"Require approved client app" control in Microsoft Entra Conditional Access will be retired in March 2026. Organizations should update their policies to use the "Require application protection policy" grant control. For more information, visit the provided link.
March 2025: plan for the Conditional Access control retirement while ID Protection alerts move to Defender XDR
The supplied March record contains three Microsoft 365 Message Center notices and no documentation additions, updates, or removals. The most consequential item is a planned March 2026 retirement of the Entra ID Conditional Access “Require approved client app” control. The period also covers the completed transition of Entra ID Protection alerts out of Defender for Cloud Apps and the rollout of a new People administrator role in Microsoft Entra.
- “Require approved client app” is scheduled for retirement in March 2026Entra ID
Microsoft’s March 13 reminder says the Conditional Access control will be retired in March 2026 and directs organizations to use the “Require application protection policy” grant control instead. This is a planned retirement, not evidence that the control has already been removed. Administrators should identify affected policies and validate the replacement before changing production policy.
- Entra ID Protection alerts moved from Defender for Cloud Apps to Defender XDRID Protection
The March 6 reminder says Entra ID Protection alerts stopped being available in Microsoft Defender for Cloud Apps on March 5, 2025, with the alerts integrated into Microsoft Defender XDR. Microsoft states that no administrator action is required, while still asking administrators to review configuration and notify users about the change in alert location.
- Microsoft Entra introduced a People administrator roleEntra ID
The March 8 notice describes a new role intended to manage people-related settings and profile photos without requiring highly privileged administration. Its rollout was stated to begin in early February 2025 and complete by late March 2025. The supplied evidence does not specify assignment steps or establish preview or general-availability status.
Review Conditional Access policies that use “Require approved client app” and plan to replace it with “Require application protection policy” before March 2026; the supplied notice does not give an exact retirement date or migration procedure. For ID Protection, Microsoft says no administrator action is required, but asks administrators to review their configuration and notify users about the new alert location in Microsoft Defender XDR. The People administrator notice describes a lower-privilege administrative option for people-related settings and profile photos, but supplies no assignment steps and does not identify the role as preview or generally available.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
3 updates by product
Microsoft Entra ID
2 updatesConditional Access
1Security
1Microsoft Entra is introducing a new People administrator role to enhance administrative capabilities in Microsoft 365. This role, based on customer feedback, allows management of people-related settings and profile photos without requiring high privileges. The rollout will begin in early February 2025 and complete by late March 2025.
Microsoft Entra ID Protection
1 updateMonitoring
1Microsoft Entra ID Protection alerts will no longer be available in Microsoft Defender for Cloud Apps starting March 5, 2025, but will be integrated into Microsoft Defender XDR. No admin action is required, but review your configuration and notify users. More details are available in the Microsoft Defender portal.
