
The macOS Registration Prompt Everyone Ignores. Microsoft Finally Killed It.
If you’ve rolled out Platform SSO on macOS, you know exactly how this goes. The Mac enrolls through ADE, the user lands on the desktop, and then the real onboarding starts. They wait for the registration banner, miss it or swipe it away, and a day later there’s a ticket that reads “I’m signed in but Outlook won’t connect.” The device sits half-registered, Conditional Access isn’t satisfied, and nobody’s quite sure why.
That gap is the thing this update closes. And it’s part of a quieter stretch of Microsoft releases that, taken together, do more for day-to-day management than the splashier announcements usually manage. Three things worth your attention right now: a cleaner macOS enrollment, better app visibility on Windows, and a faster Copilot model. None of them will trend. All three I’d turn on.
Platform SSO now runs inside macOS Setup Assistant
Here’s what changed. Platform SSO registration can now happen during Automated Device Enrollment, inside Setup Assistant, before the user ever reaches the desktop. The device registers with Entra ID, the SSO credential gets provisioned, and the user arrives at the desktop already authenticated with Conditional Access satisfied. No banner to chase. No second act.
Where you actually set this up: it’s three policies that have to work together, and the catch is that all three need to land on the same static user groups. Get the targeting wrong and enrollment just fails.
First, the Platform SSO settings catalog policy. In the Intune admin center, go to Devices → Manage devices → Configuration → Create → New policy, pick macOS and Settings catalog, then under Authentication → Extensible single sign-on → Platform SSO set “Enable Registration During Setup” to Enabled. Second, deploy Company Portal 5.2604.0 or newer as a line-of-business app, since that’s what carries the Microsoft Enterprise SSO extension. Third, your ADE enrollment profile needs Setup Assistant with modern authentication, with “Await final configuration” set to Yes.
A few things worth flagging before you roll it out. This is macOS 26 and newer only, so older fleets stay on the post-desktop flow for now. It’s static user groups, not dynamic groups and not device groups, which trips people up precisely because so much else in Intune leans on dynamic membership. And users still sign in at least twice during Setup Assistant, once to kick off enrollment and once to authenticate Company Portal and pull the SSO extension. Microsoft says a single sign-in version is coming. Until then, put a line in your rollout comms so people don’t assume the second prompt means something broke. If you’re on Smart Card auth, registration still can’t finish during Setup Assistant, so that scenario stays on the desktop path.
Windows app inventory worth actually looking at
The enhanced app inventory for Windows 10 and 11 went generally available with the May update, and it’s a real step up from Discovered apps. You get multiple syncs a day instead of the old weekly refresh, delta uploads so you’re not hauling the full list every time, and far richer metadata per app: install paths, install dates, sizes, architecture, uninstall commands, and per-user versus per-machine scope. It also captures apps across every profile that’s signed into a device, which finally makes inventory on shared machines trustworthy.
Unlike Discovered apps, this one doesn’t just switch itself on. You enable it with a Properties catalog policy. In the Intune admin center, go to Devices → Manage devices → Configuration → Create → New policy, choose Windows 10 and later, profile type Properties catalog, then add ApplicationProperties and pick what you want to collect. Assign it to device groups rather than user groups. Inventory is about the endpoint, not whoever happens to be logged in, and device targeting is what makes the multi-user collection actually work. The data shows up on the All apps page for each device, or under Tools and reports if you’ve turned on the new device view.
One limitation to plan around: the enhanced data is portal-only right now. It isn’t exposed through Graph yet, so if you’ve got automation or external reporting pulling from Discovered apps today, you can’t repoint it at this. Microsoft has signalled Graph support later in 2026. And Discovered apps is on its way out, the deprecation banner is already up, though both features run in parallel for now, so there’s no rush to rip anything out.
GPT-5.5 Instant lands in Microsoft 365 Copilot
GPT-5.5 Instant is now rolling out in Microsoft 365 Copilot. In Copilot Chat it shows up as “GPT-5.5 Quick response” in the model selector under GPT. Licensed Microsoft 365 Copilot users get priority access, everyone else gets standard access. If you build agents, it’s in Copilot Studio early release environments as GPT-5.5 Chat, and in Microsoft Foundry for developers.
It builds on GPT-5.3 Instant, and the practical difference is in tone and speed rather than benchmark bragging rights. Responses are more direct, with less verbosity and fewer unnecessary follow-up questions, so you reach a usable answer with less back and forth. Image handling is better, which matters more than it sounds when half your prompts involve a screenshot of an error or a chart someone pasted in. STEM and technical content improved too.
There’s a slower-burning point sitting underneath these model drops. Each one widens the gap between licensed and unlicensed Copilot. Priority access to the newer, faster model isn’t a footnote on a feature list anymore, it’s a difference your licensed users feel during the day. If you’re building the internal case for broader Copilot adoption, that’s a more concrete argument than another capabilities slide.
The bigger picture
None of this is the kind of update that gets a keynote. But a macOS enrollment that just works, app inventory you can actually trust, and a Copilot model that wastes less of your time are exactly the changes that compound. The flashy features get the attention. The boring ones are what make Monday quieter.
If I were picking where to start, it’d be the macOS one for any team running a Mac fleet, since it removes a whole category of ticket. The app inventory policy is ten minutes of setup for visibility you’ll keep reaching for. Copilot’s update needs nothing from you, it just shows up.
If you’ve already switched on Platform SSO during ADE, I’m curious how the double sign-in is landing with your users in practice, since that’s the one rough edge left in an otherwise clean flow. Drop a note