Intune

Microsoft Intune May 2026: Android, macOS, PKI

3 min read

Summary

Microsoft Intune’s May 2026 updates focus on reducing admin friction across Android management, macOS identity setup, and certificate renewal. Key additions include web-based Android work profile enrollment, direct APK app deployment, built-in Platform SSO registration during macOS setup, and in-place Cloud PKI issuing CA renewal.

Need help with Intune?Talk to an Expert

Introduction

Microsoft Intune’s May 2026 updates are centered on a practical goal: making device management easier without sacrificing control or security. For IT admins, the release brings meaningful improvements to Android enrollment and app deployment, macOS identity setup, and Cloud PKI renewal workflows.

What’s new in Intune for May 2026

Android management improvements

Several Android updates are now generally available:

  • Personal Work Profile Android Management API now supports a web-based enrollment flow, so users no longer need to find and install the Company Portal app before starting enrollment.
  • Direct management of Android LOB apps is now generally available for Android Enterprise fully managed and dedicated devices. Admins can upload APKs directly to Intune instead of relying on Managed Google Play.
  • Admins can now deploy multiple versions of the same app to different groups and avoid package-name limitations.
  • Mobile Threat Defense apps can receive enhanced security permissions on supported Android Enterprise devices, helping threat protection continue running even when devices apply app suspension or battery optimizations.

macOS Platform SSO during setup

Platform SSO registration during Automated Device Enrollment (ADE) for macOS is now generally available.

Previously, users had to complete PSSO registration after enrollment through a desktop notification, which was easy to miss. Now, registration happens during setup, linking the Mac to Microsoft Entra ID before the user reaches the desktop. This should reduce authentication issues, missed registrations, and compliance problems.

Cloud PKI CA renewal

Intune now supports in-place renewal of eligible Cloud PKI issuing certification authorities.

This removes the need to create a new issuing CA and manually update dependent SCEP profiles. Intune also creates a staged CA with a temporary SCEP endpoint so admins can validate issuance before activation, reducing outage and misconfiguration risks.

Why this matters for IT administrators

These updates help admins standardize and simplify common management tasks:

  • Faster, more consistent Android enrollment
  • Greater control over internal Android app distribution
  • Fewer macOS identity and compliance issues during onboarding
  • Lower operational overhead for certificate renewal
  • A smoother path for phased app migration from Configuration Manager to Intune

Microsoft also reinforced that app migration to Intune does not need to be all-or-nothing. Co-management and phased migration remain the recommended approach, especially for organizations moving workloads gradually.

Next steps

  • Review whether web-based Android work profile enrollment fits your BYOD strategy.
  • Test direct APK deployment for internal Android apps.
  • Update macOS enrollment workflows to include Platform SSO during ADE.
  • Check expiration timelines for Cloud PKI issuing CAs and plan staged renewals.
  • Reassess your Configuration Manager to Intune app migration plan using pilot groups and low-complexity apps first.

Overall, the May 2026 Intune release is less about flashy features and more about removing friction from day-to-day administration.

Need help with Intune?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

IntuneAndroid EnterprisemacOSCloud PKIapp management

Related Posts

Intune

Microsoft Intune September 2026: Deployment Controls

Microsoft Intune’s September 2026 updates add phased deployments for Windows apps and policies, a redesigned unified device view, and new Android bulk eSIM management capabilities. The release also expands advanced Intune features in government clouds, helping IT teams reduce rollout risk, troubleshoot faster, and streamline endpoint operations.

Intune

Microsoft Intune August 2026: Autopilot and Remote Help

Microsoft Intune's August 2026 updates focus on reducing manual work across the device lifecycle. Key additions include Windows Autopilot device association for pre-enrollment trust, Remote Help unattended access with remote sign-in, and new Apple management capabilities for app control and enhanced logging.

Intune

Microsoft Intune July 2026: Sync, macOS, Samsung

Microsoft Intune’s July 2026 updates improve day-to-day endpoint management with live Windows sync visibility, generally available custom compliance settings for macOS, and Samsung Knox E-FOTA firmware controls. These changes give IT admins better troubleshooting insight, stronger compliance coverage, and more predictable update management across device fleets.

Intune

Microsoft Intune E3 and E5 Add Advanced Capabilities

Microsoft has begun including advanced Intune Suite capabilities in Microsoft 365 E5, with select features now available in Microsoft 365 E3 as of July 1, 2026. The change expands access to tools such as Endpoint Privilege Management, Remote Help, Cloud PKI, Advanced Analytics, and mobile management features, giving IT teams stronger endpoint security and more streamlined operations.

Intune

Microsoft Intune June 2026: EAM, EPM, and ADE Updates

Microsoft Intune's June 2026 updates focus on keeping endpoints compliant, current, and secure with new app update, vulnerability remediation, privilege management, and enrollment capabilities. The release matters for IT admins because it reduces manual effort, improves least-privilege controls, and speeds secure device readiness across Windows and Apple platforms.

Intune

Intune in Microsoft 365 E3/E5: New Capabilities

Microsoft is adding several advanced Intune capabilities to Microsoft 365 E3 and E5 starting July 1, with eligible tenants expected to receive them by August 1. The update expands built-in endpoint management, analytics, remote support, and privilege controls, helping IT teams reduce add-ons and manage more from a single platform.