Skip to content
‹ Back to IndustriesSoftware & Technology

Intune's Windows 11 26H2 security baseline won't update existing profiles on its own

Microsoft's Windows 11, version 26H2 security baseline is now available in Intune. Existing baseline profiles don't move to it automatically. Admins have to create a new profile or update an old one, so how fast the new defaults reach devices depends on each organization's review of customized settings.

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By MarketScale Newsroom · Microsoft IntuneWindows 11 26h2Security BaselinesEndpoint Management
Share
Listen to the audio brief

Key facts, context, and what it means.

AUDIO
0:00—
Intune's Windows 11 26H2 security baseline won't update existing profiles on its own

Key takeaways

01

The Windows 11 26H2 security baseline reaches a managed fleet only when an admin creates a new profile or moves an existing one onto it, so each organization's change process sets how fast it's adopted.

02

Tenants with heavily customized baseline profiles carry most of the work: new defaults and revised guidance have to be checked against settings someone changed on purpose.

03

The NetBIOS setting will show up in a later baseline update once it's supported on in-market Windows and in the Settings Catalog. Plan on more than one baseline review this cycle.

Free workspace

Turn your Software & Technology expertise into content.

Record interviews, organize footage, and write with AI on a free trial of the MarketScale platform for qualifying companies. No demo required, no credit card.

Try it Free

Microsoft Intune now offers Microsoft's Windows security baseline for Windows 11, version 26H2. The release appeared in the service's What's new log for the week of October 5, 2026. Microsoft calls it the latest Windows security baseline available in Intune and says it reflects its current security recommendations. New settings, updated default values and revised security guidance are all part of the package.

Profiles built on an earlier security baseline won't move to the new version automatically. That makes the release a scheduling question for the endpoint engineering lead who owns Windows configuration. Someone has to decide when the fleet's security defaults change and who approves the change first. How fast an organization adopts the baseline depends on its own change process, not on when Microsoft ships a release.

Two routes onto the 26H2 settings

Admins have two options. One is to build a new baseline profile. The other is to move an existing profile to the latest version. Whichever route they take, Microsoft advises reviewing the settings before moving off an earlier baseline, and taking extra care when existing profiles include customizations. Microsoft directs readers to the Windows blog post "Windows 11, version 26H2 security baseline" for a detailed breakdown of the setting changes. The Windows MDM baseline settings reference lists how the Intune baseline for Windows 11, version 26H2 is configured by default.

Tenants running stock baselines can get through either route quickly. Tenants whose profiles have built up years of exceptions will spend their time on the review step. New settings, new defaults and revised guidance can conflict with settings someone changed for a reason, and the review is where those conflicts get caught and decided.

Before updating a customized baseline profile, list every setting it changes from default and compare that list with the 26H2 default configuration in Microsoft's Windows MDM baseline reference. Any setting on both lists needs an owner's decision before the profile moves.

One setting is missing on purpose. The Configure NetBIOS settings policy isn't in this release because it's currently supported only on Windows Insider builds. Microsoft plans to add it in a later baseline update once it's available on supported, in-market Windows versions and through the Intune Settings Catalog, and says it will announce the change when that happens. Teams that review 26H2 now should expect to look at the baseline again later.

Tenants whose profiles have built up years of exceptions will spend their time on the review step.

The manual step can feel like friction. Microsoft's own advice to review customized profiles first suggests the opt-in design is deliberate: a tuned profile stays as it is until a person approves the move. For a tenant that has never touched its baseline defaults, the safeguard does little except add a click.

Assignment also shapes which route makes sense. Microsoft Learn describes Microsoft Entra security groups as the foundation for assigning policies and profiles in Intune: admins target a group of users, devices or both, and Intune applies the configuration on check-in. A new 26H2 profile could start with a small pilot group. Updating an existing profile, by contrast, changes the settings for whatever groups that profile already targets.

Scale changes the work, too. The same documentation notes that every action in the Intune admin center is backed by a Microsoft Graph API call, so the operations can be automated through a public interface. For a team carrying many customized profiles, that could turn the settings inventory in the review step into a scripted job rather than an afternoon of clicking.

Sign-off has a permissions side as well. Rabia Noureen of the Petri IT Knowledgebase wrote in April that Intune now lets admins keep scope tags from different role assignments separate instead of merging them, a change meant to prevent accidental over-permissioning. A new Permissions Assessment Report lets teams evaluate the impact before turning the feature on. In tenants where several teams share the console, that could help keep the power to move a baseline with the people who approve the move.

Where it sits in Intune's release calendar

The baseline entry sits one week after the What's new entry for the week of September 28, which carries the label Service release 2609. Prajwal Desai, who tracks Intune releases on his blog, explains the numbering: releases use a YYMM format, so 2609 is the September 2026 release, and Intune has no separate version number. Admins can see which service release their own tenant is on under Tenant Administration, then Tenant Status.

Intune ships monthly, but Desai notes that updates sometimes land more than once in a month. These out-of-band releases are features that roll out after most of a release is complete. The 26H2 baseline is listed in its own week with no service release number attached, so it appears to fit that pattern.

For operators who own baselines, that suggests new security content may not always arrive with the monthly service release. Following the weekly page, which offers an RSS feed, is a more reliable way to know when something lands.

How Intune changes reach a tenant

2609
Service release for September 2026, in Intune's YYMM numbering
6 to 8 weeks
Typical span of a feature sprint from planning to deployment
Several days to a week
Microsoft's stated window for a monthly update to expand worldwide
Day 4+
When Intune for Government tenants receive a monthly update in Desai's regional schedule

Microsoft Learn; Prajwal Desai

Even then, "available" depends on where you sit. Microsoft says each monthly service update is validated first in its internal environments, then in a small set of customer datacenters, before it expands worldwide, and some tenants might see changes before others. Microsoft monitors the rollout and may pause or delay it, and some features roll out gradually over several weeks. Desai's regional order runs Asia Pacific on day one, Europe, the Middle East and Africa on day two and North America on day three, with government tenants after that.

For a multinational team planning a 26H2 review, that staggering could mean a colleague in another region sees new content first. The tenant's own admin center is the authoritative check.

Confirming the profile actually landed

Moving a profile to 26H2 is the easy half. The other half is knowing that devices picked it up. In a July 28 post on the Microsoft Intune Blog, Microsoft's Scott Sawyer framed the goal as control, which he said means "you push a change and know it landed." He described an updated per-device sync for Windows that triggers both the mobile device management check-in and the Intune Management Extension check-in. One sync now pulls down policy, app and script changes together.

A sync status pane shows each stage live with timestamps: notifying the device, the device connecting, policies, applications, scripts and, finally, calculating compliance. In Microsoft's example screenshot, the policies stage reads 3 of 3 succeeded. That is the line a baseline owner would be watching.

Microsoft pitches that pane as a troubleshooting tool for single devices. For a pilot group of test machines, it could also be a quick way to confirm that a changed baseline profile reached each machine before the profile is assigned more widely. That use is an inference. Microsoft hasn't tied the feature to baselines.

The last stage reaches beyond the device. According to Microsoft Learn, Intune sends device compliance state to Microsoft Entra, where Conditional Access combines it with user, app, location and Defender risk signals to allow or block access to corporate resources. A pilot sync that ends in a compliant result suggests users on those machines can still reach their resources, not only that the settings arrived.

Noureen's roundup also reported that Microsoft has improved the way Windows devices get check-in notifications. The Windows Notification Service stays in place, and Intune now also sends notifications through the same delivery technology Microsoft Teams relies on. Remote Help for Windows is the first place the change shows up. Petri says the change is meant to reduce missed check-ins, improve troubleshooting visibility and prevent delays when remote support sessions start. Microsoft said admins might have to adjust their firewall settings so the new notification endpoint works.

Because Intune applies assigned configuration on check-in, fewer missed check-ins would matter for how quickly any changed profile reaches devices, including a baseline. That benefit would depend on the firewall change being made, so it is worth confirming before a rollout.

Microsoft has also announced a full update readiness experience in Windows Autopatch. It adds dashboards that give visibility across the whole tenant, update details for each device, centralized alerts that come with remediation guidance, and an Update Readiness Checker. Organizations already on Autopatch could use those views to keep track of Windows update status across devices while their baseline profiles are under review.

Cloud PKI reaches GCC High tenants

Microsoft Cloud PKI is now available to Intune tenants in the Government Community Cloud High environment. It shipped in Service release 2609, filed under Advanced capabilities, the category formerly called the Microsoft Intune Suite.

Cloud PKI is a public key infrastructure hosted in the cloud. It handles the issuance, renewal and revocation of certificates automatically for devices managed by Intune. Those certificates let devices authenticate to organizational resources such as Wi-Fi, VPN and applications, and supported platforms include managed Windows, Android and iOS/iPadOS devices. Microsoft says tenants delivering device certificates no longer have to deploy these on-premises components:

  • An on-premises certification authority
  • Network Device Enrollment Service
  • Intune Certificate Connector

Microsoft Learn describes Intune as a service that runs entirely in the cloud with no on-premises infrastructure required. GCC High tenants that still deliver device certificates through on-premises servers now have a cloud-hosted alternative to evaluate. Tenants that already moved certificate delivery elsewhere won't see much change from this item.

Timing matters for this audience. In Desai's rollout order, government tenants get monthly updates from day four onward, after the commercial regions. If GCC High follows that slot, its admins could read about a 2609 feature before it shows up in their own console. Checking Tenant Status for the 2609 release number is the quick way to know when it is time to start that evaluation.

Featured companies

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Book DemoSee how it works15 minutes, straight to a calendar.

About the author

MarketScale Newsroom
MarketScale NewsroomEditorial Team, MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

B2B Weekly

The week in Software & Technology, and sixteen other industries, every Monday.

Ten stories, one-line takes, five minutes. Free.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free Trial

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Start a free trial and see it with your own people. For qualifying companies, no credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What your free trial includes

Hands-on access to the MarketScale platform
Media requests to your crowd, remote recording, AI writing tools
No demo required. No credit card.
For qualifying companies. Company confirmation required.

More Software & Technology Insights

Hammond tells MSPs to pick a vertical and one problem

Hammond tells MSPs to pick a vertical and one problem

N-able Head Nerd Stefanie Hammond lays out a 10-step growth playbook for MSPs that have built spare capacity, starting with one industry and one problem and a 100-account target list. She argues MSPs have a sales problem more than a lead problem, and points to her go-to-market accelerator program, with classes starting in November.

  • 01Hammond starts with revenue targets, then one industry and one problem, then a 100-account list split 20, 30 and 50.
  • 02Hammond says MSPs have a sales problem more than a lead problem: find where proposals stall and whether the right decision makers are in the room before paying for more leads.
  • 03The Dream 100 name traces to a case Chet Holmes International describes: 167 of 2,200 newspaper advertisers bought 95% of the ads, and the first close took five months of mail and calls.

Oct 5, 2026

SDLC Corp launches Pulastya AI, a voice agent platform that answers business calls from a company's own documents

SDLC Corp launched Pulastya AI, a voice agent platform that answers and places business calls 24/7 using company documents without requiring a long integration process. The platform connects to existing phone numbers and OpenAI accounts, handles calls that it cannot answer by transferring to staff, and saves full transcripts for context.

  • 01Most teams can complete setup in under 30 minutes once Twilio/Exotel, OpenAI, and documents are ready
  • 02Internal tests showed ~500 ms response; it won’t guess and hands off to staff
  • 03Designed for clinics, banks, real estate offices, hotels, schools and support teams handling administrative and informational calls like appointments, bookings, order status and inquiries

Oct 3, 2026

Google Just Put AI Chips in Orbit. The Real Story Is the Power Bill on the Ground.

Google Just Put AI Chips in Orbit. The Real Story Is the Power Bill on the Ground.

Google launched a prototype satellite carrying four Trillium TPUs to test whether the chips can survive launch and operate under orbital radiation and heat constraints, driven by power limits on the ground. It is not a data center but a survival test for durability, radiation resistance, and heat dissipation, signaling that energy availability—not chips or models—is becoming the limiting factor for AI infrastructure growth.

  • 01Project Suncatcher's first satellite is a survival test for hardware durability, not operational compute capacity for actual workloads
  • 02Orbital solar can deliver up to 8x more power, and Google research suggests launch costs could drop below $200/kg by the mid-2030s, bringing space build costs closer to some Earth equivalents.

Oct 1, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

MarketScale Newsroom
MarketScale Newsroom

Editorial Team

MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a Demo

Or call us. No forms required. We pick up. 214-945-2512