# Preserve Company Portal consent when planning Win32 auto-updates

> Will a targeting change break an available app’s supersedence auto-update path?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:24:11+00:00
- Modified: 2026-09-10T02:08:04+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Will a targeting change break an available app’s supersedence auto-update path?

## Potentially affected

Use this review for an existing Company Portal installation with available intent. Record the superseded and superseding app identities, current assignments, and how the user originally obtained the app.

## DSE recommendation

Review planned group cleanup and assignment changes with the app owner before editing them.

## Article

## Source facts

Win32 supersedence auto-update applies to available apps installed through Company Portal, not apps obtained through required assignments. Removing the user from the targeted group, removing the assignment, or changing its available intent removes the recorded consent. Restoring available targeting later does not restore that auto-update path. A superseding app also needs explicit targeting; its relationship alone is insufficient. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence).

## Applicability

Use this review for an existing Company Portal installation with available intent. Record the superseded and superseding app identities, current assignments, and how the user originally obtained the app.

## DSE recommendation

Review planned group cleanup and assignment changes with the app owner before editing them. Treat the established user-consent path as part of the deployment design, not just the presence of application files. Document the expected update population and any devices that require a different approved installation route. Review detection rules and installer behavior separately from targeting.

## Verification

Use a test device that obtained the old app from Company Portal and compare it with an otherwise similar device outside that path. Confirm that the intended new app is targeted and that the observed update matches the planned relationship. If targeting has already changed, investigate the recorded installation route before repeatedly recreating the same relationship. Preserve the assignment history and actual installed result; do not promise that retargeting alone repairs the lost consent.

## Official references

[Microsoft Learn: Add Win32 app supersedence](https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence).

## Primary reference

- Name: Add Win32 app supersedence - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/app-management/deployment/configure-win32-supersedence
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Preserve Company Portal consent when planning Win32 auto-updates,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-465-preserve-company-portal-consent-when-planning-win32-auto-updates/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
