IntuneHow-to

Rolling out Windows 11 26H2 with Intune: feature update policy, known issues, safeguard holds

How 26H2 installs as an enablement package, the Intune feature update policy and rollout options to deploy it, the known issues listed at launch, how safeguard holds show up, and how to verify a device.

Windows 11, version 26H2 reached general availability on 29 September 2026, and for devices already on 24H2 or 25H2 it installs as a small enablement package with a single restart. That makes it an easy feature update to deploy, but Microsoft listed several known issues within days and the rollout is gated by safeguard holds. In this post I'll cover how 26H2 installs, how to build the Intune feature update policy and rollout schedule, what the known issues are as of early October 2026, and how to confirm a device really is on 26H2.

How this guide is organised: How 26H2 installs → Prerequisites in Intune → Step-by-step → Verify → Safeguard holds, known issues and rollbackFlow diagram of the article's sections in reading order: 1. How 26H2 installs. 2. Prerequisites in Intune. 3. Step-by-step (4 steps: Fix the update rings first; Create the feature update policy; Pick a rollout option; Plan the rings). 4. Verify. 5. Safeguard holds, known issues and rollback. Toolbox: Remove-WindowsPackage, Test-ComputerSecureChannel, …\Appraiser\GWX, Reports › Windows updates, DisplayVersion.1How 26H2installs2Prerequisites inIntune3Step-by-step4Verify5Safeguardholds, known i…1Fix the update rings first2Create the featureupdate policy3Pick a rollout option4Plan the ringsTOOLBOXRemove-WindowsPackageTest-ComputerSecureChannel…\Appraiser\GWXReports › Windows updatesDisplayVersionHow this guide is organised: How 26H2 installs → Prerequisites in Intune → Step-by-step → Verify → Safeguard holds, known issues and rollbackFlow diagram of the article's sections in reading order: 1. How 26H2 installs. 2. Prerequisites in Intune. 3. Step-by-step (4 steps: Fix the update rings first; Create the feature update policy; Pick a rollout option; Plan the rings). 4. Verify. 5. Safeguard holds, known issues and rollback. Toolbox: Remove-WindowsPackage, Test-ComputerSecureChannel, …\Appraiser\GWX, Reports › Windows updates, DisplayVersion.1How 26H2 installs2Prerequisites in Intune3Step-by-step1Fix the update rings first2Create the feature update policy3Pick a rollout option4Plan the rings4Verify5Safeguard holds, known issues and rollbackTOOLBOXRemove-WindowsPackageTest-ComputerSecureChannel…\Appraiser\GWXReports › Windows updatesDisplayVersion
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

Status (October 2026): Microsoft declared 26H2 generally available on 29 September 2026 with a phased rollout expanding over the next few months. As of 2 October 2026, the Windows release health page for 26H2 lists four known issues: an AC-3 audio decoding issue (Confirmed, originating in KB5124010), plus USB Audio Class 1.0, domain trust and black-screen issues (all Mitigated). Re-check the release health page before each rollout phase, because statuses and workarounds change.

How 26H2 installs#

Microsoft describes 26H2 as sharing the same servicing branch and core operating system as 24H2 and 25H2. Its features already arrived, dormant, through monthly cumulative updates; the enablement package (KB5121794) switches them on. The package requires the 22 September 2026 preview update KB5124010 (OS build 26100.9546) or later and one restart, and the OS build moves to the 26300 series (the launch build is 26300.9550). Devices on 23H2 or Windows 10 take the full feature update path instead. Installing 26H2 resets the support clock: 24 months for Home and Pro, 36 months for Enterprise and Education. For end users Microsoft offers it through the Get the latest updates as soon as they're available toggle; for managed devices you decide the timing with Intune, and Microsoft may still place a safeguard hold on devices with a known compatibility problem.

Prerequisites in Intune#

  • Microsoft Intune Plan 1 plus a Windows licence that includes the Windows Autopatch entitlement.
  • Windows Pro, Pro Education, Enterprise or Education. Enterprise LTSC isn't supported by feature update policies; use update rings there.
  • Devices Intune-managed and Microsoft Entra joined or hybrid joined, with diagnostic data at least Required and the Microsoft Account Sign-In Assistant service (wlidsvc) running.
  • For reporting, turn on the Windows diagnostic data setting under Tenant administration › Connectors and tokens › Windows data.
  • Network access to the Intune, Windows Update and Windows Autopatch endpoints.
  • A role that can create device configurations (Policy and Profile manager or a custom role); report viewers need at least Read Only Operator or Help Desk Operator.

Step-by-step#

1. Fix the update rings first#

Feature update policies decide which version; update rings still own deadlines, restart behaviour and active hours. In every ring that targets your devices, set Feature update deferral period (days) to 0 and make sure feature updates aren't paused. If a ring currently uses a deferral to hold devices back, create the 26H2 policy (or a policy pinning the current version) first, wait until the report shows devices at OfferReady, and only then drop the deferral to 0, otherwise a device that scans in the gap can be offered something you didn't intend.

2. Create the feature update policy#

Go to Devices › Windows › Windows updates › Feature updates › Create profile. Give it a name, and from Feature update to deploy select Windows 11, version 26H2 (only versions still in support are listed). Choose Make available to users as a required update for a managed rollout; the optional variant needs a Windows Autopatch licence and relies on users opening Windows Update and selecting Download. The policy never downgrades a device, applies only to devices below the target version, pulls in the latest quality update as part of the upgrade, and stays in force until you change or delete it, unlike a ring pause, which expires after 35 days.

3. Pick a rollout option#

Rollout optionBehaviourUse it for
Make update available as soon as possibleOffered at the next Windows Update scanIT and pilot groups
Make update available on a specific dateOffer held until the date you setAligning with a change window
Make update available graduallyDevices split randomly into offer groups between a first and final availability date, with a days between groups interval; first date at least two days out, groups of at least 100 devicesBroad deployment

Microsoft's example: first group 1 January, final group 10 January, three days between groups gives four offer groups. If you also deploy a Settings catalog profile with Allow Windows Update for Business Cloud Processing enabled, Windows Autopatch uses intelligent rollouts to make the first group a deliberately diverse pilot of hardware and drivers rather than a random sample. Assign the policy to device groups and create it.

4. Plan the rings#

  1. IT ring: as soon as possible, a handful of devices, including one with USB audio peripherals and one Credential Guard-protected domain-joined machine given the current known issues.
  2. Pilot ring: a specific date one or two weeks later, with a representative mix of models and business apps, and anything that decodes AC-3 audio.
  3. Broad ring: gradual rollout over several weeks. Keep Azure Virtual Desktop hosts and devices that use Machine Identity Isolation in a separate, later policy until the related issues are resolved.

Verify#

In the admin center, go to Reports › Windows updates, open the Reports tab, select Windows Feature Update Report, pick the 26H2 profile and generate it. Service-side states such as Pending: Validation, Scheduled and Offering: OfferReady come first; once client data arrives you'll see Installing sub-states through to Installed: Update Installed. The Feature update failures report lists per-device alerts. On the device itself, winver should read Version 26H2 with an OS build in the 26300 range, and Update history should list the enablement package. From PowerShell:

PowerShell
Get-ComputerInfo | Select-Object OsName, OsVersion, OsBuildNumber
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion' | Select-Object DisplayVersion, CurrentBuild, UBR

Good looks like DisplayVersion of 26H2 and CurrentBuild of 26300. In Intune, Devices › All devices › the device › Device details shows the OS version after the next check-in.

Safeguard holds, known issues and rollback#

Spotting a safeguard hold#

A device under a hold simply doesn't progress past the offer in the report. To confirm it on the device, read GStatus under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Appraiser\GWX: 0 means a hold is in effect, 2 means none. The 8-digit hold ID is GatedBlockId under ...\AppCompatFlags\TargetVersionUpgradeExperienceIndicators in the subkey for the target version (Microsoft's example uses GE24H2), and Windows Update for Business reports list active holds by the same ID. Search for that ID on the release health page. Microsoft's advice is not to force past a hold in production; the Update/DisableWUfBSafeguards policy is for validation only. If an old hold lingers, check whether TLS inspection is intercepting adl.windows.com.

Known issues as listed by Microsoft (2 October 2026)#

IssueStatusWhat Microsoft says
Applications that need AC-3 (Dolby Digital) audio decoding might close unexpectedlyConfirmedFollows KB5124010 (22 September 2026) and later on 26H2, 25H2 and 24H2; mostly legacy apps using Windows' built-in decoder; fix planned in a future update.
USB Audio Class 1.0 devices fail to start (Code 10) or produce no soundMitigatedAffects many Windows versions; admins needing an immediate workaround for symptoms not yet covered by the out-of-band update should contact Microsoft Support for Business.
Domain-joined devices lose their trust relationshipMitigated26H2 starts honouring existing Machine Identity Isolation settings, which are only supported with Windows Server 2025 domain functional level; disable the feature via the same method that enabled it, restart, then run Test-ComputerSecureChannel -Repair.
Black screen or desktop loading issues after sign-inMitigatedMainly Azure Virtual Desktop hosts with FSLogix; launch explorer.exe from Task Manager as a stopgap, or deploy the Known Issue Rollback Group Policy Microsoft provides for KB5124010.

Microsoft's 26H2 update history page additionally mentions a File History problem after the September 2026 update; check that page and release health for the current list.

Rollback window#

Because the enablement package installs like a monthly update, Microsoft's guidance for removing it is to uninstall the package (through Remove-WindowsPackage or DISM, which you can deliver with an Intune script) rather than the feature update rollback used for full upgrades. For devices that took the full upgrade path, the update ring setting Set feature update uninstall period (2–60 days), CSP Update/ConfigureFeatureUpdateUninstallPeriod, controls how long the previous version's files are kept (10 days by default), and the ring's Uninstall action for feature updates only works inside that window with feature updates paused.

Tip: feature update policies don't apply during Autopilot OOBE; they take effect at the first Windows Update scan afterwards. And a device removed from every feature update policy stays enrolled in Autopatch and is offered nothing new until you assign it to another policy, so move devices between policies rather than unassigning them.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)