HomeNewsletterCommunityMVP FeedToolsArchiveBlogToday's NewsAboutServicesQuick Links★ Pro Subscribe free
← Back to Blog
Windows 11 Windows 1126H2Group PolicyRSATSecurityApp Control

Six Windows 11 26H2 Features Nobody’s Covered Yet, Straight From Microsoft

IA
Imran Awan
4 October 2026
Start here — why this post, when 26H2 is already everywhere

Windows 11, version 26H2 has had a lot written about it already — the enablement package mechanics, the driver trust changes, Settings Catalog day-zero support. This post deliberately skips all of that and covers the six features Microsoft documented in its own "IT Pro's Guide to Windows 11, version 26H2" and its what's-new page that haven't been written up anywhere yet: a post-quantum cryptography API, policy-based app removal, app update orchestration, RSAT on Arm64, dual-camera support, and a more secure batch-file mode.

No PowerShell in this one — everything here is either a Group Policy setting, something Windows does automatically, or a portal-only upgrade step. Every fact is sourced directly to Microsoft's own documentation and quoted verbatim where it matters.

Microsoft's "IT Pro's Guide" to 26H2 is long, and most IT teams read the first few sections — enablement package, servicing branch, driver changes — and stop there, because that's where the deployment-critical information lives. The last third of that guide quietly lists half a dozen features that will show up in your estate regardless of whether you went looking for them. This post is that last third, explained properly.

The short version

Windows 11, version 26H2 adds API support for NIST post-quantum cryptography (ML-KEM, ML-DSA), lets you remove more built-in Microsoft apps via Group Policy by package family name, introduces app update orchestration so participating apps can coordinate with Windows Update instead of patching independently, brings full RSAT (Server Manager, GPMC, DNS/DHCP tools, AD management) to Arm64 devices for the first time, adds Multi-App Camera so more than one app can use a webcam at once, and gives App Control for Business authors a more secure batch-file processing mode that stops a script changing itself mid-run. None of these are default-on changes you need to urgently respond to — they're capabilities worth knowing exist before a user or an app discovers them for you.

Who needs to read this

If you are…What this means for you
Desktop / app packagingYou can finally remove more built-in Microsoft apps via Group Policy, and should know app update orchestration exists before an app vendor asks you to enable it.
Arm64 device fleet ownerRSAT finally works on Arm64 — if your Arm64 devices have been second-class for admin tooling, this closes that gap directly.
Security / App Control for BusinessThe batch-file processing mode and the post-quantum crypto APIs are both things worth knowing about even before you have an immediate use for them.
Service desk / 1st lineMulti-App Camera changes expected webcam behaviour — a user asking "why can two apps use my camera at once now" has a real, documented answer.

The problem: six real features, zero write-ups

26H2 shipped on 29 September 2026, and the coverage since has concentrated almost entirely on what admins need to act on immediately: the enablement package mechanics, the driver trust removal, day-zero Settings Catalog controls. That's the right priority order — those are the things that can break a rollout.

But Microsoft's own IT Pro's Guide to 26H2 documents several more features that never made it into that first wave of coverage, simply because none of them are urgent. They don't block an upgrade, they don't need a fleet-wide policy change on day one, and most of them are off, dormant, or simply "available if you look." That's exactly the category of feature that quietly surprises a helpdesk six months later — a user with two apps fighting over a webcam, a packaging team asking why an old Microsoft app won't uninstall the normal way, a security review that turns up a crypto API nobody remembered enabling.

📋 Note: none of the six features in this post are deployment-blocking. If you're mid-upgrade and looking for what might break, the driver trust changes and the enablement package guide are the posts you want — linked in References below. This post is what to know once you're already on 26H2.

Why it happens: each feature explained, with the exact Microsoft wording

1. Post-quantum cryptography APIs (ML-KEM, ML-DSA)

Quantum computers, once powerful enough, will be able to break the encryption schemes almost everything online currently relies on. The industry's answer is a new generation of encryption algorithms designed specifically to resist that future attack — "post-quantum cryptography." Windows 11, version 26H2 is where Microsoft adds the plumbing for developers to actually use them.

Microsoft's own wording: "Windows adds API support for NIST post-quantum cryptography algorithms ML-KEM and ML-DSA in accordance with FIPS 203 and FIPS 204. You can use these algorithms for key exchange, signing, and decryption through Cryptography. You can also use Next Generation (CNG) and .NET. ML-KEM as a standalone algorithm for TLS key exchange."

In plain terms: this is an API for developers, not a setting for IT admins to flip. Nothing in your environment starts using post-quantum cryptography automatically. What changes is that any application targeting Windows can now call these algorithms through CNG or .NET, and ML-KEM specifically can be used for TLS key exchange — the handshake step where two systems agree on an encryption key before a connection starts.

✅ Tip: if your organisation has a post-quantum readiness or cryptographic-agility initiative already underway, this is the line to add to your Windows platform-capability inventory. It's a capability question for now ("can our platform do this"), not a configuration question ("is this turned on").

2. Policy-based removal of preinstalled Microsoft apps

Removing a built-in Microsoft app has historically meant per-user PowerShell, provisioned-package removal, or accepting that some apps simply come back after every feature update. 26H2 adds a genuine Group Policy path for more of these apps.

Microsoft's own wording: "With policy-based removal of preinstalled Microsoft apps, you can specify additional MSIX or APPX packaged apps for removal. Use their app package family names through Group Policy."

⚠ Gotcha: this is Group Policy only — there's no Intune CSP equivalent documented for this specific capability as of 26H2. If your estate is cloud-managed with no on-premises Group Policy, you cannot use this path and are still reliant on your existing provisioning or removal method.

Practically, this means identifying the package family name of whatever built-in app you want gone, and adding it to the relevant policy rather than scripting a removal that has to be re-run after every update.

3. App update orchestration

Today, most applications patch themselves on their own schedule, completely independent of Windows Update — which is exactly why a device can show "up to date" in Windows Update while three separate apps are quietly nagging the user to restart for their own updates.

Microsoft's own wording, from the IT Pro's Guide itself: "App update orchestration allows participating applications to coordinate updates with Windows Update for improved scheduling and a more streamlined update experience."

📋 Note: the word "participating" is doing real work here. This is an opt-in mechanism for app developers to hook into — it does not retroactively bring every installed app under Windows Update's scheduling. An app has to be built to participate before this changes anything for it. Treat this as infrastructure other vendors will adopt over time, not a switch you flip today.

4. RSAT on Arm64

Remote Server Administration Tools — the toolkit for managing Active Directory, DNS, DHCP and Group Policy from a Windows client rather than logging onto a server — has never officially supported Arm64 devices. Anyone managing AD from a Surface Pro X or another Arm-based device has had to find a workaround. 26H2 closes that gap directly.

Microsoft's own wording: "RSAT on Arm64 enables IT administrators to use tools including Server Manager, Group Policy Management Tools, DNS Server Tools, DHCP Server Tools, and Active Directory management tools on Windows 11 Arm64 devices."

✅ Tip: if your organisation has been standardising laptop admin tooling exclusively on x64 devices because of this exact gap, 26H2 removes the reason. Worth revisiting any "Arm64 devices can't be used for AD admin work" guidance you've published internally.

5. Multi-App Camera and Basic Camera mode

Historically, only one application could hold a webcam stream at a time — if Teams had it, nothing else could use it until Teams released it. 26H2 changes that specific behaviour.

Microsoft's own wording: "Multi-App Camera allows multiple applications to access the camera stream at the same time. Basic Camera mode provides simplified camera functionality that you can use for troubleshooting or improving stability. Configure Multi-App Camera and Basic Camera modes through Group Policy."

Both modes are Group Policy – configurable, which matters for two different audiences: Multi-App Camera for anyone running scenarios that genuinely need simultaneous camera access (a virtual webcam utility alongside a conferencing app, for example), and Basic Camera mode specifically as a troubleshooting lever when a camera driver or app is behaving unreliably.

6. A more secure batch-file processing mode

Batch files and Command Prompt scripts have a long-standing, rarely discussed weakness: a running script can be modified on disk while it's still executing, and the interpreter will pick up the change mid-run. That's a real attack surface for anything that writes to the same location it executes from.

Microsoft's own wording: "Administrators and Application Control for Business policy authors have additional control over how Windows processes batch files and Command Prompt scripts. You can administratively enable a more secure processing mode that prevents batch files from changing during execution."

⚠ Warning: this is administratively enabled, not on by default. If you rely on batch files or Command Prompt scripts as part of a security-sensitive workflow, this is worth evaluating directly with your App Control for Business policy rather than assuming 26H2 silently protects you. The capability exists; the protection only applies once you've turned it on.

How to verify: confirming a device is actually on 26H2

Before worrying about which of the six features above apply to you, confirm the device is actually running 26H2 in the first place — no script needed.

  1. On the device, go to Settings › System › About.
  2. Under Windows specifications, check the Version field. 26H2 shows as OS build 26300 or higher.
Settings › System › About
Windows specifications
Version26H2
OS build26300.…
⚠ Gotcha: don't compare build numbers to judge which version is "newer." 26H1 is OS build 28000 — a higher number than 26H2's 26300 — because it runs on a different Windows core entirely. If you're checking fleet-wide compliance by build number alone, compare against an explicit list of expected builds, not a greater-than check.

At the fleet level, Intune reports the OS version per device under Devices › All devices, in the OS version column — filter or sort on that column to see your 26H2 adoption at a glance.

The fix: a simple, portal-only path to 26H2 (no scripts)

This is the short version of getting a managed fleet onto 26H2, using only the Intune admin center — for the full deployment mechanics (enablement package behaviour, servicing branch detail, safeguard holds), see the dedicated deployment guide linked in References.

  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices › Windows › Feature updates for Windows 11 (under Windows update rings/policies, depending on your Intune UI version).
  3. Select Create profile, or edit an existing feature update profile.
  4. Set the Feature update version to Windows 11, version 26H2.
Devices › Windows › Feature updates for Windows 11 › Create profile
  1. Assign the profile to a pilot group first — not your whole organisation. 26H2 is delivered as a controlled feature rollout, so devices in the same ring can legitimately update at different times regardless of your own targeting.
  2. Monitor the pilot group's progress under Reports › Windows updates › Feature updates before expanding the assignment.
  3. Once the pilot confirms clean, expand the assignment to broader rings in your normal update-ring sequence.
📋 Note: devices already on 24H2 or 25H2 receive 26H2 as a lightweight enablement package rather than a full reimage — it's closer to flipping on features already present in the shared servicing branch than installing a new operating system. Devices on 26H1 cannot take this path at all; 26H1 runs on a different Windows core and needs its own separate upgrade route.
✅ Tip: if you manage devices through Windows Autopatch instead of building your own update rings, 26H2 is already included in the standard Autopatch release-management process — no separate feature-update profile is needed for Autopatch-managed devices.

Proof it worked: what each feature looks like once it's there

FeatureWhat confirms it's present
Post-quantum crypto APIsA developer can successfully call ML-KEM or ML-DSA through CNG or .NET on the device — not something visible in any UI.
Policy-based app removalA built-in Microsoft app's package family name added to the relevant Group Policy is no longer present after the next policy refresh and reboot.
App update orchestrationA participating app's own update mechanism shows up coordinated with Windows Update's own scheduling, rather than its own independent nag/restart cycle.
RSAT on Arm64Server Manager, GPMC, DNS/DHCP tools and AD management tools install and run on an Arm64 device via the normal RSAT optional-feature installation.
Multi-App CameraTwo applications can access the webcam stream simultaneously once the policy is enabled, instead of the second app being blocked.
Secure batch-file modeA batch file modified on disk mid-execution no longer has the running interpreter pick up the change — verified by App Control for Business policy authors as part of their own policy testing.
✅ Tip: most of these six are "nothing visible changes until you deliberately use them" features. The real proof-of-work here is simpler than any of the table rows above: confirm the device is genuinely on 26H2 (Section 3), and treat everything in this post as capability now available to you, not a state to audit for.

Quick reference: all six features in one table

FeatureConfigured viaDefault state
Post-quantum crypto (ML-KEM, ML-DSA)Developer API (CNG, .NET)Available for apps to call; nothing changes automatically
Policy-based app removalGroup Policy only (package family name)Off until configured
App update orchestrationApp developer opt-inInactive unless the app participates
RSAT on Arm64Standard RSAT optional-feature installNot installed by default, same as x64
Multi-App Camera / Basic CameraGroup PolicyOff until configured
Secure batch-file processingApp Control for Business policyOff until administratively enabled

Glossary

TermWhat it means here
Post-quantum cryptographyA new generation of encryption algorithms designed to remain secure even against a sufficiently powerful future quantum computer. ML-KEM and ML-DSA are two such algorithms, standardised by NIST as FIPS 203 and FIPS 204.
Package family nameThe stable identifier Windows uses for an MSIX or APPX-packaged app, independent of version number — what you reference to target an app for removal via policy.
App update orchestrationAn opt-in mechanism letting a participating application coordinate its own update schedule with Windows Update, instead of patching entirely independently.
RSAT (Remote Server Administration Tools)The set of management consoles (Server Manager, GPMC, DNS/DHCP tools, AD tools) that let you administer servers and Active Directory from a Windows client rather than signing into the server directly.
Enablement packageThe lightweight delivery mechanism used to move a device from 24H2 or 25H2 to 26H2, since all three share the same underlying servicing branch — not a full operating system reinstall.

Frequently asked questions

Do I need to do anything about post-quantum cryptography right now?

Not operationally. This is an API for developers, not a setting. Nothing in a standard managed environment starts using these algorithms automatically just because devices are on 26H2. It matters if your organisation is actively tracking post-quantum readiness as a platform capability question.

Can I remove preinstalled apps via Intune instead of Group Policy?

For this specific 26H2 capability, no — Microsoft documents it as Group Policy only. If your estate has no on-premises Group Policy infrastructure, you're still dependent on whatever app-removal method you were already using before 26H2.

Will app update orchestration change how our existing apps patch themselves?

Only for apps whose developers have specifically built them to participate. Being on 26H2 doesn't retroactively bring any existing installed app under this coordination — it's infrastructure for vendors to adopt going forward, not an automatic behaviour change.

Does RSAT on Arm64 support everything RSAT supports on x64?

Microsoft's own list names Server Manager, Group Policy Management Tools, DNS Server Tools, DHCP Server Tools, and Active Directory management tools specifically. If you depend on a different RSAT component not in that list, verify it separately before standardising Arm64 devices for that specific admin task.

Is the secure batch-file mode on by default?

No. It's an administratively-enabled capability for App Control for Business policy authors, not a default behaviour change. A device on 26H2 with no changes made is just as exposed to the mid-execution-modification issue as one on an earlier version, until the mode is deliberately turned on.

References

Related reading on EndpointWeekly

Was this post helpful?
React below — no account needed
Share this post
LinkedIn X / Twitter Reddit Bluesky

More from EndpointWeekly

Windows 11
Memory Integrity will not turn on: finding the incompatible…
Memory Integrity (HVCI) is the highest-value hardening toggle in Windows 11, and it…
Windows 11
DNS over HTTPS in Windows 11: encrypting resolution without…
Windows 11 ships a DNS over HTTPS client that most estates have never configured. Here is…
Windows 11
Hardening Remote Desktop on Windows 11: NLA, encryption level,…
Enabling RDP is one toggle. Hardening it is a dozen settings across the registry, Group…