Skip to Content

Windows 11 26H2: The Bits Worth Your Attention

30 September 2026 by
Ben Cole

Windows 11 26H2 is a small update with a few big changes hiding in it. Most of the headline features have already been trickling in through monthly updates. What 26H2 really does is switch some of them on, reset the support clock, and bring a handful of security changes that deserve a proper look before you roll it out.

Here are the bits I think are worth your time.

It's an enablement package, not an upgrade

24H2, 25H2 and 26H2 all sit on the same servicing branch. If your devices are on 24H2 or 25H2, moving to 26H2 is a small enablement package and, in most cases, a single restart.

That matters for testing. The code is already on your devices, so validation is mostly about the features that get switched on, not a whole new OS. You still get a fresh support lifecycle out of it.

Security: where the real value is

Administrator protection. Admin rights become just-in-time instead of always-on, with a separate profile for elevated work. It's a real step up against elevation-of-privilege attacks. It's off by default, so you'll need to switch it on through Intune or Group Policy. Pilot it first, because anything that quietly relies on standing admin rights will show up fast.

Driver trust is tightening. Cross-signed drivers lose their default trust. Only drivers from the Windows Hardware Compatibility Program, plus an allow list of trusted legacy drivers, are allowed. Windows audits for at least 100 hours and three restarts before it enforces. This is the one most likely to catch you out on older hardware, specialist kit or niche peripherals. Check your audit results before enforcement kicks in. How this will affect existing drivers in practice is yet to be determined, so treat the audit period as your early warning.

The quick wins:

  • Smart App Control can now be turned on or off without a clean install.
  • Third-party credential managers can store and use passkeys natively.
  • Enhanced Sign-in Security now works with external fingerprint readers, so desktops can use it too.
  • APIs for the NIST post-quantum algorithms ML-KEM and ML-DSA (FIPS 203 and 204) are now available through CNG and .NET. It's early days, but worth knowing if you care about crypto agility.

Deployment and recovery

Autopilot device association. Autopilot device preparation can now recognise trusted devices before enrolment. That brings device-targeted policies, automatic corporate enrolment and more setup options during OOBE. For anyone who moved to device preparation and missed some of the control classic Autopilot gave them, this closes much of the gap.

Point-in-time restore. A PC can be rolled back to a recent automatic restore point, including apps, settings and personal files. It won't replace proper backup, but it's a quick fix for "it broke after yesterday's change".

Settings backup grows up. First sign-in restore now works on Entra hybrid joined devices, Cloud PCs and shared multi-user machines. Enterprise State Roaming can now be managed through the same policies. That makes device refreshes and migrations noticeably smoother.

Removing bloat by policy. You can now name extra MSIX or APPX apps for removal by package family name through Group Policy. It's cleaner than removal scripts.

What switches on by default

Some features that were held back by temporary commercial controls are now switched on for business devices:

  • Windows settings backup
  • App-specific actions from the taskbar
  • Several File Explorer improvements

Policies you've already set are still respected. Even so, check what users will see, especially settings backup, so the helpdesk isn't caught off guard.

Smaller wins for admins

  • Safer batch files. A new processing mode stops batch and CMD scripts from being changed while they're running. It's a quiet fix for a known way attackers tamper with scripts.
  • More in Task Manager. You can now see NPU usage and memory, and an Isolation column shows which apps are running in an AppContainer.
  • Fewer restarts. Eligible updates now install alongside the monthly security update where possible. Devices you put to sleep manually go back to sleep after updating.
  • Camera controls. Multi-App Camera and Basic Camera mode can be managed through Group Policy. Basic mode is handy for troubleshooting video call issues.

Where I'd start

If you only do one thing with 26H2:

  1. Check your driver audit results before enforcement kicks in.

The rest is a welcome bonus. The upgrade itself is low risk. Treat the new security defaults as your to-do list.

Ben Cole 30 September 2026
Share this post
Archive
Entra Connect Upgrade
Upgrade before 30th September 2026