Version 1.39.0 Preview 11 September 19, 2026 (Preview)
Release Date: September 19, 2026
Summary
Section titled “Summary”This preview is about App Store telling you the truth about what happened in Intune, and never removing something it cannot prove it should. The person who deploys App Store can now administer it from the first sign-in, with the Admin Group as an optional second authority. Rolling back an app pauses automatic updates for it, App Updates shows the pause, and an administrator ends it with Resume Auto-Deploy. Publishing, requests and updater deletion now report what Intune actually did, packaging uses exactly the version and installer you chose, and an app deleted directly in Intune is flagged rather than forgotten. The portal also recovers cleanly from a restart in the middle of publishing, checks its own package against the published checksum on first start, and keeps keys out of its logs.
Product Enhancements
Section titled “Product Enhancements”- The person who deploys can administer straight away. The account that runs the deployment becomes the portal’s initial administrator on the first start, with no restart and nothing else to configure. The Admin Group is optional; when you supply one, its members administer alongside the initial administrator, and configuring a group never removes that administrator. See Deploy to Azure.
- A rollback pauses automatic updates for that app, and App Updates shows it. The version you rolled back from is declined, and automatic deployment is paused for the app. The app’s row in App Updates says Auto-deploy paused (rollback), its detail view shows Paused by rollback with the reason, and Resume Auto-Deploy ends the pause, recorded in the audit log with who did it. Nothing else ends it: not a restart, not an update check, and not a manual deployment. See A rollback pauses automatic updates.
- You can still deploy by hand while an app is paused. Update checks carry on, and Deploy Update deploys a newer version as usual. The version you rolled back from shows as Declined; Deploy anyway deploys it on purpose after a confirmation. Neither ends the pause.
- Packaging uses the version and installer you chose. Picking a specific version packages exactly that version, and the downloaded installer must match the catalog’s published hash. When a package offers both a machine-wide and a per-user installer, the machine-wide one is used; a package that only installs per user is refused with a clear message. See App Catalog.
- Apps deleted in Intune are flagged, not forgotten. If an app’s install app disappears from Intune, App Store keeps its record, groups and history and flags the app for attention in Store Health.
- Group Automation never removes members from incomplete data. If a run cannot look every device up, it removes nobody and reports Incomplete. See Group Automations.
- Restarts no longer interrupt publishing or updates. If the App Service restarts in the middle of publishing or an update, the work finishes when the portal starts again, without a second copy of the app in Intune.
- App Store checks the package it runs. On its first start the portal confirms its package against the published checksum for its release channel and locks itself to that exact version, so a restart cannot change what is running. A deployment made on the Preview channel now does this too, and follows the preview channel for its own updates.
- Publishing no longer waits for Microsoft Entra. Publishing records what App Store can prove immediately and completes its ownership marker on the deployment group in the background, so a publish is no longer slowed or failed by directory replication.
Bug Fixes
Section titled “Bug Fixes”- Resolved a publish reporting success when Intune refused the assignment. The publish now fails and the app stays hidden until it can be delivered.
- Resolved requests for an app that could not be delivered showing as installed, including auto-approved, bulk and retried requests.
- Resolved changing an app’s deployment group leaving the old Intune assignment in place, including for a hidden app.
- Resolved updater deletion reporting success when Intune refused it. An updater already deleted in Intune can now be closed out.
- Resolved uninstall failing for apps whose Windows name differs from their catalog name.
- Fixed the nightly Intune sync deleting App Store’s record of an app that was removed directly in Intune.
- Fixed signed storage addresses and package encryption keys being written to the application logs.
- Fixed a deployment made on the Preview channel not locking itself to its version on first start.
Important Notes
Section titled “Important Notes”- Preview only. Deploy it for evaluation with Release Channel set to Preview (Early Access). Keep production deployments on Latest.
- Automated deployments need an Admin Group. A service principal or managed identity cannot sign in, so it does not become the initial administrator.