Microsoft Intune

What’s new in Microsoft Intune – August 2026: Autopilot device association, Remote Help, macOS 27

What’s new in Microsoft Intune for August 2026: Autopilot device association generally available, unattended Remote Help and App Settings on macOS 27.

What’s new in Microsoft Intune for August 2026: Autopilot device association, unattended Remote Help and app management on macOS 27

🌐 This article was originally written in French and automatically translated. Read the original (FR)

TL;DR

In August 2026, Windows Autopilot device association becomes generally available and verifies device identity with TPM attestation before enrollment in Intune. Remote Help adds unattended access with remote sign-in on Windows, and Intune gets ready for Apple’s new OSes with app blocking on macOS 27 and enhanced logging for AppleCare cases.

Microsoft Intune’s August 2026 updates cover the whole device lifecycle: Windows Autopilot device association becomes generally available, Remote Help now offers unattended access with remote sign-in, and Intune gets ready for Apple’s upcoming OSes with app blocking on macOS 27 and an enhanced logging action for AppleCare cases.

Microsoft’s common thread: at scale, a two-minute task on one device can become months of work across thousands of devices. This month’s announcements therefore focus on repeatable processes that give admins their time back.

Here is what to remember, and what it actually changes for you.

August’s updates at a glance

Feature Platforms Status
Windows Autopilot device association Windows Generally available, rolling out with the upcoming Windows update
Remote Help: unattended access with remote sign-in Windows (physical devices) Announced this month
App Settings configuration (allowed or denied apps and binaries) macOS 27 and later Added ahead of Apple’s new OS releases
Enhanced logging action for AppleCare cases Apple devices New device action

Windows Autopilot device association: establish trust before enrollment

Device association is now generally available. It is a Windows Autopilot device preparation capability that lets you associate a device with your tenant before it enrolls in Microsoft Intune.

The main benefit is security. Device identity is verified before enrollment using cryptographic keys and TPM attestation. Only trusted devices gain access to organizational resources: trust is established earlier in the onboarding flow, not after the fact.

For teams already using Autopilot device preparation, device association also unlocks several options:

  • device-based device preparation policies;
  • out-of-box experience (OOBE) customization;
  • renaming devices before enrollment.

Watch out: the feature is rolling out and depends on the upcoming Windows update. It will become available as that OS update is released to devices. So don’t plan an immediate switch of your processes.

My take: renaming before enrollment and device-based policies are very common deployment needs. If you had ruled out Autopilot device preparation because these options were missing, now is the time to reassess it. Start with the device association overview, then Microsoft’s blog post on Autopilot device preparation.

Remote Help: unattended access with remote sign-in

Until now, a Remote Help session required a user to be present to accept the connection. With unattended access with remote sign-in, a help desk agent can securely access a physical Windows device using their own credentials, even when the device is idle and no user is signed in.

The use cases Microsoft cites are clear:

  • scheduled maintenance operations;
  • after-hours interventions;
  • support for distributed branch offices, where nobody is necessarily in front of the device.

On the governance side, access is scoped by a dedicated role-based access control (RBAC) permission. You can therefore reserve unattended support for authorized admins, on their designated set of devices. Intune keeps enforcing access and audit controls throughout every session.

For admins, habits don’t change: the unattended control session starts from the same place in the Microsoft Intune admin center as attended support.

My take: many support teams have been waiting for this, but it deserves some framing before you turn it on. Define precisely who gets the new RBAC permission and on which devices, rather than adding it to an existing role that is too broad. Details are in the guidance on unattended support with remote sign-in.

Apple devices: getting ready for the new OS releases

Apple will release its new operating systems in the coming months. Microsoft has already added capabilities in Intune to prepare you, and highlights two of them.

App Settings: block apps and binaries on macOS 27

The App Settings configuration is a native way to manage apps and binaries, including AI apps, on managed Macs running macOS 27 and later. You manage allowed and denied apps and binaries with a single policy in the Intune admin center.

What it changes: until now, preventing an app from running on a Mac meant standing up and maintaining complex open-source tooling. On a few hundred devices, that is an acceptable workaround. On a large fleet, every new app widens the gap, and the tooling ends up owned by nobody.

With AI adoption accelerating, many organizations want control over the AI apps on their devices. This native policy addresses that need directly, provided your Macs have moved to macOS 27.

Enhanced logging for AppleCare cases

The new enhanced logging option in device actions reduces the manual work of collecting logs for AppleCare support cases. The admin puts the device into an enhanced logging state, and log files go directly to the AppleCare case.

Previously, you had to ask the user to trigger log collection, then upload the files by hand. Now it is a simple device action, with fewer interruptions for users. For details on Apple’s announcements, see the WWDC26 app management updates.

Myth of the month: you need a third-party tool to deploy Defender for Endpoint

The myth: to deploy and run Microsoft Defender for Endpoint at scale, you need a dedicated third-party endpoint management tool.

In reality, the native integration between Intune and Defender for Endpoint covers onboarding, configuration and ongoing security management. From the Intune admin center, you can:

  • deploy Defender onboarding policies;
  • apply Microsoft-recommended security baselines or targeted endpoint security policies;
  • manage security settings at scale.

The integration also connects threat detection with compliance. With the appropriate policies, Defender for Endpoint risk signals inform compliance in Intune, and Conditional Access can prevent at-risk devices from accessing company resources, without manual intervention.

It matches what I see in the field: running a third-party tool alongside Intune multiplies consoles and configuration drift to reconcile. For a step-by-step rollout, Microsoft offers the new Defender and Intune Technical User Manual, which describes a sequenced path from setup to full integration.

What I recommend doing this month

  1. Evaluate Autopilot device association: if you use or are considering Autopilot device preparation, read the documentation and prepare a pilot for when the required Windows update reaches your devices.
  2. Frame unattended Remote Help support: identify the agents who need it and the devices involved, then assign the new RBAC permission in a targeted way.
  3. Inventory the apps to block on Mac, especially unapproved AI apps, so you are ready to deploy an App Settings policy on your first Macs running macOS 27.
  4. Tell your Apple support team about the new enhanced logging action: it will simplify your next AppleCare cases.
  5. Review your Defender for Endpoint integration: onboarding policies, risk-based compliance and Conditional Access, using the Technical User Manual as your guide.

Key takeaways

  • Windows Autopilot device association is generally available: device identity is verified with cryptographic keys and TPM attestation before enrollment.
  • It enables device-based device preparation policies, OOBE customization and renaming before enrollment, as the upcoming Windows update rolls out.
  • Remote Help supports unattended access with remote sign-in to physical Windows devices, scoped by a dedicated RBAC permission.
  • The App Settings configuration allows or blocks apps and binaries, including AI apps, on Macs running macOS 27 and later, with a single policy.
  • An enhanced logging device action sends log files directly to the AppleCare case, without involving the user.
  • Defender for Endpoint can be deployed and managed natively from Intune, without a third-party tool.

Frequently asked questions

What is Windows Autopilot device association?

A generally available Windows Autopilot device preparation capability that associates a device with the tenant before enrollment in Intune, verifying its identity with cryptographic keys and TPM attestation.

When will device association work on my devices?

It is rolling out with the upcoming Windows update: it becomes available as that OS update is released to devices.

Can Remote Help connect to a PC with no user present?

Yes, with unattended access with remote sign-in: the agent connects to a physical Windows device with their own credentials, even when no user is signed in. Access is controlled by a dedicated RBAC permission and audited by Intune.

How do I block an app on Mac with Intune?

On managed Macs running macOS 27 and later, the App Settings configuration lets you manage allowed and denied apps and binaries, including AI apps, with a single policy in the Intune admin center.

Sources and documentation

#Microsoft Intune#What's new in Intune#Windows Autopilot#Remote Help#macOS#Microsoft Defender for Endpoint