🇫🇷 Paris · April 2026  ·  Field Report

Modern Management Summit 2026
Paris — The Complete Debrief

I was on the ground at MEMSummit 2026 in Paris — one of Europe's most technical Modern Workplace conferences. 48 sessions, world-class speakers, and a community obsessed with pushing Intune, AI, and endpoint security to their limits. Here's everything you need to know if you weren't there.

Souhaiel Morhag
Souhaiel Morhag
MD-102 Certified · Modern Workplace Expert · MEMSummit 2026 Attendee
📅 April 28, 2026  ·  ⏱ 18 min read
48
Sessions
8
Deep Dives
5
Key Themes
10
Takeaways
1
City: Paris
🚨
Action required before June 24: The UEFI Secure Boot CAT certificate expires June 24, 2026 and the third-party signing certificate expires June 27. Microsoft has already updated 50% of 300M eligible devices automatically. Run the detection script now to classify your remaining fleet. → Jump to Session 01

🎯 5 Key Themes of MEMSummit 2026

🔐
12 sessions
Security & Zero Trust
Secure Boot rotation, Conditional Access evolution, PAW design, and cybersecurity table-top exercises dominated the security track.
🤖
8 sessions
AI in Modern Workplace
Intune AI agents, Copilot for KQL, building your own AI assistant, and the "Coding Zero to Vibing Hero" session on agentic development.
📦
9 sessions
Packaging & Deployment
Application packaging deep dives, Win11 Autopilot gotchas, DevOps-driven packaging pipelines, and cloud-native deployment strategies.
📊
7 sessions
Monitoring & Reporting
KQL mastery for endpoint admins, Intune reporting improvements, Windows Update monitoring in cloud-only environments, and Log Detective.
🍎
6 sessions
Multi-Platform Management
macOS with Intune (both sessions), Apple Device Management, unified management strategies, and the Edge Management Service.

📋 8 Sessions — In-Depth Coverage

Click any session to expand the full analysis. Each includes the key action item for your environment.

01
Secure Boot Chain Update — What, How & Why It Matters
Microsoft Core Security Team
Security UEFI Secure Boot Certificates Windows
🔴 Critical
The Microsoft Core Security team presented the most urgent change for Windows endpoint admins in 2026: the UEFI Secure Boot certificate rotation. Two critical deadlines — CAT certificate expires June 24, third-party signing certificate expires June 27. The CA 2011 certificate is being replaced by two separate CA 2023 certificates (UFCA 2023) to enable targeted revocation. Microsoft has already auto-updated 50% of the 300 million eligible devices. Devices are classified into confidence buckets (bi-weekly data science ratings) and those in the "high confidence" category receive automatic updates. The session demoed a detection script that outputs a JSON file with 13 data points, an Intune remediation script for mass deployment, and 7 automation scripts for phased rollout. OEM coordination is required for legacy hardware. PQC (Post-Quantum Cryptography) transition and 12 new certificate spectrums are coming by 2027.
⚡ Key Takeaway Run the boot manager update script now, classify your fleet into confidence buckets before June 24, and identify devices with "U PCA from 23 error" in your Intune monitoring dashboard.
02
Anomaly Detection, Device Intelligence & Copilot KQL
Microsoft Intune Product Team
Intune AI/ML KQL Copilot Endpoint Analytics
🟡 High priority
Intune's anomaly detection engine (traditional ML models) was fully demoed — covering BSODs, app crashes, severity scoring (high/medium/low), and dynamic device cohort grouping with configurable shelf life. The new multi-device query capability allows cross-tenant hardware inventory queries. Copilot translates natural language to KQL directly in the console, accessing hardware inventory cached in fast/slow streams (P90 within 1 hour). The "Tenup Score" concept was introduced as a composite health KPI. Explorer capability will expand to EPM, advanced analytics, and multi-workload support. Known gap: queries cannot be shared across geographies.
⚡ Key Takeaway Enable multi-device query in your tenant today, build a KQL baseline for hardware inventory, and use Copilot-generated queries to identify devices running outdated OS builds across your fleet.
03
Next-Level Windows & Intune Troubleshooting with AI
Microsoft MVP (15 years) · Finland
Troubleshooting Windows AI Tools Automation App Control
🔵 Informational
A 15-year Microsoft MVP delivered one of the most practical sessions of the summit. Workflow: collect logs via custom Intune remediation scripts (not the built-in Intune log collection — too slow), then feed into AI tools (Copilot, Security Copilot, ChatGPT, and Claude) for automated root cause analysis. Key demo: a 70MB, 10-minute SCCM log file was analyzed in seconds — identified two missing applications and a race condition. For Win11 upgrades: use "setupdiag" — found insufficient disk space (now requires a 25 GB compliance policy) and incompatible drivers. App Control for Business flagged as high-demand but complex. GitHub Copilot "planning mode" used live to build an analysis tool in minutes.
⚡ Key Takeaway Build a custom Intune remediation script that auto-collects logs on policy failure, feed to AI. Enforce a 25 GB free disk space compliance policy before any Win11 upgrade campaign.
04
Zero Trust, AI Agents & M365 Security — Microsoft Keynote
Leo Vera (Business Director) + Microsoft Engineering
Zero Trust Conditional Access AI Agents M365 EPM
🟡 High priority
Hard data opened: enterprise security challenges growing 8× annually, average daily AI usage 60 min/user, 70% YoY growth in AI job postings. Zero Trust reframed as a lifecycle (never-ending cycle) rather than a project. AI agents contrasted with human agents — runs 24/7, task-specific, different identity model. Key announcements: Security Copilot now included in M365 E3/E5. Latency improvements: PNI notifications now under 5 minutes. Multi-admin approval for PowerShell scripts demoed live. AI vulnerability remediation agent (Defender + Intune) automates fix recommendations with human review gate. New EPM dashboard showing elevation activities.
⚡ Key Takeaway Start designing Conditional Access policies for AI agent identities — they behave differently from user identities. Enable multi-admin approval for scripts in production.
05
Inside Intune: Architecture, Notifications & Latency
Microsoft Intune Engineering
Intune Architecture Performance IC3 Compliance
🔵 Informational
Deepest technical session — Intune's internal check-in model with real numbers. Three check-in types: client-initiated (company portal), device-initiated (login/schedule), change-based (payload/group). WLS replaced by IC3 with 4 priority categories. Key metrics: 20% reduction in notifications, 97% of change operations first attempt, 75% of MDM remediation checks wasted (now eliminated). Compliance state P90 reduced from 252 minutes to 3.7 minutes. iOS: off-peak data requests to Apple. Reporting: 97% of reports migrated to new pipeline, discovered apps from 7 days → 1–3 hours.
⚡ Key Takeaway Move to change-based group targeting — client-initiated and schedule-based generate wasted traffic. Monitor your compliance P90 against the 3.7-minute benchmark.
06
Windows Autopatch, Hotpatching & Driver Management
Microsoft Autopatch Product Team
Autopatch Hotpatch Windows Update Drivers Graph API
🟡 High priority
Hotpatch (no reboot required, available May 12, 2026): quarterly quality update followed by 2 months of lightweight security-only patches. Identical security fixes to regular B-week updates. Driver management: Graph API for reporting, OEM drivers require up to 45 days validation, two driver types. Dynamic deployment rings: up to 16 rings, percentage-based, with pinning. For Office: Cloud Updates strongly recommended over policy deferral — CDN gradual rollout makes deferral unreliable. Upcoming: individual content pausing, maintenance windows for CSPs, .NET update controls.
⚡ Key Takeaway Enable hotpatching on Windows 11 22H2+ by May 12, migrate Office to Cloud Updates, design your dynamic ring structure (up to 16 rings) with a pinned "emergency break" group.
07
Graph API Authentication — Managed Identities & Least Privilege
Community Expert · Graph API Specialist
Graph API Authentication Managed Identities PowerShell Automation
🟡 High priority
Four auth methods compared: device code (PS7, no popup), service accounts, client secrets, and managed identities (preferred). Device code: different UX between PS5 and PS7. Client secrets: 403 behavior — authentication vs authorization distinction. Managed identities: no stored credentials, no expiration, environment variables for cross-team use. Graph API pagination for large data retrieval. Beta vs V1 API risks: beta provides richer data but no support. Chrome DevTools URL capture for identifying Graph endpoints.
⚡ Key Takeaway Audit all automation scripts — any using client secrets should be migrated to managed identities. Document every permission granted.
08
PowerShell & Graph API — Advanced Admin Scripting
Endpoint Management Nerd · Youth Coach
PowerShell Graph API Automation Governance Baselines
🔵 Informational
Advanced PowerShell + Graph patterns for eliminating portal gaps. Topics: automating app uploads and OS updates, Chrome DevTools URL capture, consolidated reporting from multiple Microsoft portals. Script quality principles: hash tables over long parameters, variable splatting, minimal modules, pagination/throttling handling. New: the "IntoWind" module for advanced Intune operations. Configuration pipeline: JSON backups with timestamps, baseline comparison (23H2 vs 25H2 — acceptable error threshold ≤2). Governance gaps: ungoverned group creation, unassigned policies, scripts without descriptions.
⚡ Key Takeaway Build a baseline inventory script for your current OS version, implement a configuration pipeline with JSON backups, and run a policy assignment audit to identify orphaned policies.

💡 My Top 10 Takeaways

1
AI is no longer optional — Intune AI agents and Copilot are production-grade and delivering real ROI today.
2
Secure Boot certificate rotation in June 2026 is the most critical upcoming change for Windows admins. Prepare now.
3
Managed Identities should replace every client secret in your Intune automation pipelines — no excuses.
4
Conditional Access is evolving into an agentic policy layer — start designing for AI workloads today.
5
97% first-attempt success on Intune policy changes — the platform is more reliable than most give it credit for.
6
KQL is now a core skill for endpoint admins, not just SOC teams. If you're not writing KQL, start this week.
7
Autopatch + Hotpatching for Windows 11 is the future — less reboots, less disruption, same security posture.
8
Multi-platform is real: macOS in enterprise is growing and Intune's Apple story is much stronger than 2 years ago.
9
The packaging world is splitting: fully DevOps-driven vs fully third-party managed. Pick your path and optimize.
10
The community IS the learning — hallway conversations at MEMSummit were as valuable as the sessions themselves.
🎓

Everything from MEMSummit is on the MD-102 Exam

Intune, Autopilot, Secure Boot, KQL, Zero Trust, Conditional Access — the same topics covered at MEMSummit 2026 are what the MD-102 certification tests you on. Prepare with 1,500+ realistic practice questions.