Intune 2609, 24H2's last preview, and a cleanup job
Three things landed this week that actually change what you do on Monday, plus the usual pile of quick hits. Nothing dramatic, but the companion app retirement is going to eat someone's afternoon, so let's get into it.
top 3
1. Win32 apps show up faster (Intune service release 2609)
What changed: Intune now pushes notifications for admin-initiated and service-side Win32 app changes instead of waiting on the normal polling cycle. The Intune Management Extension also checks for Windows app assignments right after the Enrollment Status Page finishes, not on the next hourly sweep.
Why it matters for you: if you run Autopilot with ESP, you know the drill — required app shows up, ESP sits there, and you wait for the next hourly check-in before anything moves. That wait is going away for a chunk of scenarios.
What to do this week: nothing. No config change, no toggle. Just don't be surprised when a new enrollment doesn't sit on a required app as long as it used to. Community write-ups from Rudyooms and r/Intune (Sept 22 and Sept 26) already confirm the behavior in the wild.
Sources: Intune What's New | r/Intune thread | PatchMyPC writeup
2. Windows 11 24H2 just got its last preview update
What changed: KB5124010 (builds 26200.9550 / 26100.9550) shipped September 22 and it's the last non-security preview update 24H2 will get. Home and Pro on 24H2 hit end of support October 13, 2026. Enterprise and Education get until October 12, 2027.
Why it matters for you: if you've got Pro machines still sitting on 24H2 — and in a 20-200 seat shop, you probably do — this isn't just the preview updates drying up. Come October 13, 2026, those Home/Pro/Pro Education/Pro for Workstations editions get no further updates at all, including security updates. Enterprise and Education editions get a full extra year, until October 12, 2027.
What to do this week: start moving 24H2 Home/Pro devices to 25H2 this quarter — don't treat October 13 as a soft deadline, because there's no security patch cushion after it. If any of your fleet is running Enterprise or Education, you've got until October 12, 2027, but Pro boxes don't get that grace period.
Sources: Windows 11 release information | Message center MC1477005 | BleepingComputer on KB5124010
3. Microsoft 365 companion apps are retired — and that's your cleanup job
What changed: Calendar, People, and Files companion apps are retired. They'll be fully non-functional before December 16, 2026. Microsoft has already stopped installing them automatically, but if you've still got Required or Available assignments in Intune, Intune will happily keep reinstalling them on you.
Why it matters for you: this is one of those quiet jobs nobody assigns themselves until it breaks something. If these apps got pushed to your tenant via Microsoft 365 Apps updates and you're managing devices with Intune, you've got assignments to clean up.
What to do this week: turn off the auto-install setting in the Microsoft 365 Apps admin center, delete the Required/Available assignments in Intune, then uninstall across managed devices and check that it actually took.
Sources: Companion app retirement doc | r/Intune thread
quick hits
- Intune + Apple OS 27: day-zero settings catalog support for app launch rules, Apple Intelligence, Safari, Siri, DNS proxy, web content filter, and macOS login window, plus new Setup Assistant skip keys. Tech Community post
- Windows Autopatch is adding update governance — approvals, deferral, pausing, per-device reporting — rolling out September 1 through October 15. MC1478956
- Security Copilot is now bundled into Microsoft 365 E5/E7, no purchase or admin action needed, spanning Defender, Entra, Intune, and Purview. MC1478465
- Staged "wave" deployments for Intune are in public preview if you're tired of manual group-swapping. r/Intune walkthrough | Zero Trust Stories guide
- Defender for Endpoint (September): Linux desktop support in preview, memory scan for Linux in preview, WSL container plug-in support in preview, six AI-Readiness Secure Score recommendations now GA, macOS build 101.26072.0017 GA. What's new in Defender
- Entra passkeys became the default authentication method as of September 1. Microsoft-provided SMS/voice retires February 1, 2027 for most users, July 1, 2027 for Global Admins and external users. Entra ID security update | Entra.news digest
- Entra's User.ReadBasic.All no longer returns app role assignments or license details as of mid-September — switch to User.Read.All if anything depends on that. Entra.news digest
- GCC High tenants: Microsoft Cloud PKI is now available. Intune What's New
- Microsoft Dragon Copilot is now a protected app for Android/iOS MAM. Intune What's New
key dates
- September 22, 2026 — KB5124010 released, last preview update for Windows 11 24H2.
- October 13, 2026 — Windows 11 24H2 end of updates for Home/Pro/Pro Education/Pro for Workstations — no further updates of any kind after this date, including security updates.
- October 12, 2027 — Windows 11 24H2 end of updates for Enterprise/Education editions.
- September 1 – October 15, 2026 — Windows Autopatch approval controls rolling out.
- Before December 16, 2026 — Microsoft 365 companion apps fully non-functional.
- January 31, 2027 — new applications subject to Entra COOP enforcement.
- February 1, 2027 — Microsoft-provided SMS/voice MFA retires for most users, including internal guests.
- July 1, 2027 — SMS/voice MFA retires for Global Admins and external users.
- End of Q1 2027 — Intune Windows Health Attestation migrates to Azure Attestation.
- October 2026 (no specific day given) — B2B passkey registration/sign-in rollout begins.
from the trenches
The loudest complaint on r/Intune this week wasn't about a bug — it was about the pace. One admin on the companion app retirement thread put it bluntly:
"I hate this constant feeling of being in a beta environment."
Fair. Between the companion app cleanup, the ESP timing change, and the shift to native wave deployments instead of manual group-swapping, there's a lot of unscheduled homework landing in the same week.
Practical tip: if you're still doing manual group-swaps for staged rollouts, the wave deployment public preview is worth a look now rather than after it's the only option — better to learn the new pattern on your own schedule than during an outage.
My take: none of these changes is hard on its own. What hurts is that they all land in the same week with no heads-up, and in a small shop there's usually one person catching every one of them. So I'd treat the Microsoft 365 message center like a ticket queue: spend 15 minutes on it every Monday, turn anything with a date into a calendar entry, and let the rest go. The companion app cleanup is a good place to start. It's quick, the steps are documented, and it shows you whether your Intune assignments actually match what you think is deployed.
closing
That's the stack for this week — one cleanup job, one deadline to put on the calendar, and one thing you can safely ignore.
Questions, corrections, or a topic you want covered? Email me at kyle@whatisavirus.zip. If this was useful, send it to the one person on your team who reads the release notes.