- Microsoft has made Windows settings backup default-on for eligible Entra-joined work devices upgraded to Windows 11 26H2, but only where admins have not configured the policy.
- Restore is not on by default, and Intune or Group Policy settings override the default. The coverage does not say where the data is stored.
- Check whether the policy is configured, review the data question with compliance, then explicitly enable or disable it before 26H2 upgrades.
A default is a decision made for you
Microsoft has switched on Windows settings backup for eligible work devices. Where an admin never set the policy, Microsoft's default now decides.
The lesson is plain. A policy nobody configured is not neutral. Someone else can change what it does.
What Microsoft changed
BleepingComputer reported on October 1 that the backup is now on by default for PCs joined to Microsoft Entra. Entra is Microsoft's identity service for work accounts. The change covers Entra-joined and hybrid-joined machines.
These PCs must be upgraded to Windows 11, version 26H2. Microsoft released that version on September 29.
The tool was once called Windows Backup for Organizations. It keeps a copy of each employee's Windows preferences. A PC that is wiped, swapped or rebuilt then does not start from scratch. Microsoft's message center post also mentions the user's Microsoft Store app list.
Microsoft made its case in simple terms: "you don't have to guess whether their Windows settings have a backup." Users are "more likely" to have their settings and app list ready to restore.
Four conditions decide whether it applies
The default does not reach every device. According to BleepingComputer, all four conditions must hold.
First, the device runs Windows 11 26H2 and is Entra-joined or hybrid-joined. Second, it is not in a place covered by the EU Digital Markets Act.
Third, it is not in a sovereign or restricted cloud environment. Fourth, nobody has configured the backup policy.
The fourth condition matters most. Microsoft said it honors any explicit enable or disable setting. An admin who has already chosen, either way, is not affected.
What admins still control
Restore is not on by default. Restoring settings to a device still needs explicit admin setup. The change creates backups. It does not create automatic restores.
Admins keep control through mobile device management tools. They can turn the backup off in Microsoft Intune or Group Policy. Those settings take precedence over the new default.
Microsoft's release notes add a related change. Enterprise State Roaming, an older settings-sync feature, can now be managed through the same backup policies. For teams running both, that means one place to look.
Who carries the risk
The benefit is easy to picture. A laptop dies, or a user moves to a new machine. Their settings come back instead of being rebuilt by hand. The help desk spends less time on the small chores that follow a reset.
The cost falls on the admin who did not know the default had changed. Data is now collected on devices where nobody chose to collect it. Whether that matters depends on your data rules, your regulators and your contracts.
The coverage does not say where the backed-up data is stored. It does not say how long it is kept. Nor does it describe the contents beyond settings and the Store app list. Those questions belong with Microsoft's documentation and your own review.
The release notes show that defaults do not all move the same way. Administrator protection limits privilege-escalation attacks through just-in-time admin rights. Microsoft describes it as off by default. Backup is now on.
That is one observation, not a trend. It does show that Microsoft picks defaults feature by feature. You inherit each choice.
What to ask your team this week
First, ask whether the backup policy is set on your Windows fleet today. If the answer is "we never touched it", those devices are in scope once they reach 26H2, provided they also meet the other conditions.
Second, ask which devices are Entra-joined or hybrid-joined. Then ask which fall outside the four conditions. Regional rules and sovereign cloud setups change the answer.
Third, ask your privacy and compliance leads to review what a settings backup holds and where it is kept. Do this before the upgrade, not after.
Fourth, decide on purpose. Either enable the policy and plan the restore side, or disable it in Intune or Group Policy. Either choice is defensible. Leaving it blank hands the decision to the vendor.
A default is a vote cast by whoever did not show up. Set the policy so the decision is one your organisation made.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Microsoft.





