Microsoft Intune

What’s new in Microsoft Intune – September 2026: ring deployments, device page, Android eSIM

What’s new in Microsoft Intune for September 2026: ring-based deployments in preview, a new device page, bulk Android eSIM activation and Managed Home Screen.

What’s new in Microsoft Intune for September 2026: ring deployments, new device page and Android eSIM

🌐 This article was originally written in French and automatically translated. Read the original (FR)

TL;DR

In September 2026, Microsoft Intune launches ring-based deployments for Windows apps and policies in public preview, with pause, resume and reusable plans. The device page is redesigned to bring everything together in one place, eSIMs on 100 corporate-owned Android devices can be activated in one action, and Managed Home Screen lets users answer a Teams call before signing in.

Microsoft Intune’s September 2026 updates revolve around one idea: keeping change under control. On the menu: Intune deployments in public preview to roll out apps and policies in rings, a new device page that brings everything together, bulk eSIM activation on Android and an improvement to Managed Home Screen for shared devices.

Microsoft also extends several advanced capabilities to US government clouds, and uses its “Myth vs. Reality” section to remind admins of everything Delivery Optimization can do for bandwidth.

Here is what to remember, and what it actually changes for you.

September’s updates at a glance

Feature Platforms Status
Microsoft Intune deployments (deployment rings) Windows Public preview
New device page Supported platforms Default view in the admin center
Bulk eSIM activation Android Enterprise (Android 15+), corporate-owned devices New bulk action
Teams calls on Managed Home Screen before authentication Android (shared devices) Generally available
Enterprise App Management, Cloud PKI, Remote Help GCC High (and DoD for Enterprise App Management) Available this month

Microsoft Intune deployments: roll out apps and policies in rings

This is the biggest announcement of the month. Microsoft Intune deployments, in public preview, finally bring a true phased rollout model to Windows apps and policies.

The principle is the ring model well known from Windows updates:

  • you organize users and devices into rings (pilot, early adopters, production…);
  • you decide when each ring receives the assignment;
  • you apply exclusions that span the whole deployment;
  • you monitor ring activation in the Microsoft Intune admin center, and you can pause, resume or cancel an active deployment if signals deteriorate.

Deployment plans save you from reconfiguring everything each time: you define the rings, groups, exclusions and timing once, then reuse the plan for other apps and policies. For a one-off need, you can also configure rings for a single deployment.

Good news for governance: existing role-based access control (RBAC) and scope tags continue to apply.

In preview, deployments support Windows devices with:

  • Win32 apps;
  • Enterprise App Catalog apps;
  • settings catalog policies;
  • endpoint security policies.

My take: until now, a phased rollout in Intune meant juggling several groups and editing assignments by hand, step by step. Having a dedicated object, with a pause button and per-ring monitoring, will significantly reduce the risk of big app updates or security policy changes. To get started, read the Microsoft Intune deployments overview.

A redesigned device page for faster troubleshooting

The device page has been redesigned and becomes the default view in the Intune admin center. It brings together device details, recent activity, tools, reports and available actions in one place.

From Devices > All devices, just select a device to check its status, review its activity, open a report or run an action without leaving this view. A few things to note:

  • the layout is consistent across supported platforms, so there is no need to relearn the interface for each OS;
  • actions are grouped by purpose, making the right one quicker to find;
  • the page only shows actions supported by the device and permitted for the signed-in admin;
  • all tasks and reports from the previous page remain available.

Help desk teams will benefit most: a single screen to understand a device’s state (compliance, configuration, apps, Endpoint Analytics) and act on it.

Android: bulk eSIM and Teams calls on shared devices

Activate eSIMs on 100 devices in a single action

With bulk device actions, you can now activate eSIMs on 100 corporate-owned Android Enterprise devices in a single operation, using one carrier activation server URL, instead of configuring each device.

Requirements: devices running Android 15 or later, in fully managed, dedicated or corporate-owned with a work profile mode.

Another useful detail: during a bulk wipe, Intune preserves eSIMs by default. You can keep them when devices are reassigned, or remove them when devices are retired. Requirements are detailed in Manage eSIM cellular plans with device actions.

Managed Home Screen: answer a Teams call before signing in

On frontline workers’ shared devices, an urgent Microsoft Teams call could be blocked by the Managed Home Screen sign-in screen. Now, if the call arrives before authentication is complete, the user can accept or decline the call directly from the notification. Managed Home Screen then asks for the session PIN before any other activity in a protected app.

This feature is generally available. It applies to MAM-integrated apps that use the Intune App SDK, including non-Microsoft apps. The only requirement: the signed-in user must have an app protection policy assigned for the app. No specific setting needs to be enabled. See Managed Home Screen configuration.

Government clouds: new advanced capabilities in GCC High

This month, Enterprise Application Management, Microsoft Cloud PKI and Intune Remote Help become available in the GCC High cloud (Government Community Cloud with high security requirements). Enterprise Application Management is also offered to Department of Defense (DoD) organizations.

This follows the July arrival of Intune Advanced Analytics and Endpoint Privilege Management in these environments. It mainly concerns US public sector organizations, but it shows that Intune’s advanced capabilities are spreading to every cloud.

Myth of the month: Delivery Optimization isn’t enterprise-ready

Microsoft tackles a persistent myth: Intune supposedly offers no bandwidth controls for Windows content, and Delivery Optimization peer sharing supposedly isn’t suited to large organizations.

In reality, Intune lets you:

  • define peer groups;
  • set cache limits;
  • limit foreground and background download bandwidth;
  • cap monthly uploads to internet peers.

Delivery Optimization can combine peers and Microsoft Connected Cache with Microsoft content sources, and fallback-delay settings give local sources more time before an internet download starts. The Windows Update for Business Delivery Optimization report shows observed bandwidth savings and content sources over the previous 28 days.

To go further: the Delivery Optimization settings reference and the Microsoft Connected Cache overview.

What I recommend doing this month

  1. Try Intune deployments on a simple case: the next update of a Win32 app or a settings catalog policy, with two or three rings. It is a preview: keep it away from critical changes for now.
  2. Prepare your rings: if you don’t yet have well-defined pilot and early-adopter groups, now is the time to create them; they will also serve your Windows updates.
  3. Show the new device page to your help desk: a quick tour of the grouped actions and recent activity will save them time.
  4. Corporate Android fleet on Android 15 with eSIM: find your carrier’s activation server URL and test bulk activation on a few devices.
  5. Review your Delivery Optimization settings and check the 28-day report: it is often an underused source of bandwidth savings.

Key takeaways

  • Microsoft Intune deployments (public preview) roll out Win32 apps, Enterprise App Catalog apps, settings catalog and endpoint security policies in rings, on Windows.
  • A deployment can be paused, resumed or canceled, and deployment plans are reusable; RBAC and scope tags still apply.
  • The new device page becomes the default view: details, recent activity, tools, reports and actions in one place.
  • eSIMs on 100 corporate-owned Android Enterprise devices running Android 15+ can be activated in a single action, and a bulk wipe keeps them by default.
  • On Managed Home Screen, a Teams call can be accepted before authentication; the session PIN is still required for everything else (generally available).
  • Enterprise Application Management, Cloud PKI and Remote Help arrive in the GCC High cloud.

Frequently asked questions

What are Microsoft Intune deployments?

A public preview feature that rolls out a Windows app or policy in successive rings, with a schedule per ring, shared exclusions and the ability to pause, resume or cancel the deployment from the Intune admin center.

What can be deployed in rings with Intune?

In preview, deployments support Windows devices with Win32 apps, Enterprise App Catalog apps, settings catalog policies and endpoint security policies.

How many Android eSIMs can Intune activate at once?

Up to 100 corporate-owned Android Enterprise devices running Android 15 or later (fully managed, dedicated or corporate-owned with a work profile), in a single action using one carrier activation server URL.

Do I need to enable a setting to answer Teams calls on Managed Home Screen?

No. The feature is generally available and requires no specific setting: the signed-in user just needs an app protection policy assigned for the app.

Is the old Intune device page going away?

The redesigned page becomes the default view, but all tasks and reports from the previous page remain available.

Sources and documentation

#Microsoft Intune#What's new in Intune#Phased rollout#Android Enterprise#Managed Home Screen#Delivery Optimization