Microsoft published the Windows 11, version 26H2 security baseline on September 29. The package is a concrete starting point for organizations moving to the newest Windows release: it captures Microsoft’s current security recommendations, highlights changes from the 25H2 baseline, and can be tested before it becomes a broad device policy.
The important word is starting point. A baseline is not a compliance certificate or a license to overwrite every existing policy. It is a versioned set of recommendations that still needs conflict analysis, application testing, exception ownership, and a measurable rollout. The safest teams make the baseline a repeatable control cycle.
What changed from Windows 11 25H2
Microsoft’s announcement calls out changes that reduce legacy exposure and tighten the platform’s defaults. They are small enough to miss in a large policy set, but meaningful enough to create compatibility or support questions if they are pushed without a pilot.
| Baseline change | Security intent | What to test |
|---|---|---|
| Windows Ready Print driver ranking is enabled. | Prefer the modern inbox IPP class driver and reduce reliance on third-party print drivers in the stack. | Printer discovery, queue creation, driver features, print-server behavior, and any line-of-business print workflow. |
| Internet Explorer encryption support moves from TLS 1.1 and TLS 1.2 to TLS 1.2 and TLS 1.3. | Remove the obsolete TLS 1.1 option and align the recommendation to current protocol standards. | Legacy management consoles, embedded browsers, proxies, appliances, and integrations that still negotiate old protocols. |
| Additional 26H2 recommendations may appear in the package and reports. | Keep the baseline aligned with current Windows capabilities and Microsoft security guidance. | Every changed setting, not only the two examples highlighted in the announcement. |
Do not infer that an unchanged setting is low risk. The release is a version boundary, so the right comparison is your approved 25H2 posture versus the complete 26H2 package, including settings that have been removed, renamed, or given a different default.
Choose the correct management path
Microsoft supports Windows security baselines through several management paths. Pick one authority for each setting on each device population; overlapping policies with different defaults are a common source of confusing results.
| Device situation | Preferred path | Guardrail |
|---|---|---|
| Cloud-managed Windows 11 devices | Intune security baseline and device configuration policies. | Review the latest available baseline version, then pilot and monitor device-level conflicts before broad assignment. |
| Hybrid or domain-managed devices | Group Policy or Configuration Manager using the Security Compliance Toolkit package. | Document which settings remain authoritative on-premises and which are intentionally cloud-managed. |
| Exception or lab devices | Local policy or a dedicated test OU / Intune group. | Keep exceptions time-bound, named, and visible in the rollout register; never let a lab profile become an undocumented production standard. |
Microsoft explicitly warns that separate baselines can contain overlapping settings with different defaults. That is why a baseline review must include Defender, Edge, Office, firewall, VPN, application-control, and existing hardening policies—not only the Windows baseline itself.
A 30-day rollout that produces evidence
| Window | Work | Exit evidence |
|---|---|---|
| Days 1–5 | Confirm the Windows 11 26H2 adoption ring, download or reference the official baseline package, and record the version, owners, device populations, and current policy sources. | Baseline register, source links, device inventory, and named approver. |
| Days 6–10 | Generate a before-and-after comparison from the current 25H2 posture. Flag changed, removed, duplicated, and locally overridden settings. | Settings diff, conflict map, and exception candidates. |
| Days 11–18 | Pilot on representative hardware and roles: standard users, administrators, laptops, desktops, print-heavy teams, VPN users, and devices with security tooling. | Device results, application test log, help-desk notes, and rollback test. |
| Days 19–24 | Resolve conflicts, approve time-bound exceptions, and update the baseline profile or GPO with only the settings the organization is ready to own. | Signed change record, final profile, exception register, and support script. |
| Days 25–30 | Expand through deployment rings, monitor compliance and user impact, and compare the result with the pilot baseline. | Ring report, incident review, compliance trend, and next-review date. |
Tests that deserve special attention
- Printing: test IPP discovery, secure print, finishing options, label and receipt printers, print servers, and vendor-specific drivers before enabling the driver-ranking recommendation broadly.
- TLS negotiation: identify old appliances, browser-based consoles, and integrations that still require TLS 1.1. Treat a compatibility exception as a migration task with an owner and expiry date.
- Policy collisions: compare the Windows baseline with Defender, Edge, Office, firewall, and application-control baselines. Capture the effective setting on the device, not only the desired value in an admin portal.
- Supportability: give the help desk a short symptom-to-owner guide for blocked print paths, certificate errors, and policy conflicts. A secure default that cannot be diagnosed will be bypassed.
- Rollback: prove that you can remove or narrow the changed profile without leaving a device in a partially managed state.
Keep the baseline reviewable
Store the source package or official version reference, your settings diff, pilot membership, approvals, exceptions, and deployment results together. Microsoft’s baseline guidance is intentionally adaptable: it recommends using the latest baseline as a starting point while customizing it for the organization’s needs. That is a governance feature, not a reason to edit blindly.
Review the baseline at every Windows feature-update decision, when a major security control changes, and after an exception expires. If a setting is intentionally different from Microsoft’s recommendation, record the reason, compensating control, owner, and review date. This turns a static download into evidence that security engineering is active.
Frequently asked questions
What changed in the Windows 11 26H2 baseline? Microsoft highlights enabling Windows Ready Print driver ranking and moving the Internet Explorer encryption recommendation to TLS 1.2 and TLS 1.3. The complete package should still be compared with your current posture.
Should the baseline be deployed unchanged? No. Treat it as a tested starting point. Review conflicts, application dependencies, hardware coverage, and business exceptions before broad assignment.
Can Intune manage this baseline? Yes. Microsoft supports security baselines in Intune and also documents Group Policy, Configuration Manager, and local-policy paths. Keep one clear authority for each setting on each device group.
What evidence should an admin keep? Retain the source/version reference, before-and-after settings comparison, pilot membership, exception approvals, deployment results, and rollback record.
Need a Windows hardening rollout?
Accred Consulting can compare your current Windows, Intune, Defender, and Group Policy controls with Microsoft’s baseline, then build a staged rollout with conflict testing, exception ownership, and evidence your team can reuse.
Plan a Security Baseline Review