Intune

Microsoft Intune June 2026: EAM, EPM, and ADE Updates

3 min read

Summary

Microsoft Intune's June 2026 updates focus on keeping endpoints compliant, current, and secure with new app update, vulnerability remediation, privilege management, and enrollment capabilities. The release matters for IT admins because it reduces manual effort, improves least-privilege controls, and speeds secure device readiness across Windows and Apple platforms.

Need help with Intune?Talk to an Expert

Introduction

Microsoft Intune’s June 2026 release is centered on a practical goal for IT teams: keeping devices secure, compliant, and ready from day one. As organizations rely more on automation and AI-driven workflows, endpoint health and policy enforcement become even more important.

What’s new in Intune for June 2026

EAM auto-updates now generally available

Microsoft Intune Enterprise Application Management (EAM) auto-updates is now generally available. This feature automatically updates managed apps to the latest incremental release without requiring manual packaging or ongoing admin intervention.

  • Helps reduce version drift across endpoints
  • Limits exposure to known vulnerabilities between major upgrade cycles
  • Simplifies cloud-native app lifecycle management

Vulnerability Remediation Agent in public preview

A new Vulnerability Remediation Agent is now in public preview within Microsoft Security Copilot. It uses Microsoft Defender Vulnerability Management data to prioritize CVEs across Intune-managed Windows devices and apps.

Admins can see:

  • Prioritized recommendations based on CVSS, exposure impact, and affected devices
  • Copilot-assisted summaries and remediation guidance
  • Audit-friendly access through a dedicated Microsoft Entra agentic identity

This should help security and endpoint teams triage remediation work faster directly from the Intune admin center.

New Endpoint Privilege Management enhancements

Intune Endpoint Privilege Management (EPM) adds two generally available capabilities:

  • Support approval requests for non-primary users on shared devices
  • System-level network configuration support so standard users can change settings like DNS, gateway, and IP based on policy

These updates strengthen least-privilege administration without forcing IT to hand out local admin rights or create insecure workarounds.

Apple ADE enrollment experience updated

Intune is moving iOS/iPadOS and macOS automated device enrollment (ADE) profiles to a new infrastructure. This modernized experience supports more granular controls and completes enrollment time grouping (ETG) support across all platforms.

The result is faster and more complete provisioning, with apps and policies applied at enrollment so devices are secure and productive sooner.

Faster app inventory refresh

Microsoft also clarified that app inventory refresh is no longer limited by the old “seven-day” assumption. The new All Apps experience now refreshes data multiple times per day for active devices and includes richer app details such as install location, app size, and uninstall commands.

Why this matters for IT administrators

This release reduces manual overhead in several high-effort areas: app packaging, vulnerability triage, elevation approvals, and device enrollment. It also improves security posture by helping teams enforce least privilege, accelerate patching, and deliver compliant devices faster.

Next steps

  • Review EAM auto-update policies for managed applications
  • Evaluate the Vulnerability Remediation Agent preview in test environments
  • Update EPM workflows for shared or multi-user devices
  • Plan for the new Apple ADE enrollment experience
  • Note that EPM and EAM become part of Microsoft 365 E5 starting July 1 and confirm licensing readiness

Overall, the June 2026 Intune updates are aimed at giving admins more automation and control while improving endpoint security at scale.

Need help with Intune?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

IntuneEndpoint Privilege ManagementEnterprise Application ManagementApple ADEvulnerability management

Related Posts

Intune

Intune in Microsoft 365 E3/E5: New Capabilities

Microsoft is adding several advanced Intune capabilities to Microsoft 365 E3 and E5 starting July 1, with eligible tenants expected to receive them by August 1. The update expands built-in endpoint management, analytics, remote support, and privilege controls, helping IT teams reduce add-ons and manage more from a single platform.

Intune

Microsoft Intune May 2026: Android, macOS, PKI

Microsoft Intune’s May 2026 updates focus on reducing admin friction across Android management, macOS identity setup, and certificate renewal. Key additions include web-based Android work profile enrollment, direct APK app deployment, built-in Platform SSO registration during macOS setup, and in-place Cloud PKI issuing CA renewal.

Intune

Microsoft Intune April 2026: App Inventory and SSO

Microsoft Intune’s April 2026 updates improve Windows app inventory freshness, introduce modernized Linux single sign-on with Microsoft Identity Broker, and expand Apple device enrollment and management. These changes matter for IT teams that need faster device insights, stronger identity integration, and simpler support for shared or specialized endpoints.

Intune

Microsoft Intune Adds Android XR Device Management

Microsoft Intune now supports Android Enterprise management for Android XR devices, including the Samsung Galaxy XR headset. IT admins can use existing enrollment, policy, and app management workflows to test and deploy XR devices, while planning around current gaps such as kiosk mode, OEMConfig, and Remote Help.

Intune

Windows 365 and Intune: Advanced Management Gains

Microsoft outlined how Windows 365 and Intune now work more closely together to manage Cloud PCs and physical devices from a single admin experience. The update highlights advanced endpoint management capabilities such as Remote Help, advanced analytics, Endpoint Privilege Management, Cloud PKI, and Enterprise App Management, helping IT teams improve security, support, and operational efficiency.

Intune

Microsoft Intune March 2026: Apple and Admin Updates

Microsoft Intune’s March 2026 updates improve Windows notification delivery, tighten role assignment boundaries, and expand Apple device protections. The release also adds earlier app trust during Autopilot setup, general availability for Windows Autopatch update readiness, and better iOS app status reporting through Declarative Device Management.