News

Windows 11 26H2 Hits Release Preview Alongside New Autopilot Device Trust Feature

Microsoft is moving Windows 11 26H2 closer to general availability, giving enterprise IT organizations a chance to begin testing the annual feature update while also rolling out a new Windows Autopilot capability that can verify corporate PCs at the hardware level before they are enrolled.

Windows 11 26H2 is now available to Windows Insiders in the Release Preview Channel as Build 26300.9278, with a broader release planned for later this year. Rather than requiring a full OS replacement, Microsoft will deliver 26H2 as an enablement package because versions 24H2, 25H2 and 26H2 share the same servicing branch, potentially making the transition considerably less disruptive for organizations managing Windows fleets.

As a result, users may already recognize much of what appears in 26H2. For commercial devices, however, the update activates several capabilities that were introduced earlier but were not previously enabled by default. Those include Windows settings backup, app-specific actions from the taskbar and some File Explorer improvements.

Microsoft has been positioning Windows settings backup as part of a broader endpoint resilience strategy, allowing organizations to preserve user preferences and configuration data during device replacement or recovery.

Commercial customers can begin validating 26H2 through Windows Update client policies and Windows Server Update Services. Insiders can also obtain the update by selecting the download and install option in Windows Update, with ISO images expected to arrive soon.

Alongside the operating system preview, Microsoft announced device association for Windows Autopilot device preparation, extending IT control to an earlier point in the PC deployment process.

"We've heard organizations want Windows deployment to be simple for employees and predictable for IT admins," wrote Maggie Dakeva, senior product manager for Microsoft Intune.

Device association binds a physical Windows 11 PC to an organization before enrollment using hardware-backed attestation and Trusted Platform Module-based cryptographic validation. Tenant information is stored in the device's UEFI firmware, allowing the association to survive a Windows reset, operating system reinstallation or removal from management.

Once associated, a device is automatically treated as corporate-owned and can receive a device-specific preparation policy regardless of which employee signs in. Device-based assignments take precedence when both device and user policies are available.

The feature also gives administrators more control over the out-of-box experience. IT teams can preconfigure language, region and keyboard settings; hide privacy and license pages; apply naming templates; and remove account-change options from certain setup screens.

That addresses some of the customization gaps deployment experts have identified in modern provisioning. In a previous reporting , longtime deployment expert Michael Niehaus noted that Autopilot device preparation represented the platform's only major architectural change in several years.

Device association requires a physical Windows 11 device with TPM 2.0 enabled. Virtual machines are not supported because the process depends on hardware-backed identity verification.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured