Plan for Change: Windows settings backup policy is becoming a new default
🚨 The Signal: Windows 11, version 26H2 will enable device settings backup by default for unmanaged devices. This improves resilience but requires security teams to verify data handling and compliance for sensitive information.
The Impact
Unmanaged Windows 11 devices will automatically back up settings, posing a risk of sensitive data exposure if not properly governed.
- Security Teams: Risk of sensitive data being backed up to unapproved locations.
- Compliance Officers: Potential non-compliance with data residency and privacy regulations.
- IT Administrators: Need to review and explicitly configure backup policies for all devices.
- End Users: Unaware their settings are being backed up, potentially including personal or sensitive configurations.
The Action
- Identify all Windows 11 devices currently in a 'Not Configured' state for Windows settings backup.
- Determine organizational policy for user settings backup, considering data classification and residency.
- Configure Windows settings backup policy via Microsoft Intune (Devices > Configuration profiles) or Group Policy to explicitly enable or disable it.
- Communicate backup policy changes and implications to end-users and relevant stakeholders.
- Review and update data retention and privacy policies to account for Windows settings backup data.
Domain: Intune · Impact: high · Workload: Intune · Essential Eight: Regular Backups, User Application Hardening · ISM: ISM-1412, ISM-1485, ISM-1486, ISM-1511, ISM-1515, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1705, ISM-1706, ISM-1707, ISM-1708, ISM-1810, ISM-1811, ISM-1812, ISM-1813, ISM-1814, ISM-1823, ISM-1824, ISM-1859, ISM-1860