September’s changes deserve a place in the endpoint improvement backlog. My priority would be to make application delivery more predictable, test compliance recovery and prepare support teams for the updated device view. This roundup covers Microsoft’s published September updates through 30 September 2026; recommendations below are an implementation approach, not evidence of testing in a customer tenant.
September release snapshot
Microsoft lists the following changes across September, including service release 2609. Availability can arrive gradually. [1]
| Change | Published capability | Recommended action |
|---|---|---|
| Deployment plans | Staged app and policy rollout, in public preview. | Pilot a low-impact package; document stop criteria. |
| Win32 delivery | Push notifications accelerate app-change check-ins; the management extension also checks assignments after ESP completes. | Measure actual install times across office and remote devices. |
| Windows compliance | Supported devices can request reevaluation after compliance signals change. | Test recovery after remediation alongside Conditional Access. |
| Device administration | The new single-device page becomes the default; the previous page is removed. | Refresh support screenshots and navigation steps. |
| Mobile management | iOS/iPadOS 18 becomes the standard minimum; userless ADE devices have separate support terms. | Identify affected devices before communicating upgrade actions. |
| Android and Apple controls | Android Settings Catalog filters and additional Apple settings expand configuration options. | Check applicability and overlap with existing profiles. |
Make deployment speed measurable
Faster delivery is useful only when an administrator can distinguish targeting, download, installation and detection delays. For a pilot, record the assignment time, first device check-in, installer start, installer completion and reported result. Use the same package across representative network paths. Include a device that was offline when the assignment changed.
Keep detection rules, application dependencies and restart behaviour in the review. A faster response to an incorrect requirement or detection rule can distribute a mistake sooner. Retain a known-good package and a support owner who can decide whether to pause expansion.
Test compliance and access together
Use an isolated test device and an approved test account to exercise a reversible compliance failure. Record the device’s local state, Intune’s reported state and the subsequent sign-in result. Check the applicable Conditional Access result rather than treating a green device status as proof that an existing session has been reevaluated. Do not disable controls on production devices to manufacture a test.
An October action list
- Service desk: review the new device page and update the ten most-used support procedures.
- Endpoint engineering: select a non-critical Win32 app for a controlled deployment pilot.
- Identity and security: agree what evidence demonstrates successful compliance recovery.
- Mobile team: reconcile operating-system inventory with business owners and approved exceptions.
- Change owner: give each improvement an owner, acceptance criteria and a decision date.
A useful monthly review should result in a short, prioritised backlog. Avoid enabling unrelated features in one change window: separate application delivery, enrolment and security-policy changes so a fault can be traced to a specific decision.
Related September-end guides
- Deployments (preview): plans, rings and recovery
- Windows Autopilot Device Association: setup and lifecycle — an August capability examined in detail for this update.
- Teams Phone: Direct Routing vs Operator Connect — an architecture column, not a newly announced September feature.
Microsoft references
Sources checked 1 October 2026. September coverage ends 30 September 2026. Product availability, preview status and requirements can change; validate the current guidance and tenant before rollout.