Article Details

Original Article Text

Click to Toggle View

Microsoft removing Defender Application Guard from Office. Microsoft plans to remove Defender Application Guard from Office by December 2027, starting with the February 2026 release of Office version 2602. The Microsoft Defender Application Guard for Office (MDAG) is designed for Windows 10 and Windows 11 Enterprise editions, protecting users' devices by isolating untrusted Word, PowerPoint, and Excel files in a separate, Hyper-V-enabled container. This helps keep the host operating system secure, ensuring that enterprise data remains safe from attackers if a file or website is malicious. Microsoft announced that it would be deprecating MDAG two years ago, in November 2023, when it also recommended Defender for Endpoint attack surface reduction rules, Protected View, and Windows Defender Application Control as alternatives. Redmond retired MDAG five months later, in April 2024, and says that Office files will now open in Protected View, a read-only mode where most document editing functions are disabled. "Files will open in Protected View instead. Admins should enable Microsoft Defender for Endpoint ASR rules and Windows Defender Application Control to maintain security. No admin action is required for removal," Microsoft said in a Microsoft 365 message center update on Tuesday. "This change aligns with the end of support for Windows 11 version 23H2 and helps streamline the security experience for users. Documents that previously opened in Application Guard will now open in Protected View, maintaining strong protection against threats." ​According to a shared timeline, the removal will start with Office version 2602, for the Current Channel in early February 2026, for the Monthly Enterprise Channel in April 2026, and for the Semi-Annual Enterprise Channel in July 2026. Microsoft estimates that MDAG will be entirely removed from Office with the release of version 2612, which will roll out to Current Channel users in early December 2026, to the Monthly Enterprise Channel in February 2027, and the Semi-Annual Enterprise Channel in July 2027. To maintain protection against malicious Office documents, Microsoft recommends that IT admins: The removal announcement comes two years after Redmond rolled out Application Guard for Office to all Microsoft 365 customers with supported licenses. MDAG was officially launched as part of a limited preview in November 2019, and it was only available to commercial users with Microsoft 365 E5 or Microsoft 365 E5 Security licenses. Secrets Security Cheat Sheet: From Sprawl to Control Whether you're cleaning up old keys or setting guardrails for AI-generated code, this guide helps your team build securely from the start. Get the cheat sheet and take the guesswork out of secrets management.

Daily Brief Summary

VULNERABILITIES // Microsoft to Phase Out Defender Application Guard for Office by 2027

Microsoft will remove Defender Application Guard from Office by December 2027, with the process starting in February 2026 for Office version 2602.

Defender Application Guard isolates untrusted Office files in a Hyper-V-enabled container, protecting the host system from potential threats.

Microsoft suggests alternatives like Defender for Endpoint attack surface reduction rules and Protected View to maintain security after MDAG's removal.

Office files will default to Protected View, a read-only mode, to ensure continued protection against malicious documents.

The removal aligns with the end of support for Windows 11 version 23H2 and aims to simplify the security experience for users.

The phased removal will affect different Office channels, concluding with the Semi-Annual Enterprise Channel by July 2027.

IT administrators are advised to implement recommended security measures to maintain robust defenses against threats.