Windows 11 26H2 Enables Default Backup
Microsoft turns on Windows settings backup by default for Entra-joined enterprise devices on Windows 11 26H2, with admin controls preserved.
Microsoft has flipped the default switch on Windows settings backup for a broad slice of enterprise devices. The change, announced in a message center update, means many Entra-joined systems upgraded to Windows 11 26H2 will now back up user settings automatically — a shift from the opt-in posture the feature carried for nearly two years.
Admins still hold the kill switch, but the default now favors backup rather than leaving it to guesswork.
From Opt-In to Default
The Windows settings backup tool, formerly called Windows Backup for Organizations, backs up and restores enterprise users' Windows settings after a device is reset, replaced, upgraded, or reimaged. Microsoft unveiled it two years ago at the Ignite conference in November 2024 as an opt-in feature that was disabled by default.
It reached public preview in May 2025 and general availability in August 2025. As announced in July, Microsoft has now enabled the Windows settings backup policy by default for eligible devices following the release of Windows 11, version 26H2 on September 29.
The move means that for many organizations, the presence of a settings backup will no longer depend on whether an admin remembered to turn the feature on.
What the new default covers
The default-on behavior applies only to devices running Windows 11 26H2 in countries or regions not regulated by the EU Digital Markets Act, and only when those devices are not in sovereign or restricted cloud environments. The backup policy must also be unconfigured.
Even on devices meeting those conditions, restore behavior is not enabled by default. Users still need explicit admin configuration to restore Windows devices.
Microsoft framed the change as reducing uncertainty during recovery.
"If user devices ever enter recovery, you don't have to guess whether their Windows settings have a backup. With this feature on by default, users are more likely to have their settings and Microsoft Store app list available to restore after a device reset, replacement, or upgrade."
— Microsoft, in a Wednesday message center update
The company also stressed that the new default applies only if admins have not explicitly configured the policy, and that existing explicit enable or disable settings are honored. Restore behavior remains admin-controlled.
Admin control and MDM
On devices where the tool is enabled by default, IT administrators will still retain full control via mobile device management solutions.
Admins can disable the backup policy through Microsoft Intune or Group Policy, as these will take precedence over the default.
That means the change does not remove an organization's ability to opt out; it simply changes the starting state for organizations that never made an explicit choice.
Recovery and device lifecycle
The feature is designed for the moments when a Windows device's state is most fragile: after a reset, a replacement, an upgrade, or a reimage. In those scenarios, settings that live only on the device can be lost or need to be reconfigured by hand.
By backing up settings and the Microsoft Store app list, the tool aims to give users a way to restore a familiar environment without starting from scratch. The restore path, however, remains gated by admin configuration — a deliberate limit that keeps the final say with IT.
Eligibility boundaries
The default-on behavior is not universal. It is limited to Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2.
It also excludes regions regulated by the EU Digital Markets Act, and sovereign or restricted cloud environments. Devices where the backup policy has already been configured are unaffected by the new default.
Those boundaries matter for multinational organizations, which may see the default apply in some regions and not others. Admins in excluded environments will need to manage the feature explicitly if they want it enabled.
What Microsoft said
Microsoft's message center update addressed both the rationale and the guardrails. The company said the default applies only when admins haven't explicitly configured the policy, and that any existing explicit enable or disable setting is honored.
The update also confirmed that restore behavior is unchanged and remains admin-controlled. In practice, that means the backup side of the feature is what shifts to default-on, while the restore side stays opt-in through admin configuration.
What admins should check
- Eligible devices are Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2.
- The default applies only if admins haven't explicitly configured the policy; existing explicit enable or disable settings are honored.
- The default does not apply in regions regulated by the EU Digital Markets Act, in sovereign or restricted cloud environments, or where the backup policy is already configured.
- Restore behavior is not enabled by default and still requires explicit admin configuration.
- Admins can disable the backup policy through Microsoft Intune or Group Policy, which take precedence over the default.
Why it matters
For IT teams, the change reduces the chance that a device reset or replacement wipes out user settings simply because no one opted in. It also shifts the administrative burden: instead of remembering to enable backup, admins who want it off will need to configure the policy explicitly in Intune or Group Policy.
Organizations with strict data-residency requirements should pay particular attention to the geographic and cloud boundaries, since the default will not reach every environment. And because restore remains admin-controlled, the feature's recovery benefits still depend on deliberate configuration rather than default behavior.
Sources
- BleepingComputer Original source
- release of Windows 11, version 26H2 Also reporting
Continue Reading
Satlyt raises $8M for orbital AI software
Satlyt has raised an $8 million seed round to build software that runs AI models on satellites, with a launch set for Thursday.
Micron: Memory Crunch Runs to 2028
Micron warns memory supply will stay tight through 2027 and 2028, with humanoid robots adding fresh demand by decade's end.
Pentagon's Project Meridian leans on tech founders
Defense Secretary Pete Hegseth named Elon Musk, Palmer Luckey, and Newt Gingrich to co-lead a 120-day study of future warfare.