Home / Writing / Windows

Windows 11 26H2: Sixty-Six New Policies and a Typo Fix

2026.10.05 · Windows
Windows 11 26H2: Sixty-Six New Policies and a Typo Fix

It has been a while since I last went through a fresh set of ADMX files on this blog. The last one covered Windows 10 21H2, so it is that time again. Microsoft has published the Administrative Templates for Windows 11, version 26H2, and I compared them with the 25H2 package. The full comparison is attached to this post.

The short version: 26H2 is a small update with a surprisingly opinionated set of new policies. Quite a few are about AI, some are about who decides what runs on the client, and a handful can quietly break recovery or authentication if you enable them simply because they sound secure.

A small package, not a quiet release

26H2 ships as an enablement package for devices running 24H2 and 25H2. The three releases share a servicing branch, so most of the code is already on your devices and the update switches selected features on, with one restart in most cases. Enterprise and Education get 36 months of support, Home and Pro get 24, and the first monthly update is due on October 13, 2026. Microsoft's IT pro's guide and What's new for IT pros cover the details. The parts I would put on a slide:

  • Security: Administrator protection (just-in-time admin rights with profile separation), built-in Sysmon (off by default), Smart App Control that can be switched on or off without a clean install, Enhanced Sign-in Security for peripheral fingerprint readers, ML-KEM and ML-DSA in CNG and .NET, and the end of default trust for cross-signed drivers.
  • Management: Autopilot device association, settings restore at first sign-in for hybrid joined devices, Cloud PCs and multi-user environments, point-in-time restore, policy-based removal of preinstalled apps, RSAT on Arm64 and app update orchestration.
  • On by default for commercial devices: Windows settings backup, app-specific taskbar actions and the File Explorer improvements that sat behind temporary commercial controls in 25H2.

And WMIC is gone. If a login script still calls it, that script has found a new hobby: failing.

Not all of this shows up in the templates. Administrator protection, Sysmon, Smart App Control, point-in-time restore and device association have no new ADMX setting, so there is no point searching the Administrative Templates for them. Administrator protection is off by default and is configured through Security Options or Intune. Microsoft currently excludes AVD session hosts and Windows 365 Cloud PCs from support; check its requirements before adding it to an image.

The numbers, and why they are smaller than they look

The 25H2 package has 232 ADMX files and 3,621 policies; 26H2 has 236 files and 3,686 policies. That works out at 66 added, 9 changed and 1 removed, plus four new files: CAM_AI.admx, DPAPI.admx, GroupPolicyPreferencesLogging.admx and SecureBoot.admx. Two of those numbers need context.

  • The one removal is a typo fix. TurnOffAPISamping becomes TurnOffAPISampling, and the registry value changes from DisableAPISamping to DisableAPISampling as well. Nothing documents the old name as an alias, so treat them as two separate settings and check existing GPOs.
  • 21 of the additions are duplicates. The new GroupPolicyPreferencesLogging.admx defines the Group Policy Preferences logging settings that grouppolicypreferences.admx still contains, with the same IDs and the same registry keys. Both files place them in a category called Logging and tracing. I have not verified how the two definitions appear in GPMC; either copy targets the same registry values. Configure each setting in one place only.

That leaves 44 genuinely new settings. All numbers here come from Microsoft's downloadable Administrative Templates for both versions, not from templates extracted from an installation image, which can differ.

AI: hiding the prompt is not turning it off

CloudContent.admx gains Disable Copilot Pin Screen, which stops the Microsoft 365 Copilot setup recommendation from appearing at sign-in. The help text is refreshingly honest: it does not disable Copilot and does not affect licensing. Somebody will still write "AI disabled" into a change ticket. Please don't let it be you.

If the requirement is that the app goes away, Remove Microsoft Copilot App is the policy, and it comes with conditions: Microsoft 365 Copilot and Microsoft Copilot are both installed, the user did not install Microsoft Copilot themselves, and it has not been launched in the last 28 days. Users can install it again.

The new CAM_AI.admx is where agents live:

  • ConfigureAgentConnectors: 0 = user in control, 1 = force enable, 2 = force disable.
  • AgentConnectorAccessPolicy: a JSON allow list of MCP host and server connections.
  • AgentConsentDuration: how long a user's Allow lasts, in hours, from 1 to 8,760. The default is 720 hours. One click, thirty days.

The WindowsAI Policy CSP lists these as Windows Insider Preview and excludes Pro, while some template support labels are broader. Check your editions before these end up in a baseline.

Finally, Set the DLP provider ID for Recall writes SetDataLossPreventionProviderKey (REG_SZ) under the WindowsAI policy key. Recall uses that provider if it is installed correctly. Writing a string to the registry installs nothing, so a green compliance dashboard only proves that the string arrived. Microsoft's policy description limits this to Enterprise and Education client SKUs.

Privacy: defaults with exceptions

AppPrivacy.admx adds three permissions: access to text content from foreground applications, access to passkeys and passkey autofill. They follow the familiar pattern of a default (user in control, force allow or force deny) plus per-app lists of package family names stored as REG_MULTI_SZ. Per-app entries override the default, so "default deny" is exactly as strict as whoever maintains the exception list. Learn lists the passkey settings as Preview; they arrive alongside 26H2's support for passkeys in plugin credential managers.

Client control

Policy-based app removal is one of the headline management features, and in the templates it is a new element in an existing policy: DynamicRemovalList under Remove Default Microsoft Store packages from the system. Add package family names, one per line, and Windows removes those MSIX or APPX apps at OOBE and at user sign-in, skipping system components. Two details from the Learn article matter before you use it: removed apps stay blocked until you take them off the list, and multi-session environments are not supported. That excludes Windows Enterprise multi-session hosts in AVD.

Maintenance windows arrive in WindowsUpdate.admx. You choose which actions the window controls: download, install and restart; install and restart; or restart only. Anything you don't select can still happen outside the window, so restart only means exactly that. A one-time window that started more than three months ago is ignored. MaxPauseDays caps user pauses at 1 to 35 days. The Update Policy CSP marks the interval options and MaxPauseDays as Preview.

The smaller ones: DisableTaskbarPosition and DisableTaskbarSize keep the taskbar at the bottom and at its default size now that users can move it to any edge. ConfigureCameraOptions selects AutoShare or SafeMode, the template's names for Multi-App Camera and Basic Camera. EnableWindowsRestore turns settings restore on or off. And a new Defender policy lets you pick the safe deployment channel that decides when devices receive Defender platform and engine updates.

Security and recoverability: read the help before you enable

This is the section where enabling a setting because it sounds secure can cost you a weekend.

  • Disable BitLocker trust of WinRE (DisableWinRETrust): WinRE then needs the recovery key to reach the OS volume. The help lists Startup Repair, Quick Machine Recovery, push-button reset and MDM remote reset or wipe as operations that may need someone at the device. Quick machine recovery is one of the features 26H2 extends, so decide both together. AllowTrustedOfflineScan only skips the key while WinRE is still trusted.
  • NTLM Enhanced Blocking: a master switch plus criteria for accounts, devices and applications, with an audit mode that logs what would be blocked. The template links to the NTLM auditing article, which does not cover the blocking settings yet. Audit first.
  • Enable Microsoft Entra ID Authentication Enforcement on an RDP host requires Entra authentication without fallback when Network Level Authentication is enabled separately. NLA is a prerequisite; this policy does not enable it. Check every client, jump host and break-glass path first.
  • Trusted .rdp publisher thumbprints now accept sha256:, sha384: and sha512: prefixes, and the new DisableSHA1CertThumbprints option ignores legacy SHA-1 entries.
  • Secure Boot: SecureBoot.admx covers certificate deployment, deployment assists and a switch that limits the daily Secure Boot service data event. AvailableUpdatesPolicy is 22852 (0x5944) when enabled. The help warns that the setting persists after the GPO is removed and that firmware certificates cannot be rolled back from Windows. Read the servicing status for progress, not the policy value.
  • ReFS on removable disks: two new policies audit or block ReFS mounts on hot-pluggable disks and on USB or IEEE 1394 disks. A restart is needed before a change applies.
  • Clipboard and drag-and-drop copies: file group descriptor operations now reject file names that try to escape the destination folder. AllowAllCopyFGDDestinations switches that check off. Treat any GPO that enables it as an exception that needs a reason.
  • Non-standard profile paths: AllowNonStandardUserProfilePaths lets profile registry hives and AppData accept non-standard path formats. The help warns about security risks and recommends it only for an application that needs it.

The security baseline: two changes

The Windows 11, version 26H2 security baseline has a published summary listing two changes compared with 25H2:

Security baseline changes, 25H2 to 26H2
Setting25H2 baseline26H2 baseline
Printers\Configure Windows Ready Print driver rankingNot in the baseline (new in 26H2)Enabled
Internet Explorer\Internet Control Panel\Advanced Page\Turn off encryption supportUse TLS 1.1 and TLS 1.2Use TLS 1.2 and TLS 1.3

Print driver ranking makes Windows prefer the inbox Microsoft IPP Class Driver over vendor V3/V4 drivers when it installs a printer that supports IPP through USB or network discovery. Printers added directly as TCP/IP printers behave as before, and existing printers keep their driver until they are reinstalled. According to the help text, ranking is already on when nothing is configured; the GPO mainly stops local administrators from switching it off.

The TLS change sets SecureProtocols to 10240 instead of 2560. TLS 1.1 has been obsolete for years, but there is always one appliance that disagrees. Find it before the baseline does.

Changes to existing policies

Nine existing policies changed. Two of them matter: the app removal policy gained DynamicRemovalList, and the trusted .rdp publisher policy gained the SHA-1 option. Turn off background refresh of Group Policy now spells out its enabled and disabled values, and the rest are support-label changes for the Start menu recommendation settings, RPC packet privacy for printing and disconnect-on-lock for remote sessions. Those support-label changes add no registry writes.

All new policies

For completeness, here are the 45 additions that are not Group Policy Preferences logging duplicates: 44 new settings plus the renamed API sampling policy.

New ADMX policies in Windows 11, version 26H2 (excluding Group Policy Preferences logging duplicates)
ADMX filePolicyIDScope
AppDeviceInventory.admxTurn off API SamplingTurnOffAPISamplingMachine
AppDeviceInventory.admxTurn off application inbox dependency componentTurnOffApplicationInboxDependencyDataMachine
AppPrivacy.admxLet Windows apps access text content from foreground applicationsLetAppsAccessForegroundTextMachine
AppPrivacy.admxLet Windows apps access passkeysLetAppsAccessPasskeysMachine
AppPrivacy.admxLet Windows apps autofill passkeysLetAppsAccessPasskeysEnumerationMachine
AppxPackageManager.admxEnable Allowed Zones for MSIX PackagesEnableMsixAllowedZonesMachine
AppxPackageManager.admxEnable Microsoft SmartScreen checks for MSIX PackagesEnableMsixSmartScreenCheckMachine
CAM_AI.admxAgent Connector Access PolicyAgentConnectorAccessPolicyMachine
CAM_AI.admxAgent Consent DurationAgentConsentDurationMachine
CAM_AI.admxConfigure Agent ConnectorsConfigureAgentConnectorsMachine
Camera.admxConfigure Camera OptionsConfigureCameraOptionsMachine
CloudContent.admxDisable Copilot Pin ScreenDisableCopilotPinScreenMachine
CloudContent.admxDisable Get StartedDisableGetStartedMachine
CredentialProviders.admxShow NFC tap location indicator on logon screenEnableNFCTapLocationIndicatorMachine
DPAPI.admxSet the DPAPI backup keys rotation periodDomainBackupKeyRotationPeriodMachine
Explorer.admxDisable File Explorer feature to prelaunch a window in the backgroundDisableFileExplorerPrelaunchMachine
Explorer.admxMake Print Screen key yieldableMakePrintScreenKeyYieldableMachine
Kerberos.admxAllow IP address-based SPNs during Kerberos authenticationEnableTryIPSPNMachine
Ntlm.admxNTLM Enhanced BlockingBlockNtlmMachine
Printing.admxConfigure Windows Ready Print driver rankingConfigureWindowsReadyPrintDriverRankingMachine
ReAgent.admxAllow offline scan from trusted Windows Recovery EnvironmentAllowTrustedOfflineScanMachine
refs.admxControl mounting ReFS volumes on USB and IEEE 1394 disksBlockExternalBusMountMachine
refs.admxControl mounting ReFS volumes on hot-pluggable disksBlockHotplugMountMachine
SecureBoot.admxLimit Secure Boot Required Service DataLimitSecureBootRequiredServiceDataMachine
SecureBoot.admxEnable Secure Boot Certificate DeploymentSecureBoot_AvailableUpdatesPolicyMachine
SecureBoot.admxAutomatic Certificate Deployment via UpdatesSecureBoot_HighConfidenceOptOutMachine
SecureBoot.admxCertificate Deployment via Controlled Feature RolloutSecureBoot_MicrosoftUpdateManagedOptInMachine
SettingSync.admxEnable Windows RestoreEnableWindowsRestoreMachine
Sharing.admxDisableInlineComposeDisableInlineComposeMachine
Sharing.admxDisableShareAppPromotionsDisableShareAppPromotionsMachine
Taskbar.admxDisable changing the taskbar positionDisableTaskbarPositionBoth
Taskbar.admxDisable changing the taskbar sizeDisableTaskbarSizeBoth
tcpip.admxSet CLAT PermitIPxlatCfg_01_PermitNonCellularCLATMachine
tcpip.admxSet CLAT Get Prefix Information from RAIPxlatCfg_02_GetPrefixInfoFromRAMachine
tcpip.admxSet CLAT Get Prefix Information from DNSIPxlatCfg_03_GetPrefixInfoFromDNSMachine
TerminalServer.admxEnable Microsoft Entra ID Authentication EnforcementTS_MICROSOFT_ENTRA_ID_AUTHENTICATION_ENFORCEMENT_POLICYMachine
UserProfiles.admxAllow user profile registry hives and AppData from non-standard pathsAllowNonStandardUserProfilePathsMachine
VolumeEncryption.admxDisable BitLocker trust of Windows Recovery Environment (WinRE)DisableWinRETrust_NameMachine
WindowsCopilot.admxOn-Device Registry Logging LevelOnDeviceRegistryLoggingLevelMachine
WindowsCopilot.admxRemove Microsoft Copilot AppRemoveMicrosoftCopilotAppBoth
WindowsCopilot.admxSet the DLP provider ID for RecallSetDataLossPreventionProviderBoth
WindowsDefender.admxSelect the Microsoft Defender safe deployment channelRoot_DeploymentChannelMachine
WindowsExplorer.admxAllow file group descriptor operations to write to any destination pathAllowAllCopyFGDDestinationsMachine
WindowsUpdate.admxConfigure maintenance windows for automatic updatesMaintenanceWindowMachine
WindowsUpdate.admxConfigure the maximum number of days that updates can be pausedMaxPauseDaysMachine

The full comparison

The attached comparison is a single HTML file that also works offline. It lists every added, removed and changed policy with registry paths, values and the original help text, summarizes the 26H2 release and the baseline changes, and includes search, filters and a CSV export.

Note

The comparison uses Microsoft's 25H2 and 26H2 Administrative Templates with the en-US ADML files. It describes what the templates say, not what a device does with them. Where Learn still calls a setting Preview, the comparison says so.

26H2 is a small package, but the templates show where Windows management is heading: AI settings that need an owner, more control over what stays on the client, and security settings whose real cost shows up during recovery. None of them is hard to configure. The hard part, as usual, is deciding what you actually want.