GuideInformationBusiness ContinuityIT

Scope app-protection patch requirements to the intended major OS branch

How can one user's devices receive different minimum patch requirements for different major OS versions?

A controlled technology lifecycle progressing from assessment to approved production.
DSE visual intelligenceManaged IT operationsGuide · 1 min read
Executive summary

What you need to know

How can one user's devices receive different minimum patch requirements for different major OS versions?

Potentially affected

Use this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation's example version numbers.

DSE recommendation

Separate branch selection from the minimum-patch requirement.

Source facts

An Intune app-protection policy has one minimum OS value in its conditional-launch settings. Because these policies target user groups, a user with devices on different OS versions can encounter conflicting requirements. Microsoft describes separate app-protection policies scoped by OS-version filters for the different branches. App-protection policies support Managed apps filters, not Managed devices filters. Microsoft Learn.

Applicability

Use this design when intentionally supporting more than one approved major OS branch for protected applications. Confirm current platform support and the desired minimum patch level for each branch instead of copying the documentation’s example version numbers.

DSE recommendation

Separate branch selection from the minimum-patch requirement. Review each managed-app filter and its associated policy together, including how a device moving to a new major version will be handled. Keep an explicit decision for devices outside the intended branches so a missing match is not mistaken for protection.

Verification

Test one user with representative devices on the relevant major versions. Verify which policy applies, whether the intended patch threshold is enforced, and what happens after a major-version change. Compare the actual protected-app experience with the filter preview and assignment record. Resolve overlapping or uncovered populations before expanding the policies.

Official references

Microsoft Learn: Manage device operating system versions with Intune.

Primary reference

Review the official source

Manage device operating system versions with Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE