Exclude Windows 365 Cloud PCs from Administrator Protection Policy
🚨 The Signal: Windows 11 will gain an Administrator Protection feature in August 2026, enforcing least privilege. This feature is incompatible with Windows 365 Cloud PCs and must be excluded from policy to prevent user experience and application issues.
The Impact
Organizations using both Windows 11 and Windows 365 are affected, risking operational disruption if policies are misapplied.
- Windows 365 users: May experience authentication and application issues if policies are misconfigured.
- Admins: Must ensure Cloud PCs are explicitly excluded from Administrator Protection policies.
- Security Teams: Need to verify least privilege is still enforced on Cloud PCs via alternative controls.
The Action
- Identify all Windows 365 Cloud PC device groups or users within your environment.
- When Administrator Protection rolls out in August 2026, create a new policy or modify existing ones to enable the feature for physical Windows 11 devices.
- Explicitly exclude identified Windows 365 Cloud PC groups/users from the Administrator Protection policy.
- Monitor user feedback and application logs for any unexpected issues post-deployment on Cloud PCs.
Domain: Intune · Impact: medium · Workload: Other · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898