A new month always brings a new Microsoft Intune service release. The Microsoft Intune May (2605) service release was just released last week (8th of June), and introduces a range of enhancements for Android Enterprise device management, making it easier than ever for IT administrators to fine-tune policies, streamline enrollment workflows, and enhance device security. From expanded settings in the Android Enterprise settings catalog to new app management controls, this update empowers organizations to manage Android devices with greater precision and flexibility.
In this post, we’ll explore the most impactful Android-specific changes in the Microsoft Intune May 2026 (2605) service release and how they can benefit your Microsoft Intune environment.
Before you explore the new additions in Microsoft Intune for your Android Devices, verify that your tenant is on the new 2605 service release.
Go to Tenant Administration | Tenant Status and in the Tenant details tab, check if Service release is on 2605.

Device Enrollment
The Personal Work Profile implementation of the Android Management API is now generally available for enrollment. A key improvement is that users no longer need to manually install the Company Portal app before starting enrollment. Organizations can opt into a streamlined, web‑based enrollment flow that begins in the browser, with all policies delivered through the Android Management API. This brings personally owned work profile devices onto the same underlying management platform as corporate‑owned Android Enterprise deployments, giving admins a more consistent and unified policy experience across Android.
Device Configuration
Managed Home Screen
Custom top bar elements on Managed Home Screen
You can now display a custom text (free-string up to 63 characters) in the top bar of the Managed Home Screen, which can also be combined with the existing variables like serialnumber, device name, and tenant name.
Managed Home Screen exit lock task mode password now requires a device configuration profile
You can no longer set the Managed Home Screen lock task mode exit password through an app configuration policy. To define or change this password, you now need to create or modify a device configuration profile that includes the lock task mode password policy.
Go to the Microsoft Intune admin center | Devices | Android | Configuration and create a new Policy. Choose Templates as Profile type (Exit Kiosk mode settings aren’t available yet in Settings Catalog), then choose Device Restrictions.

INFORMATION: Note that these settings only become visible when you set Kiosk mode to Multi-app.
Silence apps on the Managed Home Screen to prevent session PIN bypass
You can now mute apps on devices using Managed Home Screen whenever MHS requires user authentication, such as during sign‑in or when entering a session PIN. While muted, apps can’t launch activities, show notifications, appear in recent apps, or trigger toasts, dialogs, or ringing. You can define an allowlist of apps that stay active during this locked state, ensuring essential functions like phone calls remain uninterrupted. This behavior is optional and fully configurable, allowing organizations to tailor it to their operational needs. Once the device is unlocked, all apps automatically resume normal behavior.
Go to the Microsoft Intune admin center | Devices | Android | Apps | Configuration and create a new Managed devices Policy. Choose Use configuration designer for adding this setting.

New Block Bluetooth sharing setting in the Android Enterprise settings catalog
Block Bluetooth sharing is now a new setting in Settings Catalog. When you enable this setting, Bluetooth Sharing isn’t available anymore for the managed device. This setting applies to all Corporate-Owned managed devices.
Go to the Microsoft Intune admin center | Devices | Android | Configuration and create a new Policy. Choose Settings Catalog as Profile type, then search for choose Device Restrictions.

Device Security
Strict Tunnel Mode for Microsoft Tunnel on Android
Microsoft Tunnel now supports Strict Tunnel Mode on Android Enterprise devices. When enabled, all device network traffic is routed exclusively through the VPN tunnel. If the VPN becomes unavailable, the device blocks all network traffic until the connection is restored, preventing apps from reaching the public internet outside the tunnel.
Strict Tunnel Mode is available when a Microsoft Tunnel VPN profile is configured with Always-on VPN. Administrators can also define an app exclusion list, allowing selected apps to bypass the tunnel and connect directly, even if the VPN is down.
This capability requires devices enrolled through the Android Management API (AM API). For unenrolled devices using Microsoft Tunnel with Mobile Application Management (MAM), Strict Tunnel Mode can be enabled through the Microsoft Edge app configuration policy.
Grant enhanced security permissions to a Mobile Threat Defense app on Android
A new Mobile Threat Defense (MTD) role category is now available on the MTD connector configuration page in the Microsoft Intune admin center. The Grant MTD role permissions to \<MTD partner name\> on enrolled Android COBO and COPE devices toggle lets you assign enhanced security permissions to a single MTD partner app—such as Microsoft Defender for Endpoint or a supported third‑party solution—on Android Enterprise corporate‑owned fully managed (COBO) and corporate‑owned work profile (COPE) devices.
When enabled, the selected MTD app receives the following exemptions on targeted devices:
- Suspension — The app can’t be suspended.
- Hibernation — The app is prevented from entering hibernation.
- Power restrictions — The app is exempt from power‑related limits, including app standby, and can start foreground services from the background.
- User controls — Users can’t clear the app’s data or force‑stop it.
These exemptions ensure the MTD app can deliver uninterrupted threat protection without being affected by system optimizations or user actions. Only one MTD partner can hold these elevated permissions per tenant.
For Microsoft Defender for Endpoint, an additional toggle is available: Automatically launch Microsoft Defender for Endpoint during setup on Android COBO and COPE devices. When turned on, the app launches automatically during device setup so it can complete its initial configuration without requiring user interaction.
Application Management
Protected Apps
With Service Release 2605, some new protected apps are now available in Microsoft Intune. The following apps were added:
- Caju AI by Caju AI
- Harvey AI by Harvey AI (Android)
- Notta for Intune by Notta
- SwiftConnect Mobile by SwiftConnect
Line-of-Business Apps
Direct management of Android line‑of‑business (LOB) apps in Microsoft Intune is now generally available for Android Enterprise fully managed and dedicated devices. Previously, even internal apps had to be uploaded and distributed through Managed Google Play. With this update, admins can upload APK files directly to Intune, deploy multiple versions of the same app to different user or device groups, and remove limitations such as requiring unique package names. This gives organizations greater flexibility and control over how internal Android apps are managed and delivered.
Go to the Microsoft Intune admin center | Devices | Android | Apps and create a new App. Choose Line-of-business app as Category, you’ll notice you now have two options.

So, that was an overview of all the new features in the Microsoft Intune 2605 service release for Android. Want to stay up to date? Be sure to follow me on all social media channels and stay tuned!

