top of page

The EUC Weekly Roundup: July 29 to August 5, 2026

  • Foto van schrijver: Edwin de Bruin
    Edwin de Bruin
  • 5 aug
  • 9 minuten om te lezen

This was a proper summer-holiday week. A lot of the usual crowd, the former CTPs, the VMware vExperts, the Omnissa Tech Insiders and the Microsoft MVPs, were clearly off recharging (fair enough), so the big EUC blogs were quiet and the real signal came from the Intune and endpoint community, who apparently did not get the memo about taking a break. No new NetScaler drama this week either, which after the last month or so feels like a small mercy. Here is what actually moved.



Security advisories & active deadlines


Microsoft is retiring SMS and Voice MFA in Entra ID (still the one to act on)


I flagged this deadline last week, and normally I would not repeat a topic so soon, but a new piece dropped this week that is worth surfacing on its own, and the subject is significant enough to earn a second mention. Microsoft is moving to retire SMS and voice call as MFA methods in Entra ID, and this week Thomas Marcussen published a genuinely useful migration playbook covering who is affected, what your options are, and how to buy yourself a bit more time if you are not ready. If you still have users bound to text-message codes (and be honest, you probably do), read Thomas's write-up before it becomes a support-desk fire. Phishing-resistant methods were always the destination anyway, this just sets the clock. And there is a second new piece this week that changes how you should think about the migration, which is next.


The passkey setting that controls the SMS/Voice migration


Perfect companion to the item above, and one I nearly missed. Roy Klooster dug into Microsoft Entra Passkey Dynamic Migration, the setting that governs Microsoft's automatic passkey rollout for SMS and voice users, and which is not exposed in the Entra portal. He lays out what it actually changes, what it does not, and how to control it, which is exactly the detail you want before Microsoft starts nudging your SMS-bound users toward passkeys on its own schedule rather than yours. If you are planning the MFA retirement migration, read this alongside Marcussen's playbook.


Multi-Admin Approval now enforced on Graph API calls


Jannik Reinhard flagged one that is easy to miss until it breaks your automation: Intune Multi-Admin Approval is now enforced on Graph API calls, not just clicks in the portal. If you have scripted policy changes running through Graph, they now hit the same approval gate as everything else. That is the right security posture, but if your pipelines assume they can just push, go test them before your next run quietly fails in a way nobody notices for a fortnight.


FSLogix and the Kerberos AES change is still lurking


Still worth repeating for anyone who tuned out the first time: the April 2026 Windows Server update flipped the default Kerberos encryption type from RC4 to AES-SHA1. File shares hosting FSLogix containers that have not moved to AES-SHA1 can start throwing access errors once that lands. If your profile shares are old enough to remember RC4, go validate them on a calm afternoon rather than during a Monday logon storm.


Citrix / NetScaler


Entra CA baseline changes are about to affect Citrix authentication


This is the Citrix item to read this week. Julian Jakob published a piece on August 4 about an upcoming change to how Microsoft enforces Conditional Access for applications that request only OIDC scopes or a limited set of directory scopes, part of Microsoft strengthening Entra ID's default behaviour. The catch is that this shift can change how your Citrix authentication flows behave, so if you front Citrix with Entra as the IdP, this is worth understanding before the default flips under you. It is exactly the kind of quiet platform change that does not announce itself until a login journey suddenly behaves differently.


NetScaler Zero Touch Certificate Management, explained (catch-up)


One from just outside the window (July 28) that is worth surfacing because Julian found real confusion in the field. NetScaler Console's Zero Touch Certificate Management (ZTCM) has been around a while, but there are persistent misunderstandings about what ZTCM actually does versus manual certificate handling. If you are running NetScaler Console or the Console Service and have been avoiding ZTCM because you were not quite sure what it automates, this clears it up. Not a CVE, just a genuinely useful operational explainer.


Omnissa (Horizon, Workspace ONE, App Volumes, DEM, UAG, Access)


Do not add a Server 2025 Connection Server to an old Horizon pod (catch-up)


A July catch-up from Hans Kraaijeveld at Plonius that is worth surfacing because it is exactly the kind of thing that quietly wrecks a migration. If you are moving your Omnissa Horizon Connection Servers to Windows Server 2025, you cannot just build a 2025 box and add it as a replica to an existing pod where the current Connection Servers are still on Server 2022 or older. There is an ordering dependency you need to respect first. If a Connection Server refresh is anywhere on your roadmap, read this before you build the first new VM, not after. (I am flagging this as a July post rather than strictly in-window because the source listing does not show a precise day, and I would rather be honest about that than pretend precision.)


Microsoft (Intune, Windows 365, AVD, FSLogix, Windows, Entra ID)


Windows 11 KB5101684 preview lands with 42 fixes


The fresh build this week: Microsoft released optional preview KB5101684 (build 26200.8973) on July 30, as the run-up to the August 11 Patch Tuesday. It carries 42 fixes and a pile of things that matter for managed endpoints: Windows Hello Enhanced Sign-in Security now supports external plug-in fingerprint readers, you can uninstall the image-generation AI component from Copilot+ PCs, and File Explorer finally reports file sizes in KB, MB and GB instead of pretending the whole disk is measured in kilobytes. No known issues listed, but it is still a preview, so ring it before it touches the fleet.


Registry Inventory is coming to the Properties Catalog


This is the one I am quietly excited about. Madison Cooks announced that Registry Inventory is coming to the Intune Properties Catalog, so you can check registry keys across your devices without shipping a proactive remediation just to read a value. Anyone who has ever written a detection script purely to answer "is this key set" will understand exactly why this is a nice quality-of-life win.


A faster Export API for bulk Intune reporting


Two angles on the same win this week. Microsoft's Intune Customer Success team introduced a new Export API for bulk jobs that takes compliance reporting from hours to minutes, and Roy Klooster followed up almost immediately (August 4) with the practitioner's version: a PowerShell walk-through of pulling reporting data out of Intune at scale via the Graph Export API. Read the Microsoft post for the what, and Roy's for the how. If you have ever babysat a giant tenant's compliance export, both are worth your time.


Following up on Windows 365 Reserve


Niall Brady published a July 30 follow-up on Windows 365 Reserve, continuing his testing after the initial 10-day window closed. Reserve is one of those SKUs that reads well on a slide but you really want field notes on before you build a continuity story around it, so this is the kind of hands-on write-up worth bookmarking.


Security Copilot Change Review agent, if you are on E5


If you are running E5 and sitting on free Security Compute Units, Michael Frank took a look at the Security Copilot Change Review agent. Whether the agent hype lands for you or not, "have something review my config changes before they cause an incident" is a reasonable use of spare SCUs.


Two handy endpoint fixes from the community


Two small but practical ones. Rahul Jindal demystified the new web-based enrollment for Android Work Profile devices, which is the kind of thing you want explained clearly before you flip it on. And Nicky De Westelinck shipped a remediation script to remove that new OneDrive Photos app Microsoft has been quietly dropping onto devices (the one that only works with a personal OneDrive account, thanks for that). Both are the sort of fixes that save a real support ticket.


Hardware & endpoints (10ZiG, IGEL, thin clients)


IGEL UMS 12.13.100 shipped


Fresh this week: IGEL released Universal Management Suite build 12.13.100 on July 31. It is a maintenance-and-feature release for the management layer rather than a headline OS drop, but if you run IGEL at any scale the UMS is where your day actually happens, so read the release notes before you schedule the upgrade.


Performance testing, tooling, DEX


Login Enterprise 6.8.6 ships, and Citrix testers should read the fine print


Fresh this week: Login VSI released Login Enterprise 6.8.6 on July 29. The headline additions are multi-test PDF reports for Continuous Tests and a per-application success and failure breakdown on a new multi-test results page, which is genuinely useful if you run continuous synthetic monitoring. But the bit I would not skip is the bug fixes: this build fixes the "launcher did not respond to a session request in a timely fashion" error when testing against a Citrix published desktop with Seamless Mode enabled, which affected both StoreFront and NetScaler connectors, plus a Windows 365 connector failure when a transient pop-up appears mid-script. If you gave up on a Citrix Seamless test target recently because it kept timing out, this is your fix. Also worth flagging for your own automation: upgrading to v6.7 from anything older than 6.3 invalidates all existing API tokens, so you will need to recreate them by hand.


ControlUp's August release sharpens remote control and RBAC


Fresh this week: ControlUp's August 2026 release has a properly practical set of changes for hands-on support. The File Browser now has separate RBAC permissions for user files versus system files, so you can stop handing out all-or-nothing access. There is a new Smart Consent Bypass that will start a remote session on an idle, non-responsive device after a configurable timeout (off by default, and it explicitly does not bypass consent while the user is actively working), customizable consent request messages with variables like the requesting admin's name, and a live services view on the device details Management tab where you can right-click to act on a service. Small things individually, but together they make second-line support less miserable.


A Sentinel workbook for Global Secure Access


If you are running Global Secure Access, Dustin Gullett published a Sentinel workbook for dropping, reviewing and monitoring your GSA logs so you can actually confirm everything is behaving. GSA generates plenty of telemetry, and this is a tidy way to turn that into something you can watch rather than something you occasionally grep in a panic.


Community & fun


Joey Verlinden had the busiest week in the community


While a lot of the blogroll was on a sun lounger, Joey Verlinden shipped three posts in a week. There is a clear walk-through on using Device Control to block removable storage while still allowing exceptions (the eternal USB headache), an update to his Conditional Access Framework (2026.6.1) for standing a secure tenant up quickly, and the fun one: a new Conditional Access Visualizer and Deployer tool that maps your existing CA policies visually and can push a secure baseline rapidly. If you have ever tried to explain a tangle of CA policies to an auditor with a whiteboard and a prayer, a visualizer is genuinely the tooling win of the week.


Credit where it is due


Most of this week's community finds came via Andrew Taylor's July 31 Intune newsletter, which remains the most reliable single place to catch what the endpoint community is publishing. If you only subscribe to one newsletter in this space, that is the one. The heavier EUC blogs from the former CTP, vExpert and Omnissa Tech Insider crowd (Poppelgaard, stealthpuppy and friends) were quiet this week, which at the end of July is exactly what you would expect. They will be back.

As always, if I missed something in your corner of the EUC world, or you reckon I called something wrong, drop a comment below. That is honestly how these get sharper.


This roundup is put together by "virtual me", an AI workflow powered by Claude that scans the EUC world every week so I do not have to live inside forty browser tabs. The robot gathers and drafts, but I read every line before it ships, and any question I raise while reviewing gets chased down and folded back into the article. Voice is mine, sign-off is mine, the AI just carries the buckets.


References

Microsoft retiring SMS and Voice MFA in Entra ID migration playbook (Thomas Marcussen): https://blog.thomasmarcussen.com/entra-sms-voice-mfa-retirement-playbook/

Microsoft Entra Passkey Dynamic Migration setting (Roy Klooster, RK Solutions): https://rksolutions.nl/posts/microsoft-entra-passkey-dynamic-migration/

Intune Multi-Admin Approval now enforced on Graph API calls (Jannik Reinhard): https://jannikreinhard.com/intune-multi-admin-approval-graph-api/

FSLogix Kerberos AES change and Windows Server update (Microsoft Learn): https://learn.microsoft.com/en-us/fslogix/how-to-configure-profile-container-azure-files-active-directory

Microsoft Entra CA baseline changes affecting Citrix authentication (Julian Jakob): https://www.julianjakob.com/microsoft-entra-ca-baseline-changes-affecting-citrix-authentication/

NetScaler Zero Touch Certificate Management explained (Julian Jakob): https://www.julianjakob.com/netscaler-zero-touch-certificate-management-ztcm/

Adding Windows Server 2025 Connection Servers to an existing Omnissa Horizon environment (Hans Kraaijeveld, Plonius): https://www.plonius.com/post/adding-windows-server-2025-connection-servers-to-an-existing-omnissa-horizon-environment

Windows 11 KB5101684 August 2026 preview (Pureinfotech): https://pureinfotech.com/kb5101684-windows-11-august-2026-update/

Registry Inventory in the Intune Properties Catalog (Microsoft Tech Community, Madison Cooks): https://techcommunity.microsoft.com/blog/IntuneCustomerSuccess/registry-inventory-in-microsoft-intune-verifying-whats-on-your-devices/4541312

Following up on Windows 365 Reserve (Niall Brady): https://www.niallbrady.com/2026/07/30/following-up-on-windows-365-reserve/

Security Copilot Change Review agent (Michael Frank): https://michaelsendpoint.com/intune/SecurityCopilot/ChangeReviewAgent.html

Android web-based enrollment for Work Profile devices (Rahul Jindal): https://rahuljindalmyit.blogspot.com/2026/07/demystifying-android-web-based.html

Remove OneDrive Photos app remediation script (Nicky De Westelinck): https://github.com/nickydewestelinck/MicrosoftIntune/tree/main/Scripts/Remove-OneDrivePhotos

Login Enterprise 6.8.6 release notes, July 29 2026 (Login VSI support): https://support.loginvsi.com/hc/en-us/articles/360001562939-Release-Notes

ControlUp current month release notes August 2026 (ControlUp support): https://support.controlup.com/docs/release-notes-current

Global Secure Access Sentinel workbook (Dustin Gullett): https://zerototrust.tech/global-secure-access-sentinel-workbook/

Conditional Access Framework 2026.6.1 (Joey Verlinden): https://www.joeyverlinden.com/conditional-access-framework-6/

Conditional Access Visualizer and Deployer tool (Joey Verlinden): https://www.joeyverlinden.com/conditional-access-visualizer-deployer-tool/

Intune Newsletter 31st July 2026 (Andrew Taylor): https://andrewstaylor.com/2026/07/31/intune-newsletter-31st-july-2026/

Opmerkingen


Post: Blog2_Post
bottom of page