Zendoric
← Back to the day · September 3, 2026

Microsoft Intune now allows device targeting by specific operating system version

🕒 Published on Zendoric: September 3, 2026 · 10:20

✨ AI-generated · how it's made

Microsoft Intune service update 2608, reported by the source on September 1, 2026, introduces several management and security features aimed at enterprise customers, most notably the general availability of assignment filters based on operating system version.

Microsoft Intune service update 2608, reported by the source on September 1, 2026, introduces several management and security features aimed at enterprise customers, most notably the general availability of assignment filters based on operating system version.

The central feature of this update is the general availability of the operatingSystemVersion property for both devices and managed applications. With it, IT administrators can target policies and applications to devices based on a specific build version or a range of operating system versions. When a device checks in, Intune evaluates the corresponding filter and applies the assignment only if the device meets the specified condition. The rule builder supports the comparison operators -eq, -ne, -gt, -ge, -lt and -le to compare the operatingSystemVersion value against a given version. This opens the door to scenarios such as testing a configuration first on the newest builds, excluding devices that have not yet updated from a policy, or building rules based on a specific build, which can facilitate staged rollouts and policy testing ahead of a general deployment.

Another notable addition is unattended Remote Help for Windows, which allows authorized IT staff to remotely access and troubleshoot physical PCs even when no user is signed in. The article clarifies that this capability still requires the appropriate license and prior configuration in the users' tenant, so it is not automatically available to all Intune customers.

As for Windows configuration management, Microsoft has expanded the settings catalog with new options derived from several administrative template updates. These include the ability to enable Internet Explorer Protected Mode for security zones, new Microsoft Edge policies from the Edge 150 template update, and the option to disconnect a Remote Desktop Services session when no smart card is present during interactive sign-in. New settings for Office templates have also been added, allowing administrators to create a Windows settings catalog profile to manage them.

The update also redesigns the individual device management page within the Intune admin center. The new page groups device properties, activity, available tools and reports into a single screen, and organizes remote actions under the Remote actions, Secure and Remove data menus. According to the article, it is up to IT administrators themselves to decide whether to turn off the preview of this new device design from the Devices > All devices section.

Finally, Microsoft has expanded the list of Intune protected apps with seven new additions: Superhuman Mail, Notion, Calven, Heijmans, Notability (iOS), Ben for Intune and Zoho's SDP – On Premises. These applications can now participate in the platform's app protection policies.

Taken together, this Intune update strengthens the granular control administrators have over how, when and to which devices policies are applied, with a particular emphasis on enabling more gradual and better segmented rollouts based on operating system update status, while also adding targeted improvements in remote support, Windows configuration and protected app coverage.

🔗 Related on Zendoric

Sources & references