decrypted · 2 october 2026 · vulnerabilities and patching · surveillance and privacy · digital sovereignty

Microsoft switches on cloud backup of Windows settings by default, with exemptions the UK may not share

Microsoft has switched on cloud backup of Windows settings by default for organisations. If your laptops run Windows 11 version 26H2, are joined to Microsoft Entra, and nobody ever set the policy, the decision about whether that data leaves your estate has now been made for you. Microsoft has also chosen not to make it for customers in the EU or in sovereign clouds. UK organisations should notice who got the exemption.

What changed

The feature backs up Windows settings and a list of installed Microsoft Store apps, so a replaced or reset device can be rebuilt quickly. According to BleepingComputer, it is now on by default for eligible devices after the 26H2 release, unless an administrator has already set the policy either way. Microsoft said it honours any existing explicit enable or disable setting. Restoring from a backup remains off until an administrator turns it on.

Think of it as a hotel that has started leaving a copy of your luggage list at the front desk. The list is probably harmless, and the intention is helpful. But nobody asked for it.

Who is exempt, and who is not

The default does not apply in regions covered by the EU Digital Markets Act, nor in sovereign or restricted cloud environments. The Register noted the switch from opt-in to opt-out is likely to set administrators' nerves jangling, particularly for organisations prohibited from sending this data to the cloud.

The UK is not in the EU, so the DMA carve-out does not obviously cover a UK tenant. Neither source says where the backups are stored. Treat that as a question for your supplier, not an assumption either way.

What you can see, and what to do

A default like this leaves no incident, no alert and no ticket. The only place a defender sees it is the policy configuration. So the practical steps are small:

The cost is an hour of an administrator's time; the alternative is a data flow you cannot explain to a regulator.

The Secure by Design lesson

Secure by Design says a product should be safe out of the box, and that customers should not need to be experts to stay safe. Microsoft is right that backup is a sensible default for resilience. The weakness is that the default changes which party holds the data, and it did so for some customers and not others. A secure default should protect the customer's position, not reduce it.

The better design is a prompt at upgrade time, asking the administrator once, with the exemptions open to everyone who asks. Until vendors work that way, your defence is to leave nothing not configured. Every unset policy is an invitation for a supplier to fill it in on your behalf.

Also this week

KillSec's alleged administrator is 16. Hamburg police and Europol said a coordinated operation on 30 September seized the ransomware group's leak site and five servers, secured 110 terabytes of data and led to three arrests, in Spain, Romania and the UK. The UK suspect is a man in his 20s, and the location was not given. Investigators say the group carried out around 500 successful attacks, and Europol said they also identified suspected developer, negotiator and affiliate roles. Arrests help, but a gang run by a teenager shows how low the barrier to extortion has fallen. Assume your data is worth stealing whoever is behind it.

FortiMail is being exploited before a full patch exists. Fortinet warned that CVE-2026-104286, rated 9.8, lets an unauthenticated attacker write files through crafted web requests to the management interface and run code. CISA added it to its known exploited list, with a federal deadline of 4 October. Fortinet lists fixes in 7.4.9, 7.6.7 and 8.0.2, though BleepingComputer described them as pending. Its workarounds are to disable the IBE feature and keep management access off the internet. Mail gateways hold your most sensitive correspondence, so their admin interfaces should never be reachable from outside. Because exploitation came before the fix, mitigating is not the same as being clean: look for unexpected files and logins.

Sources

If you want help working out what your suppliers' defaults are doing with your data, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.