# Intune's Windows 11 26H2 security baseline won't update existing profiles on its own

By MarketScale Newsroom · Published 2026-10-10 · Software & Technology on MarketScale
Canonical: https://www.marketscale.com/industries/software-and-technology/intunes-windows-11-26h2-security-baseline-wont-update-existing-profiles-on-its-own

> Microsoft's Windows 11 26H2 security baseline is live in Intune. Existing profiles stay put until an admin creates a new one or updates the old one.

## Key points

- The Windows 11 26H2 security baseline reaches a managed fleet only when an admin creates a new profile or moves an existing one onto it, so each organization's change process sets how fast it's adopted.
- Tenants with heavily customized baseline profiles carry most of the work: new defaults and revised guidance have to be checked against settings someone changed on purpose.
- The NetBIOS setting will show up in a later baseline update once it's supported on in-market Windows and in the Settings Catalog. Plan on more than one baseline review this cycle.

Microsoft Intune now offers Microsoft's Windows security baseline for Windows 11, version 26H2. The release appeared in the service's What's new log for the week of October 5, 2026. Microsoft calls it the latest Windows security baseline available in Intune and says it reflects its current security recommendations. New settings, updated default values and revised security guidance are all part of the package.

Profiles built on an earlier security baseline won't move to the new version automatically. That makes the release a scheduling question for the endpoint engineering lead who owns Windows configuration. Someone has to decide when the fleet's security defaults change and who approves the change first. How fast an organization adopts the baseline depends on its own change process, not on when Microsoft ships a release.

## Two routes onto the 26H2 settings

Admins have two options. One is to build a new baseline profile. The other is to move an existing profile to the latest version. Whichever route they take, Microsoft advises reviewing the settings before moving off an earlier baseline, and taking extra care when existing profiles include customizations. Microsoft directs readers to the Windows blog post "Windows 11, version 26H2 security baseline" for a detailed breakdown of the setting changes. The Windows MDM baseline settings reference lists how the Intune baseline for Windows 11, version 26H2 is configured by default.

Tenants running stock baselines can get through either route quickly. Tenants whose profiles have built up years of exceptions will spend their time on the review step. New settings, new defaults and revised guidance can conflict with settings someone changed for a reason, and the review is where those conflicts get caught and decided.

Block Field

One setting is missing on purpose. The Configure NetBIOS settings policy isn't in this release because it's currently supported only on Windows Insider builds. Microsoft plans to add it in a later baseline update once it's available on supported, in-market Windows versions and through the Intune Settings Catalog, and says it will announce the change when that happens. Teams that review 26H2 now should expect to look at the baseline again later.

> Tenants whose profiles have built up years of exceptions will spend their time on the review step.

The manual step can feel like friction. Microsoft's own advice to review customized profiles first suggests the opt-in design is deliberate: a tuned profile stays as it is until a person approves the move. For a tenant that has never touched its baseline defaults, the safeguard does little except add a click.

Assignment also shapes which route makes sense. Microsoft Learn describes Microsoft Entra security groups as the foundation for assigning policies and profiles in Intune: admins target a group of users, devices or both, and Intune applies the configuration on check-in. A new 26H2 profile could start with a small pilot group. Updating an existing profile, by contrast, changes the settings for whatever groups that profile already targets.

Scale changes the work, too. The same documentation notes that every action in the Intune admin center is backed by a Microsoft Graph API call, so the operations can be automated through a public interface. For a team carrying many customized profiles, that could turn the settings inventory in the review step into a scripted job rather than an afternoon of clicking.

Sign-off has a permissions side as well. Rabia Noureen of the Petri IT Knowledgebase wrote in April that Intune now lets admins keep scope tags from different role assignments separate instead of merging them, a change meant to prevent accidental over-permissioning. A new Permissions Assessment Report lets teams evaluate the impact before turning the feature on. In tenants where several teams share the console, that could help keep the power to move a baseline with the people who approve the move.

## Where it sits in Intune's release calendar

The baseline entry sits one week after the What's new entry for the week of September 28, which carries the label Service release 2609. Prajwal Desai, who tracks Intune releases on his blog, explains the numbering: releases use a YYMM format, so 2609 is the September 2026 release, and Intune has no separate version number. Admins can see which service release their own tenant is on under Tenant Administration, then Tenant Status.

Intune ships monthly, but Desai notes that updates sometimes land more than once in a month. These out-of-band releases are features that roll out after most of a release is complete. The 26H2 baseline is listed in its own week with no service release number attached, so it appears to fit that pattern.

For operators who own baselines, that suggests new security content may not always arrive with the monthly service release. Following the weekly page, which offers an RSS feed, is a more reliable way to know when something lands.

Block Field

Even then, "available" depends on where you sit. Microsoft says each monthly service update is validated first in its internal environments, then in a small set of customer datacenters, before it expands worldwide, and some tenants might see changes before others. Microsoft monitors the rollout and may pause or delay it, and some features roll out gradually over several weeks. Desai's regional order runs Asia Pacific on day one, Europe, the Middle East and Africa on day two and North America on day three, with government tenants after that.

For a multinational team planning a 26H2 review, that staggering could mean a colleague in another region sees new content first. The tenant's own admin center is the authoritative check.

## Confirming the profile actually landed

Moving a profile to 26H2 is the easy half. The other half is knowing that devices picked it up. In a July 28 post on the Microsoft Intune Blog, Microsoft's Scott Sawyer framed the goal as control, which he said means "you push a change and know it landed." He described an updated per-device sync for Windows that triggers both the mobile device management check-in and the Intune Management Extension check-in. One sync now pulls down policy, app and script changes together.

A sync status pane shows each stage live with timestamps: notifying the device, the device connecting, policies, applications, scripts and, finally, calculating compliance. In Microsoft's example screenshot, the policies stage reads 3 of 3 succeeded. That is the line a baseline owner would be watching.

Microsoft pitches that pane as a troubleshooting tool for single devices. For a pilot group of test machines, it could also be a quick way to confirm that a changed baseline profile reached each machine before the profile is assigned more widely. That use is an inference. Microsoft hasn't tied the feature to baselines.

The last stage reaches beyond the device. According to Microsoft Learn, Intune sends device compliance state to Microsoft Entra, where Conditional Access combines it with user, app, location and Defender risk signals to allow or block access to corporate resources. A pilot sync that ends in a compliant result suggests users on those machines can still reach their resources, not only that the settings arrived.

Noureen's roundup also reported that Microsoft has improved the way Windows devices get check-in notifications. The Windows Notification Service stays in place, and Intune now also sends notifications through the same delivery technology Microsoft Teams relies on. Remote Help for Windows is the first place the change shows up. Petri says the change is meant to reduce missed check-ins, improve troubleshooting visibility and prevent delays when remote support sessions start. Microsoft said admins might have to adjust their firewall settings so the new notification endpoint works.

Because Intune applies assigned configuration on check-in, fewer missed check-ins would matter for how quickly any changed profile reaches devices, including a baseline. That benefit would depend on the firewall change being made, so it is worth confirming before a rollout.

Microsoft has also announced a full update readiness experience in Windows Autopatch. It adds dashboards that give visibility across the whole tenant, update details for each device, centralized alerts that come with remediation guidance, and an Update Readiness Checker. Organizations already on Autopatch could use those views to keep track of Windows update status across devices while their baseline profiles are under review.

## Cloud PKI reaches GCC High tenants

Microsoft Cloud PKI is now available to Intune tenants in the Government Community Cloud High environment. It shipped in Service release 2609, filed under Advanced capabilities, the category formerly called the Microsoft Intune Suite.

Cloud PKI is a public key infrastructure hosted in the cloud. It handles the issuance, renewal and revocation of certificates automatically for devices managed by Intune. Those certificates let devices authenticate to organizational resources such as Wi-Fi, VPN and applications, and supported platforms include managed Windows, Android and iOS/iPadOS devices. Microsoft says tenants delivering device certificates no longer have to deploy these on-premises components:

- An on-premises certification authority
- Network Device Enrollment Service
- Intune Certificate Connector

Microsoft Learn describes Intune as a service that runs entirely in the cloud with no on-premises infrastructure required. GCC High tenants that still deliver device certificates through on-premises servers now have a cloud-hosted alternative to evaluate. Tenants that already moved certificate delivery elsewhere won't see much change from this item.

Timing matters for this audience. In Desai's rollout order, government tenants get monthly updates from day four onward, after the commercial regions. If GCC High follows that slot, its admins could read about a 2609 feature before it shows up in their own console. Checking Tenant Status for the 2609 release number is the quick way to know when it is time to start that evaluation.

## Sources

- [What's new in Microsoft Intune](https://learn.microsoft.com/en-us/intune/whats-new/)
- [What's new in Microsoft Intune – July](https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune-%E2%80%93-july/4537392)
- [What is Microsoft Intune? - Microsoft Intune - Microsoft Learn](https://learn.microsoft.com/en-us/intune/fundamentals/what-is-intune)
- [Intune Updates, New Features, and Service Release Numbers](https://www.prajwaldesai.com/intune-updates-new-features/)
- [What's New in Microsoft Intune – March 2026 - Petri IT Knowledgebase](https://petri.com/microsoft-intune-updates-march-2026/)

Tags: Microsoft Intune, Windows 11 26H2, security baselines, endpoint management, IT operations, Microsoft Cloud PKI, GCC High, Windows Autopatch, device compliance, change management, enterprise IT security

---
Source: MarketScale, https://www.marketscale.com/industries/software-and-technology/intunes-windows-11-26h2-security-baseline-wont-update-existing-profiles-on-its-own. Published for AI indexing and citation; cite the canonical URL. Site guide for agents: https://www.marketscale.com/llms.txt
