Meet Emmanuel Charlot, Risk and Fraud...
In this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...
Read MoreMicrosoft is preparing to release Windows 11 version 26H2, its main annual Windows update for 2026. Although the company has not yet confirmed an exact release date, general availability is expected during autumn 2026, most likely around late September or October.
For IT teams, the most encouraging aspect of 26H2 is that it should be considerably easier to deploy than a traditional operating system upgrade. Microsoft has confirmed that it shares a servicing platform with Windows 11 versions 24H2 and 25H2. On eligible, fully updated devices, the move to 26H2 should therefore be completed through a small enablement package and a single restart.
However, a smaller update does not mean a risk-free update. Version 26H2 will activate new functionality, introduce configuration changes and begin a new support lifecycle. Businesses should use the period before its release to identify affected devices, test critical software, review recovery arrangements and decide how the update will be introduced across their environment.
The name 26H2 refers to the Windows 11 feature update intended for the second half of 2026. Microsoft formally confirmed the version in June 2026 and has made preview builds available through the Experimental channel of the Windows Insider Program. According to Microsoft’s announcement, Windows 11 26H2 shares the same servicing branch as Windows 11 25H2. Versions 24H2, 25H2 and 26H2 are therefore built on the same underlying Windows platform. This allows Microsoft to deliver much of the required code through ordinary monthly cumulative updates. Some components can remain inactive on the device until an enablement package turns them on and changes the installed Windows version.
For devices already running Windows 11 24H2 or 25H2 and kept up to date, the transition to 26H2 should be much smaller than a full operating system replacement. Microsoft says the update can be completed with a single restart, providing a faster and more predictable deployment experience. Devices running an older Windows servicing branch may need a full feature update rather than the smaller enablement package. This means the installation experience, download size and compatibility risk may differ depending on the version currently installed.
At the time of writing, Microsoft has not announced an exact Windows 11 26H2 release date. The company has confirmed that 26H2 will be its annual second-half Windows 11 update. Based on Microsoft’s established release cycle, it is currently expected to become generally available around late September or October 2026.
Even after general availability, the update is unlikely to reach every compatible PC immediately. Microsoft commonly uses a gradual rollout, offering feature updates first to devices where it expects a reliable installation. Delivery can be delayed or paused where the company identifies compatibility issues involving particular applications, drivers or hardware models. Organisations should therefore avoid building deployment plans around an unofficial date. The final schedule should be confirmed after Microsoft publishes the update, its release-health information, supported processor lists and any known compatibility holds.
Windows 11 26H2 appears to focus more on recovery, resilience, performance and user control than on a major redesign of the operating system. Some changes are directly associated with 26H2, while others are being tested through the Windows Insider Program and may be released separately through monthly cumulative updates. Microsoft increasingly uses controlled feature rollouts, so not every new capability will necessarily appear on every device on the day 26H2 launches.
Point-in-Time Restore
One of the most significant developments for IT and security teams is point-in-time restore. This recovery feature allows a device to be returned to a recent working state, including its applications, settings and user files. It is intended to help organisations recover more quickly from problems such as a faulty driver, unsuccessful application installation, damaging configuration change or wider system failure.
Microsoft’s current documentation states that point-in-time restore is switched off by default on enterprise-managed systems before Windows 11 26H2. This indicates that it will become enabled by default for qualifying enterprise-managed devices running 26H2. Automatic enablement will only apply where the operating system volume is at least 200 GB. At the time of writing, Microsoft’s default configuration creates a restore point approximately every 24 hours, retains restore points for approximately 72 hours and permits the feature to use up to 2 per cent of the disk. Enterprise administrators can change the frequency, retention period and storage allowance through policy.
Restoration is initiated through the Windows Recovery Environment. This may be particularly valuable when a device cannot start normally, although organisations should test the process before relying on it during a genuine incident. Point-in-time restore can strengthen endpoint resilience, but it should not be treated as a replacement for organisational backups. The snapshots are stored on the device and may not remain available if the storage device fails, the device is lost or an attacker successfully compromises the recovery data. Critical information should continue to be protected through an independent and tested backup solution.
Windows Backup for Organisations
Windows Backup for Organisations will also become more prominent with 26H2. Beginning with Windows 11 26H2, Microsoft says Windows settings backup will be enabled by default on eligible Microsoft Entra joined and Microsoft Entra hybrid joined devices. It can preserve user settings and the list of installed Microsoft Store applications, helping users return to a familiar environment after a device is reset, reimaged or replaced.
Existing policies configured by administrators will continue to take precedence. If an organisation has explicitly enabled or disabled the backup policy, 26H2 should respect that decision. Administrators will also need to configure restoration separately, as enabling backup does not automatically give users unrestricted control over the restore process. Microsoft describes the change as a resilience baseline intended to reduce disruption and improve the speed of device recovery. Its Windows Backup for Organisations documentation explains the eligibility and policy requirements.
Organisations should review the feature before deployment. This includes identifying which settings are captured, where information is stored, which users and devices are eligible and whether the configuration aligns with the organisation’s data protection, retention, access control and recovery requirements.
File Explorer and Performance Improvements
Microsoft has made Windows performance and reliability a major focus during 2026. File Explorer is being updated to launch more quickly, respond more consistently and experience fewer freezes and delays during navigation, file selection and renaming. Microsoft is also testing a redesigned right-click context menu that opens faster and gives users greater control over which Windows commands and application extensions appear.
Other improvements include better handling of paths entered into the address bar, more understandable file-size information, expanded middle-click navigation and more reliable file-renaming behaviour. Microsoft has been working to reduce memory use, improve application responsiveness and lower interaction delays in parts of Windows that are being moved to the WinUI 3 framework. Start, Search, File Explorer and other frequently used components are expected to benefit.
Start Menu, Taskbar and Search Changes
Microsoft is testing additional personalisation options for the Start menu and taskbar. These include the ability to control which Start menu sections are displayed, choose between different Start menu sizes, use smaller taskbar buttons and reposition the taskbar. Windows Search is also being refined to provide clearer results, reduce promotional content and improve its ability to find files using partial terms within filenames or content. These changes may improve usability, particularly for users who have found the Windows 11 interface restrictive. However, organisations using tightly controlled desktop configurations should review whether new personalisation options need to be managed through policy.
Accessibility improvements are also being tested, including updates to Magnifier, voice features, screen-reader support and visual controls. These changes should be included in pilot testing where employees depend on Windows accessibility functions.
Greater Control Over Windows Update
Microsoft is also changing how users interact with Windows Update. Preview features include the ability to pause updates until a chosen date for up to 35 days, repeatedly extend the pause where necessary and restart or shut down without being forced to install a pending update. The Power menu will continue to display specific “Update and restart” and “Update and shut down” options when updates are available, but ordinary restart and shutdown options should remain available alongside them. This is intended to prevent an urgent restart or shutdown from unexpectedly becoming a lengthy update installation.
Microsoft is also adding clearer information to driver-update names, helping users and administrators identify whether an update affects display, audio, battery or another device category. The company is working towards reducing the number of update-related restarts by consolidating operating system, driver and .NET updates into a more predictable monthly experience.
For managed business devices, endpoint-management policies may override or restrict some of these user controls. Organisations should confirm how existing Intune, Group Policy, Windows Autopatch or other management settings will interact with the updated experience.
Microsoft has not announced new minimum hardware requirements specifically for Windows 11 26H2. A device that is officially supported on Windows 11 24H2 or 25H2 is therefore expected to remain eligible, subject to Microsoft’s final compatibility guidance. The current Windows 11 hardware requirements include a compatible 64-bit processor with at least two cores, 4 GB of memory, 64 GB of storage, UEFI firmware with Secure Boot capability, TPM 2.0 and DirectX 12-compatible graphics.
These are minimum requirements rather than a recommended specification for business use. A device with only 4 GB of memory may technically satisfy the Windows 11 requirements but struggle with modern browsers, videoconferencing, security software, Microsoft 365 applications and other typical business workloads. Organisations should consider device age, manufacturer support, available storage, memory, battery condition, driver availability, warranty status and expected operational life. A device that can install 26H2 is not automatically a device that should remain in service for another two or three years.
There is also an unusual exception involving Windows 11 26H1. Microsoft says devices running 26H1 will not be able to upgrade directly to 26H2 because 26H1 is based on a different Windows core. Version 26H1 was created for selected new hardware platforms rather than as a general feature update for existing Windows PCs. Those devices will receive a route to a future Windows release instead.
Version 26H2 will begin a new Windows support lifecycle when it becomes generally available. Microsoft provides 24 months of support for Windows 11 Home, Pro, Pro Education and Pro for Workstations feature updates. Enterprise and Education editions receive 36 months of support. The final 26H2 end-of-support dates will depend on its official release date.
This is particularly relevant for organisations still using Windows 11 24H2. According to Microsoft’s Windows release information, Windows 11 24H2 Home and Pro reach the end of support on 13 October 2026. Windows 11 24H2 Enterprise and Education remain supported until 12 October 2027. Windows 11 25H2 Home and Pro remain supported until 12 October 2027, while Enterprise and Education are supported until 10 October 2028.
An organisation already running 25H2 does not therefore need to deploy 26H2 immediately to remain supported. It has time to monitor the early rollout, complete testing and select an appropriate deployment date. Organisations still using Windows 11 24H2 Pro have a more immediate decision to make. They should already be planning a move to either 25H2 or 26H2 before the October 2026 support deadline.
Operating system version management is an important part of Cyber Essentials compliance. The Cyber Essentials Requirements for IT Infrastructure version 3.3 requires software to be licensed and supported by the supplier. It also requires vulnerability fixes to be applied within 14 days where the vendor describes the vulnerabilities as critical or high risk, where they have a CVSS v3 base score of 7 or above, or where the vendor does not provide severity information.
The release of 26H2 does not automatically mean every organisation must install it within 14 days. It is a feature update, and supported earlier Windows versions can continue to be used. However, an organisation cannot continue relying indefinitely on a Windows version after it reaches the end of support. Once a version stops receiving security updates, it may no longer meet the Cyber Essentials supported-software requirement. Businesses should therefore maintain an accurate inventory of operating system editions and versions, record their support deadlines and plan upgrades before those deadlines create an urgent compliance problem.
Preparation should begin with an accurate asset inventory. Every device should be recorded alongside its Windows edition, build number, hardware model, processor, available storage, management status and primary user or function. This will identify devices approaching the end of support, devices that may not be eligible for 26H2 and devices that need further investigation before deployment.
Establish a Representative Pilot Group
The pilot group should include different hardware models, departments, user roles and working arrangements. Remote users, office-based users, privileged users and employees who depend on specialist applications should all be represented. Restricting the pilot to the IT team can give a misleading impression of compatibility. IT employees may use newer hardware and a narrower range of business applications than finance, operations, audit, customer service or other departments. The pilot should run for long enough to identify intermittent problems, not simply confirm that the device restarts successfully.
Test Applications and Security Controls
Testing should cover endpoint protection, antivirus or endpoint detection and response software, full-disk encryption, VPN clients, identity systems, multifactor authentication, printers, scanners, browser extensions, accessibility software, virtualisation and line-of-business applications. Particular attention should be given to software that installs drivers, changes the Windows shell, relies on older Windows components or performs low-level monitoring. These products are more likely to experience compatibility problems following an operating system update.
Businesses should also verify that logging and monitoring continue to work. Security events, device compliance information, update status and endpoint alerts should still reach the relevant management platforms after the upgrade.
Confirm Backup and Recovery Arrangements
Before deployment, organisations should verify that important data is backed up and that restoration has recently been tested. BitLocker recovery keys should be available to authorised support personnel. Local administrator recovery processes should also be checked, particularly where devices are managed through Microsoft Entra ID or a mobile device management platform.
The organisation should document how to remove or roll back the update if a critical issue is discovered. It should also know how a device will be recovered if it cannot start normally. Point-in-time restore may eventually make this process easier, but businesses should not rely on a new recovery feature until they have confirmed that it is enabled, correctly configured and tested.
Use a Phased Deployment
A phased rollout reduces the risk of a single problem affecting every device simultaneously. Deployment can begin with IT and a small technical test group, followed by a representative business pilot. The next stage can cover general users before the update reaches critical teams, executives, privileged administrators or devices supporting time-sensitive processes.
Between each stage, the organisation should review installation failures, application problems, user reports, performance changes, security alerts and support-ticket volumes. Where a compatibility issue is identified, deployment should be paused until the cause, affected devices and available mitigation are understood.
Retain Evidence of the Decision
The deployment process should be documented. Useful evidence includes the asset inventory, pilot results, application-compatibility checks, risk decisions, approved exceptions, deployment dates, failure rates and confirmation that backups and rollback arrangements were tested. This supports internal governance and can provide evidence for Cyber Essentials Plus, ISO 27001, customer assurance, internal audit and wider risk-management activities.
There is no universal requirement to install Windows 11 26H2 on the first day it becomes available. Organisations already using Windows 11 25H2 have time to monitor the initial rollout and complete a controlled pilot. Those still using Windows 11 24H2 Pro face a more immediate support deadline and should ensure they have a documented upgrade route.
The enablement-package approach should reduce the technical risk, installation time and disruption associated with the update. It does not remove the need to test activated features, security controls, recovery functions and business-critical applications. The appropriate deployment date should be based on support status, business risk, compatibility testing and operational readiness rather than pressure to adopt the newest version immediately.
At AJC, we can help organisations assess their readiness for Windows 11 26H2, identify unsupported or unsuitable devices, review hardware and application compatibility and develop a phased deployment plan.
We can also review endpoint patching, secure configuration, vulnerability management, backup and recovery arrangements against Cyber Essentials, Cyber Essentials Plus, ISO 27001 and wider business continuity requirements.
By preparing for 26H2 before it becomes generally available, organisations can take advantage of its faster deployment and improved recovery capabilities while maintaining security, compliance and operational resilience.
Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
What is Windows 11 26H2?
Windows 11 26H2 is Microsoft’s main annual Windows 11 feature update for the second half of 2026. It uses the same underlying servicing platform as Windows 11 24H2 and 25H2.
When Will Windows 11 26H2 Be Released?
Microsoft has not announced an exact date. General availability is expected during autumn 2026, most likely around late September or October.
Is Windows 11 26H2 a Large Update?
For eligible, fully updated devices on Windows 11 24H2 or 25H2, it should be delivered through a small enablement package rather than a complete operating system replacement. Devices on older servicing branches may require a larger feature update.
Does Windows 11 26H2 Have New Hardware Requirements?
Microsoft has not announced any new 26H2-specific minimum requirements at the time of writing. PCs officially supported on Windows 11 24H2 or 25H2 are expected to remain eligible, subject to final compatibility information.
Can Windows 11 26H1 Devices Upgrade to 26H2?
No. Microsoft says 26H1 uses a different Windows core and cannot upgrade directly to 26H2. Those devices will receive a route to a future Windows release.
Does Cyber Essentials Require 26H2 to Be Installed Within 14 Days?
Not simply because it is a feature update. Cyber Essentials requires software to remain supported and requires qualifying critical and high-risk vulnerability fixes to be installed within 14 days. An organisation can continue using an earlier Windows version while that version remains supported and receives the required security updates.
Does Point-in-Time Restore Replace Organisational Backups?
No. It provides an additional local recovery option, but it does not replace independent backups, tested restoration, disaster recovery or business continuity arrangements.
Should Businesses Install 26H2 as Soon as It Is Released?
Most businesses should begin with a controlled pilot. The correct deployment date will depend on the support status of the current Windows version, hardware eligibility, application compatibility and the organisation’s operational risk.
Sources:
https://learn.microsoft.com/en-us/windows/configuration/windows-backup/?tabs=intune
https://learn.microsoft.com/en-us/windows/release-health/windows11-release-information
https://blogs.windows.com/windows-insider/2026/03/20/our-commitment-to-windows-quality/
https://learn.microsoft.com/en-us/windows/configuration/point-in-time-restore?tabs=csp
https://learn.microsoft.com/en-us/windows/configuration/windows-backup/?tabs=intune
https://www.microsoft.com/en-us/windows/windows-11-specifications?r=1
https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
In this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...
Read MoreA recent cyber security incident affecting London Stansted Airport has highlighted the risks associated with customer data, even when financial...
Read MoreWhen a data breach is attributed to human error, the underlying cause may extend far beyond the actions of one...
Read More