Skip to main content

Windows Changes & Release Notes

Latest change requests, release notes, and updates for Windows UEM.

Admin By Request 8.6 Release Notes

· One min read
Jon Griffey
IT Director for Endpoint Management

Browser download elevation: Seamless browser download handling across Chrome, Edge, and Firefox. When a user downloads and launches an executable from the browser, the new Admin By Request Browser Extension detects the action and routes it through the proper elevation flow.

Refer to Installing Admin By Request for more information.

System tray improvements: The system tray icon has been optimized for speed and reliability - it now appears immediately when Explorer starts. Additionally: The tray icon automatically restarts if the ABR process is unexpectedly closed. Logged-in users who are Azure global and device administrators now see the correct red tray icon when the Entra connector is not configured. In tray tools, the Network Adapters tray tool now correctly displays all Wi-Fi adapters, resolving previous visibility issues.

Refer to Using Tray Tools for more information.

A significant number of bug fixes and minor improvements, benefiting the broader ABR community across the Windows product range.

Implement New Recast Management Server [MECM-1P-RCST-W1.auth.tamu.edu]

· 2 min read
Jon Griffey
IT Director for Endpoint Management

Change Request 433317 Implement New Recast Management Server [MECM-1P-RCST-W1.auth.tamu.edu].

Description: Details of maintenance: This change consists of the implementation of a new Recast Management Server [MECM-1P-RCST-W1.auth.tamu.edu] and upgrade of existing Recast Console Extension agents on MECM Jump Servers and Recast Agents on workstations.

Degraded Recast Management Servers: mecm-1p-rcst-c1.auth.tamu.edu cm2-recast.as.tamu.edu

MECM Jump Servers: mgmt-3p-cst.auth.tamu.edu batcave.it.tamu.edu mgmt-2p-cst.ads.tamu.edu cm2.as.tamu.edu

Benefit of change: This change addresses issues with both former Recast Management Servers that were both in different states of degradation and could not be reverted to a functional state since no backup snapshot existed.

By implementing a new sever, its database is now on the primary sql.it.tamu.edu SQL server and the old servers may now be decommissioned.  The new server is on the latest Recast version 5.11.2511.1804, and agents and Recast Console Extensions will be upgraded on each MECM Jump Server. This brings alignment of each application version in accordance with the vendors specification for a properly configured environment.

The latest version includes several bug fixes and Right-Click Tools features outlined in the following release notes: https://docs.recastsoftware.com/help/recast-software-version-5-11-releases#recast-version-51125111804.

Impact to customers: There is no impact on campus faculty, staff, or students as it is a tool used by MECM admins. Recast Agents for OAL workstations will be upgraded and Unit Admins may deploy the new Recast Agent at their earliest convenience.

Scope Intune Company Portal as Required for 'All Devices'

· One min read
Neil Feagan
IT Professional I

Change Request 392644 Scope Intune Company Portal as Required for 'All Devices'.

Description: Details of maintenance: This change will consist of modifying the 'Assignments' for the Microsoft Company Portal application in Intune. Currently following an opt-in model, to install Company Portal on Intune-managed devices, units must 'Include' a 'scope group' associated with target devices. With this change, the built-in virtual group 'All Devices' will be assigned, enforcing the install of the application upon device enrollment into Intune, removing the need for individual units to manage and assign their own 'scope groups'.

For special use-cases where Company Portal may not be appropriate to deploy, units may still prevent the deployment by using scope-groups to 'exclude' devices from receiving the application.

Benefit of change: The Microsoft Company Portal app enables customers to install managed applications and access of other self-service resources from their Intune-managed workstation. A primary benefit of this change is to simplify the management and promote a consistent user experience.

Impact to customers: There is no expected impact to campus members and will result in a shift from the current opt-in deployment model to a more manageable opt-out model for Intune Administrators.

Move Intune 'Drive Mapping' Policies to Production State

· One min read
Neil Feagan
IT Professional I

Change Request 392747 Move Intune 'Drive Mapping' Policies to Production State.

Description: Details of maintenance: This change moves the following production-ready Intune enterprise 'template' policies to a production state, making them available to IT Units managing devices in Intune. Once in production, these Enterprise policies are intended to be used as templates by all Units to address their unique drive mapping needs. Note: The ADMX template may be copied and renamed directly in Intune, while the OMA-URI (single-drive configuration) policy must be manually recreated.

Enterprise Policy Templates Moving to Production: 02-TMPL-USER-Single-DriveMapping-v1 (Custom OMA-URI Configuration) 02-TMPL-USER-Multi-DriveMapping-v1 (ADMX Configuration)

Note: Both policy templates work in conjunction with the following Enterprise Platform Required (EPR) policy that must first be applied to enable drive mapping functionality.

02-EPR-MGMT-EnableDriveMapping-v1

Benefit of change: The primary benefit of this change is to simplify and streamline configuration management for departmental network drives mapped to Intune-managed workstations.

Impact to customers: There will be no customer impact due to the nature of this change.

Publish Forensit Migration Scripts v24.8 (Standard and SkipUser) to SCCM Following Validation by Mays

· One min read
Nicholas Swanzy
Nicholas Swanzy
Site Reliability Engineer III

Change Request 267881 Publish Forensit Migration Scripts v24.8 (Standard and SkipUser) to SCCM Following Validation by Mays.

Description: This change is in response to TDX#267783, submitted by Mays, reporting that users experienced desktop icon flashing during Forensit-based migrations. Vendor documentation confirmed this behavior as a bug fixed in Forensit version 24.8.

Platform Engineering built the following updated applications and made them available in SCCM:

Forensit Migrate-TAMUMigrationAuthUserEXP010426 v14-CLBA

Forensit Migrate-TAMUMigrationAuthUserEXP010426 v14-TAMUCS

Forensit Migrate-TAMUMigrationAuthUserEXP010426 v14-TAMUCS-SkipUser

Mays conducted testing across multiple devices—each version was tested independently. Additionally, they verified that version 24.8 resolved the flashing desktop icons on a device that had already been migrated using a previous version of the Forensit script.

These packages are now published and available in SCCM. This change does not include production assignment. Each distributed unit is responsible for testing and deployment in their respective environments.

• Impact to Customers: None as part of this change. No automatic deployments are being made.

• Impact to Other Services/Websites: None.

Enable “Allow Available Uninstall” in PatchMyPC Publisher for Win32 Apps in Intune

· One min read
Nicholas Swanzy
Nicholas Swanzy
Site Reliability Engineer III

Change Request 264345 Enable “Allow Available Uninstall” in PatchMyPC Publisher for Win32 Apps in Intune.

Description: Details of Maintenance:

A configuration update will be applied to PatchMyPC Publisher to enable the “Allow available uninstall for Win32 apps in Intune” setting. This change will allow all Available applications published via PatchMyPC to be uninstalled by end users through the Company Portal.

In addition, a Microsoft Graph API script will update all existing PatchMyPC-published Win32 apps in Intune to ensure the uninstall option is enabled for apps already marked as Available.

Benefit of Change:

Enables end-user self-service for uninstalling optional software.

Reduces IT support burden for basic uninstall requests.

Aligns PatchMyPC deployments with modern application lifecycle practices.

Retains strict control for Required applications, which are not affected.

Impact to Customers

Users will gain the ability to uninstall Available applications directly via the Company Portal.

No impact to users with Required apps or apps installed by other methods.

Users will not be prompted or forced to take any action.

Impact to Other Services/Websites

No impact expected to external services or websites.

Intune service will be used via Microsoft Graph API but within approved API usage guidelines.

Intune/SCCM Co-Management settings no longer assigned

· One min read
Jon Griffey
IT Director for Endpoint Management

Change Request 265098 Intune/SCCM Co-Management settings no longer assigned.

Description: Change Description: An emergency change was implemented to reassign the Intune Enrollment Co-management settings after it was discovered that they were no longer assigned to any device group. This reassignment was necessary to resolve an issue reported by Jon, where SCCM agents were failing to install on OAL Self-Driven Autopilot enrolled devices.

Root Cause and Initial Fix

Root Cause: The Intune Co-management settings had lost their assignments, which prevented proper SCCM agent deployment during Autopilot.

Initial Emergency Action: The Co-management settings were assigned to the device scope group for all Autopilot enrolled devices.

Immediate Outcome: This resolved the issue for OAL Self-Driven devices, as confirmed by Jon.

Disable SCCM application visibility in Company Portal to enforce an Intune-only application experience.

· One min read
Nicholas Swanzy
Nicholas Swanzy
Site Reliability Engineer III

Change Request 218049 Disable SCCM application visibility in Company Portal to enforce an Intune-only application experience..

Description: Details of Maintenance: This change will disable the setting that allows Configuration Manager (SCCM)-deployed applications to appear in the Intune Company Portal. Going forward, only applications deployed via Intune will be visible to end users. This action supports the proposed Company Portal redesign, which improves performance and simplifies the user experience by removing hybrid app listings. Benefit of Change:

Reduces Company Portal load and UI latency

Eliminates user confusion caused by duplicate SCCM and Intune app listings

Establishes Company Portal as the single, authoritative interface for Intune application access

Aligns with onboarding practices under the Unified Device Management (UDM) project

Reinforces the use of PSG and ESG targeting standards

Impact to Customers:

No interruption of service

End users will no longer see SCCM applications in the Company Portal.

End users will now need to look at Software Center for SCCM applications.

Required apps from SCCM will continue deploying silently without user interaction

Impact to Other Services/Websites:

No impact to external services or websites

SCCM and Intune infrastructure continue to operate normally

Change is limited to the frontend presentation in the Company Portal

Implementation of the “All Shared Devices” filter in Intune to support scoped application and policy assignments for Self-Driven (Shared) devices.

· 2 min read
Nicholas Swanzy
Nicholas Swanzy
Site Reliability Engineer III

Change Request 218076 Implementation of the “All Shared Devices” filter in Intune to support scoped application and policy assignments for Self-Driven (Shared) devices..

Description: Details of Maintenance: This change introduces and standardizes the use of a device filter in Intune named “All Shared Devices.” The filter is used to identify devices that are enrolled without user affinity (Self-Driven), typically used as Shared Devices in labs, kiosks, and classrooms. The filter uses the following syntax to exclude User-Driven devices enrolled using pre-provisioning: (device.enrollmentProfileName -ne "_TAMU User Driven with Pre Provision") This filter will be applied as Include or Exclude in assignments depending on the target audience. It will now serve as the standard method for distinguishing between Shared and User-Managed devices in policy and application assignments. Benefit of Change:

Enables consistent targeting logic across device management scenarios

Supports clean separation between Shared and User-Managed devices

Reduces risk of misapplication of user-focused policies to Shared Devices

Aligns with Experience Scope Group (ESG) and Policy Scope Group (PSG) design standards

Supports structured onboarding under the Unified Device Management (UDM) project

Impact to Customers:

No user disruption

Improved accuracy and consistency of application and policy targeting

Easier troubleshooting and policy validation for distributed IT admins

Impact to Other Services/Websites:

No impact to external services or platforms

Change is limited to device targeting logic in Intune