Skip to content

Security1 publisher2 min readPublished

Windows 11 26H2 turns on settings backup for Entra-joined PCs whose admins never set the policy

Microsoft has switched Windows settings backup on by default for Entra-joined and hybrid-joined PCs upgraded to Windows 11 26H2, released September 29. Tenants that never set the policy now copy users' settings and Store app lists until an admin turns it off.

The Watch · Security desk

Illustration accompanying Windows 11 26H2 turns on settings backup for Entra-joined PCs whose admins never set the policy

What happened

  • The new default touches only devices where the backup policy was never configured, and Microsoft says it honors any explicit enable or disable already in place.
  • Devices in countries regulated by the EU Digital Markets Act, and devices in sovereign or restricted cloud environments, are left out of the new default.
  • Microsoft first showed the tool at Ignite in November 2024 as an opt-in feature, then took it to public preview in May 2025 and general availability in August 2025.
  • Microsoft gave advance notice of the switch to default-on in July, before the 26H2 release took it live.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Leaving the policy unset now amounts to choosing backup. A tenant whose data rules forbid it has to write an explicit disable in Intune or Group Policy to keep the old behavior.
  • exposure Every unconfigured, eligible 26H2 machine now produces a copy of its user's settings and Store app list, held off the device, that no admin asked for.
  • constraint Multinational tenants lose a single default. EU and sovereign-cloud devices stay off while the rest turn on, so a policy audit has to be checked region by region.

As a security matter this rates low. The change is a configuration default in Windows 11 26H2 [1]. Undoing it costs one setting. Admins keep full control through mobile device management, and a disable pushed through Intune or Group Policy overrides the default [10][11].

The governance question is what gets copied and where it goes. Microsoft's stated reason is recovery. "If user devices ever enter recovery, you don't have to guess whether their Windows settings have a backup. With this feature on by default, users are more likely to have their settings and Microsoft Store app list available to restore after a device reset, replacement, or upgrade," Microsoft said in its Wednesday message center update [5]. The tool restores settings after a device is reset, replaced, upgraded or reimaged [2]. Restoring onto a replacement machine only works if the copy is held somewhere other than the original device [1]. The report does not say where that copy is stored, how long it is kept, or whether switching the policy off later deletes backups already taken.

Restore is a separate control, and the report contradicts itself on it. BleepingComputer's opening line says backup and restore are now enabled by default [1]. Further down, the same report says restore will not be enabled by default and still needs explicit admin configuration [9]. Microsoft's own text settles it. "Restore behavior is unchanged and remains admin-controlled," Microsoft said [7]. Settings are copied out by default. Nothing is written back to a device until an admin configures restore [9].

The exposure window runs from upgrade to the moment an explicit setting lands. Eligible devices with the policy unset began backing up after the 26H2 release [4]. An explicit disable applied after that takes precedence over the default [11].

What to watch

  • Microsoft documentation stating where enterprise settings backups are stored, how long they are retained, and whether disabling the policy deletes existing copies.
  • Any move to extend the default to EU Digital Markets Act regions or to sovereign and restricted clouds.
  • A later Windows release that switches restore on by default as well.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories