Windows 11, version 26H2 has had a lot written about it already — the enablement package mechanics, the driver trust changes, Settings Catalog day-zero support. This post deliberately skips all of that and covers the six features Microsoft documented in its own "IT Pro's Guide to Windows 11, version 26H2" and its what's-new page that haven't been written up anywhere yet: a post-quantum cryptography API, policy-based app removal, app update orchestration, RSAT on Arm64, dual-camera support, and a more secure batch-file mode.
No PowerShell in this one — everything here is either a Group Policy setting, something Windows does automatically, or a portal-only upgrade step. Every fact is sourced directly to Microsoft's own documentation and quoted verbatim where it matters.
Microsoft's "IT Pro's Guide" to 26H2 is long, and most IT teams read the first few sections — enablement package, servicing branch, driver changes — and stop there, because that's where the deployment-critical information lives. The last third of that guide quietly lists half a dozen features that will show up in your estate regardless of whether you went looking for them. This post is that last third, explained properly.
Windows 11, version 26H2 adds API support for NIST post-quantum cryptography (ML-KEM, ML-DSA), lets you remove more built-in Microsoft apps via Group Policy by package family name, introduces app update orchestration so participating apps can coordinate with Windows Update instead of patching independently, brings full RSAT (Server Manager, GPMC, DNS/DHCP tools, AD management) to Arm64 devices for the first time, adds Multi-App Camera so more than one app can use a webcam at once, and gives App Control for Business authors a more secure batch-file processing mode that stops a script changing itself mid-run. None of these are default-on changes you need to urgently respond to — they're capabilities worth knowing exist before a user or an app discovers them for you.
Who needs to read this
| If you are… | What this means for you |
|---|---|
| Desktop / app packaging | You can finally remove more built-in Microsoft apps via Group Policy, and should know app update orchestration exists before an app vendor asks you to enable it. |
| Arm64 device fleet owner | RSAT finally works on Arm64 — if your Arm64 devices have been second-class for admin tooling, this closes that gap directly. |
| Security / App Control for Business | The batch-file processing mode and the post-quantum crypto APIs are both things worth knowing about even before you have an immediate use for them. |
| Service desk / 1st line | Multi-App Camera changes expected webcam behaviour — a user asking "why can two apps use my camera at once now" has a real, documented answer. |
The problem: six real features, zero write-ups
26H2 shipped on 29 September 2026, and the coverage since has concentrated almost entirely on what admins need to act on immediately: the enablement package mechanics, the driver trust removal, day-zero Settings Catalog controls. That's the right priority order — those are the things that can break a rollout.
But Microsoft's own IT Pro's Guide to 26H2 documents several more features that never made it into that first wave of coverage, simply because none of them are urgent. They don't block an upgrade, they don't need a fleet-wide policy change on day one, and most of them are off, dormant, or simply "available if you look." That's exactly the category of feature that quietly surprises a helpdesk six months later — a user with two apps fighting over a webcam, a packaging team asking why an old Microsoft app won't uninstall the normal way, a security review that turns up a crypto API nobody remembered enabling.
Why it happens: each feature explained, with the exact Microsoft wording
1. Post-quantum cryptography APIs (ML-KEM, ML-DSA)
Quantum computers, once powerful enough, will be able to break the encryption schemes almost everything online currently relies on. The industry's answer is a new generation of encryption algorithms designed specifically to resist that future attack — "post-quantum cryptography." Windows 11, version 26H2 is where Microsoft adds the plumbing for developers to actually use them.
Microsoft's own wording: "Windows adds API support for NIST post-quantum cryptography algorithms ML-KEM and ML-DSA in accordance with FIPS 203 and FIPS 204. You can use these algorithms for key exchange, signing, and decryption through Cryptography. You can also use Next Generation (CNG) and .NET. ML-KEM as a standalone algorithm for TLS key exchange."
In plain terms: this is an API for developers, not a setting for IT admins to flip. Nothing in your environment starts using post-quantum cryptography automatically. What changes is that any application targeting Windows can now call these algorithms through CNG or .NET, and ML-KEM specifically can be used for TLS key exchange — the handshake step where two systems agree on an encryption key before a connection starts.
2. Policy-based removal of preinstalled Microsoft apps
Removing a built-in Microsoft app has historically meant per-user PowerShell, provisioned-package removal, or accepting that some apps simply come back after every feature update. 26H2 adds a genuine Group Policy path for more of these apps.
Microsoft's own wording: "With policy-based removal of preinstalled Microsoft apps, you can specify additional MSIX or APPX packaged apps for removal. Use their app package family names through Group Policy."
Practically, this means identifying the package family name of whatever built-in app you want gone, and adding it to the relevant policy rather than scripting a removal that has to be re-run after every update.
3. App update orchestration
Today, most applications patch themselves on their own schedule, completely independent of Windows Update — which is exactly why a device can show "up to date" in Windows Update while three separate apps are quietly nagging the user to restart for their own updates.
Microsoft's own wording, from the IT Pro's Guide itself: "App update orchestration allows participating applications to coordinate updates with Windows Update for improved scheduling and a more streamlined update experience."
4. RSAT on Arm64
Remote Server Administration Tools — the toolkit for managing Active Directory, DNS, DHCP and Group Policy from a Windows client rather than logging onto a server — has never officially supported Arm64 devices. Anyone managing AD from a Surface Pro X or another Arm-based device has had to find a workaround. 26H2 closes that gap directly.
Microsoft's own wording: "RSAT on Arm64 enables IT administrators to use tools including Server Manager, Group Policy Management Tools, DNS Server Tools, DHCP Server Tools, and Active Directory management tools on Windows 11 Arm64 devices."
5. Multi-App Camera and Basic Camera mode
Historically, only one application could hold a webcam stream at a time — if Teams had it, nothing else could use it until Teams released it. 26H2 changes that specific behaviour.
Microsoft's own wording: "Multi-App Camera allows multiple applications to access the camera stream at the same time. Basic Camera mode provides simplified camera functionality that you can use for troubleshooting or improving stability. Configure Multi-App Camera and Basic Camera modes through Group Policy."
Both modes are Group Policy – configurable, which matters for two different audiences: Multi-App Camera for anyone running scenarios that genuinely need simultaneous camera access (a virtual webcam utility alongside a conferencing app, for example), and Basic Camera mode specifically as a troubleshooting lever when a camera driver or app is behaving unreliably.
6. A more secure batch-file processing mode
Batch files and Command Prompt scripts have a long-standing, rarely discussed weakness: a running script can be modified on disk while it's still executing, and the interpreter will pick up the change mid-run. That's a real attack surface for anything that writes to the same location it executes from.
Microsoft's own wording: "Administrators and Application Control for Business policy authors have additional control over how Windows processes batch files and Command Prompt scripts. You can administratively enable a more secure processing mode that prevents batch files from changing during execution."
How to verify: confirming a device is actually on 26H2
Before worrying about which of the six features above apply to you, confirm the device is actually running 26H2 in the first place — no script needed.
- On the device, go to Settings › System › About.
- Under Windows specifications, check the Version field. 26H2 shows as OS build 26300 or higher.
At the fleet level, Intune reports the OS version per device under Devices › All devices, in the OS version column — filter or sort on that column to see your 26H2 adoption at a glance.
The fix: a simple, portal-only path to 26H2 (no scripts)
This is the short version of getting a managed fleet onto 26H2, using only the Intune admin center — for the full deployment mechanics (enablement package behaviour, servicing branch detail, safeguard holds), see the dedicated deployment guide linked in References.
- Sign in to the Microsoft Intune admin center.
- Go to Devices › Windows › Feature updates for Windows 11 (under Windows update rings/policies, depending on your Intune UI version).
- Select Create profile, or edit an existing feature update profile.
- Set the Feature update version to Windows 11, version 26H2.
- Assign the profile to a pilot group first — not your whole organisation. 26H2 is delivered as a controlled feature rollout, so devices in the same ring can legitimately update at different times regardless of your own targeting.
- Monitor the pilot group's progress under Reports › Windows updates › Feature updates before expanding the assignment.
- Once the pilot confirms clean, expand the assignment to broader rings in your normal update-ring sequence.
Proof it worked: what each feature looks like once it's there
| Feature | What confirms it's present |
|---|---|
| Post-quantum crypto APIs | A developer can successfully call ML-KEM or ML-DSA through CNG or .NET on the device — not something visible in any UI. |
| Policy-based app removal | A built-in Microsoft app's package family name added to the relevant Group Policy is no longer present after the next policy refresh and reboot. |
| App update orchestration | A participating app's own update mechanism shows up coordinated with Windows Update's own scheduling, rather than its own independent nag/restart cycle. |
| RSAT on Arm64 | Server Manager, GPMC, DNS/DHCP tools and AD management tools install and run on an Arm64 device via the normal RSAT optional-feature installation. |
| Multi-App Camera | Two applications can access the webcam stream simultaneously once the policy is enabled, instead of the second app being blocked. |
| Secure batch-file mode | A batch file modified on disk mid-execution no longer has the running interpreter pick up the change — verified by App Control for Business policy authors as part of their own policy testing. |
Quick reference: all six features in one table
| Feature | Configured via | Default state |
|---|---|---|
| Post-quantum crypto (ML-KEM, ML-DSA) | Developer API (CNG, .NET) | Available for apps to call; nothing changes automatically |
| Policy-based app removal | Group Policy only (package family name) | Off until configured |
| App update orchestration | App developer opt-in | Inactive unless the app participates |
| RSAT on Arm64 | Standard RSAT optional-feature install | Not installed by default, same as x64 |
| Multi-App Camera / Basic Camera | Group Policy | Off until configured |
| Secure batch-file processing | App Control for Business policy | Off until administratively enabled |
Glossary
| Term | What it means here |
|---|---|
| Post-quantum cryptography | A new generation of encryption algorithms designed to remain secure even against a sufficiently powerful future quantum computer. ML-KEM and ML-DSA are two such algorithms, standardised by NIST as FIPS 203 and FIPS 204. |
| Package family name | The stable identifier Windows uses for an MSIX or APPX-packaged app, independent of version number — what you reference to target an app for removal via policy. |
| App update orchestration | An opt-in mechanism letting a participating application coordinate its own update schedule with Windows Update, instead of patching entirely independently. |
| RSAT (Remote Server Administration Tools) | The set of management consoles (Server Manager, GPMC, DNS/DHCP tools, AD tools) that let you administer servers and Active Directory from a Windows client rather than signing into the server directly. |
| Enablement package | The lightweight delivery mechanism used to move a device from 24H2 or 25H2 to 26H2, since all three share the same underlying servicing branch — not a full operating system reinstall. |
Frequently asked questions
Do I need to do anything about post-quantum cryptography right now?
Not operationally. This is an API for developers, not a setting. Nothing in a standard managed environment starts using these algorithms automatically just because devices are on 26H2. It matters if your organisation is actively tracking post-quantum readiness as a platform capability question.
Can I remove preinstalled apps via Intune instead of Group Policy?
For this specific 26H2 capability, no — Microsoft documents it as Group Policy only. If your estate has no on-premises Group Policy infrastructure, you're still dependent on whatever app-removal method you were already using before 26H2.
Will app update orchestration change how our existing apps patch themselves?
Only for apps whose developers have specifically built them to participate. Being on 26H2 doesn't retroactively bring any existing installed app under this coordination — it's infrastructure for vendors to adopt going forward, not an automatic behaviour change.
Does RSAT on Arm64 support everything RSAT supports on x64?
Microsoft's own list names Server Manager, Group Policy Management Tools, DNS Server Tools, DHCP Server Tools, and Active Directory management tools specifically. If you depend on a different RSAT component not in that list, verify it separately before standardising Arm64 devices for that specific admin task.
Is the secure batch-file mode on by default?
No. It's an administratively-enabled capability for App Control for Business policy authors, not a default behaviour change. A device on 26H2 with no changes made is just as exposed to the mid-execution-modification issue as one on an earlier version, until the mode is deliberately turned on.
References
- An IT Pro's Guide to Windows 11, version 26H2 — Windows IT Pro Blog. The primary source for app update orchestration and the RSAT on Arm64 tool list, quoted verbatim in this post.
- What's new in Windows 11, version 26H2 — Microsoft Learn. The primary source for the post-quantum cryptography APIs, policy-based app removal, Multi-App Camera/Basic Camera mode, and the secure batch-file processing mode, all quoted verbatim in this post.
- Windows 11 release information — Microsoft Learn. Confirms OS build 26300 for version 26H2, used in the verification section of this post.
Related reading on EndpointWeekly
- Windows 11 26H2 with Intune: Readiness, Enablement Package and Autopatch Deployment Guide — the full deployment mechanics, with every PowerShell verification command, that this post deliberately leaves out.
- Windows Driver Policy: Cross-Signed Kernel Drivers Are No Longer Trusted — the one genuinely deployment-critical change from this same wave of 26H2 documentation.
- Intune Has Day-Zero Support for Windows 11 26H2 — the new Settings Catalog controls, including Administrator Protection, not repeated in this post.