Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

Exclude Windows 365 Cloud PCs from Administrator Protection Policy

Message ID
MC1444375
View in Message Center
Service
Windows 365
Category
Plan for Change
Tag
Admin impact
Rollout
August 2026

Details

[Introduction]

Microsoft is making Administrator protection available in Windows 11 in late August 2026. Administrator protection is a platform security feature in Windows 11 designed to ensure users run with the least privilege needed, elevating to admin rights only when necessary and only with the user’s explicit approval. This feature operates on the principle of least privilege, keeping users in a deprivileged state and granting just-in-time elevation rights only when needed.

This feature is off by default and requires admin enablement.

Administrator protection is not supported on Windows 365 Cloud PCs. Organizations that deploy Administrator protection should exclude Cloud PCs from the policy. Applying it to Cloud PCs can cause negative user experience and application compatibility issues.

[When this will happen:]

Administrator protection will roll out in Windows 11 in late August 2026. 

[How this will affect your organization:]

Who is affected

  • Windows 365 Enterprise, Windows 365 Flex, and Windows 365 Reserve end users
  • Organizations that manage both physical Windows 11 devices and Windows 365 Cloud PCs

What will happen

Administrator protection is off by default and requires admin enablement. When the feature is enabled on Windows 11 devices, users will be required to approve administrative actions when elevation is needed.

Administrator protection is not supported on Windows 365 Cloud PCs. If Administrator protection is applied to Cloud PCs, users may experience:

  • An authentication prompt when signing in to the Cloud PC
  • Additional authentication prompts for elevation tasks
  • Application elevation failures in some scenarios
  • Failure to launch Windows 365 Cloud Apps if an authentication prompt is declined

The sign-in prompt affects all users. The elevation prompts and elevation failures apply to users with local administrator rights.

Removing the Administrator protection policy assignments or disabling the feature restores the standard User Account Control (UAC) experience.

[What you need to do to prepare:]

Action is required only if your organization plans to enable Administrator protection.

  • Review Administrator protection deployment plans before broad rollout.
  • Identify Windows 365 Enterprise, Windows 365 Flex, and Windows 365 Reserve Cloud PCs managed through Intune.
  • Create an Intune assignment filter that matches Cloud PCs using supported device model properties: device.model -contains "Cloud PC" or device.model -contains "Windows 365"
  • Configure Administrator protection policy assignments to Exclude filtered devices in assignment.
  • Validate policy assignment results before production deployment.
  • If Cloud PCs were inadvertently targeted, remove the Administrator protection assignment to restore standard UAC behavior.
  • Communicate expected elevation experiences and known limitations to helpdesk and support teams.
  • Update internal deployment documentation to reflect current Windows 365 guidance.

Learn More

Administrator protection | Microsoft Learn

Create a filter for your Cloud PCs

[Compliance Considerations]

No compliance considerations identified. Review as appropriate for your organization.

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.