HomeNewsletterCommunityMVP FeedToolsArchiveBlogToday's NewsAboutServicesQuick Links★ Pro Subscribe free
← Back to Blog
Intune IntuneSecurity BaselinesWindows 1126H2TLSPrinting

Windows 11 26H2 Security Baseline Is Now Available in Intune — What Changed and How to Deploy It

IA
Imran Awan
7 October 2026

On 6 October 2026, Microsoft updated its Intune Customer Success post with a one-line note: "The Windows security baseline for Windows 11, version 26H2 is now available for all customers in Microsoft Intune." Intune's own What's New page carries the same announcement under the week of 5 October.

That closes the gap flagged here on 30 September, when Windows 11 26H2 shipped with day-zero Settings Catalog support but no Intune baseline yet. The downloadable Group Policy version of the baseline had been out since 29 September. The native Intune version is now live too. Here is exactly what changed, what didn't, and how to move your existing profiles across without breaking anything.

The short version

The 26H2 baseline is a small update: Microsoft's own baselines team lists exactly two changed settings versus 25H2. Windows Ready Print driver ranking is now Enabled, and "Turn off encryption support" moves from TLS 1.1 + 1.2 to TLS 1.2 + 1.3. Configure NetBIOS settings was left out on purpose. Your existing baseline profiles will not update themselves, and the update process does not copy your assignments or scope tags - so the real risk here is not the settings, it's the migration.

Watch this post — YouTube walkthrough
Windows 11 26H2 Security Baseline in Intune — Migrate Safely
Windows 11 26H2 Security Baseline in Intune — Migrate Safely
Endpoint Weekly
Watch on YouTube Subscribe at @EndpointWeekly

The problem: nothing in your tenant changed on its own

A new baseline version appearing in Intune does not touch a single device. Microsoft's What's New entry says it directly: "Existing security baseline profiles don't automatically update to the new version."

What does change is the status of your current profiles. The moment a newer version is published, Microsoft's documentation says the settings in profiles based on older versions become read-only. You can still rename them, edit their description, and change their assignments. You can't change a single setting inside them, and you can't create a new profile from the old version.

So if you go to tweak one value in your 25H2 baseline profile this week, you will find you can't. That is not a permissions problem on your account. It is the version lock, and the only way past it is to move that profile to 26H2.

Note: Two different Microsoft teams publish this baseline in two different forms. The Microsoft Security Baselines team released the Group Policy package in the Security Compliance Toolkit on 29 September. The Intune team shipped the MDM version on 6 October. Same recommendations, one week apart - which is why the 30 September post here said the Intune baseline "isn't published yet."

Why it happens: how baseline versions work, and what's actually new in 26H2

A security baseline is not a live feed of Microsoft's recommendations. It is a versioned template. Each version is a frozen bundle of settings and default values. When you create a profile, you are taking a copy of that template at that version, plus whatever customisations you make.

That design is deliberate. It means Microsoft can never silently change a setting on your production fleet. The trade-off is that you have to move each profile forward yourself, and decide for each one whether to keep your own changes.

The two settings that changed

Microsoft's Security Baselines blog post for 26H2 lists exactly two changes since the 25H2 baseline. Everything else carries over unchanged.

Setting25H2 baseline26H2 baseline
Configure Windows Ready Print driver rankingNot in the baselineEnabled (new setting)
Turn off encryption supportTLS 1.1 and TLS 1.2Use TLS 1.2 and TLS 1.3
Configure NetBIOS settingsNot in the baselineNot in the baseline - deliberately left out (see below)

Change 1: Windows Ready Print driver ranking

What it does, in plain English: when a new printer is installed, Windows will prefer Microsoft's own built-in driver - the Microsoft IPP Class Driver - over a third-party driver from the printer manufacturer. IPP is the Internet Printing Protocol, a standard most modern printers speak.

Why Microsoft wants it on: third-party print drivers run with high privileges inside the print stack, and they have been a long-running source of serious vulnerabilities. Microsoft's own wording is that enabling it reduces "reliance on third-party print drivers in the stack, narrowing the overall print driver attack surface."

When it actually applies - this is the detail most summaries skip. Microsoft's post says driver ranking only kicks in when a printer is installed through a connection method that supports IPP, "such as USB or network multicast discovery." If the printer doesn't support IPP, "or is installed directly as a TCP/IP printer, there's no change in behavior." It also only affects new printer installs, not printers already on the device.

How to set it outside the baseline, if you need to:

Gotcha: As of this writing, Microsoft's Printers CSP reference still lists this policy's applicable OS as "Windows Insider Preview" - even though it is now in a production baseline and the 26H2 Settings Catalog. That is very likely the CSP page lagging behind, not the baseline being wrong. Still, don't take either page's word for it: confirm the setting actually lands on one of your own 26H2 pilot devices before you assume it does across the fleet.

Change 2: Turn off encryption support (TLS 1.2 and TLS 1.3 only)

What it does, in plain English: this policy controls which versions of TLS - the encryption that protects web traffic - are allowed for connections made through Windows' old Internet Explorer networking component, called WinINet. Its internal Group Policy name, Advanced_SetWinInetProtocols, gives that away.

What changed: the 25H2 baseline allowed TLS 1.1 and TLS 1.2. The 26H2 baseline allows TLS 1.2 and TLS 1.3. Microsoft's reasoning: "TLS 1.1 is now considered obsolete and is no longer recommended for enterprise environments."

Who could notice: anything that connects through WinINet to a server that only speaks TLS 1.1. In practice that means old internal web apps, ageing appliances with built-in admin pages, and legacy line-of-business software. A modern site that supports TLS 1.2 will not notice anything.

What's deliberately missing: Configure NetBIOS settings

Microsoft's 29 September note already flagged NetBIOS as "pending", and it did not make this release. The What's New entry explains why: the policy "is currently supported only on Windows Insider builds." Microsoft plans to add it in a future baseline update once it is available on supported, in-market Windows versions and in the Settings Catalog.

That means a further 26H2 baseline update is already expected. When it lands, your profiles will go read-only again and you will repeat the process below.

How to verify: find out which version your profiles are on

Before you change anything, get a list of every baseline profile in the tenant and the version each one uses.

  1. Sign in to the Microsoft Intune admin center.
  2. Go to Endpoint security › Security baselines.
  3. Look at the Security Baseline for Windows 10 and later row. The Last Published date should now be early October 2026.
  4. Select that baseline, then select Versions. This shows which versions your profiles are on and how many profiles use each one.
  5. Select Profiles. Any profile on an older version shows an arrow icon telling you a newer version exists.
Endpoint security › Security baselines › Security Baseline for Windows 10 and later › Versions

Here is the kind of picture you are looking for. The profile names below are examples - yours will differ:

Intune Admin Center - Security Baseline for Windows 10 and later - Profiles (illustrative)
Baseline - Corporate devices Version 25H2 · newer version available
Baseline - Kiosk devices Version 24H2 · newer version available
Baseline - Pilot ring Version 26H2 · latest

Next, check the two changed settings in each old profile. Open the profile, go to Properties, and expand Configuration settings. Note whether you ever customised either "Turn off encryption support" or anything under Printers. This matters in the next section.

Finally, capture a "before" picture on one pilot device, so you have something to compare against later. This command, run in an elevated PowerShell window, lists what the encryption support policy has currently written to the registry:

PowerShell (as Administrator) - before the 26H2 baseline
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings' -ErrorAction SilentlyContinue | Select-Object SecureProtocols # Write down the number shown. If the value is missing entirely, the # policy isn't applied to this device by any baseline or profile yet.

You don't need to decode the number. You only need to see it change after the 26H2 baseline lands, which is your proof the new TLS setting arrived.

The fix: move to the 26H2 baseline safely

You have two ways forward. Microsoft's documentation supports both.

Either way, the update creates a new, side-by-side profile. Your old profile is left exactly as it was, still assigned, still applying.

Watch out: The update process does not copy assignments or scope tags to the new profile. Microsoft's documentation is explicit: they "aren't carried over and remain blank." Forget to assign the new profile and it applies to no devices. Assign it but leave the old one assigned too, and the same devices receive two baselines with different values for the same setting - which is a conflict you will have to clean up.

Option A: update an existing profile (keeps your customisations)

  1. In the Intune admin center, go to Endpoint security › Security baselines › Security Baseline for Windows 10 and later.
  2. On the Profiles page, tick the checkbox next to the profile you want to move, then select Update Version.
  3. On the Update Version pane, choose Accept baseline changes but keep my existing setting customizations. (The other option, Accept baseline changes and discard existing setting customizations, gives you a pure default 26H2 profile.)
  4. Select Create. This opens the upgrade workflow for the new profile.
  5. On Basics, give it a clear name, for example Baseline - Corporate devices - 26H2.
  6. On Configuration settings, check the two changed settings by hand. Search for encryption support and driver ranking and confirm each shows the value you expect.
  7. On Scope tags, re-add the same scope tags the old profile had. They are not copied.
  8. On Assignments, assign it to a pilot group only for now.
  9. On Review, select Create. Microsoft notes that once saved, the profile immediately deploys to its assigned groups.
Security baselines › Profiles › select profile › Update Version
Gotcha: "Keep my existing setting customizations" means exactly that. If at some point you customised "Turn off encryption support" in your 25H2 profile - say, to keep an old TLS 1.1 app working - that customisation is carried into the new profile, and you will not get Microsoft's new TLS 1.2 + 1.3 value. Settings you left at the default pick up the new default. That's why step 6 above asks you to check the two changed settings by hand rather than trust the option name.

Option B: create a fresh 26H2 profile

  1. Go to Endpoint security › Security baselines and select Security Baseline for Windows 10 and later.
  2. Select Create policy. New profiles always use the latest version, which is now 26H2.
  3. On Basics, enter a name and description.
  4. On Configuration settings, review the defaults and change only what your environment genuinely needs.
  5. Add Scope tags, then Assignments to a pilot group.
  6. On Review + create, select Create.

Then: pilot, cut over, clean up

  1. Pilot for at least a few days on devices that represent your real estate. Test two things specifically: any internal web app or appliance page that might still be TLS 1.1 only, and installing a USB or auto-discovered network printer to confirm the Microsoft IPP Class Driver covers what your users need.
  2. Cut over one group at a time. Add a production group to the new 26H2 profile and, in the same sitting, remove that same group from the old profile.
  3. Clean up. Once the old profile has no assignments left, Microsoft says you can delete it. Keeping it unassigned for a week or two first gives you a quick reference if something needs comparing.
Tip: Because only two settings changed, this is one of the lowest-risk baseline updates Microsoft has shipped. That makes it a good moment to practise the update workflow properly - pilot group, one group at a time, remove old assignments as you go. The next update, when NetBIOS is added, will follow exactly the same steps.

Proof it worked

Check three places once the pilot devices have checked in.

  1. Versions view: go back to Security Baseline for Windows 10 and later › Versions. As you cut over, the profile count on 26H2 should rise and the count on older versions should fall to zero.
  2. Device status: open the new profile and review its device and per-setting status. Healthy pilot devices report Succeeded. Any setting showing Conflict almost always means the same device is still assigned to the old profile as well.
  3. On a pilot device: re-run the registry check from the verify section. The SecureProtocols value should now differ from the "before" number you wrote down.
PowerShell (as Administrator) - after the 26H2 baseline
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings' -ErrorAction SilentlyContinue | Select-Object SecureProtocols # Good: the number is different from your "before" reading. # Same number as before: the device is still getting the old value - # check for a leftover old-profile assignment or a carried-over customisation.

For printing, install a test printer over USB or via network discovery on a pilot device. If the printer supports IPP, its driver should show as the Microsoft IPP Class Driver in the printer's properties. Remember that printers added directly by TCP/IP address are not affected, so don't use one of those as your test.

References

Microsoft MVP community deep-dives

AuthorPostWhat it adds
Anoop C Nair (MVP)Windows 11 26H2 Security Baseline in Microsoft IntuneA screen-by-screen walkthrough of creating a new 26H2 baseline profile in the admin center

Related on EndpointWeekly

Was this post helpful?
React below — no account needed
Share this post
LinkedIn X / Twitter Reddit Bluesky

More from EndpointWeekly

Intune
Enrollment Time Grouping and Client-Driven Compliance: Two…
Enrollment Time Grouping puts a device in its target group during enrollment instead of…
Intune
Intune Has Day-Zero Support for Windows 11 26H2: New Settings…
Windows 11 26H2 shipped September 29, 2026, and Intune already has day-zero Settings…
Intune
What's Actually Changing in Intune and Windows for 2026 (No…
Licensing got simpler, Windows devices now have two ways to talk to the cloud, and new…