Windows settings backup is now enabled by default for eligible devices

🚨 The Signal: Windows 11, version 26H2, will enable settings backup by default for eligible devices. This enhances user recovery but requires security teams to verify data residency and compliance for backed-up settings.

The Impact

Admins and Security Teams are affected by potential data residency risks and the need to validate backup configurations.

  • Security Teams: Risk of non-compliant data storage if settings backup includes sensitive information in unapproved regions.
  • Admins: Need to verify existing Intune/GPO policies to ensure they override the new default where necessary.
  • Compliance Officers: Must assess if backed-up settings fall under specific data residency or privacy regulations.

The Action

  1. Review existing Intune/GPO policies for 'Windows settings backup' to ensure explicit configuration where required.
  2. Assess the types of settings backed up to determine if they contain sensitive data subject to data residency requirements.
  3. For devices in privacy-sensitive countries or sovereign clouds, explicitly disable Windows settings backup if not compliant.
  4. Update internal documentation and compliance attestations to reflect the default-on status of Windows settings backup.

Domain: Intune · Impact: medium · Workload: Intune · Essential Eight: Regular Backups · ISM: ISM-1511, ISM-1515, ISM-1705, ISM-1706, ISM-1707, ISM-1708, ISM-1810, ISM-1811, ISM-1812, ISM-1813, ISM-1814