Deploying Microsoft 365 Apps through Intune is straightforward. The channel decision is not. It determines how often your users get new features, how long security updates are supported, and how much testing overhead your team carries. Get it right once and it runs itself.
The channel decision
Microsoft 365 Apps ships on three main update channels: Current Channel, Monthly Enterprise Channel, and Semi-Annual Enterprise Channel. Each has a different cadence for feature updates, a different support window, and different operational implications.
Current Channel delivers new features as soon as they’re ready – typically several times a month. Security updates also arrive as needed rather than on a fixed schedule. It’s the fastest path to new capabilities and the shortest gap between Microsoft releasing a fix and your users receiving it. The tradeoff is that updates aren’t predictable by date, which makes scheduling user communications harder.
Monthly Enterprise Channel delivers feature and security updates on the second Tuesday of each month – the same day as Windows quality updates. One update per month, predictable date, two months of rollback support as of 2025 (extended to three months from July 2025). This is the right default for most managed environments. It’s what Windows Autopatch uses. Updates are tested before release because features in this channel have already shipped to Current Channel users first.
Semi-Annual Enterprise Channel delivers feature updates in January and July. As of July 2025, Microsoft reduced the support window from 14 months to 8 months and officially repositioned this channel for unattended devices and specialized workloads that require extensive testing before new features arrive. The Semi-Annual Enterprise Channel Preview was retired entirely in July 2025. If you’re on Semi-Annual for standard knowledge workers, Microsoft’s direction is clear: move to Monthly Enterprise Channel.
Monthly Enterprise Channel is the right default. Predictable schedule, tested releases, one update per month. Semi-Annual is for unattended devices, not for managed knowledge worker fleets.
Deploying through Intune
In Intune, Microsoft 365 Apps deploy as a built-in app type – Microsoft 365 Apps for Windows 10 and later – rather than a Win32 package. Go to Apps → Add → Microsoft 365 Apps for Windows 10 and later. The configuration wizard lets you select which apps to include, the update channel, the architecture, and whether to accept the license terms on behalf of users.
For most environments, select 64-bit architecture. 32-bit is a legacy requirement that applies only if you have specific add-ins or integrations that can’t run in 64-bit – check before defaulting to 32-bit, and if you don’t have a confirmed reason, use 64-bit.
The apps to include are worth thinking through before clicking through the defaults. The default selection installs the full Office suite. If you have users who don’t need specific apps – Access, Publisher, or Skype for Business – exclude them. Fewer installed apps means a smaller attack surface, faster installs, and less disk usage. You can always create additional app packages that include specific apps for the users who need them.
One important note on channel configuration: if you deploy M365 Apps using the Configuration designer in the Intune UI and assign the app as Required, the channel selected in the app configuration will be re-evaluated and enforced every policy refresh. If you also have a Settings Catalog policy setting a different channel, you’ll get channel flipping – the device oscillates between channels. Match your app configuration channel and your update channel policy, or configure channel exclusively through a Settings Catalog policy and leave it unspecified in the app configuration.
Controlling the channel after deployment
Channel is controlled through a Settings Catalog policy targeting the Update Channel (2.0) setting under Microsoft Office 2016 (Machine) → Updates. This is the supported way to manage channel in Intune – not through the app configuration, and not through Group Policy if you want Intune to own it. A GPO that writes to the Windows Update registry path for Office will take precedence over MDM, so check for existing GPOs before deploying a channel policy.
Also enable “Automatically update Office” in the same policy – hiding this from users prevents them from turning off updates. And confirm the “Office Automatic Updates 2.0” scheduled task is enabled on your devices – it’s the mechanism that actually applies channel changes and triggers update checks. Without it, channel policies deliver but don’t take effect.
If you’re moving devices between channels – particularly from a faster channel to a slower one – be aware that downgrading isn’t always straightforward. Moving from Current Channel to Monthly Enterprise Channel is supported. Moving to an older build requires uninstalling and reinstalling. Plan channel changes before deployment rather than after.
Visio and Project
Visio and Project deploy as separate app packages in Intune – they don’t install as part of the main M365 Apps package. When you deploy them, configure their update channel to match the channel you’ve set for the core M365 Apps installation. Mismatched channels between Office and Visio or Project causes update conflicts and can produce unexpected behavior. The channel configuration in the Visio or Project package needs to match your Settings Catalog channel policy.
Monitoring update compliance
Intune doesn’t have a built-in report that shows M365 Apps update compliance by build version. The Microsoft 365 Apps Admin Center at config.office.com does – the Inventory section shows every build version, its channel, and whether it’s current or out of support across your fleet. If you’re managing M365 Apps at any scale, this is worth bookmarking and checking monthly alongside your Windows update compliance reports.
Intune Deployment Guide · Phase 7: Applications
‹ Previous: [7.1.1] Deploying Win32 Applications
Next: [7.1.3] Winget in Intune: The Poor Man’s App Delivery ›




