Windows 11 26H2 Is Here: What to Do with Autopilot and Intune (and How to Report on It)

Windows 11 26H2 is generally available as of September 29, 2026. For most organizations running Windows Autopilot and Microsoft Intune, this is the calmest annual feature update in years: devices on 24H2 or 25H2 get a tiny enablement package and a single restart. But “calm” is not the same as “nothing to do”. There are lifecycle deadlines only weeks away, a new Windows 11 branch (26H1) that cannot take 26H2 at all, features that are now switched on by default for commercial devices, and a reporting stack that simply shows nothing if you have not flipped the right switches.

This post is the practical version: what Windows 11 26H2 actually is, what to do in Intune and Autopilot this week, what to be aware of before you press deploy, and how to report on the rollout so you can prove where every device is. All screenshots are from my own tenant, taken on release day.

If you want the Autopatch ring design and pilot-to-production exit criteria in more depth, I covered that earlier in Windows 11 26H2: Upgrade Paths, Autopatch & Pilot to Production. This post focuses on the GA release itself, Autopilot, Intune policy and reporting.

Windows 11 26H2 at a glance

General availabilitySeptember 29, 2026
Build26300 (10.0.26300.x)
Delivery for 24H2 and 25H2Enablement package (KB5121794), single restart
Delivery for 23H2 and Windows 10Full feature update (media-based, several GB)
Windows 11 26H1 devicesNot eligible for 26H2 (different Windows core)
Servicing36 months for Enterprise and Education, 24 months for Home and Pro
Hardware requirementsUnchanged from Windows 11 (TPM 2.0, UEFI Secure Boot, supported CPU)

Windows 11 24H2, 25H2 and 26H2 share one servicing branch. The code for most 26H2 features has already been delivered to your devices through the monthly cumulative updates, sitting dormant. The enablement package flips the version to 26H2, activates the features that were held back and resets the support clock. That is why Microsoft calls it a “predictable and low-disruption update”, and why app compatibility testing you already did on 24H2 or 25H2 largely carries forward.

Why you should not wait: the lifecycle dates that matter now

The most important reason to act on Windows 11 26H2 this month has nothing to do with new features. It is the support calendar:

  • Windows 11 24H2 Home and Pro reaches end of servicing on October 13, 2026. That is two weeks after 26H2 GA. Many small and mid-size businesses run Pro, often on Autopilot devices that shipped from the OEM with 24H2.
  • Windows 11 23H2 Enterprise and Education ends on November 11, 2026. These devices need a full feature update, not the enablement package.
  • Windows 11 24H2 Enterprise and Education is supported until October 13, 2027, and 25H2 Enterprise and Education until October 11, 2028.

If you have Pro devices on 24H2, 26H2 (or at minimum 25H2) needs to be on them before mid-October. The good news is that the enablement package makes that realistic even on a short timeline.

Step 1: Find out what you actually have

Before you create a single policy, get an honest inventory of Windows versions in the tenant. The quickest view is Devices > Windows > Windows devices with the OS version column visible. Build numbers map to versions like this:

BuildVersionPath to 26H2
10.0.19045Windows 10 22H2Full upgrade (hardware permitting)
10.0.22631Windows 11 23H2Full feature update
10.0.26100Windows 11 24H2Enablement package
10.0.26200Windows 11 25H2Enablement package
10.0.26300Windows 11 26H2Already there
10.0.28000Windows 11 26H1Not eligible, stays on the 26H1 path

My own tenant is a good example of why this matters. It is small, but it already contains three different stories: several 25H2 devices (26200) that will take the enablement package, one 23H2 device (22631) that needs a full upgrade, and one brand-new device on 26H1 (28000) that will never be offered 26H2.

Windows 11 26H2 Intune Windows devices OS version column
Windows devices in Intune with the OS version column: 25H2 (26200), 23H2 (22631) and a 26H1 device (28000) in the same tenant.

For anything beyond a handful of devices, export the list or pull it with Microsoft Graph PowerShell and group by build:

Connect-MgGraph -Scopes "DeviceManagementManagedDevices.Read.All"

$map = @{ '19045'='Win10 22H2'; '22631'='23H2'; '26100'='24H2'; '26200'='25H2'; '26300'='26H2'; '28000'='26H1' }

Get-MgDeviceManagementManagedDevice -All -Filter "operatingSystem eq 'Windows'" -Property "deviceName,osVersion" |
    Group-Object { ($_.OsVersion -split '\.')[2] } |
    Select-Object @{n='Build';e={$_.Name}}, @{n='Version';e={$map[$_.Name]}}, Count |
    Sort-Object Build

Pay special attention to edition. A 24H2 device on Enterprise has another year of support; the same build on Pro runs out on October 13.

Step 2: Clean up your update rings before you deploy

Feature update policies and update rings work together, and the combination is where most “why is nothing happening?” tickets come from. Microsoft’s guidance is clear: when you use a feature update policy, set the feature update deferral period in the update ring that targets the same devices to 0 days. The feature update policy then controls which version the device gets and when. A ring that still defers feature updates can block or delay the version you are trying to deliver, and the device will report PolicyConflictDeferral in the failure report.

Intune update rings with feature update deferral before Windows 11 26H2 rollout
Update rings in my tenant: several rings still defer feature updates by 5 to 7 days. Set this to 0 days on rings that share devices with a feature update policy.

While you are in the rings, check three more things:

  • Paused rings. A ring that was paused during an incident and never resumed will stop 26H2 as effectively as a deferral (PolicyConflictPause).
  • Windows 10 leftovers. Rings and policies named for Windows 10 often still carry old settings. Windows 10 reached end of support on October 14, 2025, and any remaining devices need an upgrade plan or ESU.
  • Conflicting GPOs. On hybrid or co-managed devices, a WSUS or deferral GPO that still applies will fight the MDM policy. Confirm the Windows Update workload sits with Intune.

Step 3: Create the Windows 11 26H2 feature update policy

Go to Devices > Windows > Windows updates > Feature updates. On release day the tab already shows Autopatch update readiness tiles, and in my tenant a yellow banner that we will come back to in the reporting section. The Create menu now offers both a classic Feature Update Policy and an Autopatch multi-phase release.

Intune Windows updates Feature updates tab with Autopatch update readiness
The Feature updates tab with Autopatch update readiness and a warning that Windows diagnostic data features are not enabled.

Choose Feature Update Policy. Windows 11, version 26H2 is already the default in the Feature update to deploy list, alongside 25H2, 24H2 and 23H2. Note that 26H1 is not in the list: it is not a feature update target, it is a separate branch for specific new hardware.

Intune feature update policy with Windows 11 version 26H2 selected
Creating a feature update deployment: Windows 11, version 26H2 is available and selected by default on GA day.

Settings I recommend for the first wave:

  • Name: something that tells the next admin what it is, for example WIN-FU-26H2-Pilot.
  • Required vs. optional: use Make available to users as a required update for managed rollout. The optional setting is useful for a self-service early adopter group, but you give up control of timing.
  • Rollout options: As soon as possible for the pilot, Gradually for broad. Gradual rollout spreads offers across groups and days, which protects your network and your service desk.
  • Assignments: device groups, not user groups. Start with IT, then a pilot of 5 to 10 percent across hardware models and departments, then broad.

Two behaviors to keep in mind. First, a feature update policy is also a “stay here” instruction: devices targeted by an existing 24H2 or 25H2 policy will not move to 26H2 until you change or replace that policy. Search for old feature update policies before you wonder why nothing happens. Second, a device should be in exactly one feature update policy. If it lands in two, the failure report shows DeploymentConflict and only the first assigned deployment is effective. Use exclusions to keep pilot and broad groups mutually exclusive.

If you use Windows Autopatch, create an Autopatch multi-phase release instead and let the Test, First, Fast and Broad rings stagger 26H2 for you. Plan any group changes first: you cannot edit an Autopatch group while a feature update release is in progress for it.

What to do if you use Windows Autopilot

Autopilot does not install a new Windows version. It provisions whatever image the OEM put on the device, whether that is 24H2, 25H2 or eventually 26H2. What happens after enrollment is controlled by your update policies. That leads to a few concrete tasks.

Make sure new devices land in the 26H2 policy on day one

New hardware arriving this quarter will mostly ship with 24H2 or 25H2. If your broad 26H2 policy targets a static group that nobody updates, every new Autopilot device will be one version behind from its first boot, and new Pro devices on 24H2 are two weeks from end of servicing. Target the policy at the same dynamic or device preparation device group your Autopilot devices land in, for example a dynamic group on the Autopilot ZTDID attribute:

(device.devicePhysicalIDs -any (_ -startsWith "[ZTDId]"))

For Autopilot device preparation, the device group you configure in the device preparation policy works the same way. Because the eKB is only a restart, new devices move to 26H2 shortly after the user has signed in, without a long upgrade experience.

Know what happens during OOBE

The Enrollment Status Page setting Install Windows quality updates (might restart the device) installs the monthly quality update during OOBE. It does not install the 26H2 feature update, so your ESP timing does not change. The version move happens after provisioning, driven by the feature update policy. If you have customers or users who expect “the latest Windows” out of the box, that is the expectation to set.

Look at device association for Autopilot device preparation

Windows 11 26H2 brings device association for Windows Autopilot device preparation. It lets you identify trusted corporate devices before enrollment, which enables device-targeted policies, automatic corporate enrollment and more customization during OOBE. That closes one of the biggest gaps between device preparation and classic Autopilot profiles. It sits under Devices > Windows > Enrollment, right above the device preparation policies.

Intune Windows enrollment with Autopilot device preparation and device association
Windows enrollment in Intune: Windows Backup and Restore, Device association, Autopilot device preparation and classic Windows Autopilot.

Decide on Windows Backup and Restore

In 26H2, Windows settings backup is enabled by default for eligible commercial devices, and the first sign-in restore experience now also supports Microsoft Entra hybrid joined devices, Cloud PCs and multi-user environments. For device refresh with Autopilot this is genuinely useful: the user signs in on the new device and gets settings and their Microsoft Store app list back. Administrator-configured policies are still honored, so if your organization has decided against it, make that decision explicit with the Windows Backup and Restore enrollment setting and the settings catalog, rather than relying on a default that just changed.

Plan for 26H1 hardware

Windows 11 26H1 ships on specific new devices and runs on a different Windows core. Microsoft states that these devices cannot update to 26H2. For Autopilot this means you will enroll a growing number of devices with build 28000 that are newer than 26H2 by build number but are not “on 26H2”. Check anything that makes decisions based on OS version:

  • Compliance policies that use Valid operating system builds ranges, for example 10.0.26100 to 10.0.26300. A 28000 device falls outside and becomes noncompliant, which with Conditional Access means blocked.
  • Dynamic groups and assignment filters on deviceOSVersion or osVersion that use startsWith “10.0.26”.
  • Reports and dashboards that calculate “on latest version” by comparing strings.

Reset, wipe and reimaging

Autopilot Reset and a local wipe reinstall from the device’s current OS, so a device that has taken 26H2 stays on 26H2. If you still maintain a corporate image for reimaging before Autopilot, update it to 26H2 media so reimaged devices do not start their life on a version that is about to go out of support.

What to be aware of in Windows 11 26H2

Most of these changes are good news. They are listed here because each of them can surprise a user, a script or a service desk if you did not know it was coming.

Features that are now on by default for commercial devices

Some features were delivered earlier through monthly updates but held back on commercial devices by temporary enterprise feature control. 26H2 enables them by default: Windows settings backup, app-specific actions from the taskbar, and a set of File Explorer enhancements. Tell your service desk and update end-user documentation before the pilot, not after. Also resist using the AllowTemporaryEnterpriseFeatureControl policy to force dormant features on across production: it bypasses exactly the controlled validation that the enablement model gives you.

WMIC is gone

The WMI command-line tool (WMIC) is removed and is no longer available as a Feature on Demand on 24H2 and later. Search your Intune remediations, platform scripts, Win32 app install commands and detection scripts for wmic and replace it with Get-CimInstance. A detection script that silently fails will make a Win32 app show as “not installed” and trigger reinstall loops.

# Old
wmic bios get serialnumber
# New
(Get-CimInstance -ClassName Win32_BIOS).SerialNumber

Cross-signed drivers lose default trust

Windows changes how the kernel trusts third-party drivers. Default trust for the old cross-signed driver program is removed. Drivers from the Windows Hardware Compatibility Program and an allow list of trusted legacy drivers are still allowed. Windows audits driver compatibility for at least 100 hours and three restarts before enforcement kicks in, which is exactly the kind of delayed impact that slips past a two-day pilot. Include devices with old scanners, label printers, VPN clients, dongles and specialist lab or production hardware in your pilot, and keep them there long enough.

Hotpatch is on by default for eligible devices

My tenant shows an Hotpatch Enablement banner on the Windows updates page: eligible devices receive hotpatch updates automatically, unless you configured hotpatch yourself in a quality update policy or opt out. That fits well with 26H2, since a feature update restart moves the device to a new baseline and hotpatch keeps restarts down afterwards. Just make sure your change process knows that “patched” no longer always means “restarted”.

New security capabilities are off until you turn them on

Several of the most interesting 26H2 features for Intune admins are available but not enabled. They are worth a proof of concept once the rollout is stable:

  • Administrator protection: just-in-time elevation with profile separation instead of standing admin rights. Enable with Intune or Group Policy, and test together with Endpoint Privilege Management if you use it.
  • Built-in Sysmon: System Monitor is now part of Windows, logs to the Windows Event Log and supports your own configuration files. No more packaging Sysmon as a Win32 app.
  • Smart App Control can be turned on or off without a clean install.
  • Passkey plugin credential managers and Windows Hello Enhanced Sign-in Security with supported external fingerprint readers.
  • Post-quantum cryptography APIs (ML-KEM and ML-DSA) in CNG and .NET.
  • A more secure batch file processing mode that prevents batch files from changing during execution, useful for Application Control for Business policy authors.

Recovery features to configure deliberately

Point-in-time restore can roll a PC back to a recent restore point, including apps, settings and personal files. Quick machine recovery can run a one-time remediation scan, but stays off on domain-joined or enterprise-managed devices unless you enable it. Both are useful for the service desk, and both should be decisions in your baseline rather than something you discover during an incident. The new policy-based removal of preinstalled Microsoft apps also accepts additional MSIX or APPX package family names, which may let you retire a removal script or two.

What users will notice

The redesigned Start menu with a scrollable All section, category and grid views, a taskbar that can move to the top, left or right and a smaller taskbar option, File Explorer and Windows Search improvements, Multi-App Camera, and fewer restarts because Windows Update bundles eligible updates with the monthly security update. None of these need a policy on day one, but a short “what’s new” note to users saves tickets.

Reporting on Windows 11 26H2 in Intune

A rollout you cannot measure is a rollout you cannot finish. Intune has good built-in reporting for feature updates, but it depends on prerequisites that many tenants, including my own, do not have turned on.

Prerequisite: turn on Windows data

Go to Tenant administration > Connectors and tokens > Windows data and enable Enable features that require Windows diagnostic data in processor configuration. For the readiness and compatibility reports, also enable Windows license verification, which confirms you own eligible Windows Enterprise licensing. Devices must send at least Required diagnostic data, and the feature update wizard itself reminds you to enable Windows health monitoring with the Windows Update scope to get detailed device states and errors.

Intune Windows data connector for Windows diagnostic data and license verification
Connectors and tokens > Windows data. Both toggles are off in my tenant, which is why the reports below have nothing to show.

This is a tenant-wide decision with a privacy dimension, so involve whoever owns data processing in your organization. But if it stays off, you are deploying 26H2 blind. This is what the Windows Autopatch feature update report looks like without it:

Windows Autopatch feature updates report not available without prerequisites
Reports > Windows Autopatch > Windows feature updates: “Reports are not available” when the tenant prerequisites are missing.

Service-side data from Windows Update usually arrives within an hour. Client-side data is processed in batches and refreshes about every eight hours, and only after you configure data collection. Turn it on at least a few days before the pilot so you have a baseline.

Before the rollout: readiness and compatibility risks

Go to Reports > Windows updates > Reports. Six reports live here:

Intune Windows updates reports list for Windows 11 26H2 reporting
Reports > Windows updates > Reports: feature update, distribution, expedited, readiness, compatibility risks and driver reports.
  • Windows Feature Update Device Readiness Report: pick Windows 11 26H2 as target OS and get per-device readiness with system requirement, app, driver and other issues. Run it before you assign the broad policy.
  • Windows Feature Update Compatibility Risks Report: the same data turned around, grouped by app and driver, so you can see which single driver blocks 40 devices.
  • Windows Update Distribution Report: how many devices are on each quality update level. Useful because a device far behind on cumulative updates is also a device that tends to struggle with feature updates.

For 24H2 and 25H2 devices the readiness report should be mostly green, as they already run the shared code base. The real value is on 23H2 and Windows 10 devices, which take a full upgrade, and in finding devices that fail Windows 11 hardware requirements.

During the rollout: feature update report and failures

The Windows Feature Update Report (Reports > Windows updates > Reports) shows status per policy. Select your 26H2 policy, generate the report and filter by update status. Each device moves through states such as Offer received, Download start, Install complete, Restart required and finally Update installed. For an enablement package the whole journey is short, so devices stuck in Restart required for days tell you that users are not restarting, not that the update is broken.

The Feature update failures report (Devices > Monitor) is where you troubleshoot. These alerts are the ones I see most in real 26H2-style rollouts:

AlertWhat it meansWhat to do
PolicyConflictDeferralAn update ring defers feature updatesSet feature deferral to 0 days on the ring
PolicyConflictPauseUpdates are paused on the deviceResume the ring or remove the pause GPO
DeploymentConflictDevice is in more than one feature update policyFix group membership and exclusions
SafeguardHoldMicrosoft is holding the update for a known issueLook up the hold ID on Windows release health
IncompatibleServicingChannelDevice is on an Insider or preview channelMove it to the retail (GA) channel
DeviceRegistrationInvalidGlobalDeviceIdDevice cannot register with Windows UpdateMake sure the Microsoft Account Sign-In Assistant service is not disabled
EndOfServiceApproachingThe current version is close to end of servicingPrioritize these devices, typically 24H2 Pro and 23H2

The MSA service one deserves a special mention: many hardening baselines disable the Microsoft Account Sign-In Assistant to block consumer accounts, and that silently breaks Windows Update deployment service registration. Block consumer accounts with the account policy instead and leave the service running.

Proving the result: version counts over time

Management rarely asks “what is the update substate of device 4711”. They ask “how many are done”. Three ways to answer that:

  • Windows devices export or the Graph PowerShell snippet from step 1, run weekly and saved. Simple and works without any prerequisites.
  • Windows Autopatch reports if you deploy with Autopatch: feature update status per Autopatch group and ring.
  • Windows Update for Business reports in Log Analytics for trend lines and custom dashboards.

With Windows Update for Business reports enabled, a simple KQL query gives you the current version distribution across the fleet:

UCClient
| where TimeGenerated > ago(2d)
| summarize arg_max(TimeGenerated, *) by AzureADDeviceId
| summarize Devices = count() by OSVersion
| order by Devices desc

Pin it to an Azure workbook, add a line per week and you have the burn-down chart for the 26H2 project. Define your exit criteria up front, for example 95 percent of active devices on 26H2 within 30 days of broad deployment, with the remaining devices individually explained (offline, safeguard hold, 26H1 hardware, pending replacement).

A realistic Windows 11 26H2 rollout plan

For a typical Intune and Autopilot tenant, this is the plan I would run:

  1. Week 0 (now): turn on Windows data and license verification. Inventory versions and editions. Fix ring deferrals, pauses and old feature update policies. Search scripts for WMIC.
  2. Week 0 to 1: run the device readiness and compatibility risks reports for 26H2. Deploy 26H2 as soon as possible to IT devices.
  3. Week 1: pilot group across all hardware models, including devices with legacy drivers. Prioritize 24H2 Pro devices because of the October 13 deadline.
  4. Week 2 to 4: broad deployment with gradual rollout. Add the Autopilot device group so new hardware follows automatically. Start the full upgrade for 23H2 Enterprise devices, which end on November 11.
  5. Week 4 onwards: work the failure report, chase the long tail, and start proof of concepts for Administrator protection, built-in Sysmon and point-in-time restore.

Windows 11 26H2 checklist for Intune and Autopilot

  • Inventory builds and editions; identify 24H2 Pro (Oct 13, 2026) and 23H2 Enterprise (Nov 11, 2026).
  • Set feature update deferral to 0 days on rings that share devices with feature update policies.
  • Replace or retarget existing 24H2 and 25H2 feature update policies.
  • Create a 26H2 feature update policy: IT, pilot, broad, with mutually exclusive groups.
  • Include your Autopilot or device preparation device group in the broad assignment.
  • Handle 26H1 (build 28000) devices in compliance ranges, dynamic groups and filters.
  • Decide explicitly on Windows settings backup and restore.
  • Remove WMIC from scripts and detection rules.
  • Keep legacy-driver devices in the pilot for more than 100 hours and three restarts.
  • Enable Windows data and Windows license verification for reporting.
  • Run readiness and compatibility risk reports before broad deployment.
  • Track Feature update failures and version counts weekly until exit criteria are met.

Frequently asked questions

Is Windows 11 26H2 a full upgrade?

Not for devices on Windows 11 24H2 or 25H2. They receive an enablement package (KB5121794) that activates 26H2 with a single restart. Devices on 23H2 or Windows 10 need a full feature update.

Does Windows Autopilot install Windows 11 26H2 during setup?

No. Autopilot provisions the OS version that is on the device. The Enrollment Status Page can install quality updates during OOBE, but the move to 26H2 happens after provisioning through your feature update policy or Autopatch release.

Can Windows 11 26H1 devices upgrade to 26H2?

No. 26H1 runs on a different Windows core and is not on the 24H2, 25H2 and 26H2 servicing branch. Microsoft will offer those devices their own future upgrade path.

Why are my Intune Windows update reports empty?

Most often because the Windows data connector is off. Enable features that require Windows diagnostic data in processor configuration and, for readiness reports, Windows license verification under Tenant administration > Connectors and tokens > Windows data. Then allow time for data to arrive.

How long is Windows 11 26H2 supported?

As an annual H2 release, 26H2 gets 36 months of servicing for Enterprise and Education and 24 months for Home and Pro, counted from GA.

Wrapping up

Windows 11 26H2 is the kind of release that rewards preparation over heroics. The update itself is a restart. The work is in the plumbing around it: rings that do not fight your feature update policy, Autopilot devices that are targeted from their first check-in, compliance rules that understand 26H1, scripts that do not depend on WMIC, and reporting that is switched on before you need it. Get those right this week and the October 13 deadline for 24H2 Pro becomes a non-event.

References

Getting Ready for Windows 11, version 26H2: Upgrade Paths, Autopatch, and Tracking Pilot to Production

Microsoft has confirmed the next annual feature update, Windows 11, version 26H2, and the headline for IT is a familiar one: this is an enablement package (eKB), not a full OS swap. If you have been through the 24H2 to 25H2 cycle, the playbook is almost identical – but there are a couple of new wrinkles worth planning around. This post walks through the supported upgrade paths, how you drive it with Windows Autopatch and Intune, and how to actually track the rollout from pilot to production.

What 26H2 actually is

26H2 shares the same servicing branch as 24H2 and 25H2. That means for devices already on those versions, the upgrade is delivered as a tiny enablement package – around 174 KB – that simply flips the version and build number (build 26300) after a single restart. No multi-gigabyte download, no long offline phase, no feature-update reboot marathon. The new capabilities ship continuously through monthly cumulative updates and are switched on by the eKB.

Microsoft frames it as “a predictable, low-disruption update experience for organizations and IT professionals,” and from a deployment standpoint that is exactly what it is – an update ring approval rather than a migration project. Expect general availability in the fall of 2026, in line with previous H2 releases.

Upgrade paths – know your starting point

The delivery method depends entirely on the version a device is sitting on today:

  • Windows 11 24H2 / 25H2 – direct eKB upgrade. ~174 KB, one restart. This is the easy 95% for most managed fleets.
  • Windows 11 23H2 and older – different servicing branch, so no eKB. These need the full feature-update media path (~6.5 GB download and the full upgrade experience).
  • The 26H1 caveat – 26H1 sits on a separate Windows core branch and does not roll forward to 26H2 via the standard enablement path. If you have any 26H1 (specialized/insider) devices, plan a different route for them.
  • Windows 10 – no shortcut here. These are full upgrades (or, frankly, replacements) and should already be on your end-of-support migration plan.
Windows 11 26H2 upgrade paths: 24H2/25H2 via enablement package, 23H2 and older via full media, 26H1 on a separate branch
Upgrade paths to 26H2 depend on the version a device sits on today.

Action before fall: run an inventory split by OS version now. Anything not already on 24H2/25H2 is your long-tail – get those onto a current branch first so 26H2 becomes a one-restart eKB rather than a 6.5 GB project.

Driving it with Windows Autopatch

If you are on Autopatch, 26H2 is close to trivial to approve – it appears in the feature update flow like any other release, and because the payload is tiny, distribution can complete in a day rather than weeks.

The mechanics you already rely on still apply. Autopatch groups split your estate into deployment rings – Test, First, Fast, and Last. If you do not define extra rings, Test acts as your pilot and Last as production. Releases flow sequentially through the rings, and Autopatch monitors device telemetry the whole way – if failure or compatibility signals spike, it can automatically pause progression to the next ring.

  • Pilot: keep Test/First small but representative – mix hardware models, key line-of-business apps, and a few power users who will actually report friction.
  • Soak time: because the eKB is so small, the temptation is to rush. Resist it – the value of a pilot is the soak window, not the download time. Give each ring a real bake period to surface app and driver issues.
  • Safety net: you retain Pause, Resume, and Rollback for feature updates directly from Intune if a ring goes sideways.

Not on Autopatch? The same model is available with Intune Feature Update profiles plus Update Rings – you target 26H2 as the feature update version and stagger deferrals/rings manually. You lose the automatic ring progression and telemetry-driven pause, but the staged approach is the same.

Autopatch deployment rings Test, First, Fast, Last with telemetry-driven pause and rollout tracking
Autopatch rings, the telemetry safety net, and what to watch as you promote from pilot to production.

Tracking pilot to production

This is where most rollouts get loose. “We deployed it” is not the same as “we can prove the estate moved.” Here is the reporting stack I lean on:

  1. Reports > Windows Autopatch – the two Autopatch reports give you ring-level rollout status and quality/feature update health. This is your primary “where is each ring” view.
  2. Reports > Device management > Windows Updates – the feature update report and readiness reporting validate which devices are eligible and which are blocked, before and during the push.
  3. Email notifications – make sure your Autopatch admin contacts are current so you actually receive the proactive alerts rather than discovering issues in a dashboard.
  4. A simple version-count KQL/report – track devices reporting build 26300 over time as your single “percentage on 26H2” number for management. Watch the curve per ring, not just the total.

Define your exit criteria before you start: e.g. pilot ring at >95% success with zero unresolved Sev-1 app issues for X days before releasing the next ring. Let the telemetry and your soak window – not the trivial download size – gate each promotion.

Support lifecycle

The usual split applies: Enterprise, Education, IoT Enterprise and Enterprise multi-session get 36 months of support, while Home, Pro, Pro Education and Pro for Workstations get 24 months (support running to roughly October 2028). Factor that into whether 26H2 is a “move now” or a “this fall” decision for each ring.

A short pre-flight checklist

  • Inventory by OS version – identify anything not on 24H2/25H2.
  • Get the long-tail (23H2 and older, Windows 10) onto a current branch first.
  • Flag any 26H1 devices for a separate path.
  • Confirm Autopatch groups / Intune feature update profiles and rings are sane.
  • Verify Autopatch admin contacts and reporting access.
  • Write down your per-ring exit criteria and soak windows.

Further reading and references

Bottom line: 26H2 is an approval, not a migration – for the devices that are on a current branch. Spend your effort on the long-tail and on a disciplined pilot-to-production cadence, and the eKB itself will be the least interesting part of the project.

Optimizing Software Packaging – What To Know About Advanced Installer

One of the best tools that IT professionals can have in their arsenal is a packaging tool. This simplifies their tasks and saves them time. Businesses need to provide their IT teams with comprehensive packaging tools that are easy to deploy and highly compatible.

One such product that has garnered a significant amount of interest is Advanced Installer. What you get with this powerful packaging tool for developers, businesses, and ISVs, among others, is an advanced application packaging software. It simplifies software deployment in a big way.

And before fully committing, organizations can try out the trial version. It comes with full features allowing them to make a more informed decisions. To help you with that task, let’s go over what you have to look forward to with Advanced Installer.

Introduction

As already mentioned, Advanced Installer is a software packaging and deployment tool designed to eliminate the challenges often encountered with packaging and updating software.

Clients get an all-in-one packaging tool that can create, edit, update, and repackage MSI, EXE, App-V, APPX, and MSIX. Because of the user-friendly and intuitive design as well as the plethora of features and capabilities, IT professionals should expect an application that optimizes the packaging process.

Businesses will also appreciate how easy the integration will be. They’ll also enjoy the compatibility that provides support for various platforms and formats. In addition, IT professionals can easily create customizable and visually appealing installers. They can also benefit from the integration of Advanced Installer with popular development tools and environments.

Ultimately, using Advanced Installer gives your organization a product that enables you to build reliable MSI packages. These meet the latest Microsoft Windows logo certification requirements and generally follow the recommended Windows Installer best practices.

Requirements

Before proceeding with the purchase and installation of Advanced Installer, it’s also important to be aware of the specific requirements that the application demands. In the table below, you’ll find both the hardware and software requirements that you need to know.

HardwareSoftware
Required minimum: Core 2 class CPU1GB RAM1366 × 768 screen resolution 2GB hard drive spaceAdvanced Installer IDE – for Advanced Installer to run properly on a system, you will need: Windows 7 or newer. The latest Windows Platform SDK. However, this is optional as it will only be required when building certain types of packages.
What is recommended: i5 class CPU4GB RAM1920 × 1200 screen resolution 10GB hard drive spaceCreate Install Packages – Advanced Installer produces MSI or EXE install files that are designed to run on: Windows 7 or newer Windows Server 2008 R2 or newer.  
 Create MSIX Packages – Advanced Installer produces MSIX packages that are designed to run on: Windows 10 version 1507 or newer Windows Server 2016 (Long Term Servicing Channel) or newer.
 For Java – Advanced Installer for Java can create install bundles to install Java programs on these versions of MacOS: Mac OS 10.x Power PC Mac OS 10.x Intel.
 Windows 10/11 Compatibility – Advanced Installer and the EXE/MSI install packages it generates have been shown to work on Windows 10 and Windows 11.

Latest upgrades

Some new, recently announced updates for Advanced Installer are available. One in particular of great interest is the new nested Context Menus for File Associations in MSIX. The goal of this feature is to give organizations a more organized and efficient user interface. It ultimately streamlines the management of file associations.

As a result of this, you should have improved navigation and better usability. Moreover, clients will now also find a reboot option for NewPrerequisite and UpdatePrerequisite command lines coupled with support for Java versions 19 through 22.

The above improvements combine with new translations for default strings, a refactored build log for improved clarity, and an AppInstaller theme that is now supporting BrowseDlg dialog for a better user experience. More than just the new features, however, Advanced Installer has addressed challenges that clients were facing, including:

  • Fix EXE icon issue in non-English language projects.
  • Addressing the problem of the “Install side-by-side” option not always preserved on upgrades.
  • Fixing the reboot prompt issues during uninstallation.
  • Resolved the issue that was causing files to be digitally signed twice in an MSIX build.
  • Address the problem causing the description field to fail to set MSI name in UAC using trusted signing.
  • Corrected the issue causing the system to not prompt for the certificate password when the entered password was incorrect.
  • Resolved the problem of scheduled tasks failing if they were scheduled to run at task creation.

Available features

In the table below, you’ll find a few of the wide range of features that Advanced Installer has to offer.

ArchitectEnterpriseProfessionalFreeware
Repackager – seamlessly capture, customize, and repackage existing installations into MSI packages. Upgrade legacy setups to Windows Installer technology.Updater – checking for downloads and installation of patches and updates is done automatically.IIS – Web Sites, Virtual Directories and Web Applications, App-Pools, User Accounts.MSI – create valid MSI setups for your applications that meet all the written and unwritten Windows Installer rules.
MSI Quick-Edit – enables you to create, transform, or edit existing MSI packages directly from the Advanced Installer GUI.JSON Files Updates – without writing any code, you can manage JSON files that are part of the installation package or present on the target machine.Multilingual and Localized – get over 30 translations that are all ready to use, as well as easy to modify and create.UAC – build installers that will run seamlessly on Windows 10/8.1/8/7/Vista supporting the security model.
MSIX Custom Scripts – use PowerShell scripts to resolve any of the compatibility issues of your application after you create an MSIX.Installer Continuous Integration – provides built-in support for integration with Azure DevOps, GitHub Actions, Jenkins, TeamCity, and Bamboo.Themes – also get over 50 built-in beautiful themes to give your installer a professional look.Imports – bring in relevant imports from Visual Studio, InstallShield LE, Inno Setup, WiX, Eclipse, NSIS, and regular MSI/MSM packages.
MSIX Package Editor – can offer an immediate view of your package content, enabling you to customize anything from Advanced Installer’s user interface.Dialog Editor – enables you to visually customize existing installer dialogs or create new ones entirely from scratch.Custom Actions – if you execute your code during installation, you can extend your installer’s capabilities.32-bit or 64-bit – provides the option to build setups that both run and install on 32-bit processors and/or the latest 64-bit Intel and AMD CPUs.
MSIX Modification Packages – enables you to extend and update your MSIX packages. You’ll also be able to separate your main application package from its updates, thus speeding up Windows 10 updates.Convert EXE installers to MSIs – an extremely capable wizard that converts any EXE setup into an MSI ready for network deployment through Active Directory.Native Launcher – create a native launcher for your Java applications and customize the process name, file name, icon, version, splash-screen, JRE/JDK detection and selection, user-friendly error handling.Side-by-side – if you have different versions of your application and want to not only install them simultaneously but have them running side by side, you can easily create packages for all the different versions.
Package Support Framework – the capabilities of the PSF integration for MSIX packages will allow you to minimize any AppCompat issues without writing any code.Office Add-ins – leverage the included specialized templates to greatly simplify the creation of installers for popular software platform extensions, plug-ins, and add-ins.Prerequisites – search for, download, and install prerequisite applications, frameworks, and run-times.Upgrades – older versions of your product installed on the user’s machine will be detected and upgraded. Additionally, installation over newer ones will be blocked.

Pricing and Licensing

Once you have decided to use Advanced Installer, you can go ahead and start the purchase from the purchase page. For those who may need additional clarification on any issue, they can quickly find assistance with the support team. Once completed, you can start planning to deploy the package you choose on certain machines.

Fortunately, there is no limit to the number of machines you can deploy a package. As long as you have a licensed version of Advanced Installer, you can successfully create an unlimited number of install packages. You can then distribute these packages royalty-free to any number of users

When it comes to the issue of upgrades, you can purchase your subscription/license upgrade from the upgrades page. After upgrading your subscription, you’ll need to log out before logging in again. Once logged into Advanced Installer, you can refresh your subscription details. For clients with perpetual licenses, their license keys won’t change.

All they have to do is run the registration wizard once more in Advanced Installer. You can get access to the features from the new edition to which you upgraded by opening the project in Advanced Installer. In the toolbar, go to Home > Options > Project Type tab, and choose the desired project type.

The table below contains information regarding the pricing structure.

 ArchitectEnterpriseProfessional
Cost$359 per user per month. The option for a team subscription is available.$139 per user per month. The option for a team subscription is available.$39 per user per month. The option for a team subscription is available.
What you getIn addition to everything that Enterprise offers, you will also get Repackager, MSI Quick-Edit, Reports Generator, App-V, MSIX (Re)packaging, MSIX Package Editor, SCCM, and Intune.In addition to everything you get in Professional, you also get CI/CD Integration, Dialog Editor, Updater, XML Patching, Databases, Trial and Licensing, Merge Modules Authoring, EXE to MSI (wrapper), Automated VM Testing, and Drivers.The main features available include Trusted Signing Native Integration, Visual Studio Extension, PowerShell Automation, MSIX, Themes, Services, Prerequisites, IIS, .NET, COM, ODBC, Internationalisation, Java Native Launcher, and Installer Analytics.

Registration process

After purchasing Advanced Installer, you can now begin the registration process. However, if you are using the Freeware version, registration is not necessary. Clients that opt for the Professional, Enterprise, and Architect versions will require a valid registration to continue use after the trial period has lapsed. All you need to do is navigate to the File > Help > Register menu.

ONLINE REGISTRATION

If you want to download the license online, then the first thing you’ll need is an internet connection. With that established, Advanced Installer will connect to the appropriate server and download the license file to your device.

REGISTRATION BY EMAIL

In this case, an internet connection is not a requirement for the device in question. Once you have noted your Computer ID, you can email it in using any other device connected to the internet. Coupled with the valid License Key, you should forward these details to support at advancedinstaller.com. You can also expect to receive your response within 48 hours. The response will contain your license file as well as additional instructions.

LICENSE SERVER REGISTRATION

This method of registration by using a license server is only a valid option for owners with floating licenses. You’ll need to verify that your network administrator has correctly installed and configured the License Server. You won’t be able to complete the registration if you don’t have both the server’s host name and the port number.

Wrap up

Organizations are constantly searching for productivity tools that can empower their teams and increase operational efficiency. Tools such as Advanced Installer are ideal in that they can simplify tasks such as packaging and deployment of software. The capabilities of this application will deliver a faster overall process and a seamless installation experience that minimizes headaches. And as we move forward Advanced Installer will only get better as the development team leverages the feedback from clients.

MicrosoftStoreAppUpdater script

A simple way to update Microsoft Store Apps

This script will inititae update for Microsoft Store Apps and applications available using winget.
By default it will delete the logfile if older then 30 days.

Should run with local administrative rights or as system

When deploying new computers, there might be modern apps without processed updates.
Can also update on regular machines in use.

Works with Windows 365 Deployments and regular OSD using ConfigMgr/MDT

https://github.com/ThomasMarcussen/assortedScripts

Automate Configuration Manager Application Creation

A simple script example to automate the application creation process in ConfigMgr or Configuration Manager.

RebootBehavior set to NoAction, Accepted values: BasedOnExitCode, NoAction, ForceReboot, ProgramReboot
AutoInstall $true – indicates whether a task sequence action can install the application
Added Action to Distribute the Content to the DP Group at the end

Configuration Manager Checklist:

  • Application Name
  • With a deployment type: Same application name
  • Content Location
  • Installation Program
  • Uninstall program
  • Repair Program
  • Detection method (a specific MSI Product code)
  • User expierence: Install for system if resource is device; otherwise install for user
  • Logon requirement: weather or not a user is logged on

    Published on Github:

https://github.com/ThomasMarcussen/assortedScripts/blob/master/Create_SCCMApplication_1.0.1.ps1

New Microsoft Edge based on Chromium – error status: 1603

I recently ran into to an issue deploying the New Microsoft Edge, for some reason it kept failing with Error status 1603 on most of the systems.

The deployment version was version: 87.0.664.47
It kept failing on a lot of systems with build: 1803. I did suspect a missing KB of some kind. However, I did not find any apparent prerequisites missing.

Tried the same method for the latest version – 87.0.664.60. Both downloaded from: https://www.microsoft.com/en-us/edge/business/download and everything seemed to be working. It’s now deployed to more then 2000 systems.

CustomAction DoInstall returned actual error code -2147219187 (note this may not be 100% accurate if translation happened inside sandbox)

Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor.  Action DoInstall, location: C:\WINDOWS\Installer\MSI9085.tmp, command: /silent /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft Edge&needsAdmin=True&usagestats=0&ap=stable-arch_x64" /installsource enterprisemsi /appargs "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&installerdata=%7B%22distribution%22%3A%7B%22msi%22%3Atrue%2C%22system_level%22%3Atrue%2C%22verbose_logging%22%3Atrue%2C%22msi_product_id%22%3A%2292749E40-069E-3467-BB1F-78BB266190E2%22%2C%22allow_downgrade%22%3Afalse%2C%22do_not_create_desktop_shortcut%22%3Afalse%2C%22do_not_create_taskbar_shortcut%22%3Afalse%7D%7D" 

MSI (s) (10:A8) [13:21:48:649]: Product: Microsoft Edge -- Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor.  Action DoInstall, location: C:\WINDOWS\Installer\MSI9085.tmp, command: /silent /install "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&appname=Microsoft Edge&needsAdmin=True&usagestats=0&ap=stable-arch_x64" /installsource enterprisemsi /appargs "appguid={56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}&installerdata=%7B%22distribution%22%3A%7B%22msi%22%3Atrue%2C%22system_level%22%3Atrue%2C%22verbose_logging%22%3Atrue%2C%22msi_product_id%22%3A%2292749E40-069E-3467-BB1F-78BB266190E2%22%2C%22allow_downgrade%22%3Afalse%2C%22do_not_create_desktop_shortcut%22%3Afalse%2C%22do_not_create_taskbar_shortcut%22%3Afalse%7D%7D" 

MSI (c) (C4:44) [13:21:48:771]: Windows Installer installed the product. Product Name: Microsoft Edge. Product Version: 87.0.664.47. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 1603.

Any ideas, other then deploying latest and greatest? Let me know.

Deploy Microsoft Edge Chromium Using PowerShell App Deployment Toolkit (PSADT)

The new Microsoft Edge is based on Chromium and was released on January 15, 2020. It is compatible with all supported versions of Windows. Installing the browser will replace the legacy version of Microsoft Edge on Windows 10. Deploy Microsoft Edge Chromium using the PowerShell App Deployment Toolkit.

PowerShell App Deployment Toolkit (PSADT) is a great framework to deploy and manage application deployment. It is free of charge. Additionally, it is downloadable from https://psappdeploytoolkit.com/.

The published script is here on Github

Deploy Microsoft Edge

This deployment script example does the following within the PSADT framework:

Pre-Install:
If Microsoft Edge is open, it will prompt the user to close it or delay the deployment three times (Comment line 120 if you prefer to just shut it down.)
Also, as a Pre-installation task it searches the add/remove program list for any version of Microsoft Edge and uninstalls it.

Install:
It then installs the MSI file from the Files directory – MicrosoftEdgeEnterpriseX64.msi
The latests version of Microsoft Edge for Business version can also we downloaded from – https://www.microsoft.com/en-us/edge/business/download

Uninstall:
Uninstalltion is performed using the name from Add/remove programs (same as for the pre-install step) so this will require no changes. (Line 181)

Repair:
If needed repair can be enabled (or updated for other versions)
(Modify line 203 if deploy other versions)

Microsoft Edge follows the Modern Lifecycle policy. Learn more about supported Microsoft Edge releases.

MSiX Insider Preview Build 1.2019.522.0

First insider preview release for the upcoming public release in July.

New Features:

  • Support for desktop installers that require restart – read more
    • Auto-login option for restart
  • New options in app settings
    • Specify a default cert to sign packages with
    • Specify exit codes for installers that require restart


Known “bugs/features”

  • Negative reboot exit codes are currently not supported
  • If Default cert is specified, you still need to select to sign your package
  • During remote or VM restarts, there might be an extra login prompt
  • Restore defaults button doesn’t remove certificate password or installer exit codes
  • There are some UI incongruencies

You can find the full history of MSIX Packaging Tool release notes here.


List Packages that run in user context (Run with user’s rights)

Introduction

After last weeks post with the script sample to list Packages that run in user context, there where some good feedback from people still using packages, and requiring a list of packages that install within the user context (Run with user’s rights / Execution mode as user)

It seemed that many was still using Packages, either as a result of legacy migration or to avoid some application re-packaging.

So here is the followup post, with a new script to list all packages and package with programs that run in user context.

From my point of view, its still the same; Using PSADT pretty much any package can be converted to be installed as system, and the needed stuff (registry keys, files etc) in the user context can be added in a structured and controlled way.

I do still come across some applications that i would prefer to have in MSI with all settings etc added, at least for simplicity, for those packages I still prefer to use Advanced Installer.
When talking Advanced Installer, they also have a great support for MSIX, that makes to process so much easier and cost efficient.

This script will list all packages with programs, that is configured to install as user (within the user context)

All you need to do is configure the path to your import module and set the site code.

A file will be created in “C:\TEMP\Packages_and_Programs_Run_Mode_List.csv” with the following format:

“Package Name”,”Package ID”,”Program Name”,”Run with USER’s right”
“My Application”,”BB10001D”,”execute”,”TRUE

With the example above we have a package ‘My Application’ that has a run mode configured: Run with user’s rights

Properties on the program, where the program run enviroment is configured to Run with Users’s rights


Download the script from TechNet Gallery – https://gallery.technet.microsoft.com/Generate-a-list-of-d8778d4c?redir=0



List Applications that run in user context (Install for User)

Introduction

When deploying applications sometimes they are created to install within the active users context.
This means that the actual installation requires the users to have the needed permissions to the filesystem, registry and etc.
In some cases local administrative rights are needed to perform the application installation, this is not a good practice.

As applications mature for the modern design of the Windows Operating System or we choose to remove the users administrative rights due to security reasons, we may need to list and change the behavior of existing Applications.

This script was created to list applications that is configured to run with Installation behavior: Install for User

The actual output will end up in the export csv file

Script Download [download id=”893″]



Today with the modern management tools and applications, the users should not have local administrative rights on a permanent basis.
Most, if not all applications can be repackaged to deploy without the need for administrative rights.



Useful links:

PowerShell Application Deployment Toolkit: https://psappdeploytoolkit.com
Advanced Installer: https://www.advancedinstaller.com/
Access Director Enterprise: https://ctglobalservices.com/access-director-enterprise/