Windows 365: More Flexibility Without Giving Up Security

Share this post:

The way we work has changed.

Image showing the way we work these days

Users expect to be able to work from home, from a customer site, while travelling, or sometimes from a device that isn’t even owned by the company. For IT departments, however, every additional device and location potentially creates another security challenge.

Traditionally, flexibility and security tended to work against each other.

Give users more freedom, and you often increase the attack surface.

Lock everything down, and users start complaining that IT is making their job impossible.

Windows 365 changes that equation.

Instead of putting the corporate Windows environment directly on the device sitting in front of the user, Windows 365 provides a Cloud PC running in Microsoft’s cloud. Microsoft describes Windows 365 as providing the full Windows experience on different devices, including Windows, macOS, iOS, and Android. [microsoft.com]

That opens up some interesting possibilities.


Your PC Doesn’t Necessarily Have to Be a PC Anymore

Think about the traditional setup.

An employee receives a laptop containing:

  • Windows
  • Microsoft 365 Apps
  • Business applications
  • Company configuration
  • Cached corporate information
  • User profiles and settings

If that laptop breaks, disappears, or becomes unavailable, you suddenly have a productivity problem and potentially a security problem.

With Windows 365, the user’s Windows environment can instead live in Microsoft’s cloud.

The physical device becomes the way to access the workplace, rather than being the workplace itself.

A user could, depending on organizational policy, access their Cloud PC from a Windows computer, Mac, iOS device, or Android device. [microsoft.com]

That separation between the endpoint and the corporate Windows environment is one of the things that makes Windows 365 interesting.


Scenario 1: Working From Almost Anywhere

Imagine an employee normally working from a managed corporate Windows laptop.

They travel to another office and don’t have their laptop available.

In a traditional environment, this might mean preparing another corporate device before they can continue working.

With Windows 365, they can potentially access the same Cloud PC from another suitable device.

Their Windows environment hasn’t moved.

The access device changed.

Microsoft specifically positions Windows 365 for scenarios where organizations want users to access Windows from different devices while being able to scale Cloud PCs as business requirements change. [microsoft.com]

For organizations with consultants, travelling employees or distributed teams, that’s a big difference.


Scenario 2: Contractors and Temporary Workers

Another scenario I find particularly interesting is contractors.

Giving an external consultant access to corporate resources can quickly become complicated.

Do you:

  • Buy them a corporate laptop?
  • Ship that laptop across the country, or even internationally?
  • Allow their personal computer?
  • Give their unmanaged device direct access to Microsoft 365 and business applications?
  • Build a traditional VDI environment specifically for them?

Windows 365 gives organizations another option.

Instead of putting the corporate workspace on the contractor’s physical computer, IT can provide a managed Cloud PC.

The contractor gets the Windows environment required to perform the job while the organization retains control over that Cloud PC.

For temporary, seasonal, shift-based and part-time workers, Microsoft also offers Windows 365 Flex, formerly Windows 365 Frontline. For temporary, seasonal, shift-based, and part-time workers, Microsoft also offers Windows 365 Flex, formerly Windows 365 Frontline. Windows 365 Flex includes Dedicated and Shared modes, allowing organizations to provide Cloud PCs to different types of workers while licensing around concurrent usage. [microsoft.com]

That can make Cloud PCs interesting beyond the traditional permanent employee.


Scenario 3: Bring Your Own Device Without Bringing Your Own Security Problems

BYOD has always created an uncomfortable discussion for IT.

Users like using their own computers.

Security teams usually like them considerably less.

An unmanaged computer might:

  • Be missing security updates
  • Have unwanted software installed
  • Be shared with family members
  • Have weak local security
  • Be outside normal IT management

Windows 365 doesn’t magically make an untrusted endpoint trustworthy.

What it does provide is another architecture for dealing with the situation.

Rather than treating the unmanaged computer as the corporate computer, it can be used to connect to a managed Cloud PC.

Microsoft explicitly lists BYOD and remote-work scenarios among the use cases for Windows 365 Flex. [microsoft.com]

This distinction is important.

You don’t necessarily need to treat the computer as a trusted corporate endpoint simply because someone is using it to access work.

You still need to secure the connection and control what can happen between the local device and the Cloud PC, but you’re starting from a very different security model.


This Is Where Zero Trust Becomes Important

Moving Windows into the cloud doesn’t automatically make it secure.

You still need to decide: Who can access this Cloud PC, from where, and under which conditions?

Fortunately, Windows 365 fits very naturally into Microsoft’s Zero Trust approach.

Microsoft’s latest Windows 365 deployment guidance recommends a cloud-native, Zero Trust-aligned model and organizes deployment decisions around areas including identity, networking, images, updates, management, user data and client access. [learn.microsoft.com]

Zero Trust essentially changes the mindset from:

You’re inside my network, therefore I trust you.

to principles including:

Verify explicitly, use least-privilege access, and assume breach.

Those are the principles Microsoft identifies in its Zero Trust guidance for Windows 365. [learn.microsoft.com]

And this is where Windows 365 becomes much more interesting when combined with Microsoft Entra ID and Microsoft Intune.


Conditional Access Becomes Your Front Door

If somebody attempts to access a Cloud PC, identity becomes extremely important.

Microsoft identifies Entra Conditional Access as a primary control for conditionally granting access to the Windows 365 service. [learn.microsoft.com]

That allows organizations to build access decisions around their security requirements rather than simply asking whether the user knows a password.

For example, your security design might consider controls around:

  • Strong authentication
  • User identity
  • Sign-in risk
  • Location
  • Device compliance
  • The application being accessed

The exact policies should always be designed around the organization’s environment and risk profile.

But the important architectural difference is that access is evaluated before simply trusting the connection.

The Cloud PC Is Still an Endpoint

There’s another misconception worth addressing.

A Cloud PC is not something that can simply be deployed and forgotten.

It is still a Windows endpoint.

It needs:

  • Configuration
  • Updates
  • Security policies
  • Application deployment
  • Monitoring
  • Compliance policies

For Windows 365 Enterprise, Cloud PCs can be managed through Microsoft Intune, allowing IT departments to apply many of the same endpoint-management skills and processes they already use for physical PCs. Windows 365 Enterprise Cloud PCs are managed through Microsoft Intune, allowing IT teams to use many of the same management tools and processes they already use for physical Windows devices. [microsoft.com]

For an organization already managing Windows 11 through Intune, this is particularly attractive.

You don’t need a completely separate management philosophy just because Windows is running somewhere else.

Security Starts Before Windows Even Loads

Microsoft also enables several security technologies by default on new Cloud PCs.

These include:

  • Virtual TPM
  • Secure Boot
  • Hypervisor-protected Code Integrity
  • Microsoft Defender Credential Guard

Microsoft notes that HVCI and Credential Guard are enabled by default for Cloud PCs using a Windows 11 gallery image. [learn.microsoft.com]

These controls help provide a strong security foundation for the Windows environment itself.

But, again, I wouldn’t look at any single feature as the reason Windows 365 is secure.

The real strength comes from combining layers.

Think in Layers

A well-designed Windows 365 environment could look something like this:

This is much closer to how modern endpoint security should be approached.

There isn’t one magic security setting.

Identity, endpoint configuration, access control and data protection work together.

Microsoft itself separates Windows 365 security into securing Cloud PC access, the Cloud PC device, and Cloud PC data. [learn.microsoft.com]

Flexibility Isn’t Only About Working Remotely

When people hear “Cloud PC”, they often immediately think:

remote workers.

But there are many more scenarios.

For example:

Contractors

Provide a corporate Windows environment without necessarily providing them with the same physical hardware model as permanent employees.

Temporary employees

Provision a Windows environment for the duration of their assignment.

Developers and administrators

Provide an isolated Windows workspace appropriate to a specific role or access model.

Consultants

Access the same Windows environment while moving between customer locations.

BYOD

Allow supported personal devices to act as an access point to a centrally managed Windows environment.

Shift and frontline workers

Windows 365 Flex can support workers who need Cloud PC access during particular working sessions without necessarily requiring a traditional one-user, one-PC model. [microsoft.com]

Suddenly Windows 365 becomes less about “putting desktops in Azure” and much more about changing where the boundary between the user and the IT-managed Windows environment sits.

It Can Also Change Device Lifecycle Thinking

There’s another advantage that doesn’t always receive enough attention.

Separating Windows from the physical endpoint changes how you can think about hardware.

When someone’s workstation is their physical laptop, replacing that laptop means replacing their working environment too.

When their working environment is a Cloud PC, the access device and the Windows environment have separate lifecycles.

That could be valuable when:

  • A laptop fails
  • A user temporarily needs another device
  • Someone works from multiple locations
  • A contractor uses their own hardware
  • Hardware procurement takes longer than expected

It doesn’t mean physical endpoint management disappears.

It means the endpoint doesn’t necessarily contain the entire workplace anymore.

Windows 365 Is Not a Security Shortcut

This might be the most important part.

Don’t deploy Windows 365 and assume:

“It’s in Microsoft’s cloud, so security is taken care of.”

That’s not Zero Trust.

Identity still needs to be protected.

Conditional Access still needs to be configured correctly.

Cloud PCs still need to be managed.

Applications still need updating.

Users still need appropriate permissions.

Data still needs protection.

Incidents still need to be monitored.

Microsoft’s current Windows 365 deployment guidance explicitly recommends considering identity, networking, images, updates, management, user data, clients and supportability as part of the architecture. [learn.microsoft.com]

The platform provides the building blocks.

It’s still our job as IT professionals to use them properly.

Flexibility and Security Don’t Have to Be Opposites

For me, that’s the most interesting thing about Windows 365.

We’re used to making a compromise.

More flexibility usually means less control.

More security usually means restricting what users can do.

Windows 365 gives IT departments another way to approach that problem.

The device in someone’s hands no longer necessarily needs to be their corporate Windows environment.

Instead, Windows can follow the user through their Cloud PC while IT maintains centralized control over that environment.

Combine that with Microsoft Entra ID, Conditional Access, Intune, and Microsoft’s Zero Trust approach, and you get something much more interesting than simply hosting a Windows virtual machine in the cloud.

You get a different way of thinking about the corporate PC.

The future of endpoint management might not be about managing every computer a user touches.

It might be about securely delivering the right Windows environment wherever that user happens to be.

Share this post:

Windows 11 Insider Experimental (Future Platforms) Preview Build 29683.1000

Share this post:

Hi all, last Wednesday Microsoft released Windows 11 Build 29683.1000 to the Experimental (Future Platforms) Channel.

screenshot of Winver showing the new build

Quick and smooth upgrade, pin access still worked after this upgrade, however my fingerprint wasn’t recognized anymore on my Surface Laptop 13inch, after reregistering the fingerprint all is fine.

Enjoy flighting!

Changes and improvements gradually being rolled out*

  • This update includes a small set of general improvements and fixes that improve the overall experience for Insiders running this build on their PCs.

[General]

  • Symbols were missing for our previous flight. They should be available for this one.

Known issues

  • We’re investigating reports that some Insiders aren’t able to use the internet after the previous flight.
  • We’re also aware of and investigating reports of VMware devices green screening.

source: Flight Hub

Share this post:

Windows 11 Insider Experimental (26H1) Preview Build 28120.3181

Share this post:

Hi all, last Wednesday Microsoft released Windows 11 Build 28120.3181 to the Experimental (26H1) Channel.

Changes and improvements gradually being rolled out*

  • This update includes a small set of general improvements and fixes that improve the overall experience for Insiders running this build on their PCs.

[Windows Search]

  • New Windows Search experience with inline actions: We’re beginning to roll out a new Windows Search experience built on WinUI 3 that is faster, more efficient, and features a streamlined design that makes results easier to scan. We’re also introducing inline actions, allowing you to quickly complete tasks directly. Turn on dark mode or Bluetooth, adjust your screen brightness, mute your device, or arrange windows from Windows Search.
  • We’re improving how Windows Search understands what you’re looking for, including better matching for typos and synonyms. We’ll continue fine-tuning these improvements over the coming weeks. For more information detailing the new changes, check out the Windows Insider Blog.
  • English is the only supported language for this initial release.
screenshot of the Feature Flags showing the new search option
  • After upgrading to this build, restart your device before the New Windows Search Experience feature flag is visible.
Screenshot of the new Windows Search experience.

[Narrator]

Read and explore math equations with Narrator

We’re adding math reading and navigation support in Narrator, bringing clearer and more natural math experiences to users who are blind or have low vision. Math is at the heart of STEM education and learning, and this update helps students and professionals independently read, understand, and explore equations, formulas, and scientific notation with confidence.

With this update, Narrator can read math equations aloud in supported Microsoft 365 apps, including Word and PowerPoint. Instead of announcing every symbol individually, Narrator reads equations in a structured, natural way that reflects how they’re meant to be understood. For example, when Narrator reaches a fraction, it reads the numerator and denominator together so you can understand the relationship between them.

You can also explore equations in more detail with a dedicated math navigation mode. Press Narrator key + Alt + N to turn on math navigation, then use the arrow keys to move through different parts of the equation, such as fractions, exponents, and roots. This mode lets you move through an equation one part at a time instead of hearing the full expression all at once. Press Esc to exit math navigation mode.

Math reading is available as soon as you install this build, with no additional download or setup required. To try it, turn on Narrator by pressing Windows key + Ctrl + Enter, then open a supported document that contains mathematical equations and use your standard Narrator reading commands. You can also personalize the experience in Math reading settings in Narrator settings, including speech style and math navigation preferences.

We’re continuing to refine this experience and plan to expand it to more scenarios over time. We’re beginning to roll this out to Windows Insiders, so it might not be available to everyone right away.

Screenshot of the Narrator Math reading settings page in Windows Settings.
The Narrator Math reading settings page in Windows Settings.

Math reading and navigation support

  • Building on the math reading and navigation support introduced for Narrator in Build 26340.9354, we’re expanding the experience with additional language and browser support. Narrator math reading now supports a total of six languages: English (United States), English (United Kingdom), Traditional Chinese, Finnish, German, and Spanish. You can choose your preferred language under Math reading settings in Narrator settings.
  • Math reading is also now available for supported web content in Microsoft Edge Stable version 153.0.4234.32 and later and Chrome Stable version 153.0.8010.18 and later, making it easier to read and explore equations across more of the places where students and professionals work.
The Narrator Math reading settings page in Windows Settings.

Feedback: Share your thoughts in Feedback Hub (WIN + F) under Accessibility > Narrator.

[Taskbar]

  • Improved underlying state persistence of taskbar settings related to multiple monitors across monitor connections and disconnections.

source: Flight Hub

Share this post:

Windows 11 Insider Experimental Preview Build 26340.9616

Share this post:

Hi all, last Wednesday Microsoft released Windows 11 Build 26340.9616 to the Experimental Channel.

A fast and smooth upgrade brining along the new search experience, if you’re not seeing the feature active yet make sure to check the feature flags under your Windows Insider settings here:

don’t forget to reboot to activate any changed you made to the flags

While the release was 7 October 2026, the widget notification feature was enabled on the 9th an interesting new evolution in flighting.

Happy Flights!

Changes and improvements gradually being rolled out

[Windows Search]

  • New Windows Search experience with inline actions: We’re beginning to roll out a new Windows Search experience built on WinUI 3 that is faster, more efficient, and features a streamlined design that makes results easier to scan. We’re also introducing inline actions, allowing you to quickly complete tasks directly. Turn on dark mode or Bluetooth, adjust your screen brightness, mute your device, or arrange windows from Windows Search.
  • We’re improving how Windows Search understands what you’re looking for, including better matching for typos and synonyms. We’ll continue fine-tuning these improvements over the coming weeks. For more information detailing the new changes, check out the Windows Insider Blog.
  • English is the only supported language for this initial release.
  • After upgrading to this build, restart your device before the New Windows Search Experience feature flag is visible.
Screenshot of the new Windows Search experience.

[Battery status widget]

  • As part of our continued commitment to making Widgets more useful for everyday moments, we’re introducing the Battery Status widget for Insiders on newer builds. This widget provides a unified view of battery levels for your PC and peripheral devices, helping you quickly assess power status without hunting through multiple UI locations. Add it by going to Widgets board > Add widgets > Battery Status.
UI showing the new Battery Status widget, providing a unified view of battery levels across your PC and connected devices.

[Kerberos enhancements]

  • IAKerb is now enabled by default for Windows client. IAKerb is a Kerberos extension that allows Windows authentication to succeed in scenarios where traditional Kerberos can’t be used because a direct connection to a domain controller is unavailable. This extension helps reduce reliance on NTLM while improving compatibility for modern authentication scenarios. For additional background, implementation details, and early preview information, see Reducing NTLM Dependency: IAKerb and LocalKDC in Windows Insider Preview.

[Task Manager]

  • Task Manager is expanding process grouping to allow apps to combine otherwise separate background processes into a single unified category rather than relying solely on traditional parent-child trees. This makes an app’s resource usage easier to understand. Microsoft Defender is the first app to use this capability.

[Windows Update]

  • Fixed the issue causing some Insiders with Windows Sandbox enabled to get error 0x80073712 when attempting to install the latest updates.

[Security]

  • We’ve updated the security key PIN entry experience, removing the “other user” icon for a clearer sign-in experience.
UI showing the updated security key sign-in experience with a streamlined PIN entry screen.

[Taskbar]

  • Fixed an issue impacting some Insiders recently, which was causing the taskbar app window previews to become slower and noticeably lag over time.

[Settings]

  • Removed the backplate from the Settings icon when UAC is invoked from within Settings.

[File Explorer]

  • Added support for font preview and installation in the File Explorer and desktop context menus.

[Widgets]

  • Windows can now notify you when a new widget becomes available following app installation, making it easier to discover and add widgets to your Widgets Board. Selecting the alert opens Widgets Board, where newly available widgets are highlighted and can be quickly added to your board.

[Other]

  • Fixed an issue with msmpeg2ac3dec.dll which was leading to some apps and games crashing recently.

source: Flight Hub

Share this post:

Windows 11 Insider Experimental (Future Platforms) Preview Build 29680.1000

Share this post:

Hi all, last Friday Microsoft released Windows 11 Build 29680.1000 to the Experimental (Future Platforms) Channel

screenshot of winver showing the buildnumber

Smooth flight and this time I did not lose Hello Pin access post upgrade, only recall was not active until I opened the app and used hello to authenticate.

Happy Flights!

Changes and improvements gradually being rolled out*

  • This update includes a small set of general improvements and fixes that improve the overall experience for Insiders running this build on their PCs.

[Windows Share]

  • Added the ability to pin your favorite apps in the Windows share window.

[Settings]

  • Updated Settings > Apps > Installed apps to show the version number at the top level for packaged apps, as it already does for other apps.

[File Explorer]

  • This update adjusts how the preview pane handles files downloaded from the web. For HTML files, a new Preview anyway button lets you acknowledge the warning and preview the file. Non-HTML files, such as PDFs, are now previewed automatically.
  • Fixed an issue causing the previews in File Explorer to have an unexpected bar in the middle in recent flights.

[Family Safety]

  • Improved family safety messaging when applications are blocked because of age-restricted parental controls.

[Taskbar]

  • Fixed a few small visual polish issues when using the taskbar in alternate positions.

[Audio]

  • Fixed an issue affecting certain USB Audio Class 1.0 devices, including some multichannel audio headsets, that could prevent the device from working correctly after installing the latest updates.

[Remote Desktop]

  • Fixed an issue causing Remote Desktop to not use the correct window size after recent flights.

[Other]

  • Fixed an issue causing some Insiders to experience extreme lag over time after updating to the last two flights.

Known issues

  • We’re working on a fix for an issue causing some Insiders to experience noticeably decreased performance when interacting with the system the longer they use the latest builds.
  • [Fixed] We’re investigating an issue where VMware Workstation Pro 17.6.4 might display a blank window when reopening a virtual machine after it has been created and closed. We’re working on a fix and will provide an update in a future build.
  • We’re also aware of and investigating reports of VMware devices green screening.

source: Flight Hub

Share this post:

Windows 11 Insider Experimental (26H1) Preview Build 28120.3151

Share this post:

Hi all, last Friday Microsoft released Windows 11 Build 28120.3151 to the Experimental (26H1) Channel

screenshot of winver shoring the build number

Smooth and fast flights for all my devices in this channel, the cloud rebuild option works great !

Changes and improvements gradually being rolled out*

  • This update includes a small set of general improvements and fixes that improve the overall experience for Insiders running this build on their PCs.

[Windows Magnifier]

  • Magnifier now gives you more control over how you zoom. You can type an exact zoom percentage directly in the Magnifier toolbar to land on precisely the level you need.
  • We’ve also added preset step increments (5%, 10%, 25%, 50%, 100%, 150%, 200%, and 400%) to the Settings dropdown, so you can jump to common levels in a single click. Whether you need a subtle boost or a dramatic close-up, Magnifier adapts to how you want to zoom.
Enter an exact percentage or jump to preset steps – 5% up to 400%.

[Cloud rebuild]

  • We’re updating Cloud rebuild, the recovery option that restores a Windows 11 PC to a clean, known-good state by performing a full OS reinstall, with two additions.
  • Cloud rebuild can now sanitize the device’s drives as part of the rebuild. When you start a rebuild in WinRE, choose Remove files if you’re keeping the PC, or Remove & sanitize files before recycling, returning, or reassigning it. The sanitize option uses the storage hardware’s erase capability to securely erase data before Windows is reinstalled and is irreversible.
  • IT administrators can now configure and start a Cloud rebuild remotely through the Recovery CSP, using either the currently installed build or a target build you specify.
UI showing new Cloud rebuild file removal options

[File Explorer]

  • Customizations
    • Improved File Explorer to keep folder view customizations, such as sorting and icon size preferences, consistent across different access paths and apps.
  • Address bar improvements
    • The address bar now supports paths containing double backslashes and quotation marks, for example, C:\Users\user or "C:\Users\user", improving compatibility with a wider range of inputs.
    • Improved reliability of the address bar suggestion dropdown so it now consistently closes after an item is selected.
  • Refinements to the rename experience
    • Fixed an issue where text would be repeatedly selected while renaming items in folder views.
    • Fixed an issue where updated names with case-only changes weren’t immediately reflected in folder views across local and cloud storage.

source: Flight Hub

Share this post:

Windows 11 Insider Experimental Preview Build 26340.9596

Share this post:

Hi all, last Friday Microsoft released Windows 11 Build 26340.9596 to the Experimental Channel

screenshot of Winver running the build

Smooth upgrades here, great spot by Maison da Silva, clicking an app card in the Microsoft store app crashes dwm.exe, resulting in a temporary freeze of the interface (Feedback Hub: https://aka.ms/AA13rrhh)

screenshot of reliability monitor showing the dwm crash

On Surface devices the surface app crashes repeatedly in the background without impact for the user (Feedback Hub: https://aka.ms/AA13rrpb) *** update, only reproduces with 2 monitors connected

screenshot of the reliability monitor showing the app-crash

Changes and improvements gradually being rolled out

[Unicode]

  • We’ve updated Windows text shaping support for Unicode 17.0, helping Windows correctly display and shape newly encoded characters and scripts. Unicode 17.0 added 4,803 characters, including support for four newly encoded scripts: Beria Erfe, Sidetic, Tai Yo, and Tolong Siki.
  • These updates help keep Windows text support current as the Unicode Standard evolves and improve support for languages and writing systems used by people around the world.

[File Explorer]

  • Address Bar now supports ‘~’ , making it quicker to navigate directly to your user profile folder and subfolders (e.g., “~\AppData”).

[Settings]

  • We’re making performance improvements to the Settings home page, which should result in reduced loading times in certain scenarios.

[Recovery]

  • We’re adding a new entry point for Cloud Rebuild under Settings > System > Recovery, making it easier to access the feature from Settings.

Known issues

  • We’re investigating an issue causing some Insiders to be unable to install the latest updates and see error 0x80073712. We believe this issue is related to having Windows Sandbox installed. As a workaround, try disabling Windows Sandbox.

source: Flight Hub

Share this post:

Windows 11 26H2 Is Here: What IT Pros Should Check Before Deploying It

Share this post:

Windows 11 26H2 (26300.x builds) is now generally available, and at first glance this looks like one of the easier Windows feature updates we’ve had in a while.

For organizations already running Windows 11 24H2 or 25H2, Microsoft says 26H2 uses the same servicing foundation and can be delivered to eligible devices through a small enablement package instead of a traditional full operating system upgrade.

That sounds like an easy win.

But easy to install doesn’t mean you should simply push it to every device tomorrow.

Here’s what I think IT pros should look at before starting their Windows 11 26H2 rollout.

What makes Windows 11 26H2 different?

The biggest difference isn’t really 26H2 itself. It’s how Microsoft is servicing Windows.

Windows 11 24H2, 25H2 and 26H2 share the same servicing foundation. Many of the features associated with 26H2 have therefore already arrived on devices through normal monthly updates. The 26H2 enablement package activates selected functionality and moves the device onto the new release lifecycle.

For IT departments, that potentially means:

  • Less disruption to users
  • A smaller feature update
  • Less validation work than with a traditional OS upgrade
  • The same familiar update management tools

Microsoft describes the update as requiring a single restart in most scenarios for eligible 24H2 and 25H2 devices.

That makes 26H2 interesting for anyone managing Windows through Microsoft Intune.

Don’t confuse “enablement package” with “no testing needed”

This is the part where I’d still be cautious.

Even when the underlying Windows platform hasn’t dramatically changed, the state of the device after upgrading can change.

Microsoft specifically notes that 26H2 enables capabilities for commercial organizations that had previously been controlled through temporary commercial controls.

For example, Windows settings backup is enabled by default on eligible commercial devices, although Microsoft says existing administrator-configured policies continue to be respected.

So my recommendation remains the same:

Don’t deploy a Windows feature update everywhere at once just because Microsoft made the upgrade easier.

Use deployment rings.

A simple rollout model

For a typical Intune-managed environment, I like keeping the rollout understandable.

Ring 0, IT devices

Start with devices used by:

  • IT administrators
  • Endpoint engineers
  • Support engineers
  • People who can recognize and properly report an issue

The goal isn’t just checking whether Windows boots.

Test things such as:

  • VPN
  • Microsoft 365 Apps
  • Teams
  • OneDrive
  • Printers
  • Windows Hello
  • BitLocker
  • Conditional Access
  • Defender for Endpoint
  • Business-critical applications
  • Drivers and docking stations

Ring 1, Pilot users

Next, select users from different departments and hardware models.

Don’t make the classic mistake of testing only on ten identical Surface devices sitting in IT.

You want variation.

Ring 2, Early production

Once the pilot group looks healthy, move to a larger part of the organization.

This is where you start validating the deployment at a more realistic scale.

I would use this ring to:

  • Include a larger mix of users and devices
  • Monitor update installation and device health
  • Watch support tickets for unexpected issues
  • Check application and driver problems
  • Verify compliance and security policies still apply correctly
  • Pause the wider rollout if something unexpected appears

The important difference from the pilot ring is scale. The update has already passed technical testing, but you still haven’t exposed the entire organization.

Ring 3, Broad production

Finally, deploy Windows 11 26H2 to the remaining eligible devices.

At this point you should already have confidence from the previous three rings, but broad deployment doesn’t mean you’re finished.

Continue monitoring:

  • Update failures
  • Devices stuck on an older Windows version
  • Non-compliant devices
  • Driver problems
  • Application issues
  • Defender health
  • User-reported problems

The goal isn’t simply to get every device onto 26H2.

The goal is to get every eligible device onto 26H2 without creating unnecessary disruption for the business.

For example:

deployment rings flow

If something behaves differently under 26H2, you want to discover it before hundreds or thousands of endpoints have made the jump.

Check your Intune policies first

Before deploying 26H2, I’d review at least:

  • Windows Update rings
  • Feature update policies
  • Driver update policies
  • Security baselines
  • Settings Catalog policies
  • Compliance policies
  • Endpoint Security policies
  • Any existing Windows version filters

This last one deserves some attention.

I’ve seen environments where perfectly good deployment designs eventually break because somebody created a dynamic group, assignment filter or script years ago that checks for a specific Windows build or version.

Windows gets upgraded, but the forgotten logic doesn’t.

26H2 also brings new management resources

Microsoft has already published updated resources specifically for organizations evaluating 26H2, including:

  • Windows 11 26H2 security baseline
  • 26H2 Administrative Templates
  • Group Policy Settings Reference
  • Windows 11 26H2 update history
  • Windows release health information

These are worth checking before moving your production devices.

In particular, compare your existing security configuration against the new baseline rather than blindly importing a new baseline and assigning it to production.

A security baseline should be evaluated, not simply deployed.

Intune itself is changing too

There is another reason this is an interesting moment for endpoint administrators.

Microsoft continues to change how Intune delivers software and configuration.

In the September 2026 Intune service update, for example, Microsoft introduced faster Win32 application delivery using push notifications for administrator-initiated and service-side changes. Devices can check in sooner after app changes rather than just waiting for the normal polling cycle.

Microsoft has also announced Intune deployments in public preview, designed to gradually roll out applications and device configuration policies to Windows devices using deployment rings.

It shows where modern Windows management is heading:

controlled, observable and gradual deployment instead of “assign to All Devices and hope for the best.”

And Windows Autopatch gets more interesting

There’s also an important Windows Autopatch change coming.

Microsoft says that starting October 15, Autopatch will provide more granular control over Windows quality updates, including individual approval of monthly security, non-security and out-of-band updates.

Microsoft also says updated reporting will provide visibility into approval, applicability, installation progress and deployment status.

For organizations already using Intune and Autopatch, this is something I’d definitely investigate.

It moves update management closer to the question administrators actually want answered:

“Which update is installed on which device, and where is something going wrong?”

Rather than simply:

“I assigned the policy.”

Those are two very different things.

My approach to 26H2

If I were preparing an Intune environment today, my checklist would look something like this:

1. Inventory

Know exactly how many devices are running each Windows version.

2. Check compatibility

Identify hardware, drivers and business applications that require additional validation.

3. Review Intune

Look for policies, filters, scripts or groups with version-specific dependencies.

4. Build a small IT ring

Get 26H2 onto devices belonging to people who can properly troubleshoot problems.

5. Expand to pilot users

Include different departments, device models and working scenarios.

6. Monitor

Don’t measure deployment success purely by whether the update was assigned. Look at whether it actually installed and whether the endpoint remains healthy.

7. Roll out broadly

Only after the first groups give you confidence.

Final thoughts

Windows 11 26H2 looks like a relatively straightforward feature update for organizations already running 24H2 or 25H2.

And that’s good news.

But I wouldn’t use the enablement-package approach as an excuse to skip proper deployment practices.

If anything, feature updates becoming easier means we can spend less time fighting the upgrade mechanism and more time building a proper deployment process around it.

Inventory. Pilot. Monitor. Expand.

The technology behind Windows Update has changed considerably.

Our deployment strategy should change with it.

Important note:

If you’re still running 24H2, end of support is October 13th 2026 for Pro, October 12th 2027 for Enterprise

Sources & more info:

Share this post:

Windows 11 Insider Experimental (26H1) Preview Build 28120.3122

Share this post:

Hi all, last Friday Microsoft released Windows 11 Build 28120.3122 to the Experimental (26H1) Channel

A quick flight with no big changes, all smoothly installed here.

Changes and improvements gradually being rolled out*

  • This update includes a small set of general improvements and fixes that improve the overall experience for Insiders running this build on their PCs.

source: Flight Hub

Share this post:

Windows 11 Insider Experimental Preview Build 26340.9577

Share this post:

Hi all, last Friday Microsoft released Windows 11 26340.9577 to the Experimental Preview Channel

Smooth upgrades here on all experimental devices, Happy Flighting!

Changes and improvements gradually being rolled out

[Start menu]

  • See more of your latest activities at a glance: Phone companion for the Start menu now shows more of your recent activity, with a scrollable side pane so you can view even more without leaving the Start menu.
The phone companion in Start with a scrollable pane for viewing more recent mobile activity.

[Settings]

  • Windows Insiders will now see Energy Recommendations directly in Quick Settings, making it easier to discover and take actions that can help reduce energy consumption and improve device sustainability.
  • Made some small visual refinements to the design of the temporary files section under Settings > System > Storage.

[Narrator]

  • Building on the math reading and navigation support introduced for Narrator in Build 26340.9354, we’re expanding the experience with additional language and browser support. Narrator math reading now supports a total of six languages: English (United States), English (United Kingdom), Traditional Chinese, Finnish, German, and Spanish. You can choose your preferred language under Math reading settings in Narrator settings.
  • Math reading is also now available for supported web content in Microsoft Edge Stable version 153.0.4234.32 and later and Chrome Stable version 153.0.8010.18 and later, making it easier to read and explore equations across more of the places where students and professionals work.
The Narrator Math reading settings page in Windows Settings.

[Audio]

  • Fixed an issue affecting certain USB Audio Class 1.0 devices, including some multichannel audio headsets, that could prevent the device from working correctly after installing the latest updates.

[Taskbar]

  • Improved underlying state persistence of taskbar settings related to multiple monitors across monitor connections and disconnections.

source: Flight Hub

Share this post: