding another dashboard and more about reducing manual work before enrolment, during remote support and across Apple configuration. Each capability is valuable, but each also changes an existing trust or support boundary. Treat availability in the portal as the start of assessment, not an instruction to enable it broadly.

Service release 2608Windows and ApplePublished 27 August 2026

Release summary

CapabilityWhat changedImmediate enterprise question
Unattended Remote Help for WindowsAn authorised helper can sign in to a physical corporate Windows device with their own credentials without the user being present.Which support roles and device groups genuinely need unattended access?
Windows Autopilot device associationAutopilot device preparation can bind a physical Windows 11 device to the organisation before enrolment.How will procurement, hardware identity and decommissioning records remain accurate?
Enhanced Apple configurationIntune expands declarative management for required VPP apps and adds settings for testing upcoming Apple OS controls.Which settings are production-ready, and which are only for OS 27 beta validation?

Unattended Remote Help sign-in for Windows

This is not simply an attended screen-sharing session with the consent dialog removed. The helper authenticates with their own organisational credentials and starts a separately authenticated Windows session. Microsoft states that the capability applies to physical, corporate-owned, Intune-managed Windows devices and is initiated from the Intune admin centre.

Security boundaryUnattended access should be treated as privileged administrative access. Restrict it with least-privilege Intune RBAC, scoped device groups, strong Conditional Access, phishing-resistant authentication where practical, PIM activation and session audit review.

Before enabling it

  • Confirm the tenant and user/device licensing entitlement rather than assuming visibility means entitlement.
  • Create a dedicated helper group instead of extending an existing broad helpdesk role.
  • Use scope groups and scope tags to prevent support staff reaching unrelated business units or privileged devices.
  • Define acceptable use: incident response, kiosks, shared workstations and after-hours remediation are different risk cases.
  • Validate privacy, employee monitoring, audit retention and Cyber approval requirements.
  • Test proxy and firewall paths, including the current Remote Help endpoints, through the enterprise web-security stack.

Windows Autopilot device association

Device association is part of Windows Autopilot device preparation. It binds a Windows 11 device to the organisation before enrolment and uses hardware-backed validation to strengthen device identity. Associated devices can be marked corporate-owned and can receive device-targeted assignments, device naming and additional out-of-box experience customisation.

What improves

  • Corporate ownership is established earlier.
  • Device-targeted policy can apply before a user-driven identity exists.
  • Naming and OOBE can be more predictable.
  • Hardware identity raises the bar for unauthorised devices.

What still needs design

  • Supplier and reseller registration process.
  • Replacement motherboard and repair workflow.
  • Duplicate or stale device records.
  • Ownership transfer and secure decommissioning.

Do not confuse device association with the older Windows Autopilot device registration model or assume that every classic Autopilot profile setting has an equivalent in device preparation. Build a small Windows 11 test ring and validate the complete OOBE path, including ESP, applications, certificates, Conditional Access and break-glass recovery.

Enhanced macOS settings configuration

For service release 2608, Microsoft added Declarative Device Management support for required Apple Volume Purchase Program apps on macOS 26 and later, including automatic app updates and improved status. Intune also added Settings Catalog options for testing Apple OS 27 beta controls across App Settings, Web Content Filter and Siri Settings.

Interpret the headline carefullyThe new Settings Catalog entries are available for testing upcoming Apple OS behaviour. Their presence does not make an OS beta suitable for production. Keep preview profiles isolated from the production Mac fleet.

Recommended Apple validation

  1. Create a macOS beta-only device filter and an isolated assignment group.
  2. Inventory existing custom profiles and preference files that may overlap the new native settings.
  3. Test required VPP app install, update, rollback and status reporting on macOS 26.
  4. Validate web content filtering alongside the organisation’s endpoint security and secure web gateway agents.
  5. Confirm that Platform SSO, certificates, Defender and system extensions remain healthy after policy refresh.
  6. Document the production migration path only after Apple and Microsoft mark the required operating system and controls supported.

Actions for Intune administrators

  • Check Tenant administration > Tenant status and confirm service release 2608.
  • Review current Remote Help licensing, RBAC, scope groups and Conditional Access.
  • Identify a business-owned set of unattended support scenarios; do not start with all Windows devices.
  • Compare Autopilot device preparation and classic Autopilot dependencies before changing procurement.
  • Separate Apple OS beta testing from production configuration profiles.
  • Record feature state, decision owner, pilot cohort, rollback trigger and evidence location.

A safe pilot pattern

RingScopeExit evidence
LabIT-owned non-production devicesFunctional flow, logging and rollback validated.
Technical pilotEndpoint engineering and service deskRBAC, Conditional Access, network and support procedures validated.
Business pilotSmall, representative cohortUser impact, failure rate and helpdesk demand within agreed tolerance.
Controlled rolloutPhased production groupsChange approval, monitoring and stop criteria active.

Microsoft references

  1. What’s new in Microsoft Intune — August
  2. What’s new in Microsoft Intune
  3. Plan for Remote Help
  4. Windows Autopilot: What’s new
  5. Use the Intune settings catalog

Review note: Preview state, licensing and tenant rollout can change. Validate the live Microsoft documentation and your own tenant before production deployment.