{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/",
        "slug": "dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/"
        },
        "title": "Preserve Company Portal consent when planning Win32 auto-updates",
        "summary": "Will a targeting change break an available app’s supersedence auto-update path?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:11+00:00",
        "modified_at": "2026-09-10T02:08:04+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 233,
        "potentially_affected": "Use this review for an existing Company Portal installation with available intent. Record the superseded and superseding app identities, current assignments, and how the user originally obtained the app.",
        "dse_recommendation": "Review planned group cleanup and assignment changes with the app owner before editing them.",
        "primary_source": {
            "name": "Add Win32 app supersedence - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Win32 supersedence auto-update applies to available apps installed through Company Portal, not apps obtained through required assignments. Removing the user from the targeted group, removing the assignment, or changing its available intent removes the recorded consent. Restoring available targeting later does not restore that auto-update path. A superseding app also needs explicit targeting; its relationship alone is insufficient. <a href=\"https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review for an existing Company Portal installation with available intent. Record the superseded and superseding app identities, current assignments, and how the user originally obtained the app.</p>\n<h2>DSE recommendation</h2>\n<p>Review planned group cleanup and assignment changes with the app owner before editing them. Treat the established user-consent path as part of the deployment design, not just the presence of application files. Document the expected update population and any devices that require a different approved installation route. Review detection rules and installer behavior separately from targeting.</p>\n<h2>Verification</h2>\n<p>Use a test device that obtained the old app from Company Portal and compare it with an otherwise similar device outside that path. Confirm that the intended new app is targeted and that the observed update matches the planned relationship. If targeting has already changed, investigate the recorded installation route before repeatedly recreating the same relationship. Preserve the assignment history and actual installed result; do not promise that retargeting alone repairs the lost consent.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Add Win32 app supersedence</a>.</p>",
        "content_text": "Source facts\nWin32 supersedence auto-update applies to available apps installed through Company Portal, not apps obtained through required assignments. Removing the user from the targeted group, removing the assignment, or changing its available intent removes the recorded consent. Restoring available targeting later does not restore that auto-update path. A superseding app also needs explicit targeting; its relationship alone is insufficient. Microsoft Learn.\nApplicability\nUse this review for an existing Company Portal installation with available intent. Record the superseded and superseding app identities, current assignments, and how the user originally obtained the app.\nDSE recommendation\nReview planned group cleanup and assignment changes with the app owner before editing them. Treat the established user-consent path as part of the deployment design, not just the presence of application files. Document the expected update population and any devices that require a different approved installation route. Review detection rules and installer behavior separately from targeting.\nVerification\nUse a test device that obtained the old app from Company Portal and compare it with an otherwise similar device outside that path. Confirm that the intended new app is targeted and that the observed update matches the planned relationship. If targeting has already changed, investigate the recorded installation route before repeatedly recreating the same relationship. Preserve the assignment history and actual installed result; do not promise that retargeting alone repairs the lost consent.\nOfficial references\nMicrosoft Learn: Add Win32 app supersedence.",
        "content_markdown": "## Source facts\n\nWin32 supersedence auto-update applies to available apps installed through Company Portal, not apps obtained through required assignments. Removing the user from the targeted group, removing the assignment, or changing its available intent removes the recorded consent. Restoring available targeting later does not restore that auto-update path. A superseding app also needs explicit targeting; its relationship alone is insufficient. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence).\n\n## Applicability\n\nUse this review for an existing Company Portal installation with available intent. Record the superseded and superseding app identities, current assignments, and how the user originally obtained the app.\n\n## DSE recommendation\n\nReview planned group cleanup and assignment changes with the app owner before editing them. Treat the established user-consent path as part of the deployment design, not just the presence of application files. Document the expected update population and any devices that require a different approved installation route. Review detection rules and installer behavior separately from targeting.\n\n## Verification\n\nUse a test device that obtained the old app from Company Portal and compare it with an otherwise similar device outside that path. Confirm that the intended new app is targeted and that the observed update matches the planned relationship. If targeting has already changed, investigate the recorded installation route before repeatedly recreating the same relationship. Preserve the assignment history and actual installed result; do not promise that retargeting alone repairs the lost consent.\n\n## Official references\n\n[Microsoft Learn: Add Win32 app supersedence](https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve Company Portal consent when planning Win32 auto-updates",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/",
                "headline": "Preserve Company Portal consent when planning Win32 auto-updates",
                "description": "Will a targeting change break an available app’s supersedence auto-update path?",
                "abstract": "Will a targeting change break an available app’s supersedence auto-update path?",
                "articleBody": "Source facts\nWin32 supersedence auto-update applies to available apps installed through Company Portal, not apps obtained through required assignments. Removing the user from the targeted group, removing the assignment, or changing its available intent removes the recorded consent. Restoring available targeting later does not restore that auto-update path. A superseding app also needs explicit targeting; its relationship alone is insufficient. Microsoft Learn.\nApplicability\nUse this review for an existing Company Portal installation with available intent. Record the superseded and superseding app identities, current assignments, and how the user originally obtained the app.\nDSE recommendation\nReview planned group cleanup and assignment changes with the app owner before editing them. Treat the established user-consent path as part of the deployment design, not just the presence of application files. Document the expected update population and any devices that require a different approved installation route. Review detection rules and installer behavior separately from targeting.\nVerification\nUse a test device that obtained the old app from Company Portal and compare it with an otherwise similar device outside that path. Confirm that the intended new app is targeted and that the observed update matches the planned relationship. If targeting has already changed, investigate the recorded installation route before repeatedly recreating the same relationship. Preserve the assignment history and actual installed result; do not promise that retargeting alone repairs the lost consent.\nOfficial references\nMicrosoft Learn: Add Win32 app supersedence.",
                "datePublished": "2026-09-10T00:24:11+00:00",
                "dateModified": "2026-09-10T02:08:04+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve Company Portal consent when planning Win32 auto-updates"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 233,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Add Win32 app supersedence - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence"
                }
            }
        ]
    }
}