Windows 11 26H2: Sixty-Six New Policies and a Typo Fix
It has been a while since I last went through a fresh set of ADMX files on this blog. The last one covered Windows 10 21H2, so it is that time again. Microsoft has published the Administrative Templates for Windows 11, version 26H2, and I compared them with the 25H2 package. The full comparison is attached to this post.
The short version: 26H2 is a small update with a surprisingly opinionated set of new policies. Quite a few are about AI, some are about who decides what runs on the client, and a handful can quietly break recovery or authentication if you enable them simply because they sound secure.
A small package, not a quiet release
26H2 ships as an enablement package for devices running 24H2 and 25H2. The three releases share a servicing branch, so most of the code is already on your devices and the update switches selected features on, with one restart in most cases. Enterprise and Education get 36 months of support, Home and Pro get 24, and the first monthly update is due on October 13, 2026. Microsoft's IT pro's guide and What's new for IT pros cover the details. The parts I would put on a slide:
- Security: Administrator protection (just-in-time admin rights with profile separation), built-in Sysmon (off by default), Smart App Control that can be switched on or off without a clean install, Enhanced Sign-in Security for peripheral fingerprint readers, ML-KEM and ML-DSA in CNG and .NET, and the end of default trust for cross-signed drivers.
- Management: Autopilot device association, settings restore at first sign-in for hybrid joined devices, Cloud PCs and multi-user environments, point-in-time restore, policy-based removal of preinstalled apps, RSAT on Arm64 and app update orchestration.
- On by default for commercial devices: Windows settings backup, app-specific taskbar actions and the File Explorer improvements that sat behind temporary commercial controls in 25H2.
And WMIC is gone. If a login script still calls it, that script has found a new hobby: failing.
Not all of this shows up in the templates. Administrator protection, Sysmon, Smart App Control, point-in-time restore and device association have no new ADMX setting, so there is no point searching the Administrative Templates for them. Administrator protection is off by default and is configured through Security Options or Intune. Microsoft currently excludes AVD session hosts and Windows 365 Cloud PCs from support; check its requirements before adding it to an image.
The numbers, and why they are smaller than they look
The 25H2 package has 232 ADMX files and 3,621 policies; 26H2 has 236 files and
3,686 policies. That works out at 66 added, 9 changed and 1 removed,
plus four new files: CAM_AI.admx, DPAPI.admx,
GroupPolicyPreferencesLogging.admx and SecureBoot.admx.
Two of those numbers need context.
- The one removal is a typo fix.
TurnOffAPISampingbecomesTurnOffAPISampling, and the registry value changes fromDisableAPISampingtoDisableAPISamplingas well. Nothing documents the old name as an alias, so treat them as two separate settings and check existing GPOs. - 21 of the additions are duplicates. The new
GroupPolicyPreferencesLogging.admxdefines the Group Policy Preferences logging settings thatgrouppolicypreferences.admxstill contains, with the same IDs and the same registry keys. Both files place them in a category called Logging and tracing. I have not verified how the two definitions appear in GPMC; either copy targets the same registry values. Configure each setting in one place only.
That leaves 44 genuinely new settings. All numbers here come from Microsoft's downloadable Administrative Templates for both versions, not from templates extracted from an installation image, which can differ.
AI: hiding the prompt is not turning it off
CloudContent.admx gains Disable Copilot Pin Screen,
which stops the Microsoft 365 Copilot setup recommendation from appearing at
sign-in. The help text is refreshingly honest: it does not disable Copilot and
does not affect licensing. Somebody will still write "AI disabled" into a change
ticket. Please don't let it be you.
If the requirement is that the app goes away, Remove Microsoft Copilot App is the policy, and it comes with conditions: Microsoft 365 Copilot and Microsoft Copilot are both installed, the user did not install Microsoft Copilot themselves, and it has not been launched in the last 28 days. Users can install it again.
The new CAM_AI.admx is where agents live:
ConfigureAgentConnectors: 0 = user in control, 1 = force enable, 2 = force disable.AgentConnectorAccessPolicy: a JSON allow list of MCP host and server connections.AgentConsentDuration: how long a user's Allow lasts, in hours, from 1 to 8,760. The default is 720 hours. One click, thirty days.
The WindowsAI Policy CSP lists these as Windows Insider Preview and excludes Pro, while some template support labels are broader. Check your editions before these end up in a baseline.
Finally, Set the DLP provider ID for Recall writes
SetDataLossPreventionProviderKey (REG_SZ) under the WindowsAI policy
key. Recall uses that provider if it is installed correctly. Writing a string to
the registry installs nothing, so a green compliance dashboard only proves that
the string arrived. Microsoft's policy description limits this to Enterprise
and Education client SKUs.
Privacy: defaults with exceptions
AppPrivacy.admx adds three permissions: access to text content
from foreground applications, access to passkeys and passkey autofill. They
follow the familiar pattern of a default (user in control, force allow or force
deny) plus per-app lists of package family names stored as REG_MULTI_SZ.
Per-app entries override the default, so "default deny" is exactly as strict as
whoever maintains the exception list. Learn lists the passkey settings as
Preview; they arrive alongside 26H2's support for passkeys in plugin credential
managers.
Client control
Policy-based app removal is one of the headline management
features, and in the templates it is a new element in an existing policy:
DynamicRemovalList under Remove Default Microsoft Store packages
from the system. Add package family names, one per line, and Windows removes
those MSIX or APPX apps at OOBE and at user sign-in, skipping system components.
Two details from the
Learn article
matter before you use it: removed apps stay blocked until you take them off the
list, and multi-session environments are not supported. That excludes Windows
Enterprise multi-session hosts in AVD.
Maintenance windows arrive in WindowsUpdate.admx.
You choose which actions the window controls: download, install and restart;
install and restart; or restart only. Anything you don't select can still happen
outside the window, so restart only means exactly that. A one-time window
that started more than three months ago is ignored. MaxPauseDays
caps user pauses at 1 to 35 days. The
Update Policy CSP
marks the interval options and MaxPauseDays as Preview.
The smaller ones: DisableTaskbarPosition and
DisableTaskbarSize keep the taskbar at the bottom and at its default
size now that users can move it to any edge. ConfigureCameraOptions
selects AutoShare or SafeMode, the template's names for Multi-App Camera and Basic
Camera. EnableWindowsRestore turns settings restore on or off. And a
new Defender policy lets you pick the safe deployment channel that
decides when devices receive Defender platform and engine updates.
Security and recoverability: read the help before you enable
This is the section where enabling a setting because it sounds secure can cost you a weekend.
- Disable BitLocker trust of WinRE (
DisableWinRETrust): WinRE then needs the recovery key to reach the OS volume. The help lists Startup Repair, Quick Machine Recovery, push-button reset and MDM remote reset or wipe as operations that may need someone at the device. Quick machine recovery is one of the features 26H2 extends, so decide both together.AllowTrustedOfflineScanonly skips the key while WinRE is still trusted. - NTLM Enhanced Blocking: a master switch plus criteria for accounts, devices and applications, with an audit mode that logs what would be blocked. The template links to the NTLM auditing article, which does not cover the blocking settings yet. Audit first.
- Enable Microsoft Entra ID Authentication Enforcement on an RDP host requires Entra authentication without fallback when Network Level Authentication is enabled separately. NLA is a prerequisite; this policy does not enable it. Check every client, jump host and break-glass path first.
- Trusted .rdp publisher thumbprints now accept
sha256:,sha384:andsha512:prefixes, and the newDisableSHA1CertThumbprintsoption ignores legacy SHA-1 entries. - Secure Boot:
SecureBoot.admxcovers certificate deployment, deployment assists and a switch that limits the daily Secure Boot service data event.AvailableUpdatesPolicyis 22852 (0x5944) when enabled. The help warns that the setting persists after the GPO is removed and that firmware certificates cannot be rolled back from Windows. Read the servicing status for progress, not the policy value. - ReFS on removable disks: two new policies audit or block ReFS mounts on hot-pluggable disks and on USB or IEEE 1394 disks. A restart is needed before a change applies.
- Clipboard and drag-and-drop copies: file group descriptor
operations now reject file names that try to escape the destination folder.
AllowAllCopyFGDDestinationsswitches that check off. Treat any GPO that enables it as an exception that needs a reason. - Non-standard profile paths:
AllowNonStandardUserProfilePathslets profile registry hives and AppData accept non-standard path formats. The help warns about security risks and recommends it only for an application that needs it.
The security baseline: two changes
The Windows 11, version 26H2 security baseline has a published summary listing two changes compared with 25H2:
| Setting | 25H2 baseline | 26H2 baseline |
|---|---|---|
| Printers\Configure Windows Ready Print driver ranking | Not in the baseline (new in 26H2) | Enabled |
| Internet Explorer\Internet Control Panel\Advanced Page\Turn off encryption support | Use TLS 1.1 and TLS 1.2 | Use TLS 1.2 and TLS 1.3 |
Print driver ranking makes Windows prefer the inbox Microsoft IPP Class Driver over vendor V3/V4 drivers when it installs a printer that supports IPP through USB or network discovery. Printers added directly as TCP/IP printers behave as before, and existing printers keep their driver until they are reinstalled. According to the help text, ranking is already on when nothing is configured; the GPO mainly stops local administrators from switching it off.
The TLS change sets SecureProtocols to 10240
instead of 2560. TLS 1.1 has been obsolete for years, but there is always one
appliance that disagrees. Find it before the baseline does.
Changes to existing policies
Nine existing policies changed. Two of them matter: the app removal policy
gained DynamicRemovalList, and the trusted .rdp publisher policy
gained the SHA-1 option. Turn off background refresh of Group Policy now
spells out its enabled and disabled values, and the rest are support-label
changes for the Start menu recommendation settings, RPC packet privacy for
printing and disconnect-on-lock for remote sessions. Those support-label changes
add no registry writes.
All new policies
For completeness, here are the 45 additions that are not Group Policy Preferences logging duplicates: 44 new settings plus the renamed API sampling policy.
| ADMX file | Policy | ID | Scope |
|---|---|---|---|
| AppDeviceInventory.admx | Turn off API Sampling | TurnOffAPISampling | Machine |
| AppDeviceInventory.admx | Turn off application inbox dependency component | TurnOffApplicationInboxDependencyData | Machine |
| AppPrivacy.admx | Let Windows apps access text content from foreground applications | LetAppsAccessForegroundText | Machine |
| AppPrivacy.admx | Let Windows apps access passkeys | LetAppsAccessPasskeys | Machine |
| AppPrivacy.admx | Let Windows apps autofill passkeys | LetAppsAccessPasskeysEnumeration | Machine |
| AppxPackageManager.admx | Enable Allowed Zones for MSIX Packages | EnableMsixAllowedZones | Machine |
| AppxPackageManager.admx | Enable Microsoft SmartScreen checks for MSIX Packages | EnableMsixSmartScreenCheck | Machine |
| CAM_AI.admx | Agent Connector Access Policy | AgentConnectorAccessPolicy | Machine |
| CAM_AI.admx | Agent Consent Duration | AgentConsentDuration | Machine |
| CAM_AI.admx | Configure Agent Connectors | ConfigureAgentConnectors | Machine |
| Camera.admx | Configure Camera Options | ConfigureCameraOptions | Machine |
| CloudContent.admx | Disable Copilot Pin Screen | DisableCopilotPinScreen | Machine |
| CloudContent.admx | Disable Get Started | DisableGetStarted | Machine |
| CredentialProviders.admx | Show NFC tap location indicator on logon screen | EnableNFCTapLocationIndicator | Machine |
| DPAPI.admx | Set the DPAPI backup keys rotation period | DomainBackupKeyRotationPeriod | Machine |
| Explorer.admx | Disable File Explorer feature to prelaunch a window in the background | DisableFileExplorerPrelaunch | Machine |
| Explorer.admx | Make Print Screen key yieldable | MakePrintScreenKeyYieldable | Machine |
| Kerberos.admx | Allow IP address-based SPNs during Kerberos authentication | EnableTryIPSPN | Machine |
| Ntlm.admx | NTLM Enhanced Blocking | BlockNtlm | Machine |
| Printing.admx | Configure Windows Ready Print driver ranking | ConfigureWindowsReadyPrintDriverRanking | Machine |
| ReAgent.admx | Allow offline scan from trusted Windows Recovery Environment | AllowTrustedOfflineScan | Machine |
| refs.admx | Control mounting ReFS volumes on USB and IEEE 1394 disks | BlockExternalBusMount | Machine |
| refs.admx | Control mounting ReFS volumes on hot-pluggable disks | BlockHotplugMount | Machine |
| SecureBoot.admx | Limit Secure Boot Required Service Data | LimitSecureBootRequiredServiceData | Machine |
| SecureBoot.admx | Enable Secure Boot Certificate Deployment | SecureBoot_AvailableUpdatesPolicy | Machine |
| SecureBoot.admx | Automatic Certificate Deployment via Updates | SecureBoot_HighConfidenceOptOut | Machine |
| SecureBoot.admx | Certificate Deployment via Controlled Feature Rollout | SecureBoot_MicrosoftUpdateManagedOptIn | Machine |
| SettingSync.admx | Enable Windows Restore | EnableWindowsRestore | Machine |
| Sharing.admx | DisableInlineCompose | DisableInlineCompose | Machine |
| Sharing.admx | DisableShareAppPromotions | DisableShareAppPromotions | Machine |
| Taskbar.admx | Disable changing the taskbar position | DisableTaskbarPosition | Both |
| Taskbar.admx | Disable changing the taskbar size | DisableTaskbarSize | Both |
| tcpip.admx | Set CLAT Permit | IPxlatCfg_01_PermitNonCellularCLAT | Machine |
| tcpip.admx | Set CLAT Get Prefix Information from RA | IPxlatCfg_02_GetPrefixInfoFromRA | Machine |
| tcpip.admx | Set CLAT Get Prefix Information from DNS | IPxlatCfg_03_GetPrefixInfoFromDNS | Machine |
| TerminalServer.admx | Enable Microsoft Entra ID Authentication Enforcement | TS_MICROSOFT_ENTRA_ID_AUTHENTICATION_ENFORCEMENT_POLICY | Machine |
| UserProfiles.admx | Allow user profile registry hives and AppData from non-standard paths | AllowNonStandardUserProfilePaths | Machine |
| VolumeEncryption.admx | Disable BitLocker trust of Windows Recovery Environment (WinRE) | DisableWinRETrust_Name | Machine |
| WindowsCopilot.admx | On-Device Registry Logging Level | OnDeviceRegistryLoggingLevel | Machine |
| WindowsCopilot.admx | Remove Microsoft Copilot App | RemoveMicrosoftCopilotApp | Both |
| WindowsCopilot.admx | Set the DLP provider ID for Recall | SetDataLossPreventionProvider | Both |
| WindowsDefender.admx | Select the Microsoft Defender safe deployment channel | Root_DeploymentChannel | Machine |
| WindowsExplorer.admx | Allow file group descriptor operations to write to any destination path | AllowAllCopyFGDDestinations | Machine |
| WindowsUpdate.admx | Configure maintenance windows for automatic updates | MaintenanceWindow | Machine |
| WindowsUpdate.admx | Configure the maximum number of days that updates can be paused | MaxPauseDays | Machine |
The full comparison
The attached comparison is a single HTML file that also works offline. It lists every added, removed and changed policy with registry paths, values and the original help text, summarizes the 26H2 release and the baseline changes, and includes search, filters and a CSV export.
Note
The comparison uses Microsoft's 25H2 and 26H2 Administrative Templates with the en-US ADML files. It describes what the templates say, not what a device does with them. Where Learn still calls a setting Preview, the comparison says so.
26H2 is a small package, but the templates show where Windows management is heading: AI settings that need an owner, more control over what stays on the client, and security settings whose real cost shows up during recovery. None of them is hard to configure. The hard part, as usual, is deciding what you actually want.