MC540749: "Require approved client app" control in Azure AD Conditional Access will be retired in March 2026

Announcement IDMC540749Published Date04-13-2023
ServiceIntuneLast Updated04-13-2023
CategoryPlan for changeExpiration Date03-31-2026
Roadmap IDAction Required by Date
TagsAdmin impact, Retirement


Summary
                MC540749: "Require approved client app" control in Azure AD Conditional Access will be retired in March 2026


More Information

In March 2026, Azure Active Directory (Azure AD) and Microsoft Intune will retire the Conditional Access Require approved client app grant control. Instead we recommend utilizing the "Require application protection policy" grant control, which provides the same data loss and protection with additional benefits.

How this will affect your organization:

If you have a Conditional Access policy with "Require approved client app" grant control configured, after this change, you will no longer be able to enforce this control, it will be as if this grant is not selected.

What you need to do to prepare:

We recommend updating your Conditional Access policy to using the "Require application protection policy" grant control. 

Previous Post Next Post