Microsoft has enabled Windows Backup for Organizations by default for eligible Microsoft Entra-joined and hybrid-joined devices upgraded to Windows 11 version 26H2. The service preserves users’ Windows settings and Microsoft Store app lists, allowing the data to be used following device resets, replacements, upgrades, or reimaging. The change expands the organizational Windows Backup capability Microsoft introduced in 2025.
The default applies only when administrators have not explicitly configured the relevant policy; existing enablement or disablement settings override it. Devices in EU Digital Markets Act-regulated regions and sovereign or restricted cloud environments are excluded. Restoration is not automatically enabled and still requires administrators to explicitly configure a restore policy, leaving organizations responsible for assessing data-handling, regional-compliance, and endpoint-management implications.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft made the feature generally available; it was subsequently known as Windows settings backup.
The enterprise backup feature entered public preview as a tool to preserve Windows settings and Microsoft Store app lists.
Microsoft introduced Windows Backup for Organizations as an opt-in capability that was disabled by default at its Ignite event.
Microsoft enabled the Windows settings backup policy by default for eligible Entra-joined and hybrid-joined devices upgraded to Windows 11 26H2 where administrators had not explicitly set the policy. The default excludes EU Digital Markets Act-regulated regions and sovereign or restricted cloud environments; restoration remains administrator-controlled.
Windows 11 version 26H2 was released, providing the upgrade condition for eligible Entra-joined and hybrid-joined enterprise devices to receive the new backup-policy default.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.