[Introduction]
Microsoft is making Administrator protection available in Windows 11 in late August 2026. Administrator protection is a platform security feature in Windows 11 designed to ensure users run with the least privilege needed, elevating to admin rights only when necessary and only with the user’s explicit approval. This feature operates on the principle of least privilege, keeping users in a deprivileged state and granting just-in-time elevation rights only when needed.
This feature is off by default and requires admin enablement.
Administrator protection is not supported on Windows 365 Cloud PCs. Organizations that deploy Administrator protection should exclude Cloud PCs from the policy. Applying it to Cloud PCs can cause negative user experience and application compatibility issues.
[When this will happen:]
Administrator protection will roll out in Windows 11 in late August 2026.
[How this will affect your organization:]
Who is affected
- Windows 365 Enterprise, Windows 365 Flex, and Windows 365 Reserve end users
- Organizations that manage both physical Windows 11 devices and Windows 365 Cloud PCs
What will happen
Administrator protection is off by default and requires admin enablement. When the feature is enabled on Windows 11 devices, users will be required to approve administrative actions when elevation is needed.
Administrator protection is not supported on Windows 365 Cloud PCs. If Administrator protection is applied to Cloud PCs, users may experience:
- An authentication prompt when signing in to the Cloud PC
- Additional authentication prompts for elevation tasks
- Application elevation failures in some scenarios
- Failure to launch Windows 365 Cloud Apps if an authentication prompt is declined
The sign-in prompt affects all users. The elevation prompts and elevation failures apply to users with local administrator rights.
Removing the Administrator protection policy assignments or disabling the feature restores the standard User Account Control (UAC) experience.
[What you need to do to prepare:]
Action is required only if your organization plans to enable Administrator protection.
- Review Administrator protection deployment plans before broad rollout.
- Identify Windows 365 Enterprise, Windows 365 Flex, and Windows 365 Reserve Cloud PCs managed through Intune.
- Create an Intune assignment filter that matches Cloud PCs using supported device model properties: device.model -contains "Cloud PC" or device.model -contains "Windows 365"
- Configure Administrator protection policy assignments to Exclude filtered devices in assignment.
- Validate policy assignment results before production deployment.
- If Cloud PCs were inadvertently targeted, remove the Administrator protection assignment to restore standard UAC behavior.
- Communicate expected elevation experiences and known limitations to helpdesk and support teams.
- Update internal deployment documentation to reflect current Windows 365 guidance.
Learn More
Administrator protection | Microsoft Learn
Create a filter for your Cloud PCs
[Compliance Considerations]
No compliance considerations identified. Review as appropriate for your organization.