Microsoft adds new Intune updates to enhance Windows support and security management

Microsoft introduces significant updates to Intune, including unattended Remote Help, controlled Defender Antivirus configuration, and expanded inventory controls, aiming to give IT administrators tighter management and security enforcement on Windows devices.

Microsoft has added a set of Intune updates aimed at giving administrators tighter control over Windows support and security management. The most notable change is unattended Remote Help for physical Windows PCs, which lets authorised support staff connect without waiting for an end user to accept the session. According to Microsoft documentation, the feature is limited to x64 editions of Windows 10 and Windows 11 that are enrolled in Intune and joined to Microsoft Entra, or hybrid joined, and it does not extend to virtual machines or personally owned devices.

To use unattended control, administrators must also deploy the Azure Virtual Desktop agent and bootloader on the target device, alongside the Intune Management Extension, and remote desktop access must be enabled. Microsoft says the helper must have the appropriate role-based access control permission for unattended control, and the session is launched through the Windows App web client. If a user is logged on, Windows gives them a brief prompt to allow or decline the connection; if they do not answer, the desktop is locked and the technician connects to a separate session.

On the security side, Microsoft has introduced Controlled Configuration for Defender Antivirus in public preview. Microsoft Learn says the aim is to make Intune the single authoritative source for Defender settings, so conflicting changes from Group Policy, Configuration Manager or local scripts no longer override centrally managed policy. The feature builds on Tamper Protection but is broader in scope, applying to Antivirus and attack surface reduction settings configured through Intune.

The preview is not unlimited. Microsoft says the target device must run Windows 10, Windows 11 or Windows Server 2019, together with Defender platform version 4.18.26060.3004 or later. In practice, that means security teams should verify compatibility before relying on it to prevent configuration drift. Microsoft also notes that settings outside the controlled policy can revert to defaults, so the feature is best seen as a way to enforce a defined baseline rather than a blanket lock on every Defender option.

Intune is also expanding inventory and targeting controls. The properties catalogue can now collect selected Windows registry data from managed devices, though Microsoft limits the initial release to the HKEY_LOCAL_MACHINE hive, caps individual values at 6 KB and restricts collection to 100 keys per device. At the same time, the operatingSystemVersion assignment filter has reached general availability, replacing the older osVersion string-based approach with proper numerical comparisons. That should make policy scoping more reliable for Windows build numbers, especially when targeting specific releases. Microsoft has also updated the single-device page in the admin centre, with a new default layout and a deeper synchronisation action that now covers configuration profiles, applications and scripts.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.