I ran into a strange issue today and wanted to write it down. Partly to save someone else the trouble, and partly because I’m now pretty sure this is a bug and not just me clicking the wrong thing.
A bit of background first. The Enterprise App Management (EAM) side of Intune lets you deploy apps straight from Microsoft’s catalog. No more packaging or manual works. When a newer version comes out, Intune shows it in a report under Apps > Monitor > Enterprise App Catalog apps with updates. The idea is simple. You click the app, hit Update, and Intune creates the latest version as a new app that supersedes the old one. The old installs then move up to the new version.
That’s how it’s meant to work. Here’s what actually happened.
Following the normal steps:
I was testing this with Docker Desktop (x64). I had deployed it as an EAM catalog app, and a newer version (4.78.0.229452) showed up in the report, just like it should.
I clicked on the app. On the overview page there’s an Update button at the top. One thing I noticed here: Intune shows a small warning that says “This app can update itself. App updates will come directly from the publisher…” Docker is one of those apps that can update on its own. Its Update Method was even listed as Auto-update. Keep that in mind, because it’s why I doubted myself at first.
Clicking Update opens the Supersede with latest app wizard. This part looks completely fine while you’re going through it:
1. You go through App information, Program, Requirements, Detection rules, and Scope tags. All good.
2. You reach the Supersedence step. Intune has already added the old Docker Desktop app under “Apps that this app will supersede.”
3. The Uninstall previous version toggle is set to No by default. That means update in place instead of replacing. Which is what you want for a version update.
4. You click Next, reach the review screen, and the supersedence is right there in the summary before you save.
Every screen tells you the same thing. This new app will supersede the old one. So you save it.
And then it’s gone.
This is where it breaks. After the new app is created, I opened its Supersedence tab, expecting to see the old Docker Desktop app listed.
It wasn’t there. The list was empty. The relationship the wizard showed me twice, once on the supersedence step and once on the review page, just didn’t save.
I thought maybe it was a display glitch, so I opened the Relationship viewer on both apps to check. Nothing there either. The new app shows no link to the old one, and the old app shows no link to the new one. After saving, Intune treats them as two completely separate apps.
So the supersedence you set up during the update is accepted, shown to you, and then dropped on save. No warning, no error.
Why this matters?
If you don’t catch it, this is a real problem. The whole point of the Update button is to build an update chain so devices with the old version move to the new one. No supersedence link means no chain. Your existing installs never learn there’s a newer version, and you end up with two separate apps instead of a proper update path. The report says the update is done, but nothing is actually superseding anything on the devices.
The tricky part is that it looks like it worked. You only find out by going back into the new app and checking the Supersedence tab yourself, which most people won’t do after the wizard just told them everything was set.
At first I blamed the self-updating app.
With Docker, I wasn’t sure. Its Update Method was set to Auto-update, and there was that warning saying the app updates itself. So my first thought was that Intune drops the supersedence on purpose because a self-updating app doesn’t “need” it. That would have been annoying but at least it would make some sense.
So I tested a second app to rule that out.
I picked Notepad++ (x64), version 8.6.9. This one is different in every way that matters here. Its Update Method is set to Supersedence, not Auto-update. It doesn’t self-update. The warning on its page is just the plain “A newer version of this app is available in the Enterprise App Catalog.” No self-update note at all.
I ran the exact same Update flow. Same result. The wizard added the old version, showed it on the review screen, let me save, and then the new app came out with an empty Supersedence tab. The Relationship viewer showed no link between the two, same as Docker.
That settles it for me. This isn’t about self-updating apps. A normal catalog app, set to supersede, still loses its supersedence on save. It’s a bug in the update flow itself.
What I’m doing about it:
For now the workaround is boring but it works. After you run the Update flow, go back into the new app, open the Supersedence tab, and add the old version by hand if it’s missing. Then check the Relationship viewer to make sure it stuck before you assign anything. Don’t trust the wizard’s word for it.
I’ve already raised a bug post in the Microsoft Management Advisors Teams channel program, and I’m waiting on confirmation of the bug and the next steps. I’ll update this post once I hear back. If you’ve seen the same thing on your own EAM catalog apps, I’d love to know. Two apps that were completely different, one auto-updating and one set to supersede, both dropped the relationship the same way. So I doubt it’s just me.
Until then, check your Supersedence tab after every EAM update.