Intune

Microsoft Intune February Update: Multi-Admin Approval & Apple DDM

3분 읽기

요약

Microsoft’s February Intune update adds multi-admin approval for device configuration and compliance policies, requiring a second admin to approve critical changes before they take effect. The release also improves Advanced Analytics device query results and expands Apple Declarative Device Management support, helping organizations strengthen change control, reduce configuration risk, and manage Apple devices more precisely at scale.

Intune 관련 도움이 필요하신가요?전문가와 상담하기

Introduction: Why this matters

Workarounds in device management often start as convenience—but they can quietly increase risk. Duplicated policies, overly broad software update deployments, and unreviewed changes expand the attack surface and undermine Zero Trust practices like least privilege and strong change control. This month’s Intune improvements are aimed at reducing those gaps by adding approvals, better fleet analytics, and more precise Apple policy targeting.

What’s new in Intune (February)

1) Multi-admin approval expands to compliance and configuration policies

Intune now supports additional multi-administrator approval options for:

  • Device configuration policies created via the Settings catalog
  • Device compliance policies

With multi-admin approval enabled, creating, editing, or deleting these critical policies requires approval from a second administrator before changes take effect. This builds on approvals already available for other high-impact areas (apps, scripts, device actions like wipe/retire/delete, RBAC roles, and device categories).

Why it’s important: This adds practical governance to prevent accidental or unauthorized policy changes—especially valuable in environments where configuration drift can quickly lead to non-compliance.

2) Advanced Analytics: richer Multiple Device Query (MDQ) results

Advanced Analytics now includes improved MDQ usability and precision:

  • Operator details are now shown in query results, including join types (such as leftanti and rightsemi) to help identify “missing” device conditions more accurately.
  • Clickable join syntax in MDQ results for faster navigation to device details.
  • Improved error messaging.
  • Simplified joins: admins can now join results on the Device field without custom Device syntax.

Why it’s important: Better query fidelity helps admins find compliance gaps, missing configurations, or device cohorts at scale—critical for Zero Trust decisions that depend on accurate inventory and state data.

3) Apple DDM policies now support assignment filters

Previously, Declarative Device Management (DDM) policies couldn’t use assignment filters, limiting targeting flexibility (for example, separating corporate vs. personal devices). Now, Intune supports assignment filters for DDM-based policies, aligning the experience with traditional MDM-based policies.

Examples:

  • Target software updates only to devices on iOS 17+ using an OS version filter.
  • Target ADE supervised devices while excluding personal devices using an enrollment profile name filter.

Why it’s important: As Apple expands DDM across iOS, iPadOS, macOS, visionOS, and tvOS, admins need consistent, precise targeting to avoid overreaching deployments.

Impact on IT admins and end users

  • Admins gain stronger change control for high-impact policies, improved troubleshooting and fleet analysis via MDQ enhancements, and reduced need for duplicate policies or blanket update assignments.
  • End users benefit from fewer unintended policy changes and more appropriate update targeting (especially for BYOD scenarios).

Action items / Next steps

  • Review whether multi-admin approval should be enabled for compliance and Settings catalog configuration policies in your tenant.
  • Update internal change management guidance to include the new approval workflow and confirm audit log retention meets governance needs.
  • If you use Apple DDM, revisit your assignment strategy and implement filters to better separate corporate and personal device experiences.
  • For analytics-heavy environments, re-check MDQ queries and take advantage of improved joins and operator visibility to tighten fleet reporting.

Intune 관련 도움이 필요하신가요?

전문가가 Microsoft 솔루션 구현 및 최적화를 도와드립니다.

전문가와 상담하기

Microsoft 기술 최신 정보 받기

Intunemulti-admin approvalAdvanced AnalyticsApple DDMassignment filters

관련 기사

Intune

Microsoft Intune App Security for AI Workflows

Microsoft is expanding Intune’s app security capabilities with enhanced app inventory in May and Enterprise Application Management auto-updates in July, giving IT teams better visibility into managed and user-installed Windows apps and faster deployment of software updates. These changes matter because they help organizations spot risky or unauthorized apps sooner, reduce version drift, and lower exposure to vulnerabilities as AI-driven workflows increasingly depend on secure endpoint applications.

Intune

Microsoft Intune for MSPs Adds 3 Multi-Tenant Partners

Microsoft has added three new validated multi-tenant partners to its Intune for MSPs ecosystem—AvePoint Confidence Platform: Elements Edition, CyberDrain CIPP, and SoftwareCentral Tenant Manager—expanding tools for centralized automation, governance, security visibility, and policy standardization across customer tenants. This matters because it gives managed service providers more Microsoft-aligned options to reduce manual work, replace custom scripts, and manage multi-tenant environments more securely and efficiently.

Intune

Intune App Protection in Edge for Business on Windows

Microsoft announced public preview support for Intune App Protection Policies in Edge for Business work profiles on Windows, allowing organizations to protect corporate data in the browser even on PCs already managed by another tenant. This matters because it gives contractors and partner users secure access to business apps without requiring full device enrollment, while enforcing controls like download redirection, copy/paste restrictions, and clearer Entra-based onboarding.

Intune

Intune 2026년 1월 업데이트: Win32 설치·EPM·Apple 등록

Microsoft Intune의 2026년 1월 업데이트는 Win32 앱에 PowerShell 스크립트 설치 관리자를 직접 업로드할 수 있게 하고, EPM에 현재 사용자 컨텍스트 유지 및 scope tags 지원을 추가했으며, 운영 승인·요청을 모아보는 Admin tasks를 GA로 제공한 것이 핵심입니다. 이로써 앱 배포와 권한 상승, 승인 워크플로의 속도와 유연성은 높아지고, 감사 추적·규정 준수·관리 가시성도 함께 강화돼 IT 운영 효율에 직접적인 영향을 줍니다.

Intune

Microsoft Intune Admin Tasks GA: EPM·MAA 단일 큐

Microsoft Intune의 Admin Tasks가 GA로 출시되며, EPM 권한 상승 요청, Microsoft Defender for Endpoint 보안 remediation, Multi Admin Approval(MAA) 요청을 하나의 우선순위 큐에서 통합 관리할 수 있게 됐습니다. 이는 관리자의 대응 속도와 감사 추적성을 높이고, 중요 작업에 대한 거버넌스와 보안을 강화해 침해 위험을 줄인다는 점에서 의미가 큽니다.

Intune

Intune Technical Takeoff 2026 3월 세션·AMA 총정리

Microsoft Intune Technical Takeoff 2026는 3월 매주 월요일 라이브 세션과 AMA로 진행되며, Zero Trust 보안, Windows Autopilot Device Prep 전환, Windows 365 관리, AI 기반 엔드포인트 운영 등 실무 중심 주제를 다룹니다. 라이브 Q&A, 사전 질문, 자막·트랜스크립트 제공까지 포함돼 관리자가 최신 Intune 방향성과 구현 팁을 엔지니어링 팀으로부터 직접 확인할 수 있다는 점에서 중요합니다.