{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/",
        "slug": "dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/"
        },
        "title": "Scope app-protection patch requirements to the intended major OS branch",
        "summary": "How can one user's devices receive different minimum patch requirements for different major OS versions?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:58+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 208,
        "potentially_affected": "Use this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation's example version numbers.",
        "dse_recommendation": "Separate branch selection from the minimum-patch requirement.",
        "primary_source": {
            "name": "Manage device operating system versions with Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>An Intune app-protection policy has one minimum OS value in its conditional-launch settings. Because these policies target user groups, a user with devices on different OS versions can encounter conflicting requirements. Microsoft describes separate app-protection policies scoped by OS-version filters for the different branches. App-protection policies support Managed apps filters, not Managed devices filters. <a href=\"https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation&#8217;s example version numbers.</p>\n<h2>DSE recommendation</h2>\n<p>Separate branch selection from the minimum-patch requirement. Review each managed-app filter and its associated policy together, including how a device moving to a new major version will be handled. Keep an explicit decision for devices outside the intended branches so a missing match is not mistaken for protection.</p>\n<h2>Verification</h2>\n<p>Test one user with representative devices on the relevant major versions. Verify which policy applies, whether the intended patch threshold is enforced, and what happens after a major-version change. Compare the actual protected-app experience with the filter preview and assignment record. Resolve overlapping or uncovered populations before expanding the policies.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Manage device operating system versions with Intune</a>.</p>",
        "content_text": "Source facts\nAn Intune app-protection policy has one minimum OS value in its conditional-launch settings. Because these policies target user groups, a user with devices on different OS versions can encounter conflicting requirements. Microsoft describes separate app-protection policies scoped by OS-version filters for the different branches. App-protection policies support Managed apps filters, not Managed devices filters. Microsoft Learn.\nApplicability\nUse this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation’s example version numbers.\nDSE recommendation\nSeparate branch selection from the minimum-patch requirement. Review each managed-app filter and its associated policy together, including how a device moving to a new major version will be handled. Keep an explicit decision for devices outside the intended branches so a missing match is not mistaken for protection.\nVerification\nTest one user with representative devices on the relevant major versions. Verify which policy applies, whether the intended patch threshold is enforced, and what happens after a major-version change. Compare the actual protected-app experience with the filter preview and assignment record. Resolve overlapping or uncovered populations before expanding the policies.\nOfficial references\nMicrosoft Learn: Manage device operating system versions with Intune.",
        "content_markdown": "## Source facts\n\nAn Intune app-protection policy has one minimum OS value in its conditional-launch settings. Because these policies target user groups, a user with devices on different OS versions can encounter conflicting requirements. Microsoft describes separate app-protection policies scoped by OS-version filters for the different branches. App-protection policies support Managed apps filters, not Managed devices filters. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions).\n\n## Applicability\n\nUse this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation’s example version numbers.\n\n## DSE recommendation\n\nSeparate branch selection from the minimum-patch requirement. Review each managed-app filter and its associated policy together, including how a device moving to a new major version will be handled. Keep an explicit decision for devices outside the intended branches so a missing match is not mistaken for protection.\n\n## Verification\n\nTest one user with representative devices on the relevant major versions. Verify which policy applies, whether the intended patch threshold is enforced, and what happens after a major-version change. Compare the actual protected-app experience with the filter preview and assignment record. Resolve overlapping or uncovered populations before expanding the policies.\n\n## Official references\n\n[Microsoft Learn: Manage device operating system versions with Intune](https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Scope app-protection patch requirements to the intended major OS branch",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/",
                "headline": "Scope app-protection patch requirements to the intended major OS branch",
                "description": "How can one user's devices receive different minimum patch requirements for different major OS versions?",
                "abstract": "How can one user's devices receive different minimum patch requirements for different major OS versions?",
                "articleBody": "Source facts\nAn Intune app-protection policy has one minimum OS value in its conditional-launch settings. Because these policies target user groups, a user with devices on different OS versions can encounter conflicting requirements. Microsoft describes separate app-protection policies scoped by OS-version filters for the different branches. App-protection policies support Managed apps filters, not Managed devices filters. Microsoft Learn.\nApplicability\nUse this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation’s example version numbers.\nDSE recommendation\nSeparate branch selection from the minimum-patch requirement. Review each managed-app filter and its associated policy together, including how a device moving to a new major version will be handled. Keep an explicit decision for devices outside the intended branches so a missing match is not mistaken for protection.\nVerification\nTest one user with representative devices on the relevant major versions. Verify which policy applies, whether the intended patch threshold is enforced, and what happens after a major-version change. Compare the actual protected-app experience with the filter preview and assignment record. Resolve overlapping or uncovered populations before expanding the policies.\nOfficial references\nMicrosoft Learn: Manage device operating system versions with Intune.",
                "datePublished": "2026-09-10T00:24:58+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Scope app-protection patch requirements to the intended major OS branch"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 208,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Manage device operating system versions with Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions"
                }
            }
        ]
    }
}