Skip to content
Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune

Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune

Written By Anoop C Nair
Last Updated February 26, 2025
Posted In Intune
SHARE

Let’s discuss using Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune. As you all know, securing devices with different operating systems is essential. In that case, Microsoft Intune plays a major role. Microsoft Intune plays an important role in controlling the OS version of devices within the organization by using filters and app conditional launch settings.

Do you know that Controlling the OS version is sometimes much needed in the case of any vulnerability that happens to older OS versions? Vulnerable OS versions are not suitable for devices. Utilizing filters and app conditional launch settings in Microsoft Intune effectively manages device operating system versions.

Ensure that devices run the minimum required OS version, which helps applications function smoothly. Filters and app conditional launches are crucial components of Microsoft Intune. Filters allow administrators to select specific devices based on device details and OS versions.

App conditional launch settings enhance security by allowing and denying applications access based on the device’s health and compliance status. This post will examine how conditional launch and filters work together and their steps.

Patch My PC

Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune

We discussed extensively using filters and app conditional launches to manage the previous version in Microsoft. Additionally, there are some important points to consider. It’s essential to understand how to create filters and develop a target app using those filters. So, let’s begin with that.

How to Create Filters

To begin, log in to the Microsoft Intune admin center. Next, navigate to Tenant Administration and select the Filters option. On the right side, you will see a “Create” option click on that. Then, choose “Managed Apps.” Refer to the screenshot below for guidance.

Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune - Fig.1
Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune – Fig.1

After that, you need to fill in the basic details of the policy. Once you’ve done that, you will proceed to the rules section. On the rules page, select the property as OS and set the version operator to start with. The value should be 18. If you want to use the Preview option if you want.

  • Then Click on the Next.
Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune - Fig.2
Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune – Fig.2

Create an App with a Filter

For Create and target apps with a filter on microsoft intune are some important steps. For that, first, you have to sign in to the Microsoft Intune admin center. Then, you have to navigate through Apps > App Protection Policy. Then select the platform you want, such as APP, iOS/iPadOS.

Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune - Fig.3 - Creds to MS
Enforce Minimum OS Version Requirements for Security Using Filters and Conditional Launch in Microsoft Intune – Fig.3 – Creds to MS

After providing the basic details, you can complete the Apps, Data Protection, and Access Requirements pages with the appropriate app protection policy settings for iOS, Android, or Windows, as per your organization’s needs. On the Conditional Launch page (or Health Checks page for Windows APP), within the Device Conditions section, specify the OS minor or patch release to set as the minimum version.

ExampleInfo
SettingMin OS version
Value18.2.1
ActionBlock access/Wipe data/Warn, (as per the action required for your organization)
Using Filters and App Conditional Launch to Control OS Version with Microsoft Intune – Table.1
Using Filters and App Conditional Launch to Control OS Version with Microsoft Intune - Fig.4 Creds to MS
Using Filters and App Conditional Launch to Control OS Version with Microsoft Intune – Fig.4 Creds to MS

To assign the policy to the correct major OS version, use the filter that you created earlier on the Assignments page. After making your selections, save the policy by clicking “Create” on the Review and Create page. For example, the filter will target devices running iOS 18, with APP conditional launch settings requiring version 18.2.1, ensuring it does not apply to other major iOS versions.

Using Filters and App Conditional Launch to Control OS Version with Microsoft Intune - Fig.5 Creds to MS
Using Filters and App Conditional Launch to Control OS Version with Microsoft Intune – Fig.5 Creds to MS

Reference

Using filters and APP conditional launch to control the OS version with Microsoft Intune

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read