Microsoft has announced the availability of its Windows 11, version 26H2 security baseline in Intune. The new baseline, which reflects updated security recommendations, was included in the service’s update log for the week of October 5, 2026. However, organizations must note that existing baseline profiles will not transition to the new version automatically. IT administrators are required to create a new profile or manually update their existing ones to utilize the new settings.
The process for updating security settings is now a matter of organizational decision-making, as the speed at which the new defaults are adopted will depend on how quickly individual companies review and approve the changes. Microsoft emphasizes the importance of evaluating any customizations before moving away from the older baseline.
Updating to the 26H2 Security Settings
IT administrators have two primary options for embracing the 26H2 security settings: building a new baseline profile or modifying an existing profile to fit the new standards. Microsoft advises reviewing the settings thoroughly, especially for profiles that have undergone extensive customization. A guide on the changes can be found in the “Windows 11, version 26H2 security baseline” blog post.
Organizations with default baseline profiles are expected to transition more rapidly than those with customized profiles that have years of tailored exceptions. During the review process, administrators will need to ensure that new settings do not conflict with any established custom configurations.
It’s important to note that one significant setting, the Configure NetBIOS settings policy, is absent from this release. Microsoft has indicated that this setting will be included in a future update, specific to supported Windows versions. Teams involved in security reviews should be prepared to reassess the 26H2 baseline once it becomes available.
The update aligns with Intune’s release calendar, which sees new features and security updates rolled out monthly, although updates may sometimes occur more frequently. System administrators can check which service release their tenant is currently using under the Tenant Administration settings within Intune.
Ensuring that profile updates have been successfully applied is a crucial step in the process. Microsoft has improved sync capabilities for devices, allowing for a more efficient way to confirm that changes have been implemented. This updated syncing mechanism consolidates multiple checks into one, providing immediate feedback on the status of policy changes.
Another recent enhancement is the introduction of Cloud PKI, now available to Intune tenants in the Government Community Cloud High environment. This service automates the management of digital certificates, allowing devices to authenticate to various organizational resources without the need for on-premises infrastructure.
As the review and implementation phases begin, administrative teams are encouraged to monitor their status within the Intune admin center for the latest updates on these developments.

