Python Editing in Excel: What IT Admins Need to Know
Excel now supports editing and running Python code in-app. Here’s how to enable it, best practices for rollout, and common issues to watch for.
What's new across Microsoft endpoint management — short, sourced summaries, updated as Microsoft ships. For deeper, hands-on guides, see Articles.
52 updates
Excel now supports editing and running Python code in-app. Here’s how to enable it, best practices for rollout, and common issues to watch for.
Intune now supports Declarative Device Management for required Apple VPP apps on iOS/iPadOS 17.2+ and macOS 26+. Here’s what admins need to know.
How Automatic App Installation lets IT admins push apps and scripts to devices before a user logs in, cutting first-day downtime and setup errors.
A practical look at Device Association in Windows 11 - what it does, why it matters, how to enable it, and best practices for IT admins.
Intune adds Notion, Superhuman Mail, and Calven to its protected apps list, letting admins apply app protection policies to more third-party apps.
Windows 365 Reserve now supports bulk provisioning and deprovisioning of up to 1,000 Cloud PCs per request, cutting admin effort during large-scale events.
Intune’s Apple settings catalog gains new payloads, including App Settings and Web Content, with support for Apple OS 27 betas. Here’s what admins …
Microsoft Entra Kerberos key rotation now handles incoming trust referral flows more reliably, improving hybrid authentication stability for admins.
How device association lets IT admins bind Windows 11 hardware to their organisation before Intune enrollment, and why it strengthens security.
What Screen Capture Protection does, how it blocks screenshots and recordings in remote sessions, and what admins should check before enabling it.
New Windows App settings in the Windows settings catalog let admins control auto-updates, sign-out behaviour and desktop shortcuts.
Microsoft Entra improves Kerberos key rotation reliability for incoming trust referral flows, reducing authentication disruptions in hybrid environments.
A practical look at Screen Capture Protection, the Windows feature that blocks screen capture of remote session content, and how admins turn it on.
Intune now integrates with Samsung Knox E-FOTA so admins can manage firmware updates for corporate-owned Samsung devices from the Intune admin center.
Microsoft added Windows App (Azure Virtual Desktop) settings to the Intune settings catalog, covering updates, First Run Experience and shortcuts.
Automatic mode for Windows 365 is now generally available, streamlining Cloud PC device preparation and provisioning for IT admins.
What Modern Auto-Reconnect does, how it restores sessions after brief network interruptions, and why IT admins should care about it.
Microsoft is extending screen capture protection to web-based remote connections. Here’s what the feature blocks and how admins should approach it.
Microsoft’s ServiceNow Knowledge and Catalog connectors now honour role-based permissions, giving admins tighter control over connector access.
Microsoft Copilot connectors now run content and identity crawls in parallel, so ingested data reaches users faster. What IT admins should know.
Windows 365 Cloud Apps can now be provisioned with Autopilot device preparation, in public preview for Windows 365 Reserve customers.
Configure Windows App options such as automatic updates and user logoff intervals using the Windows settings catalog in Microsoft Intune.
Microsoft Copilot can now surface rich images from files and meetings in its responses. Here’s what the change means for IT admins and end users.
Microsoft has redesigned the OneNote Notebook Overview with a clearer layout and quicker access to common notebook actions. Here’s what changes for users.
Windows Autopilot device preparation now honours managed installer policy for app installs, improving reliability for organisations using app control.
Windows 11, version 25H2 is now supported for OS deployment and in-place upgrades, giving admins a supported path to the latest Windows 11 release.
Microsoft has pushed the automatic install of monthly security updates during Windows Autopilot device preparation to 9 September 2025. What admins should do.
How to attach Autopilot device preparation policies to Cloud PC provisioning so apps, scripts and settings land before users sign in.
Microsoft is tightening PowerShell execution policy during Cloud PC provisioning, requiring downloaded scripts to be digitally signed. Here’s what it …
Microsoft Entra now validates Kerberos tickets against both primary and secondary keys, reducing authentication failures during key rotation.
A new boot image option lets Configuration Manager use a Windows Boot Loader signed with Windows UEFI CA 2023. Here’s what it does and how to enable it.
Configuration Manager 2509 makes Windows PE boundary-aware, changing how OSD task sequences evaluate boundaries and select content sources.
Windows BYOD via Microsoft Entra registration lets users reach corporate resources from personal PCs without domain join. What IT admins should review.
Microsoft has refreshed the Edge administrative templates in the Windows settings catalog, giving admins new policies for permissions, search and features.
From 2509, WinPE-based OSD needs a management point in the boot device’s boundary group — or the task sequence fails early with a ’no valid MP …
Device Preparation can install the monthly security update during OOBE so devices hand over already patched — at the cost of 20-40 minutes and a restart you …
The Enrolment Status Page times out for boring, fixable reasons — a blocking app that never lands, a device-vs-user phase mismatch, or a Win32 dependency chain …
A quick round-up of recent M365 Copilot changes worth an admin’s attention — responses now surface images inline, Copilot can list email attachments, and …
The Service Connection Tool in 2509 gets real logging, prerequisite checks that fail loudly, and a Connect step that stops before importing a half-downloaded …
Intune can now schedule and enforce Samsung firmware updates through Knox E-FOTA — closing the one gap that always sat outside your patch story on corporate …
Win32, Store and Enterprise App Catalog apps used to be skipped during device prep to dodge conflicts. Managed installer support means they now install in OOBE …
Compliance policy vs compliance policy settings, why ’not evaluated’ isn’t the same as ‘compliant’, and the Conditional Access …
Kerberos key rotation could break authentication when referral tickets were signed with a secondary key. Entra now validates against both keys during rollover — …
External SAML federation no longer needs the user’s email domain to match a preconfigured IdP domain — which quietly kills a whole category of ‘why …
A single checkbox in 2509 automates the Secure Boot / KB5025885 boot-loader mitigation for your boot images — but only on WDS-less PXE distribution points, …
AI agents that hold their own user accounts are now first-class Conditional Access targets — you can scope policy to them, apply agent risk, and require …
Windows 365 now sets the machine-scope execution policy to RemoteSigned during provisioning. Good for security — but if you enforce AllSigned via Intune or GPO, …
Users can now reach internal apps from their own Windows machines via Entra registration and the Private Application traffic profile — no domain join, no full …
You can now deprovision multiple Cloud PCs in the grace period at once, instead of waiting out seven days or clicking through them one at a time — a small admin …
Device Preparation’s automatic mode provisions Cloud PCs and shared devices with no user driving, and the app cap has quietly gone up to 25 — enough that …
Windows 365 Cloud PCs provisioned through Citrix can now use Autopilot Device Preparation, so the Citrix path finally gets the same ‘apps and scripts land …
Microsoft Authenticator now refuses to add or use work accounts on jailbroken or rooted devices — secure by default, no admin toggle, and no Intune enrolment …