Microsoft Intune Now Lets Admins Target Devices Based on Specific OS Versions

The new filtering capability could make staged deployments and policy testing easier, but administrators will need to decide how and where to apply it.

Windows-11-notebook-tablet

Key Takeaways:

  • IT teams can now use Remote Help on unattended Windows devices without requiring a logged-in user.
  • OS version assignment filters are now generally available for managed devices and apps.
  • Microsoft Intune introduces a redesigned device management page and expands the protected apps list.

Microsoft Intune’s 2608 service release brings various management and security updates for enterprise customers. The update also gives administrators more control over device views, OS-based policy assignments, Windows configuration settings, and protected apps across managed environments.

One of the most notable additions is unattended Remote Help for Windows. This feature allows authorized IT staff to remotely access and troubleshoot physical PCs even when no user is logged in. However, Remote Help still requires appropriate licensing and prior setup in the users’ tenant.

New policy settings for Windows

Microsoft Intune has added new Windows settings catalog options across various administrative template refreshes. This update allows IT admins to configure Turn on Protected Mode for Internet Explorer security zones and new Microsoft Edge policies from the Edge 150 template refresh. They can also set the Disconnect if a Remote Desktop Services session when no smart card is present option for interactive logon.

Microsoft has also introduced new settings for Office templates for enterprise customers. This feature allows administrators to create a Windows settings catalog profile to configure them.

New single device page

Microsoft has introduced an improved single-device management page in the Intune admin center. This new page groups device properties, activity, tools, and reports on one screen. Administrators can access remote actions under the Remote actions, Secure, and Remove data menus. It’s up to the IT admins to disable Preview new device view on the Devices > All devices page.

OS version assignment filters

Microsoft has announced the general availability of the operatingSystemVersion property for managed devices and managed apps. This feature allows IT admins to target devices based on specific operating system versions or build range. When a device checks in, Microsoft Intune evaluates the filter and applies the assignment only when the device matches the filter.

Administrators can choose to build rules based on a specific OS build, test a configuration on newer builds first, or exclude devices that have not updated. The rule builder uses -eq, -ne, -gt, -ge, -lt, and -le to compare operatingSystemVersion to a version value.

Last but not least, Microsoft has added seven additional apps to the Intune protected apps list. These include Superhuman Mail, Notion, Calven, Heijmans, Notability (iOS), Ben for Intune, and SDP – On Premises from Zoho. The company mentioned that these apps can participate in app protection policies.