# What’s new in Microsoft Intune – September 2026: ring deployments, device page, Android eSIM

> What’s new in Microsoft Intune for September 2026: ring-based deployments in preview, a new device page, bulk Android eSIM activation and Managed Home Screen.

- URL: https://benjamintestart.fr/en/whats-new-microsoft-intune-september-2026/
- Author: Benjamin Testart (Devices Practice Leader & Microsoft Intune consultant)
- Published: 2026-10-09
- Updated: 2026-10-09
- Category: Microsoft Intune
- Language: en
- Tags: Microsoft Intune, What's new in Intune, Phased rollout, Android Enterprise, Managed Home Screen, Delivery Optimization
- Version française: https://benjamintestart.fr/fr/nouveautes-microsoft-intune-septembre-2026/

## TL;DR

In September 2026, Microsoft Intune launches ring-based deployments for Windows apps and policies in public preview, with pause, resume and reusable plans. The device page is redesigned to bring everything together in one place, eSIMs on 100 corporate-owned Android devices can be activated in one action, and Managed Home Screen lets users answer a Teams call before signing in.

Microsoft Intune’s September 2026 updates revolve around one idea: **keeping change under control**. On the menu: **Intune deployments** in public preview to roll out apps and policies in rings, a **new device page** that brings everything together, **bulk eSIM activation** on Android and an improvement to **Managed Home Screen** for shared devices.

Microsoft also extends several advanced capabilities to US government clouds, and uses its “Myth vs. Reality” section to remind admins of everything Delivery Optimization can do for bandwidth.

Here is what to remember, and what it actually changes for you.

## September’s updates at a glance

| Feature | Platforms | Status |
| --- | --- | --- |
| Microsoft Intune deployments (deployment rings) | Windows | Public preview |
| New device page | Supported platforms | Default view in the admin center |
| Bulk eSIM activation | Android Enterprise (Android 15+), corporate-owned devices | New bulk action |
| Teams calls on Managed Home Screen before authentication | Android (shared devices) | Generally available |
| Enterprise App Management, Cloud PKI, Remote Help | GCC High (and DoD for Enterprise App Management) | Available this month |

## Microsoft Intune deployments: roll out apps and policies in rings

This is the biggest announcement of the month. **Microsoft Intune deployments**, in **public preview**, finally bring a true **phased rollout** model to Windows apps and policies.

The principle is the ring model well known from Windows updates:

- you organize users and devices into **rings** (pilot, early adopters, production…);
- you decide **when each ring receives the assignment**;
- you apply **exclusions that span the whole deployment**;
- you monitor ring activation in the Microsoft Intune admin center, and you can **pause, resume or cancel** an active deployment if signals deteriorate.

**Deployment plans** save you from reconfiguring everything each time: you define the rings, groups, exclusions and timing once, then reuse the plan for other apps and policies. For a one-off need, you can also configure rings for a single deployment.

Good news for governance: existing **role-based access control (RBAC)** and **scope tags** continue to apply.

In preview, deployments support Windows devices with:

- **Win32 apps**;
- **Enterprise App Catalog** apps;
- **settings catalog** policies;
- **endpoint security** policies.

My take: until now, a phased rollout in Intune meant juggling several groups and editing assignments by hand, step by step. Having a dedicated object, with a pause button and per-ring monitoring, will significantly reduce the risk of big app updates or security policy changes. To get started, read the [Microsoft Intune deployments overview](https://learn.microsoft.com/en-us/intune/device-management/deployments/overview).

## A redesigned device page for faster troubleshooting

The **device page has been redesigned** and becomes the **default view** in the Intune admin center. It brings together device details, **recent activity**, **tools**, **reports** and available **actions** in one place.

From **Devices > All devices**, just select a device to check its status, review its activity, open a report or run an action without leaving this view. A few things to note:

- the **layout is consistent** across supported platforms, so there is no need to relearn the interface for each OS;
- actions are **grouped by purpose**, making the right one quicker to find;
- the page only shows actions **supported by the device** and **permitted for the signed-in admin**;
- all tasks and reports from the previous page **remain available**.

Help desk teams will benefit most: a single screen to understand a device’s state (compliance, configuration, apps, Endpoint Analytics) and act on it.

## Android: bulk eSIM and Teams calls on shared devices

### Activate eSIMs on 100 devices in a single action

With **bulk device actions**, you can now **activate eSIMs on 100 corporate-owned Android Enterprise devices** in a single operation, using **one carrier activation server URL**, instead of configuring each device.

Requirements: devices running **Android 15 or later**, in **fully managed**, **dedicated** or **corporate-owned with a work profile** mode.

Another useful detail: during a **bulk wipe**, Intune **preserves eSIMs by default**. You can keep them when devices are reassigned, or remove them when devices are retired. Requirements are detailed in [Manage eSIM cellular plans with device actions](https://learn.microsoft.com/en-us/intune/device-management/actions/update-cellular-data-plan).

### Managed Home Screen: answer a Teams call before signing in

On **frontline workers’** shared devices, an urgent **Microsoft Teams** call could be blocked by the **Managed Home Screen** sign-in screen. Now, if the call arrives before authentication is complete, the user can **accept or decline the call directly from the notification**. Managed Home Screen then asks for the **session PIN** before any other activity in a protected app.

This feature is **generally available**. It applies to MAM-integrated apps that use the **Intune App SDK**, including non-Microsoft apps. The only requirement: the signed-in user must have an **app protection policy** assigned for the app. No specific setting needs to be enabled. See [Managed Home Screen configuration](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-home-screen).

## Government clouds: new advanced capabilities in GCC High

This month, **Enterprise Application Management**, **Microsoft Cloud PKI** and **Intune Remote Help** become available in the **GCC High** cloud (Government Community Cloud with high security requirements). Enterprise Application Management is also offered to **Department of Defense (DoD)** organizations.

This follows the July arrival of **Intune Advanced Analytics** and **Endpoint Privilege Management** in these environments. It mainly concerns US public sector organizations, but it shows that Intune’s advanced capabilities are spreading to every cloud.

## Myth of the month: Delivery Optimization isn’t enterprise-ready

Microsoft tackles a persistent myth: Intune supposedly offers no bandwidth controls for Windows content, and **Delivery Optimization** peer sharing supposedly isn’t suited to large organizations.

In reality, Intune lets you:

- define **peer groups**;
- set **cache limits**;
- limit **foreground and background download bandwidth**;
- **cap monthly uploads** to internet peers.

Delivery Optimization can combine peers and **Microsoft Connected Cache** with Microsoft content sources, and **fallback-delay** settings give local sources more time before an internet download starts. The **Windows Update for Business Delivery Optimization report** shows observed bandwidth savings and content sources over the **previous 28 days**.

To go further: the [Delivery Optimization settings reference](https://learn.microsoft.com/en-us/windows/deployment/do/waas-delivery-optimization-reference) and the [Microsoft Connected Cache overview](https://learn.microsoft.com/en-us/windows/deployment/do/mcc-ent-edu-overview).

## What I recommend doing this month

1. **Try Intune deployments** on a simple case: the next update of a Win32 app or a settings catalog policy, with two or three rings. It is a preview: keep it away from critical changes for now.
2. **Prepare your rings**: if you don’t yet have well-defined pilot and early-adopter groups, now is the time to create them; they will also serve your Windows updates.
3. **Show the new device page** to your help desk: a quick tour of the grouped actions and recent activity will save them time.
4. **Corporate Android fleet on Android 15 with eSIM**: find your carrier’s activation server URL and test bulk activation on a few devices.
5. **Review your Delivery Optimization settings** and check the 28-day report: it is often an underused source of bandwidth savings.

## Key takeaways

- Microsoft Intune deployments (public preview) roll out Win32 apps, Enterprise App Catalog apps, settings catalog and endpoint security policies in rings, on Windows.
- A deployment can be paused, resumed or canceled, and deployment plans are reusable; RBAC and scope tags still apply.
- The new device page becomes the default view: details, recent activity, tools, reports and actions in one place.
- eSIMs on 100 corporate-owned Android Enterprise devices running Android 15+ can be activated in a single action, and a bulk wipe keeps them by default.
- On Managed Home Screen, a Teams call can be accepted before authentication; the session PIN is still required for everything else (generally available).
- Enterprise Application Management, Cloud PKI and Remote Help arrive in the GCC High cloud.

## Frequently asked questions

### What are Microsoft Intune deployments?

A public preview feature that rolls out a Windows app or policy in successive rings, with a schedule per ring, shared exclusions and the ability to pause, resume or cancel the deployment from the Intune admin center.

### What can be deployed in rings with Intune?

In preview, deployments support Windows devices with Win32 apps, Enterprise App Catalog apps, settings catalog policies and endpoint security policies.

### How many Android eSIMs can Intune activate at once?

Up to 100 corporate-owned Android Enterprise devices running Android 15 or later (fully managed, dedicated or corporate-owned with a work profile), in a single action using one carrier activation server URL.

### Do I need to enable a setting to answer Teams calls on Managed Home Screen?

No. The feature is generally available and requires no specific setting: the signed-in user just needs an app protection policy assigned for the app.

### Is the old Intune device page going away?

The redesigned page becomes the default view, but all tasks and reports from the previous page remain available.

## Sources and documentation

- [Microsoft Intune Blog: What’s new in Microsoft Intune – September](https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-september/ba-p/4537394)
- [Microsoft Learn: Microsoft Intune deployments overview](https://learn.microsoft.com/en-us/intune/device-management/deployments/overview)
- [Microsoft Learn: Manage eSIM cellular plans with device actions](https://learn.microsoft.com/en-us/intune/device-management/actions/update-cellular-data-plan)
- [Microsoft Learn: Configure Managed Home Screen](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-home-screen)
- [Microsoft Learn: Delivery Optimization settings reference](https://learn.microsoft.com/en-us/windows/deployment/do/waas-delivery-optimization-reference)
