Microsoft Edge: Retirement of Windows Information Protection (WIP) and Microsoft Defender Application Guard (MDAG)

🚨 The Signal: Microsoft is retiring Windows Information Protection (WIP) and Defender Application Guard (MDAG) in Edge by September 2026. These legacy data protection features are deprecated, requiring a shift to modern Purview DLP and Intune app protection policies for data loss prevention.

The Impact

Organizations using WIP or MDAG on Windows 10 devices face a security risk if they do not transition to modern data loss prevention controls.

  • Security Teams: Risk of data exfiltration if legacy WIP/MDAG policies are not replaced.
  • Admins: Need to reconfigure data protection policies for Edge on Windows 10.
  • Compliance Officers: Potential gaps in data loss prevention attestation.

The Action

  1. Identify all Windows 10 devices currently configured with WIP or MDAG for Microsoft Edge.
  2. Plan migration to Microsoft Purview Data Loss Prevention (DLP) policies for endpoint data protection.
  3. Implement Microsoft Intune app protection policies for managed applications and data.
  4. Review and update relevant security documentation and incident response plans.
  5. Communicate changes to affected users and IT support teams.

Domain: Purview · Impact: high · Workload: Microsoft Purview · Essential Eight: User Application Hardening · ISM: ISM-1412, ISM-1485, ISM-1486, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1823, ISM-1824, ISM-1859, ISM-1860