Microsoft Enables Windows 11 Backup Setting by Default for Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Microsoft has enabled Windows settings backup by default for eligible devices running Windows 11, version 26H2, turning an opt-in function into a baseline resilience capability.

The change, generally available from September 29, applies only when administrators have left the backup policy in the Not Configured state; existing explicit enable or disable decisions remain authoritative.

The feature, renamed Windows settings backup and restore from Windows Backup for Organizations, preserves user settings, preferences, and the list of installed Microsoft Store applications. By capturing that information before a laptop is lost, reset, replaced, upgraded, or reimaged, Microsoft aims to reduce disruption during device recovery and hardware refresh projects.

Microsoft is not activating restoration automatically. The default-on behavior covers backup only, while the restore experience remains disabled unless an administrator separately enables it through Microsoft Intune, Group Policy, or a supported mobile device management platform. This separation lets organizations control whether users can reapply a saved profile during the out-of-box experience or at first sign-in.

On supported configurations, an automatic backup task runs every eight days. Users can also start one manually from the Windows Backup application and, where organizational policy permits, select whether Windows remembers preferences and the Microsoft Store app list through Settings > Accounts > Windows backup. Administrators can restrict those choices through policy.

The new baseline has a deliberately limited scope. A device must run Windows 11 26H2 or later, reside outside countries or regions regulated by the EU Digital Markets Act, operate outside sovereign or restricted cloud environments, and have its backup policy set to Not Configured.

Windows 11 Backup Setting by Default

Devices in privacy-sensitive regions, restricted clouds, or earlier supported Windows 11 releases remain off by default, while systems originally running version 26H1 will receive equivalent treatment with a later feature update.

For IT teams, the policy-precedence rule is the most important operational detail. An explicitly disabled backup policy continues to block the feature, and an explicitly enabled policy continues working as configured.

Organizations satisfied with automatic backup on eligible endpoints need to take no action, but security and compliance teams may prefer to set the policy explicitly to create an auditable record of administrative intent.

Administrators can manage backup through the Intune Settings Catalog under Administrative Templates > Windows Components > Sync your settings > Enable Windows Backup.

The equivalent Group Policy setting uses the same path, while MDM providers can apply the SettingsSync policy configuration service provider. Microsoft warns against mixing Group Policy and CSP configuration sources because conflicting controls can produce unexpected results.

Enterprises planning to use recovery should validate identity and enrollment prerequisites rather than assuming backup guarantees restoration. Backup supports eligible Microsoft Entra joined or hybrid-joined devices, but restoration has additional build, profile, enrollment, and Autopilot requirements. Conditional Access policies may also interrupt token acquisition unless the required Microsoft service is permitted.

From a cybersecurity and resilience perspective, the change closes a common operational gap: discovering after an incident that endpoint personalization data was never captured.

It does not replace full endpoint, application, or business-data backups, but it can shorten user recovery after destructive malware remediation, device failure, or forced reimaging.

Organizations should therefore review policy state, regional eligibility, data-governance requirements, restore controls, and recovery testing before broad 26H2 deployment.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Microsoft Enables Windows 11 Backup Setting by Default for Organizations appeared first on Cyber Security News.