MDOP is out of support

MDOP is out of support: Next Steps for Intune, Entra ID, Windows

Last Updated

August 11, 2026

Posted In

As of April 14, 2026, MDOP is out of support. That means Microsoft no longer provides security updates, bug fixes, or technical support for any MDOP components. Modernizing away from MDOP reduces legacy infrastructure, strengthens security posture, and positions endpoint management for the future of Windows.

For many IT teams, the Microsoft Desktop Optimization Pack, better known as MDOP played an important role in managing Windows environments. It helped organizations visualize applications, manage BitLocker, recover broken PCs, roam user settings, and control Group Policy changes.

If your organization still relies on MDOP and its components, Microsoft does provide cloud-native replacement options, and it is essential to know about them. In this article, I will explain those supported options that should help enterprises.

Note: From what I have understood, there is no single replacement product for the entire MDOP. Instead, Microsoft’s recommended direction is to distribute those workloads across modern, supported capabilities in Microsoft Intune, Microsoft Entra ID, Windows 11, Configuration Manager, MSIX, and Windows recovery technologies.

Why MDOP Is Retiring

Let’s understand why MDOP was introduced and why Microsoft is retiring it.

MDOP was introduced and used when:

  • The devices were Active directory domain-joined.
  • Management was on-premises.
  • Security relied on network boundaries.
  • Imaging and re-imaging were standard practice.

Today, organizations are shifting to:

  • Cloud-native management.
  • Zero Trust security.
  • Identity-based access control.
  • Lightweight provisioning (Windows Autopilot).
  • Continuous compliance.

Prerequisites for MDOP migration

Before replacing anything, identify which MDOP components are still in use in your organization. Here is the list of MDOP components to check if your organization still depends on:

  • App-V for application virtualization
  • MBAM for BitLocker administration and recovery
  • DaRT for offline troubleshooting and recovery
  • UE-V for user settings synchronization
  • AGPM for Group Policy change control

Once you know what is still active, you can prioritize migration based on business impact and risk. If you haven’t started planning yet, Microsoft recommends starting with MBAM since Intune is the most direct replacement. Then, you can work through App-V, DaRT, UE-V, and AGPM based on what’s still in use.

Replacing MDOP Components with Modern Microsoft Solutions

The table below provides a practical mapping between common MDOP tools and their modern alternatives, which include Microsoft Entra ID, Intune, and Windows.

MDOP ComponentOriginal PurposeModern Replacement / Direction
App-VApplication virtualizationMSIX, MSIX App Attach, Intune, Configuration Manager for existing packages
MBAMBitLocker management and recoveryBitLocker management in Microsoft Intune with Microsoft Entra ID key escrow
DaRTOffline diagnostics and recoveryWindows Recovery Environment, Quick Machine Recovery, Intune remote actions
UE-VUser settings roamingWindows 365 Cloud PC, Windows Backup for Organizations, OneDrive Known Folder Move, app-native sync
AGPMGroup Policy change controlIntune Multi Admin Approval, Intune settings catalog, role-based access control, policy-as-code practices

A Practical Migration Checklist

A successful MDOP transition should be planned, not rushed. Use the following checklist as a starting point.

  1. Identify active MDOP dependencies: Document which MDOP tools are still in use and who depends on them.
  2. Prioritize MBAM replacement: Move BitLocker management to Intune and verify that recovery keys are backed up to Microsoft Entra ID.
  3. Build an App-V exit plan: Keep critical existing packages running where needed, but shift new packaging to MSIX.
  4. Validate recovery workflows: Define how IT will handle non-booting or broken machines using WinRE, Intune, Quick Machine Recovery, bootable media, or Autopilot redeployment.
  5. Review user settings requirements: Decide which settings and files need to follow users across devices, then map those needs to OneDrive, Enterprise State Roaming, Edge sync, or app-native sync.
  6. Establish policy change controls: Use Intune governance features such as Multi Admin Approval and role-based access control to protect sensitive configuration changes.
MDOP is out of support - Migration Checklist
MDOP is out of support – Migration Checklist

Conclusion

MDOP has actually served Windows administrators well for many years, but its support lifecycle has ended, unfortunately. Organizations that continue using unsupported MDOP components should treat this as a modernization priority.

I would say MDOP’s retirement isn’t just a forced migration, it’s a chance to modernize your entire device management strategy. By moving to Intune and Microsoft’s cloud-native tools, you gain:

  • Improve security through cloud-based management
  • Centralize device and policy administration
  • Integrate encryption and compliance with Conditional Access
  • Reduce dependency on legacy on-premises servers and lower infrastructure costs
  • Support Windows 11 and modern endpoint management

The organizations that make this transition now will be better positioned for Windows 11, Zero Trust, and the next generation of cloud-first endpoints. Please share in the comments section how you intend to replace MDOP in your company with more contemporary solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *

Prajwal Desai

Prajwal Desai is a highly accomplished technology expert and a 14-time Dual Microsoft MVP (Most Valuable Professional), specializing in Microsoft Intune, SCCM, Windows 365, Enterprise Mobility, and Windows. As a renowned author, speaker, and community leader, he is widely recognized for sharing his in-depth expertise and insights through his blog, YouTube channel, conferences, webinars, and other platforms.