Skip to Content

MC1459120 Update app protection policies with legacy targeting setting to assignment filters

Summary

  • Microsoft Intune is retiring support for the legacy App Protection Policy (APP) setting “Target to apps on all device types” for policies that currently use legacy device management state targeting.
  • Affected APP policies should be moved to Managed apps assignment filters so targeting behavior matches admin expectations.
  • Microsoft’s telemetry indicates your tenant has policies using the legacy targeting configuration, so existing targeting may stop working as expected if no changes are made.
  • Admins should review each APP policy, create the appropriate assignment filter, assign it while keeping legacy targeting in place, and only then remove the legacy targeting configuration.
  • If the change is not handled correctly, policy targeting and enforcement gaps can occur, especially for managed device scenarios and third-party or partner MDM-managed devices.

Primary Service: Intune
Admin Impact: High
User Impact: Low
Release Start: 11 Jan 2027
Release End: 11 Jan 2027
Services: Intune
Category: Plan for change
Tags: Admin Action, User Adoption

History

8/21/2026 Item Added to Message Center

Microsoft Message

Starting January 11, 2027, or soon after, we are ending support for the legacy Intune app protection policy (APP) “Target to apps on all device types” setting and policies should be updated to use assignment filters. Using the legacy targeting settings can take precedence over assignment filters, resulting in policy targeting behavior that may not align with admin expectations.

Important: To prevent gaps in policy enforcement, do not remove or disable the legacy targeting configuration until the new assignment filter has been assigned to the policy.

How does this affect my organization

Our telemetry indicates that you currently have the legacy setting “Target to apps on all device types” configured for specific device management states. Once support for the legacy APP targeting setting has ended, the setting will no longer apply. Policies that have not been updated to use assignment filters exclusively may experience gaps in targeting or enforcement.

Note: If the device is MDM-managed by a third-party or partner service, the managed app assignment filters will not match to the more granular management types.

What you need to do to prepare

Before this change, to avoid any interruption in policy targeting, perform the following steps in order to move to assignment filters:

1. Review existing APP policies. Policies with “Target to apps on all device types” set to “No” are using the legacy targeting configuration and should be updated to assignment filters:

  1. Navigate to the Intune admin center > Apps > Protection to edit existing APP policies.
  2. Select an existing policy to review if it has a legacy setting.
  3. In the Intune App Protection pane, select Properties.
  4. In the section titled Apps, if “Target to apps on all device types” is set to “No” move on to step 2. If “Target to apps on all device types” is set to “Yes” no action is needed for this policy, go back to Apps > Protection to review other policies.

2. Create a “Managed apps” assignment filter using app.deviceManagementType that reflects the targeting behavior you want to maintain. For example, (app.deviceManagementType -eq “Automated Device Enrollment user-associated devices”). Note, we recommend creating and using a filter to include (app.deviceManagementType -ne “Unmanaged”) to ensure that the filter applies to managed devices only.

If your legacy policy was configured to target iOS/iPadOS “Managed” devices, your new assignment filter should include:

  • Managed
  • Automated Device Enrollment user-associated devices
  • Automated Device Enrollment userless devices
  • Account Driven User Enrollment
  • Device Enrollment with Company Portal and Web Enrollment

If your legacy policy was configured to target Android “Android Enterprise” devices, your new assignment filter should include all relevant Android device types listed below:

  • Corporate-owned dedicated devices with Entra ID Shared mode
  • Corporate-owned dedicated devices without Entra ID Shared mode
  • Corporate-owned with work profile
  • Corporate-owned fully managed
  • Personally-owned work profile

3. Assign the filter to the existing policy while the legacy targeting configuration remains enabled. Updating existing policies helps avoid unintended changes to group targeting and policy assignments:

  1. In the Intune App Protection policy pane, select Properties.
  2. In the section titled Assignments, select “Edit”.
  3. In the section titled Included group, select “Edit Filter” > “Include filtered devices in assignment” and select the Managed apps filter you created.
  4. Review and save your changes.

4. Remove the legacy targeting configuration. After confirming the assignment filter is configured correctly, update the legacy setting in the policy to target All device types. Assignment filters will become the primary targeting mechanism, and the legacy setting will no longer be visible or editable in the admin center.

5. Repeat steps 1 to 4 for each Intune APP policy in your tenant.

6. Monitor policy deployment to validate policy application and compliance after the change.