Windows will start backing up work laptops by default in 2026

Microsoft is flipping its enterprise settings backup tool from opt-in to opt-out for Windows 11 26H2, and IT teams have until later this year to decide if they want it on.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: a modern business laptop open on a clean office desk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Microsoft will enable Windows settings backup by default on Entra-joined business PCs running Windows 11 version 26H2, expected later in 2026.
  • The feature reached general availability in August 2025 after debuting as opt-in at Microsoft's November 2024 Ignite conference.
  • Devices in EU-regulated countries, sovereign clouds, or restricted cloud environments are excluded from the default-on change.
  • IT admins retain full control and can disable the backup through Microsoft Intune or Group Policy.
  • Restoring settings to a new device still requires explicit admin configuration.

Microsoft is about to change a quiet default on millions of work laptops.

Starting with Windows 11 version 26H2, the operating system will automatically back up a user's Windows settings to the cloud on company-managed PCs. Today that feature is off unless an IT team switches it on. Soon it'll be on unless they switch it off.

The news was first reported by BleepingComputer after Microsoft posted the change to its admin message center.

What is actually being backed up?

Windows settings. Not files, not emails, but the preferences that make a laptop feel like yours: wallpaper, accessibility options, language choices, app layout and similar bits of configuration.

The tool was unveiled at Microsoft's Ignite conference in November 2024 as opt-in, reached public preview in May 2025, and hit general availability in August 2025. Until now, an IT administrator had to turn it on through a policy. That's the piece that's changing.

Should ordinary workers care?

Mostly in a good way. If your work laptop dies or gets stolen, your replacement can look and feel like the old one within minutes rather than a painful afternoon of clicking through menus.

The catch: backup only runs on devices signed in to a company's Microsoft Entra account, which is Microsoft's cloud identity service that ties your laptop to your employer. Personal PCs aren't affected.

Restoring settings to a new device still needs an admin to allow it. Backup is default-on; restore stays default-off. This fits a broader pattern we've been watching: our 7 July story on Microsoft's Cloud Rebuild tool showed the same cautious logic, where recovery features are staged so admins keep a hand on what data flows where.

Who is excluded?

Microsoft is carving out several groups. Devices in countries governed by the EU Digital Markets Act, a law limiting how large tech firms can bundle their services, won't get the default-on treatment. Sovereign cloud setups (special Microsoft cloud versions used by governments) and other restricted cloud environments are also excluded.

Everywhere else, eligible business PCs are in scope.

When does this happen?

Microsoft product manager Miranda Leschke confirmed the default-on behaviour will appear in the Windows Insider Program Experimental channel starting July 2026, then take broad effect when Windows 11 version 26H2 becomes generally available later that year. Machines still on version 26H1 will get the same treatment at their next feature update.

Admins who want to keep things as they are can pre-empt the change now. Setting the backup policy to disabled through Microsoft Intune or Group Policy will override the new default. Microsoft has been explicit: any policy an admin sets wins over the default.

Is there a security angle?

Yes, and it cuts both ways.

Cloud backup of settings speeds up device replacement after a lost or stolen laptop, which is a genuine incident-response win. At the same time, any expansion of what a corporate identity account holds is worth protecting. If an attacker compromises an Entra account, they also inherit a tidy profile of that user's device preferences across machines.

This isn't a vulnerability. It's a default. But defaults are how most security decisions actually get made in the real world: quietly, by the vendor, on behalf of everyone who never opens the settings panel. For security teams already watching Entra account hygiene closely, this is one more reason to care.

IT teams have a few months to decide what they want the answer to be.

© 2026 Threat Vectr