Windows settings backup is now enabled by default for eligible devices
🚨 The Signal: Windows 11, version 26H2, will enable settings backup by default for eligible devices. This enhances user recovery but requires security teams to verify data residency and compliance for backed-up settings.
The Impact
Admins and Security Teams are affected by potential data residency risks and the need to validate backup configurations.
- Security Teams: Risk of non-compliant data storage if settings backup includes sensitive information in unapproved regions.
- Admins: Need to verify existing Intune/GPO policies to ensure they override the new default where necessary.
- Compliance Officers: Must assess if backed-up settings fall under specific data residency or privacy regulations.
The Action
- Review existing Intune/GPO policies for 'Windows settings backup' to ensure explicit configuration where required.
- Assess the types of settings backed up to determine if they contain sensitive data subject to data residency requirements.
- For devices in privacy-sensitive countries or sovereign clouds, explicitly disable Windows settings backup if not compliant.
- Update internal documentation and compliance attestations to reflect the default-on status of Windows settings backup.
Domain: Intune · Impact: medium · Workload: Intune · Essential Eight: Regular Backups · ISM: ISM-1511, ISM-1515, ISM-1705, ISM-1706, ISM-1707, ISM-1708, ISM-1810, ISM-1811, ISM-1812, ISM-1813, ISM-1814