# Scope app-protection patch requirements to the intended major OS branch

> How can one user's devices receive different minimum patch requirements for different major OS versions?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:58+00:00
- Modified: 2026-09-10T02:04:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

How can one user's devices receive different minimum patch requirements for different major OS versions?

## Potentially affected

Use this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation's example version numbers.

## DSE recommendation

Separate branch selection from the minimum-patch requirement.

## Article

## Source facts

An Intune app-protection policy has one minimum OS value in its conditional-launch settings. Because these policies target user groups, a user with devices on different OS versions can encounter conflicting requirements. Microsoft describes separate app-protection policies scoped by OS-version filters for the different branches. App-protection policies support Managed apps filters, not Managed devices filters. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions).

## Applicability

Use this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation’s example version numbers.

## DSE recommendation

Separate branch selection from the minimum-patch requirement. Review each managed-app filter and its associated policy together, including how a device moving to a new major version will be handled. Keep an explicit decision for devices outside the intended branches so a missing match is not mistaken for protection.

## Verification

Test one user with representative devices on the relevant major versions. Verify which policy applies, whether the intended patch threshold is enforced, and what happens after a major-version change. Compare the actual protected-app experience with the filter preview and assignment record. Resolve overlapping or uncovered populations before expanding the policies.

## Official references

[Microsoft Learn: Manage device operating system versions with Intune](https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions).

## Primary reference

- Name: Manage device operating system versions with Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-updates/manage-os-versions
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Scope app-protection patch requirements to the intended major OS branch,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-418-scope-app-protection-patch-requirements-to-the-intended-major-os-branch/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
