Intune

Microsoft Intune February Update: Multi-Admin Approval & Apple DDM

3 min read

Summary

Microsoft’s February Intune update adds multi-admin approval for device configuration and compliance policies, requiring a second admin to approve critical changes before they take effect. The release also improves Advanced Analytics device query results and expands Apple Declarative Device Management support, helping organizations strengthen change control, reduce configuration risk, and manage Apple devices more precisely at scale.

Need help with Intune?Talk to an Expert

Introduction: Why this matters

Workarounds in device management often start as convenience—but they can quietly increase risk. Duplicated policies, overly broad software update deployments, and unreviewed changes expand the attack surface and undermine Zero Trust practices like least privilege and strong change control. This month’s Intune improvements are aimed at reducing those gaps by adding approvals, better fleet analytics, and more precise Apple policy targeting.

What’s new in Intune (February)

1) Multi-admin approval expands to compliance and configuration policies

Intune now supports additional multi-administrator approval options for:

  • Device configuration policies created via the Settings catalog
  • Device compliance policies

With multi-admin approval enabled, creating, editing, or deleting these critical policies requires approval from a second administrator before changes take effect. This builds on approvals already available for other high-impact areas (apps, scripts, device actions like wipe/retire/delete, RBAC roles, and device categories).

Why it’s important: This adds practical governance to prevent accidental or unauthorized policy changes—especially valuable in environments where configuration drift can quickly lead to non-compliance.

2) Advanced Analytics: richer Multiple Device Query (MDQ) results

Advanced Analytics now includes improved MDQ usability and precision:

  • Operator details are now shown in query results, including join types (such as leftanti and rightsemi) to help identify “missing” device conditions more accurately.
  • Clickable join syntax in MDQ results for faster navigation to device details.
  • Improved error messaging.
  • Simplified joins: admins can now join results on the Device field without custom Device syntax.

Why it’s important: Better query fidelity helps admins find compliance gaps, missing configurations, or device cohorts at scale—critical for Zero Trust decisions that depend on accurate inventory and state data.

3) Apple DDM policies now support assignment filters

Previously, Declarative Device Management (DDM) policies couldn’t use assignment filters, limiting targeting flexibility (for example, separating corporate vs. personal devices). Now, Intune supports assignment filters for DDM-based policies, aligning the experience with traditional MDM-based policies.

Examples:

  • Target software updates only to devices on iOS 17+ using an OS version filter.
  • Target ADE supervised devices while excluding personal devices using an enrollment profile name filter.

Why it’s important: As Apple expands DDM across iOS, iPadOS, macOS, visionOS, and tvOS, admins need consistent, precise targeting to avoid overreaching deployments.

Impact on IT admins and end users

  • Admins gain stronger change control for high-impact policies, improved troubleshooting and fleet analysis via MDQ enhancements, and reduced need for duplicate policies or blanket update assignments.
  • End users benefit from fewer unintended policy changes and more appropriate update targeting (especially for BYOD scenarios).

Action items / Next steps

  • Review whether multi-admin approval should be enabled for compliance and Settings catalog configuration policies in your tenant.
  • Update internal change management guidance to include the new approval workflow and confirm audit log retention meets governance needs.
  • If you use Apple DDM, revisit your assignment strategy and implement filters to better separate corporate and personal device experiences.
  • For analytics-heavy environments, re-check MDQ queries and take advantage of improved joins and operator visibility to tighten fleet reporting.

Need help with Intune?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

Intunemulti-admin approvalAdvanced AnalyticsApple DDMassignment filters

Related Posts

Intune

Microsoft Intune July 2026: Sync, macOS, Samsung

Microsoft Intune’s July 2026 updates improve day-to-day endpoint management with live Windows sync visibility, generally available custom compliance settings for macOS, and Samsung Knox E-FOTA firmware controls. These changes give IT admins better troubleshooting insight, stronger compliance coverage, and more predictable update management across device fleets.

Intune

Microsoft Intune E3 and E5 Add Advanced Capabilities

Microsoft has begun including advanced Intune Suite capabilities in Microsoft 365 E5, with select features now available in Microsoft 365 E3 as of July 1, 2026. The change expands access to tools such as Endpoint Privilege Management, Remote Help, Cloud PKI, Advanced Analytics, and mobile management features, giving IT teams stronger endpoint security and more streamlined operations.

Intune

Microsoft Intune June 2026: EAM, EPM, and ADE Updates

Microsoft Intune's June 2026 updates focus on keeping endpoints compliant, current, and secure with new app update, vulnerability remediation, privilege management, and enrollment capabilities. The release matters for IT admins because it reduces manual effort, improves least-privilege controls, and speeds secure device readiness across Windows and Apple platforms.

Intune

Intune in Microsoft 365 E3/E5: New Capabilities

Microsoft is adding several advanced Intune capabilities to Microsoft 365 E3 and E5 starting July 1, with eligible tenants expected to receive them by August 1. The update expands built-in endpoint management, analytics, remote support, and privilege controls, helping IT teams reduce add-ons and manage more from a single platform.

Intune

Microsoft Intune May 2026: Android, macOS, PKI

Microsoft Intune’s May 2026 updates focus on reducing admin friction across Android management, macOS identity setup, and certificate renewal. Key additions include web-based Android work profile enrollment, direct APK app deployment, built-in Platform SSO registration during macOS setup, and in-place Cloud PKI issuing CA renewal.

Intune

Microsoft Intune April 2026: App Inventory and SSO

Microsoft Intune’s April 2026 updates improve Windows app inventory freshness, introduce modernized Linux single sign-on with Microsoft Identity Broker, and expand Apple device enrollment and management. These changes matter for IT teams that need faster device insights, stronger identity integration, and simpler support for shared or specialized endpoints.