Windows 11 Turns On Backup by Default for Eligible Enterprise Devices

Microsoft has shifted Windows 11 version 26H2 so eligible corporate devices now have backup enabled by default. What used to be an opt-in choice becomes baseline protection—assuming the organization hasn’t already explicitly enabled or disabled the feature. This change rolled out on September 29, 2026.

What the default backup does

The setting, now called Windows Settings Backup and Restore for Organizations (previously “Windows Backup for Organizations”), preserves user configurations, display preferences, and the inventory of Microsoft Store apps. Its goal is to make device recovery, upgrades, replacements, or reimaging more seamless—so fewer settings are lost if a device is reset or replaced.

However, only the backup side is turned on automatically. The ability to restore those settings remains off by default unless an administrator enables it via tools like Microsoft Intune, Group Policy, or another supported mobile device management (MDM) solution. This lets organizations decide when and how users can apply saved profiles—whether during setup or sign-in.

Eligibility and policy rules

Automatic backups kick in only on devices meeting specific criteria: running Windows 11 build 26H2 or later, residing in regions not governed by the EU Digital Markets Act, operating outside sovereign or restricted cloud environments, and having no explicit backup policy already set (i.e. the policy is “Not Configured”).

Other devices—such as those in EU-regulated territories, restricted clouds, or with earlier Windows 11 versions—won’t have the feature turned on automatically. They may be included when updated to compatible builds, but not until then.

How backups operate and what admins need to know

On eligible machines, backups happen every eight days by default. Users can also trigger them manually via the Windows Backup app. Preferences and the Microsoft Store app list settings are accessible under Settings › Accounts › Windows backup—unless disallowed by organizational policy.

Administrators manage the policy settings through Intune’s Settings Catalog (Administrative Templates › Windows Components › Sync your settings › Enable Windows Backup), corresponding Group Policy paths, or via the SettingsSync CSP for MDM. Mixing management tools with overlapping policies can cause conflicts, so Microsoft advises choosing one source of control.

Restoration and compliance considerations

Backup is supported for devices joined to Microsoft Entra (or hybrid-joined), but restoring saved profiles involves stricter prerequisites—correct build versions, proper enrollment, and Autopilot configuration. Conditional Access policies also need to permit required authentication service access; otherwise, restoration may fail.

Even with backup turned on, this doesn’t replace full backups of endpoints, applications, or critical business data. It’s a resilience layer to reduce friction in recovery after device failure, malware infection, or forced reimaging—but only when properly configured and tested.

Organizations should audit whether policies are explicitly set, confirm regional eligibility, verify that restoration prerequisites are met, and run recovery drills before rolling out 26H2 broadly.

Why this matters: data-loss incidents often expose that users’ settings and preferences were never backed up. By making backup default, Microsoft closes a gap in endpoint resilience—and gives IT teams a foundation for faster recovery. Watch whether enterprises begin enforcing full restore workflows, how they handle policy propagation, and whether digital sovereignty laws affect eligibility going forward.