Upgrade to Windows 11 26H2 Using Intune: Enterprise Deployment Guide

Table of content

Quick Answer: To upgrade managed devices to Windows 11 version 26H2 in Microsoft Intune, set the Feature update deferral period to 0 days within your Windows Update Ring policy, then create a Feature Update deployment policy targeting “Windows 11, version 26H2”. For devices already running Windows 11 24H2 or 25H2, the upgrade installs rapidly through an enablement package without a full operating system reinstallation.

Windows 11 26H2 Servicing Architecture and Upgrade Mechanics

Microsoft released Windows 11 version 26H2 (OS Build 26300) as an annual feature update. For enterprise systems administrators, understanding how Microsoft delivers this update determines deployment timelines, bandwidth planning, and downtime expectations.

The upgrade path depends directly on the source operating system build:

  • Devices running Windows 11 version 24H2 or version 25H2 share a common core operating system structure with 26H2. New features were delivered in a dormant state through preceding monthly cumulative updates. Upgrading eligible endpoints requires an enablement package (EKB), which acts as an activation switch, providing a fast installation and typically requiring a single restart in most scenarios.
  • Devices running older Windows releases (such as Windows 11 22H2 or 23H2, and Windows 10) cannot receive the 26H2 enablement package directly. Windows 11 22H2 is out of support, and 23H2 is approaching end of servicing. These devices follow a supported feature update or operating system upgrade path and may require multiple restarts.
Source Operating SystemRecommended 26H2 Upgrade PathDeployment TypeRestart
Windows 11 25H2Direct upgrade to 26H2Enablement PackageTypically 1
Windows 11 24H2Direct upgrade to 26H2Enablement PackageTypically 1
Windows 11 23H2Upgrade using supported Windows installation or feature update pathFull feature update / OS upgradeMultiple may be required
Windows 11 22H2Upgrade to a supported Windows 11 release before or alongside migration to 26H2Full OS upgrade pathMultiple may be required
Windows 10 22H2Windows 11 in-place upgrade, subject to hardware and eligibility requirementsFull OS upgradeMultiple may be required
Important: Windows 11 26H2 is delivered as an enablement package only to eligible devices already running Windows 11 24H2 or 25H2. Devices running older Windows versions follow a different feature update or operating system upgrade path and should not be represented as receiving the 26H2 enablement package directly.
Important Prerequisite Check: Before deploying Windows 11 26H2, verify that target machines meet Microsoft minimum hardware requirements (TPM 2.0, UEFI Secure Boot, and supported 64-bit processors). If a device fails these requirements, Microsoft telemetry triggers a safeguard hold and Intune will report the update as OfferReady or NotApplicable without applying it.

Enterprise Prerequisites for Intune Feature Update Policies

Before creating the deployment profile in the Microsoft Intune admin center, confirm that your tenant and endpoints meet these four technical requirements:

  • Licensing: Endpoints must be licensed for Windows 10/11 Enterprise E3 or E5, Microsoft 365 Enterprise E3 or E5, Microsoft 365 Business Premium, or Windows 10/11 Education A3 or A5.
  • Management Authority: Devices must be enrolled in Microsoft Intune and either Microsoft Entra joined or Microsoft Entra hybrid joined.
  • Windows Diagnostic Data: Telemetry must be configured to at least Required (Basic). If diagnostic data is turned off, Intune cannot monitor update progress or generate compliance reports.
  • Network Endpoints: Firewalls and proxy servers must allow outbound traffic to Microsoft Update and Windows Update for Business endpoints (including *.prod.do.dsp.mp.microsoft.com and *.delivery.mp.microsoft.com).
Windows 11 Version 25H2 OS Build 26200 Winver Baseline Before Upgrade
Figure 1: Baseline client running Windows 11 version 25H2 (OS Build 26200.9457) before initiating the 26H2 upgrade.

Step 1: Configure Windows Update Rings to Prevent Policy Conflicts

One of the most frequent errors in enterprise update management is configuring feature update deferral days inside an Update Ring while simultaneously assigning a Feature Update policy. When both policies conflict, the update ring deferral settings can override or stall the feature update policy rollout.

To establish a clean update architecture, configure your Update Ring as follows:

  1. Sign in to the Microsoft Intune admin center.
  2. Navigate to Devices > Windows > Windows updates (or Quality updates) and select your target Update Ring policy.
  3. Under Update settings, set Feature update deferral period (days) to 0. Setting this value to 0 hands full version authority over to your Feature Update policy.
  4. Set Upgrade Windows 10 devices to Latest Windows 11 release to No if you want your Feature Update policy to control exactly which devices upgrade.
  5. Configure your deployment deadlines under User experience settings. For instance, set a 5-day deadline for feature updates and a 2-day grace period to ensure predictable compliance across remote devices.
Intune Windows Update Ring Configuration with Feature Update Deferral Period 0 Days

Figure 2: Update ring configuration setting Feature update deferral period to 0 days with a 5-day feature update deadline.

Step 2: Create the Windows 11 26H2 Feature Update Policy

With update rings configured, you can now define the target operating system release. Feature update policies pin managed devices to a specific version of Windows, preventing unwanted upgrades until you explicitly approve the next release.

  1. In the Intune admin center, navigate to Devices > Windows > Windows updates.
  2. Select the Feature updates tab from the top navigation.
  3. Click + Create and select Create feature update policy from the dropdown menu.
Navigate to Windows Updates Feature Updates Blade and Click Create Feature Update Policy

Figure 3: Locating the Feature updates tab and launching the policy creation workflow.

Step 3: Define Deployment Settings and Version Targets

On the Deployment settings screen, specify the profile details and select the target build:

  • Name: Provide a descriptive identifier, such as Upgrade to Windows 11 version 26H2.
  • Description: Document the scope of the deployment for your team (for example, Feature updates policy to upgrade Windows 11 devices to version 26H2).
  • Feature update to deploy: Open the dropdown menu and select Windows 11, version 26H2.
  • Update Availability: Select Make available to users as a required update. This setting ensures the update installs automatically according to your update ring deadlines rather than waiting for manual user initiation.
  • Rollout options: Select Make update available as soon as possible for pilot groups. For broad production groups, you can select gradual rollout to stage deployment across defined scheduling intervals.
Select Windows 11 Version 26H2 as Required Feature Update Deployment in Intune

Figure 4: Configuring deployment settings targeting Windows 11, version 26H2 as a required update.

Step 4: Assign Policy to Phased Pilot Groups

A structured phased deployment minimizes operational risk. Never assign a new major feature release to all enterprise endpoints simultaneously. Target a pilot validation ring first.

  1. On the Assignments tab, click Add groups under Included groups.
  2. Select your designated pilot device group (for example, TechEUC - UAT).
  3. Under Excluded groups, add any sensitive device groups, kiosk devices, or executive systems that must remain on their current production baseline until initial pilot validation concludes.
  4. Click Next to proceed.
Assign Windows 11 26H2 Feature Update Policy to TechEUC UAT Device Group

Figure 5: Targeting the deployment policy to the pilot user acceptance testing group (TechEUC – UAT).

Step 5: Review and Deploy the Policy

On the Review + create tab, verify all configured parameters. Confirm that the Target version reads Windows 11, version 26H2, Rollout options are set to ImmediateStart, and the correct pilot group is listed.

Click Create. Intune will compile the policy and prepare device targeting across your tenant.

Review Summary and Confirm Creation of Windows 11 Version 26H2 Policy in Microsoft Intune

Figure 6: Final review summary confirming the deployment parameters before creation.

Step 6: Trigger Client Sync and Validate Installation

Once assigned, Intune pushes the policy to targeted endpoints during their regular check-in cycle. In a lab or pilot scenario, you can accelerate policy delivery directly from the client device.

To force an immediate check-in, open a PowerShell prompt as administrator on the client machine and run the following command to trigger the Intune Management Extension and Device Enrollment sync:



POWERSHELL • Sync-IntuneDevice.ps1

# Trigger immediate MDM sync with Microsoft Intune
Get-ScheduledTask -TaskPath "\Microsoft\Windows\EnterpriseMgmt\*" | Where-Object { $_.TaskName -like "*Schedule created by enrollment client*" } | Start-ScheduledTask

# Initiate Windows Update detection cycle
$WUSession = New-Object -ComObject Microsoft.Update.Session
$WUSearcher = $WUSession.CreateUpdateSearcher()
$WUSearcher.Search("IsInstalled=0 and Type='Software'") | Out-Null

After the check-in completes, open Settings > Windows Update. The client will detect the feature update policy and begin downloading Windows 11, version 26H2.

Windows 11 Version 26H2 Pending Restart Notification in Windows Update Settings

Figure 7: Windows 11, version 26H2 installation complete and pending restart with organization deadline enforcement.

When the download and staging finish, Windows prompts for a restart. Following the reboot, open the run dialog (Windows Key + R), type winver, and press Enter to verify the active build.

Winver Dialog Confirming Windows 11 Version 26H2 OS Build 26300 Successful Upgrade

Figure 8: Winver dialog confirming successful upgrade to Windows 11 Version 26H2 (OS Build 26300.9457).

Step 7: Monitor Enterprise Compliance in Intune Reports

After deploying to your pilot ring, monitor the tenant-level progress through Intune reporting tools:

  1. In Intune admin center, navigate to Reports > Windows updates.
  2. Select Windows 10 and later feature updates.
  3. Under Feature update policy, choose your policy (Upgrade to Windows 11 version 26H2).
  4. Click Generate again to refresh telemetry data.
Intune Feature Update Reports Generating Windows 10 and Later Feature Updates Compliance

Figure 9: Generating the feature updates compliance report in Intune Reports blade.

The report displays the aggregate deployment state for every targeted endpoint. Successful devices appear with an Installed state and Success aggregate status.

TechEUC-1 Device Status Installed Success on Windows 11 Version 26H2 in Intune Report

Figure 10: Device TechEUC-1 verified with Installed state and Success aggregate status for Windows 11 version 26H2.

Troubleshooting Common Windows 11 26H2 Upgrade Issues

When an endpoint fails to receive or install the 26H2 update, use these diagnostic channels to isolate the root cause.

1. Client Registry Policy Verification

When you deploy feature updates through native Intune Feature Update profiles, Microsoft uses the cloud-orchestrated Windows Update for Business deployment service (WUfB-DS) rather than writing legacy static target version strings to the local registry. The primary confirmation that Intune has enrolled the client in feature update servicing is the FeatureUpdateEnrolled flag.

To inspect the active MDM policy state on the endpoint, open PowerShell as an administrator and execute:



POWERSHELL • Check-WUfBPolicy.ps1

# Verify Intune WUfB-DS enrollment and policy parameters
$RegPath = "HKLM:\SOFTWARE\Microsoft\PolicyManager\current\device\Update"
Get-ItemProperty -Path $RegPath | Select-Object FeatureUpdateEnrolled, DeferFeatureUpdatesPeriodInDays, ConfigureDeadlineForFeatureUpdates, TargetReleaseVersion, TargetReleaseVersionInfo

A properly enrolled device displays:

  • FeatureUpdateEnrolled = 1 (confirms the device is registered with the cloud deployment service, which handles 26H2 targeting dynamically).
  • DeferFeatureUpdatesPeriodInDays = 0 (confirms that ring deferrals are zeroed to avoid policy contention).
  • ConfigureDeadlineForFeatureUpdates = 5 (reflects your configured deployment deadline in days).
  • TargetReleaseVersion and TargetReleaseVersionInfo may appear empty on native Intune profiles. These legacy values populate only when version targeting is explicitly enforced via Settings Catalog, Administrative Templates, or Group Policy rather than the native deployment service.

2. Event Viewer Diagnostic Logs

Open Event Viewer and navigate to Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin.

  • Event ID 813: Confirms the client successfully applied MDM update policy strings from Intune.
  • Event ID 814: Details specific policy value changes pushed to the operating system.
  • Event ID 404: Indicates policy processing failure, typically due to conflicting Group Policy or configuration manager co-management workloads.
Event Viewer Event ID 813 DeviceManagement-Enterprise-Diagnostics-Provider MDM PolicyManager Verification

Figure 11: Event Viewer Event ID 813 confirming successful MDM PolicyManager update application for Windows 11 26H2.

3. Checking Safeguard Holds

Microsoft automatically places safeguard holds on devices with known hardware or driver incompatibilities to prevent faulty upgrades. To check if a device is blocked by a safeguard hold, query the Windows Update diagnostic log via PowerShell:



POWERSHELL • Check-SafeguardHolds.ps1

# Inspect Safeguard Hold IDs on local machine
$HoldPath = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Update\TargetingInfo\Installed\Client.OS.*"
Get-ItemProperty -Path $HoldPath -ErrorAction SilentlyContinue | Select-Object Version, SafeguardHoldList

4. Microsoft Account Sign-in Assistant Service (wlidsvc)

Windows Update for Business requires the Microsoft Account Sign-in Assistant service to authenticate device identity with Microsoft cloud update infrastructure. If this service is disabled by hardening scripts, feature updates fail silently with error code 0x80070422.

Verify that wlidsvc startup type is set to Manual or Automatic:



POWERSHELL • Verify-WlidSvc.ps1

Get-Service -Name wlidsvc | Select-Object Name, Status, StartType

Rollback and Uninstall Procedures

If an unexpected application conflict emerges after deploying Windows 11 26H2, administrators have two recovery mechanisms:

  • Intune Uninstall Period: Within your Update Ring policy, the setting Set feature update uninstall period (2 – 60 days) defines how long the Windows.old recovery directory remains active on the machine. During this window, users or administrators can roll back from Settings > System > Recovery > Go back.
  • Enablement Package Removal: If the device was upgraded via the enablement package from 24H2 or 25H2, the update can be uninstalled rapidly like a standard quality update using DISM without reinstalling the entire operating system.


POWERSHELL • Rollback-26H2Package.ps1

# Query installed enablement packages using DISM in PowerShell
Get-WindowsPackage -Online | Where-Object { $_.PackageName -like "*Enablement*" -or $_.PackageName -like "*26H2*" } | Select-Object PackageName, PackageState

# Remove the identified enablement package and return to previous build
dism.exe /Online /Remove-Package /PackageName:<PackageIdentity> /Quiet /NoRestart

Frequently Asked Questions

Can I upgrade directly from Windows 10 to Windows 11 26H2 using Intune?

Yes. If your Windows 10 endpoints meet the hardware prerequisites for Windows 11, assigning the Windows 11 26H2 feature update policy initiates a full in-place operating system migration. The client downloads the complete installation image, stages the files, and upgrades across a maintenance reboot.

Why is my Feature Update policy not applying to pilot devices?

The most common cause is non-zero deferral days configured in your Windows Update Ring policy. Ensure the Feature update deferral period is set to 0 days. Additionally, check that diagnostic data is set to at least Required and verify that the device is not held by a Microsoft safeguard hold.

How long does the 26H2 upgrade take on Windows 11 24H2 or 25H2?

On eligible 24H2 or 25H2 endpoints, the upgrade is delivered as an enablement package that provides a fast installation. Because the code is already dormant in preceding cumulative updates, the package activates the new feature set and typically requires a single restart in most scenarios.

What happens to devices running unsupported processors?

Devices with unsupported CPUs or lacking TPM 2.0 will fail hardware evaluation checks performed by Windows Update for Business. Intune will report these machines with a status of OfferReady or NotApplicable, and the update will not install.

Can users postpone the Windows 11 26H2 restart?

Yes, up until the deadline specified in your Update Ring policy. Once the deadline and grace period elapse, the Windows Update client automatically schedules and executes the restart to complete installation.

Related Intune Playbooks and Guides


TechEUC - Atoofa Shaikh
FIVERR PRO VERIFIED 12+ YRS EXPERIENCE

Atoofa Shaikh

Senior Microsoft 365, EUC & Cloud Endpoint Architect

Need custom Win32 App Packaging, PowerShell Automation, Zero-Touch Intune Autopilot, or SCCM Co-Management for your enterprise or MSP? I specialize in production-grade deployment architectures with zero downtime.

Table of content

Subscribe to Blog

Signup to our weekly newsletter