It looks like Microsoft is getting ready to disable two legacy security features in Edge. These two features are Defender Application Guard (MDAG) and Windows Information Protection (WIP), and they will be retired late next month.
While Microsoft has been steadily replacing other popular features like Drop in Edge, this change will only affect business users on Windows 10. The development came to light when Neowin spotted the official Microsoft advisory in an internal admin portal. However, we spotted the same notice on CloudScout.
For those unfamiliar with these features, MDAG was a virtual sandbox that isolated suspicious websites. So let’s say the user accidentally clicked on a link that contained malware; the threat would remain trapped inside the virtual container, rather than spreading to your entire computer.
WIP, on the other hand, was a security feature that was designed to prevent regular users from copying company data to non-business applications and websites.
Both of these security features have already been deprecated for a considerable time. So think of this as a clean-up of the old guardians of your computer.
As pointed out by the publication, Microsoft had already discontinued WIP in 2022, encouraging organizations to transition to the modern Microsoft Purview data loss prevention (DLP) solutions. Meanwhile, MDAG was removed from Windows 11, version 24H2, and is no longer available. Additionally, both features had to be manually enabled.
That said, Microsoft Edge is also undergoing a similar transition as it prepares to deprecate Manifest V2 extensions.
With the launch of Edge version 154, scheduled for the end of September 2026, the two features will no longer be available in the browser.
Microsoft’s advisory note stated that organizations utilizing the tools may experience a “loss of security protection” and advised administrators to begin the transition to their modern counterparts.
The company recommends that users of Windows Information Protection migrate to Microsoft Purview Information Protection and Endpoint Data Loss Prevention.
Meanwhile, those who used Defender Application Guard are encouraged to rely on built-in Edge security technologies or browser isolation products from other vendors.
