Windows 11 26H2 Enables Settings Backup by Default for Eligible Devices
Windows 11 26H2 enables settings backup by default on eligible unconfigured Entra-joined commercial devices.
Microsoft has automatically enabled Windows settings backup for eligible commercial devices on Windows 11 version 26H2 when the related policy is left Not Configured. Previously called Windows Backup for Organizations, it stores supported settings, preferences, and the Microsoft Store app list on Entra joined and hybrid joined devices, with automatic backups about every eight days. Explicit enable or disable settings are not overridden, and administrators must still configure restore separately. The default does not apply in EU Digital Markets Act regions or sovereign and restricted cloud environments, and it is not a full system-image or personal-file backup.
- The default applies on Windows 11 26H2 only if backup policy is Not Configured.
- Eligible devices are commercial Microsoft Entra joined or hybrid joined endpoints.
- Restore remains separately controlled and is not turned on by this change.
- EU Digital Markets Act regions and sovereign or restricted clouds are excluded.
- Backups recur about every eight days and are not full file or image backups.
Full article586 words · extracted from gbhackers.com · click to collapse
Microsoft has automatically enabled Windows settings backup for eligible commercial devices running Windows 11, version 26H2. Microsoft positions this capability as a vital resilience measure for enterprise endpoint recovery.
The change is applicable when organizations have left the relevant backup policy in a “Not Configured” state. Administrators’ decisions to explicitly turn the feature on or off will remain unchanged.
Windows Enables Settings Backup
Previously known as Windows Backup for Organizations, this functionality preserves supported Windows settings, user preferences, and the list of installed Microsoft Store applications.
Its purpose is to minimize disruption following a device reset, replacement, reimage, upgrade, or migration. This lets users quickly return to a familiar working environment instead of manually rebuilding settings and app inventories.
Microsoft describes this change as a new resilience baseline meant to eliminate uncertainty about whether a recoverable configuration exists when an endpoint undergoes recovery.
While the new default behavior affects the backup process, restore behavior remains unchanged and is still fully under administrator control. IT teams must separately configure restore policies before users can restore backed-up settings or Microsoft Store app lists on a replacement or recovered endpoint.
This distinction matters for security and endpoint-management teams: enabling a backup baseline does not automatically allow data restoration across different devices, tenants, or recovery scenarios.
Windows settings backup is designed for enterprise environments using Microsoft Entra ID. Eligible devices include Microsoft Entra joined and Microsoft Entra hybrid joined systems that meet Microsoft’s supported configuration requirements.
This default enablement is limited to Windows 11 version 26H2 or later, provided the organization has not previously configured the policy. Additionally, it does not apply in regions regulated by the EU Digital Markets Act or to sovereign and restricted cloud environments.
For organizations that had previously deployed Windows Backup for Organizations, this update will not override existing governance. An explicitly enabled setting will remain enabled, and an explicitly disabled setting will remain disabled.
Administrators can continue to manage this feature through Microsoft Intune, Group Policy, or other supported mobile device management platforms. In Intune, the setting is in the Settings Catalog under Administrative Templates > Windows Components > Sync your settings> Enable Windows Backup.
When active, Windows performs an automatic settings backup every eight days. Depending on organizational policy, users can also manually initiate a backup through the Windows Backup app.
Users can select which supported preferences and the Microsoft Store app list are included through the Windows backup controls in Settings. However, this feature is not a full system-image or personal-file backup, and organizations should not treat it as a replacement for endpoint data protection, file backup, or disaster-recovery measures.
The rollout coincides with the Windows 11 2026 Update, which shares the same servicing foundation as Windows 11 versions 24H2 and 25H2.
For compatible systems, Microsoft indicates that transitioning to 26H2 can occur via a smaller enablement package instead of a complete operating system upgrade, simplifying adoption for enterprise fleets already on supported servicing branches.
For defenders and IT administrators, the primary action is to review existing endpoint policies before broadly deploying version 26H2. Organizations should ensure that backups align with data residency, identity, device replacement, and incident recovery requirements, and explicitly configure backup and restore policies rather than relying solely on the new default settings.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.