Microsoft Edge Enterprise is rolling out a tight deadline for commercial administrators, giving them just seven days to migrate away from two long-standing isolation and conditional-access technologies: WIP and MDAG. Until admins move to Microsoft Purview and alternative isolation tools, their managed deployments risk broken configurations and inactive sandboxes.
- Status: Deprecation/migration notice with a seven-day deadline.
- Affected: Microsoft Edge Enterprise (commercial) deployments relying on WIP (Web Application Protection) and MDAG (Mobile Application Gateway).
- Deadline: Seven days to transition.
- Migration path: Microsoft Purview plus alternative isolation tools.
Understanding Microsoft Edge WIP and MDAG
To see why this deadline matters, it helps to know what these two technologies actually do. WIP stands for Web Application Protection, a web-based MDM agent that Microsoft originally shipped as “MDM Web SSO.” It powers Conditional Access for managed web apps, letting an enterprise browser verify that a user and device meet your zero-trust rules before unlocking content.
MDAG is the Mobile Application Gateway, the on-premises reverse proxy that Microsoft once called the Intune App Gateway. It sits behind your corporate firewall and lets Intune-managed apps, including the app-isolation sandbox in Edge Enterprise, reach managed back-end services without exposing them to the public internet.
Together, these two tools have been the backbone of managed browsing in the commercial Edge for years. WIP handles who gets in, and MDAG handles how managed traffic flows back to your servers. That’s why a migration notice for both is a sizeable change.

What’s changing in Edge Enterprise
According to the report, Microsoft is steering administrators toward Microsoft Purview and a set of alternative isolation tools, phasing out the standalone WIP and MDAG stack. The exact reasoning hasn’t been spelled out in full, but the pattern fits Microsoft’s broader push to consolidate device, app, and data protection under the Purview umbrella.
For IT teams, that means a single console to manage conditional access, app isolation, and data governance rather than juggling separate gateways. It’s the same consolidation strategy Microsoft has applied across other products, and it’s why the migration is being framed as an upgrade rather than a teardown.
What isn’t clear is how much of the current WIP/MDAG configuration carries over, and whether any custom policies will need to be rebuilt from scratch. Until Microsoft publishes a detailed changelog, admins should treat the seven-day window as a heads-up, not a finished plan.
The seven-day window
The tight timeline is the part that gives most admins pause. A seven-day migration window is short enough that it forces a decision, but long enough that a rushed move can leave things half-configured. If you’re managing a fleet of managed devices, you’ll want to map out the steps before the clock runs out.
Practically, that means checking which of your deployments still depend on WIP for conditional access and which rely on MDAG for the isolation sandbox. Anything that can’t be moved to Purview or the replacement isolation tool within the window is the risk.
Microsoft hasn’t confirmed whether the deadline is hard or flexible, so treat it as a soft deadline until official documentation says otherwise. Plan for the worst case: if the sandbox stops working, managed browsing loses a key layer of protection.

What happens if you don’t move
The headline consequence is blunt: affected commercial deployments face broken configurations and inactive sandboxes. In practice, that means managed users could lose the app-isolation layer that keeps risky browsing separate from your data, and conditional-access policies may stop enforcing.
For an end user, the most visible symptom would be a managed Edge that no longer behaves like a managed browser. The sandbox that normally runs in a separate, purer environment could go quiet, and conditional-access prompts could start failing.
For IT admins, the deeper problem is less obvious. A broken configuration doesn’t always throw an error; it can simply stop working in the background, which is exactly why the notice came with a deadline rather than a support ticket.
What this means for you
For everyday users, there’s little to worry about directly—this is an admin-side change. But if your work device runs managed Edge, you may notice the browser behaving differently once the migration window closes. The isolation that keeps a managed browser safe could lapse if your org hasn’t moved to Purview.
For admins, the takeaway is straightforward: don’t wait for the deadline to bite. Review your WIP and MDAG dependencies now, test the migration path against Microsoft Purview, and rebuild any policies that won’t carry over. The seven days is short, but the cleanup from a broken sandbox is longer.
How to get it
Start by inventorying every managed deployment and tagging whether it uses WIP for conditional access or MDAG for app isolation. Then work with your Microsoft Purview admin to provision the replacement isolation tool and re-point conditional-access policies.
Because the details aren’t fully published yet, verify each step against official Microsoft channels before relying on the seven-day timeline. If a change of this size reaches your fleet, expect Microsoft to follow up with a fuller changelog and migration guide—watch for that.
Until then, treat the notice as a real but incomplete warning. Plan the migration, but don’t assume the path is finished until Microsoft confirms it.
Source: Neowin
Over to you: If you run Edge Enterprise, will you rush the migration within seven days, or hold out for Microsoft’s fuller changelog first?



