Microsoft Gives Edge Users a Deadline to Replace MDAG and WIP


edge passkey enterprises
Image credit: Microsoft

Microsoft is entering the final stage of retiring Microsoft Defender Application Guard, while Windows Information Protection support in Microsoft Edge will also end.

According to Message Center advisory MC1459132, Microsoft plans to complete the change by the end of September 2026. The move mainly affects organizations still using the technologies with Microsoft Edge on Windows 10, since Microsoft has already removed MDAG from Windows 11.

MDAG and WIP stop working with Edge 154

Microsoft says Windows Information Protection and Microsoft Defender Application Guard will no longer function in Microsoft Edge 154 and newer once the rollout finishes.

Organizations that still depend on either technology could lose those protections if they upgrade Edge without first moving to supported alternatives.

Microsoft wants administrators to identify any remaining deployments and complete their migration before the end of September.

Microsoft has been retiring MDAG for years

The retirement should not come as a surprise to administrators who have followed Microsoft’s security changes over the past few years.

Microsoft deprecated Defender Application Guard for Microsoft Edge in December 2023. It later removed MDAG entirely from Windows 11 version 24H2.

Ending support inside Edge now represents one of the final stages of the technology’s retirement.

MDAG originally allowed organizations to isolate untrusted websites and files in a hardware-based container, reducing the risk that malicious content could access the rest of a user’s system.

Windows Information Protection is also going away

Microsoft discontinued Windows Information Protection in 2022, but some organizations may still have policies that depend on it.

Microsoft recommends moving data protection workloads to supported technologies, including Microsoft Purview Information Protection or Data Loss Prevention, Endpoint DLP, and Microsoft Intune app protection policies.

These tools provide newer options for controlling how organizational data moves between applications, devices, and services.

What can replace Microsoft Defender Application Guard?

Organizations still using MDAG should evaluate Microsoft Edge’s built-in security features as part of their migration.

Microsoft also recommends considering other first-party or third-party isolation technologies when Edge’s existing protections do not meet an organization’s security requirements.

Administrators should test any replacement before retiring existing MDAG configurations, particularly in environments where Application Guard forms part of a broader browser isolation or threat containment strategy.

IT admins should prepare before September

Organizations should review their environments now rather than waiting for Edge 154 to arrive.

Administrators should:

  • Check for remaining WIP and MDAG configurations.
  • Identify users and devices that still depend on them.
  • Choose supported security and data protection alternatives.
  • Test replacement policies before removing existing configurations.
  • Complete migrations before the end of September 2026.

Microsoft is making other changes that IT administrators need to prepare for as well. The company is retiring Entra ID CSS properties, while Microsoft has also fixed a maximum-severity Entra ID security flaw.

Via Neowin

More about the topics: browser, Edge, microsoft

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages