MC781581 - Plan for Change: Migrate classic Conditional Access policies

Message Center

This announcement expired on Aug 11, 2024 and is no longer active in Message Center.

Service

Microsoft Intune

Last Updated

May 17, 2024

Published Apr 19, 2024

Tag

Updated message
User impact
Admin impact

Act by

Jun 30, 2024

Summary

Azure AD Graph is retiring, and admins must migrate classic Conditional Access policies to Microsoft Graph by June 30, 2024. Failure to migrate will prevent new device enrollment and compliance via the Company Portal and Intune apps across various platforms.

More information

Updated May 17, 2024: We have updated the timing of this change below. Thank you for your patience.

Azure Active Directory (Azure AD) Graph has been deprecated since mid-2023 and is in its retirement phase to allow applications time to migrate to Microsoft Graph. As part of our ongoing efforts to prepare for this, we will be updating the Intune Company Portal infrastructure to move to Microsoft Graph. With this update, by June 30, 2024, admins must migrate classic Conditional Access (CA) to the new policies and disable or delete policies for the Company Portal and Intune apps to continue working.

How this will affect your organization:

If you are using classic Conditional Access policies, you will need to migrate these policies.

User impact: If you do not migrate your policies, users will not be able to enroll new devices via the Company Portal and they will not be able to make non-compliant devices compliant (if non-compliance is caused by a classic CA policy or a condition within a classic CA policy). This applies to:

  • Windows Company Portal
  • Intune Company Portal website
  • Android Company Portal
  • Intune app for Android Enterprise
  • Intune app for Android (AOSP)
  • iOS Company Portal
  • macOS Company Portal

What you need to do to prepare:

Before June 30, 2024, migrate your classic CA policies. For instructions, see Migrate from a classic policy - Microsoft Entra ID | Microsoft Learn.

We have published a blog with these details and will provide any additional updates or changes to the timeline there: Support tip: Migrate classic Conditional Access policies