How to Exclude Non-Entra Devices from Microsoft 365 App Updates
Question details
Administrators need to exclude non-Entra registered virtual machines from automatic Microsoft 365 cloud updates.

- Product
- Microsoft 365 Apps
- Device & OS
- not provided
- Scenario
- Managing Microsoft 365 App cloud updates on nonpersistent Citrix virtual machines.
- Observed behavior
- Non-Entra registered virtual machines are being included in the cloud update inventory, causing disruptive daytime updates.
Ensure you have global administrator or Microsoft 365 Apps administrator privileges to access the Microsoft 365 Apps admin center.
Configure Exclusion Groups or Request Tenant Support
Use the Microsoft 365 Apps admin center to assign Microsoft Entra exclusion groups, or contact Microsoft Support for tenant-specific guidance on non-Entra VMs.
Cloud update configurations in Microsoft 365 heavily depend on Microsoft Entra device registration and group targeting. Because nonpersistent Citrix VMs are not Entra registered by default, standard group exclusions may not apply normally.
You should verify your tenant settings and then escalate the configuration to Microsoft Support if the virtual machines cannot be registered.
Log in to the Microsoft 365 Apps admin center with your admin credentials and navigate to the Tenant settings.
Review the 'Cloud update' section to confirm if and how your nonpersistent Citrix virtual machines are listed in the device inventory.
If the devices can be provisionally registered, create a specific Microsoft Entra group for them and apply this group to the exclusion list in the Cloud update settings.

Experience a Lightweight Office Alternative for Virtual Environments
If managing complex Microsoft 365 updates and Microsoft Entra device registrations is burdensome for your nonpersistent Citrix VMs, consider WPS Office. It provides a lightweight, deployment-friendly alternative that doesn't force disruptive daytime cloud updates.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package.
- 2. Deploy to Virtual Machines: Install WPS Office on your golden image or deploy it across your nonpersistent Citrix VMs.
- 3. Manage Updates Locally: Control software updates locally without relying on mandatory Microsoft Entra device registration.

Frequently Asked Questions
Why are non-Entra registered devices included in Microsoft 365 cloud updates?
Microsoft 365 Apps cloud update inventory can sometimes detect devices running the apps even if they are not fully Microsoft Entra registered, queuing them for mandatory updates based on tenant defaults.
Can I exclude virtual machines from cloud updates without Microsoft Entra groups?
Currently, exclusion targeting in the Microsoft 365 Apps admin center relies exclusively on Microsoft Entra ID groups. Devices typically must be Entra registered to be successfully grouped and excluded.
How else can I stop Office updates on nonpersistent Citrix VMs?
Administrators often use Registry keys, Group Policy Objects (GPOs), or specific Office Deployment Tool (ODT) XML configurations to disable automatic updates on nonpersistent virtual machines.
Where can I get help for tenant-specific Microsoft Entra issues?
You should post your scenario in the Microsoft Entra Q&A forums on Microsoft Learn, or open a direct support request through the Microsoft 365 admin center for personalized engineering guidance.




