decrypted · 2 october 2026 · vulnerabilities and patching · surveillance and privacy · digital sovereignty
Microsoft switches on cloud backup of Windows settings by default, with exemptions the UK may not share
Microsoft has switched on cloud backup of Windows settings by default for organisations. If your laptops run Windows 11 version 26H2, are joined to Microsoft Entra, and nobody ever set the policy, the decision about whether that data leaves your estate has now been made for you. Microsoft has also chosen not to make it for customers in the EU or in sovereign clouds. UK organisations should notice who got the exemption.
What changed
The feature backs up Windows settings and a list of installed Microsoft Store apps, so a replaced or reset device can be rebuilt quickly. According to BleepingComputer, it is now on by default for eligible devices after the 26H2 release, unless an administrator has already set the policy either way. Microsoft said it honours any existing explicit enable or disable setting. Restoring from a backup remains off until an administrator turns it on.
Think of it as a hotel that has started leaving a copy of your luggage list at the front desk. The list is probably harmless, and the intention is helpful. But nobody asked for it.
Who is exempt, and who is not
The default does not apply in regions covered by the EU Digital Markets Act, nor in sovereign or restricted cloud environments. The Register noted the switch from opt-in to opt-out is likely to set administrators' nerves jangling, particularly for organisations prohibited from sending this data to the cloud.
The UK is not in the EU, so the DMA carve-out does not obviously cover a UK tenant. Neither source says where the backups are stored. Treat that as a question for your supplier, not an assumption either way.
What you can see, and what to do
A default like this leaves no incident, no alert and no ticket. The only place a defender sees it is the policy configuration. So the practical steps are small:
- Check in Intune or Group Policy whether the Windows settings backup policy is configured at all. Not configured is now a decision by Microsoft.
- Set it explicitly, on or off, and record who decided and why.
- Hold the 26H2 rollout until you have done so. Devices on earlier versions keep their earlier behaviour.
- If you handle regulated or sensitive data, ask your data protection officer whether this is a new transfer you must document.
The cost is an hour of an administrator's time; the alternative is a data flow you cannot explain to a regulator.
The Secure by Design lesson
Secure by Design says a product should be safe out of the box, and that customers should not need to be experts to stay safe. Microsoft is right that backup is a sensible default for resilience. The weakness is that the default changes which party holds the data, and it did so for some customers and not others. A secure default should protect the customer's position, not reduce it.
The better design is a prompt at upgrade time, asking the administrator once, with the exemptions open to everyone who asks. Until vendors work that way, your defence is to leave nothing not configured. Every unset policy is an invitation for a supplier to fill it in on your behalf.
Also this week
KillSec's alleged administrator is 16. Hamburg police and Europol said a coordinated operation on 30 September seized the ransomware group's leak site and five servers, secured 110 terabytes of data and led to three arrests, in Spain, Romania and the UK. The UK suspect is a man in his 20s, and the location was not given. Investigators say the group carried out around 500 successful attacks, and Europol said they also identified suspected developer, negotiator and affiliate roles. Arrests help, but a gang run by a teenager shows how low the barrier to extortion has fallen. Assume your data is worth stealing whoever is behind it.
FortiMail is being exploited before a full patch exists. Fortinet warned that CVE-2026-104286, rated 9.8, lets an unauthenticated attacker write files through crafted web requests to the management interface and run code. CISA added it to its known exploited list, with a federal deadline of 4 October. Fortinet lists fixes in 7.4.9, 7.6.7 and 8.0.2, though BleepingComputer described them as pending. Its workarounds are to disable the IBE feature and keep management access off the internet. Mail gateways hold your most sensitive correspondence, so their admin interfaces should never be reachable from outside. Because exploitation came before the fix, mitigating is not the same as being clean: look for unexpected files and logins.
Sources
- BleepingComputer: Microsoft enables Windows settings backup by default for orgs
- The Register: Microsoft makes Windows settings backup the default in 26H2
- BleepingComputer: Police dismantle KillSec ransomware gang allegedly led by 16-year-old
- The Hacker News: Police Arrest 16-Year-Old Suspected of Running KillSec
- BleepingComputer: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
If you want help working out what your suppliers' defaults are doing with your data, get in touch.
More like this
- The AD FS zero-day hiding inside a record Patch Tuesday 15 july 2026
- A Zammad zero-day chain let an AI agent breach the people who find zero-days 1 october 2026
- The Dutch build an exit from Microsoft, and Microsoft corrects its evidence to MPs 27 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.