Configuration Manager 2603 entered the Early Update Ring on May 5, 2026 and became globally available on May 27, 2026. The release is not a feature drop. It is a security and modernisation pass that aligns Configuration Manager with the Microsoft Secure Future Initiative, removes a long-standing legacy dependency, and tightens defaults on the Cloud Management Gateway. It is also the last update before Configuration Manager transitions to an annual major-release cadence with version 2609 in September 2026.
The release is documented under KB 37426535 and the What's new in version 2603 article on Microsoft Learn. Support for 2603 runs from May 5, 2026 to November 4, 2027 — the standard 18-month window that Microsoft has reiterated as part of the cadence shift.
What Changed in the Release Model
The wider context for 2603 is the cadence announcement that Microsoft published in November 2025 on the Configuration Manager blog: from version 2609 onwards, Configuration Manager moves from three releases per year to one. The official rationale points to Intune as the destination for new device-management innovation, with Configuration Manager refocused on security, stability, and long-term support of on-premises estates. The 18-month support lifecycle per version is retained, and hotfix roll-ups are positioned as exception-only events.
That positioning is visible in 2603 itself. The release contains no marquee feature. The headline items are NAA access hardening, CMG cipher tightening, the removal of the SQL Server Native Client dependency, and a refresh of the SQL Server Management Objects to the SMO 17 baseline. This is the profile of a release written for an operations team, not a launch event.
Acquiring the Update
Since May 27, 2026 version 2603 is a standard in-console update available to every hierarchy that runs version 2409 or later. The Updates and Servicing node of the console surfaces it on the next synchronization cycle after the site server polls Microsoft. Sites on builds older than 2409 must first update to 2409 (or any intermediate version) before 2603 becomes installable.
The site server requires a working service connection point at the top tier of the hierarchy, .NET Framework 4.8 on every site system, an ODBC driver of version 18.4 or later for the SQL Server, and a Windows ADK version that is on the supported matrix for Configuration Manager. The full pre-update sequence is documented in the installation checklist.
After the site update completes, the post-update checklist on the same Microsoft Learn page walks through the client update — sites should also push the new client baseline to managed devices because some of the fixes (the ARM64 client push, the tenant-attach EDR regression, the WUfB-redirect on co-managed clients) only take effect once the client itself is on the matching version.
Historical note — the Early Update Ring window
Between May 5 and May 27, 2026 the release was only obtainable through the Early Update Ring opt-in. A Microsoft-signed PowerShell script published under aka.ms/KB37426535_EnableEarlyRing had to be executed once on the top-level site server:
# Run on the CAS or stand-alone primary site server, elevated
.\EnableEarlyUpdateRing2603.ps1 <SiteServer_Name>
# Example
.\EnableEarlyUpdateRing2603.ps1 cmprimary01
After the script ran, the 2603 update surfaced in the Updates and Servicing node within ten to fifteen minutes. The opt-in was temporary and tied to this release — it did not enrol the hierarchy permanently into any preview channel. Estates that opted in during that window are now on the same code as the general-availability install; no follow-up action is needed.
For new installs after May 27, the Early Update Ring script is no longer relevant — the regular in-console update flow is the canonical path.
Security and Hardening Changes
Three of the security changes in 2603 deserve attention for any production hierarchy.
Network Access Account access restrictions
Access to Network Access Account information is now restricted to supported OSD media task sequence scenarios. The change enforces additional permission requirements and removes legacy access paths. The detail is documented in KB 37447175, which was first applied in 2503 and is carried forward into 2603. The prerequisite checker for the NAA was updated in the same pass to acknowledge scenarios where NAA remains required — Request State Store steps and Apply OS Image with direct DP access — so existing OSD workflows continue to function without false-positive alerts.
For an estate that runs HTTPS-only client communication and modern OSD scenarios, the practical impact is small. For an estate that still depends on NAA across legacy paths, the change is the moment to inventory those paths and migrate them. The Microsoft guidance has been moving in this direction for several releases; 2603 enforces it more strictly.
Cloud Management Gateway: DHE ciphers off, padding check on
Weak Diffie-Hellman Ephemeral cipher suites are disabled on Cloud Management Gateway instances. The remaining surface is TLS 1.3 (AES_256_GCM and AES_128_GCM) plus the TLS 1.2 ECDHE family. In parallel, the EnableCertPaddingCheck registry keys are set by default on CMG Virtual Machine Scale Set instances, which mitigates CVE-2013-3900 — the WinVerifyTrust signature validation issue.
The CMG outbound-traffic alert and the Total Outbound data metric were also fixed for CMGv2 (the VMSS-based deployment), which previously did not emit network-out metrics correctly. Estates that monitor CMG egress will see populated graphs again after the upgrade.
SQL Server Native Client dependency removed
The deprecated SQL Server Native Client (sqlncli.msi) is removed from every Configuration Manager component and site role. The product no longer ships the file as a redistributable. Existing installations of sqlncli can be uninstalled safely from site systems after the upgrade.
The SQL Server Management Objects and the Microsoft System CLR Types are updated from the SQL Server 2014-era versions to the SMO 17 baseline. PKI certificate handling for site-system-to-SQL communication is now formally tested and documented, including private-key access and the BitLocker Management portal registry thumbprint configuration.
This is the kind of change that does not show up in a status report and does not change a console workflow, but it removes a class of brittle, unsupported dependencies from the estate. In practice, sites that had silent compatibility warnings about SQL Native Client in their event logs will see those warnings disappear after the upgrade.
Bug Fixes Worth Reading
The 2603 fix list is long. Several items are worth highlighting because they describe failure modes that DACH estates have actually encountered.
Windows 11 ARM64 client push
Client push installation through CcmSetup no longer fails with 0x80070643 on Windows 11 ARM64 devices when the upgrade source is ConfigMgr 2409 or 2503. The failure was caused by the upgrade attempting to uninstall a 32-bit Management Point Provider component that does not exist on ARM64. The same release also fixes Import-CMDriver so that ARM64 is no longer silently filtered out of the Supported Platforms list when drivers are imported from INF files.
For Surface Pro X and Copilot+-class fleets, both fixes matter. The combination meant that ARM64 devices either did not receive the client at all, or received it without ARM64-targeted drivers in the matching driver packages.
Orchestration Group reset and replication
Two replication-side fixes land in 2603. The Orchestration Group member reset function now also clears the HKLM\SOFTWARE\Microsoft\CCM\Orchestration\RequestSent registry key, preventing clients from being stuck waiting for an orchestration lock and unable to install updates. A separate race condition that previously allowed multiple servers to install updates and reboot simultaneously — instead of one at a time as the group was configured — is also resolved.
For estates that run patch orchestration through Orchestration Groups on production server collections, both fixes change behaviour in the expected direction.
Co-managed compliance: a date to mark
An internal service required for device compliance checks is being deprecated in October 2026. Following the deprecation, compliance checks in Software Center may fail in co-managed environments where the Compliance workload is managed by Intune. The remediation is to install 2603 (or later) before October 2026.
This is the deadline embedded in the 2603 release. For estates that run co-management with the Compliance workload at Intune, October 2026 is a real cut-off and 2603 is the dependency.
Co-managed devices: WUfB updates no longer hijacked to WSUS
When third-party updates are enabled on a Configuration Manager site, the Windows Update scan-source registry settings on co-managed clients were being modified incorrectly. The practical consequence was severe: Feature Updates and Quality Updates that were intended for Microsoft Intune / Windows Update for Business were silently redirected to WSUS / Configuration Manager. The Windows Update workload assignment in the Co-management Configuration was ignored.
Estates that ran the pattern "Windows Update workload at Intune, 3rd-party updates at ConfigMgr" — a common co-management compromise in DACH — saw their WUfB rings stop receiving the expected updates. The 2603 fix restores the scan-source assignment to the workload boundary it was supposed to honour.
For sites that have observed Feature Update rollouts missing on co-managed devices despite a clean Intune deployment configuration, this fix is the explanation and the remediation. After upgrading to 2603, the next scan cycle re-aligns the scan source on each affected client.
SQL Server Always On: site upgrades no longer fail on AG databases
Site upgrades on hierarchies whose Site Database participates in a SQL Server Always On Availability Group previously failed. The cause was the UpgradeDatabase function attempting to set the database to SINGLE_USER mode — an operation SQL Server rejects on a database that participates in an AG. The upgrade rolled back and the hierarchy stayed on the old version.
For estates running SQL HA on the Site Database, this was a hard blocker on every CB update. The 2603 fix detects the AG membership and routes the upgrade through the AG-aware path. Customers who deferred earlier CB updates because of this exact failure mode can now proceed.
The fix lands in the same release as the broader SQL modernisation pass (sqlncli removal, SMO 17, PKI-cert handling for site-to-SQL communication including private-key access and the BitLocker Management portal registry thumbprint configuration). For SQL-administrator teams, 2603 is the release that consolidates the SQL story.
Tenant attach: an EDR regression closed
Intune Endpoint Detection and Response policies now apply correctly on ConfigMgr clients through tenant attach in non-co-managed configurations. The release notes describe this as a regression fix for an issue introduced in 2503. Sites that observed missing EDR policy application after upgrading to 2503 have their fix in 2603.
Tenant attach: false 'Signature Update Overdue' on healthy Defender clients
The Windows Defender Antivirus reporting pipeline for tenant-attached ConfigMgr clients was incorrectly showing the Signature Update Overdue field as True on clients whose signature definitions were demonstrably current. The misreport surfaced in Intune-side antivirus dashboards and triggered remediation workflows against healthy endpoints.
Defender operations teams that run the Intune dashboard as the single source of truth for AV health saw the noise floor of false Overdue alerts climb after enabling tenant attach. The 2603 fix corrects the field calculation; the next reporting cycle clears the false positives.
For estates that built Sentinel or PowerBI dashboards on top of this field, the post-2603 reading is the trustworthy one — the pre-2603 baseline should be discarded rather than back-corrected.
Smaller items with real-world impact
Several other fixes in the KB summary deserve a single-line acknowledgement:
New-CMCloudManagementGatewayaccepts-IsUsingExistingGroup $truetogether with-ServerAppClientId, enabling fully automated CMG deployment into existing Azure resource groups without an interactive credential prompt.- Microsoft Connected Cache setup no longer fails with
ReturnCode 13631517on distribution points behind a proxy that requires absolute-form URLs. The connectivity test was using relative-form URLs in violation of the HTTP RFC. - The All Application deployments reports no longer multiply rows by the number of deployment collections when error or unknown states are queried.
- Build-and-Capture task sequences on Windows 11 24H2 media (November/December 2024 builds) no longer surface a Why did my PC restart dialog during deployment of the captured image.
- The
System.Linq.Dynamic.Corelibrary used by the AdminService is updated to 1.7.1, resolving CVE-2023-32571 — a remote code execution vulnerability through dynamic LINQ injection. - The stored procedure
spCanDisableLEDBATcan produce aSubquery returned more than 1 valueerror inWSUSCtrl.logwhen one DP server name is a substring of another (e.g.cmdp01.contoso.localmatchescmdp01-archive.contoso.local). The fix uses proper delimiters in theLIKEpattern so that the match is exact. - CMPivot queries dispatched through the AdminService no longer fail with
400 Bad Requestbecause of aKustoParserissue. Prior to the fix, the query path silently fell back to the SMS Provider — which required additional Script Read permissions and broke role-based CMPivot rollouts that had been scoped to AdminService only. - Applications carrying OS requirements such as All x64 Windows 11 and higher Clients no longer fail OSD with a
404when the client downloads the OS requirement policy definition after a CB upgrade. Apps that had been removed from task sequences as a workaround can be re-added after the upgrade. - Anti-malware policy validation now correctly enforces that wildcards cannot be used in the server name portion of UNC paths — consistent with Microsoft Defender for Endpoint documentation. Policies that relied on the unenforced behaviour need to be revisited.
- The misleading NAA requirement warning in the Distribution Points tab of the Task Sequence deployment wizard is rewritten to reflect when NAA is actually required. This is a separate change from the NAA prerequisite-checker update covered above — both ship in the same release.
Deprecations and Removed Surfaces
Three items leave the product surface in 2603.
The deprecated Asset Intelligence synchronization point site role is removed from the site-roles selection UI. The role had been non-functional for some time; the UI removal closes the door on accidental installation.
The Software Update Health Troubleshooting Dashboard is hidden in this release. The Microsoft KB describes the cause as severe performance issues in large environments: the underlying vSMS_SUAutoRemediation SQL view could accumulate tens of millions of rows, freezing the console and overloading the SQL server. The dashboard returns when the underlying performance behaviour is addressed.
The Upgrade Readiness / Desktop Analytics entries are removed from the Management Insights Cloud Services category. The service itself was retired earlier; the dashboard entries pointed nowhere and are now gone.
Recommendation
With 2603 now generally available, the upgrade decision narrows to when, not whether and how.
Co-managed estates with Intune Compliance. The October 2026 compliance-service deprecation is a hard date. Installing 2603 before that point is the documented mitigation. The release should be planned into a pilot collection in June, exercised through August, and promoted to broader rings in time for the autumn deadline.
Non-co-managed estates running production CMG, ARM64 endpoints, third-party update Orchestration Groups, or SQL Always On Site Databases. The cipher tightening on CMG, the ARM64 client-push and driver-import fixes, the Orchestration Group consistency fix, and the SQL Always On upgrade-path fix together justify a near-term pilot. The release is profiled as security-and-stability — exactly the profile that benefits from earlier deployment.
All other estates. The 2609 release in September 2026 is the first version of the new annual cadence. Estates with no specific 2603 pain-point can validate directly against 2609 at GA. The 18-month support window of 2603 carries to November 2027 — there is no operational pressure to install 2603 if no listed fix targets a known issue in the environment. The 2609 baseline becomes the strategic anchor for forward-looking estates.
Rule of thumb: Configuration Manager 2603 is the last semi-annual release. It is a security update first, a feature release zero, and a planning checkpoint last. With general availability since May 27, the decision is no longer when to opt into the Early Update Ring — it is whether 2603 carries enough relevant fixes to justify a CB-update cycle now, or whether the next move is straight to 2609 in September.
Sources: What's new in version 2603 — Microsoft Learn, KB 37426535 Summary of changes — Microsoft Learn, KB 37447175 NAA security update — Microsoft Learn, Checklist for installing update 2603 — Microsoft Learn, Announcing the Annual Release Cadence — Microsoft Configuration Manager blog. All version, support-date, KB-number, registry-path, and CVE references verified against the Microsoft Learn articles linked above as of 2026-06-09. The general-availability statement "As of May 27, 2026, version 2603 is globally available for all customers to install" is taken verbatim from the What's-new article. Publication history: initial 2026-05-23 — extended on 2026-06-09 with the co-managed WUfB-redirect, SQL Always On site-upgrade, and tenant-attach Defender false-positive sections plus six additional Smaller-items entries; re-stamped the same day to reflect the General-Availability transition that removed the Early Update Ring opt-in as the canonical install path.