# Windows Backup for Organizations with Intune: the complete 2026 guide

> Back up and restore users' Windows settings during a PC refresh with Intune: prerequisites, configuration, Autopilot and troubleshooting.

- URL: https://benjamintestart.fr/en/windows-backup-for-organizations-intune/
- Author: Benjamin Testart (Devices Practice Leader & Microsoft Intune consultant)
- Published: 2026-10-05
- Updated: 2026-10-05
- Category: Windows
- Language: en
- Tags: Windows Backup for Organizations, Microsoft Intune, Windows Autopilot, Windows 11, Microsoft Entra ID
- Version française: https://benjamintestart.fr/fr/windows-backup-for-organizations-intune/

## TL;DR

Windows Backup for Organizations (now named Windows settings backup and restore) backs up Microsoft Entra ID users' Windows settings and list of Microsoft Store apps to the cloud, then restores them during the OOBE of a new Microsoft Entra joined PC. In Intune, you need a Settings catalog policy with "Enable Windows Backup" and the tenant-wide "Show restore page" turned on.

Windows Backup for Organizations lets you back up a Microsoft Entra ID user's Windows settings and list of Microsoft Store apps to the cloud, then automatically restore them during the OOBE of their new PC. In Intune, you turn it on with two settings: a Settings catalog policy for backup, and the tenant-wide "Show restore page" option for restore.

I covered this feature in a video on my YouTube channel. This article walks through the same approach in writing, with the exact prerequisites, the pitfalls I run into with customers and the points to watch on the Autopilot side.

## What is Windows Backup for Organizations?

Windows Backup for Organizations is the enterprise flavor of Windows Backup. As I write this, Microsoft is renaming it **Windows settings backup and restore**, so you'll see both names in the documentation and consoles for a while.

The goal is simple: when a user changes PCs (hardware refresh, migration from Windows 10 to Windows 11, reset after an incident), they get back their wallpaper, dark mode, accessibility settings, Start menu layout or File Explorer preferences, without the service desk having to step in.

How it works:

1. The administrator enables the backup policy.
2. A scheduled task automatically backs up settings **every eight days**. Users can also start a manual backup from the **Windows Backup** app (**Back up** button).
3. On the new PC, after Entra ID authentication in OOBE, a page offers to restore a backup from a previous device or to set up the PC as new.

Note: Microsoft announced that starting with **Windows 11, version 26H2**, backup will be enabled by default on eligible devices. Existing administrator-configured policies (enabled or disabled) are still honored, and restore must still be enabled explicitly.

## What is backed up… and what isn't

Microsoft publishes a detailed catalog of supported settings. In short, on Windows 11:

| Category | Examples backed up and restored | Examples not supported |
|---|---|---|
| System | Night light, notifications, Do not disturb, Snap windows, show file extensions | Rename this PC, notification sounds |
| Personalization | Background, colors and mode, themes, lock screen, Start layout, taskbar behaviors | Taskbar pinned layout, "most used apps" |
| Devices | Pointer speed, touchpad, pen, AutoPlay, Windows-managed default printer | Pen button as right-click |
| Time & language | Time zone, touch keyboard options | Language preferences and dictionary |
| Accessibility | Text size, Magnifier, Narrator, color filters, Sticky keys | Starting Magnifier or Narrator before sign-in |
| File Explorer | Hidden files, extensions, compact view, check boxes | — |
| Accounts | — | Accounts, Wi-Fi networks and passwords |
| Windows Update | — | No settings |

Two points are worth stressing to your users and management:

- **Files are out of scope.** The documentation only covers settings and the list of Microsoft Store apps. Documents remain OneDrive's job.
- **Win32 and LOB apps aren't restored.** Only the Microsoft Store apps in the backup are reinstalled. Your line-of-business apps keep coming through Intune.

On Windows 10, the scope is narrower (for example, no Snap or themes). That makes sense, since Windows 10 is only used to **back up** before migrating; restore only happens on Windows 11.

## Prerequisites

### Backup

The user must be signed in with a Microsoft Entra ID account, on a **Microsoft Entra joined** or **hybrid joined** device, running at least:

- Windows 10, version 22H2, build 19045.6216 or later;
- Windows 11, version 22H2, build 22621.5768 or later;
- Windows 11, version 23H2, build 22631.5768 or later;
- Windows 11, version 24H2, build 26100.4946 or later.

### Restore during OOBE

- **Microsoft Entra joined** device (no hybrid join at this stage).
- Windows 11 22H2 (22621.3958+), 23H2 (22631.3958+) or 24H2 (26100.4770+ according to the Windows documentation).
- The user must have at least one backup.
- If Autopilot is used, the profile must be in **user-driven** mode.

If your PCs ship with an image older than July 2025, enable the **Install Windows quality updates** setting in your enrollment status page (ESP) profile so the PC gets the required updates during OOBE.

### Restore at first sign-in

Microsoft also documents a restore at **first sign-in** after enrollment, on Windows 11 24H2 (26100.7922+) or 25H2 (26200.7922+). It accepts Microsoft Entra joined **or hybrid joined** devices, which opens the door for fleets that aren't "cloud native" yet.

### Roles, licensing and clouds

- The tenant-wide restore setting requires the **Intune Service Administrator** role (or Global Administrator).
- The feature isn't available in Government clouds (GCC High, sovereign) or in China (21Vianet).
- For settings roaming (formerly Enterprise State Roaming), Microsoft states that an appropriate license is required, for example Microsoft 365, EMS, Microsoft Entra ID or Windows E3/E5.
- Windows 11 SE, Holographic, IoT Core and Team (Surface Hub) editions aren't supported.

## Configure backup and restore in Intune

### Step 1: enable backup with the Settings catalog

1. Sign in to the Microsoft Intune admin center (intune.microsoft.com).
2. Go to **Devices** > **Manage devices** > **Configuration** and create a policy.
3. Choose the **Windows 10 and later** platform and the **Settings catalog** profile type.
4. In the **Administrative Templates\Windows Components\Sync your settings** category, add **Enable Windows Backup** and set it to **Enabled**.
5. Assign the policy to a group of users or devices, then save.

If you prefer OMA-URI, the matching CSP is:

```text
./Device/Vendor/MSFT/Policy/Config/SettingsSync/EnableWindowsbackup
Type: string – Value: `<enabled/>`
```

Don't mix GPO and CSP for this feature: Microsoft warns that combining both leads to unexpected results.

### Step 2: show the restore page

1. In the Intune admin center, go to **Devices** > **Enrollment**, **Windows** tab.
2. Under **Enrollment options**, select **Windows Backup and Restore**.
3. For **Show restore page**, select **On**.
4. Select **Save**.

This setting is **tenant-wide**: it applies to every Windows device that enrolls, and it's only delivered at enrollment time. Changing it later has no effect on devices that are already enrolled.

There's a second option, applied **after** enrollment: the **Enable Windows Restore** setting in the **Windows Backup And Restore** category of the Settings catalog (CSP `./Device/Vendor/MSFT/WindowsBackupAndRestore/EnableWindowsRestore`). It follows the normal policy refresh cycle and can be targeted by group.

### Step 3: control what users can change

On the device, users manage their options in **Settings** > **Accounts** > **Windows backup**: **Remember my preferences** and **Remember my apps**. If you want to lock these choices, the "Do not sync" policies under **Sync your settings** let you turn off specific groups (accessibility, personalization, language, apps…).

## Windows Autopilot: what works and what doesn't

This is the point that raises the most questions in projects. Restore is **not** supported with:

- **self-deploying** mode;
- the **technician flow** of pre-provisioning (Autopilot for pre-provisioned deployment);
- **Autopilot Reset**;
- Microsoft Entra **hybrid** join in OOBE;
- manual enrollment through the Settings app, via Group Policy or via Configuration Manager co-management;
- **shared or userless** devices.

In practice, the target scenario is **Autopilot user-driven mode with Microsoft Entra join**: the user authenticates, sees the restore page, picks their old PC, then the ESP continues. For pre-provisioning, the documentation only excludes the technician flow; I recommend validating the user flow on a pilot before rolling out broadly.

## The end-user experience in OOBE

Here's what the user sees on their new PC:

1. They start the PC, choose their language and network, then sign in with **the same work account** as on the old device.
2. A restore page displays their list of backups (one PC per line).
3. They select the old device and select **Continue**, or choose to set up the PC as new.
4. Setup completes and the settings and Store apps are restored automatically.

My field advice: brief users before delivery. A simple message such as "on the restore screen, pick your old PC" saves a lot of clicks on "set up as new".

## Monitoring and troubleshooting

### The per-device report

1. Go to **Devices**, **Windows** tab, and open the device.
2. Select **Enrollment**.
3. Find the **Windows Backup and Restore profile** row.

Possible statuses are: Not Applicable, No policy assigned, Succeeded, Failed, No Backup Profiles and Setup as New PC Selected. "No Backup Profiles" usually means the old PC never backed up.

### The causes I see most often

- **Conditional Access**: a policy that requires a compliant device can block the token during OOBE ("You can't get there from here"). Microsoft recommends allowing the service with AppId `d32c68ad-72d2-4acb-a0c7-46bb2cf93873`.
- **Phishing-resistant MFA**: if you enforce a strong authentication strength, the restore experience app (`74d197dc-b84d-4d43-a1b2-b5bf3bb91c11`) can trigger a security key prompt. On a Hyper-V VM this is blocking: use a Temporary Access Pass.
- **Hardening policies**: if **EnableActivityFeed**, **PublishUserActivities**, **UploadUserActivities**, **EnableCDP** or **AllowConnectedDevices** are set to **Disabled**, backup doesn't happen. A classic on tenants built from older baselines.
- **Build too old**: check the exact build number, not just the version.

### View or delete backed-up data

Backups can be accessed through the Microsoft Graph beta APIs, or more simply with the PowerShell module published by Microsoft:

```powershell
Install-Module WindowsBackupAdmin -Scope CurrentUser
Get-WindowsBackup -UserId user@contoso.com
Remove-WindowsBackup -UserId user@contoso.com
```

Handy for a GDPR request or to clean up the data of a departed employee.

## Comparison with Enterprise State Roaming and OneDrive

| | Windows Backup for Organizations | Enterprise State Roaming | OneDrive (Known Folder Move) |
|---|---|---|---|
| Scope | Windows settings + list of Store apps | Roaming of some settings across devices | User files (Desktop, Documents, Pictures…) |
| Timing | Backup every 8 days, restore at OOBE or first sign-in | Continuous sync | Continuous sync |
| Management | Intune / CSP / GPO | Now through Windows settings backup and restore policies | OneDrive policies |

Important: Microsoft has moved **Enterprise State Roaming** management into Windows settings backup and restore. Management from the Microsoft Entra portal was only planned until the end of June 2026; after that, only policy-based management is supported. If you were using ESR, make sure your Intune policies take over.

The three building blocks are therefore **complementary**: OneDrive for files, Windows Backup for the Windows environment, Intune for apps and configuration.

## My take as a consultant

Windows Backup for Organizations doesn't replace a migration strategy, but it removes a large part of the friction users feel during a device refresh. My approach:

1. Enable backup **several weeks before** the rollout, so every user has at least one recent backup.
2. Turn on "Show restore page" once your user-driven Autopilot profiles are validated.
3. Test Conditional Access and MFA on a pilot before opening it to everyone.
4. Communicate clearly: "your settings come back, your files are in OneDrive, your apps arrive through the Company Portal".

Well prepared, it's one of the features that delivers the most perceived value for minimal configuration effort.

## Key takeaways

- Backup works on Microsoft Entra joined or hybrid joined devices; restore during OOBE requires a Microsoft Entra joined device.
- Two Intune settings are required: "Enable Windows Backup" in the Settings catalog and "Show restore page" under Devices > Enrollment > Windows.
- With Autopilot, only user-driven mode is supported: not self-deploying mode, not the pre-provisioning technician flow, not Autopilot Reset.
- Settings and the list of Store apps are restored, not files or Win32 apps: OneDrive and Intune remain essential.
- When it fails, check Conditional Access, Activity Feed / CDP policies and the device's "Windows Backup and Restore profile" status.

## Frequently asked questions

### Does Windows Backup for Organizations back up user files?

No. The feature backs up Windows settings and the list of installed Microsoft Store apps. For files, rely on OneDrive and Known Folder Move.

### Can a backup be restored on a PC that is hybrid joined to Active Directory?

Not during OOBE: restore at enrollment requires a Microsoft Entra joined device, and hybrid join is listed among the unsupported provisioning methods. Microsoft does document a first sign-in restore, on recent Windows 11 24H2/25H2 builds, which accepts hybrid joined devices.

### Does Windows Backup for Organizations work with Autopilot self-deploying mode?

No. Microsoft states that the Autopilot profile must use user-driven mode. Self-deploying mode, the pre-provisioning technician flow and Autopilot Reset aren't supported.

### Which role is required to turn on the restore page in Intune?

The "Show restore page" setting is a tenant-wide setting that requires the Intune Service Administrator role (or Global Administrator). It applies to all Windows devices that enroll.

## Sources and documentation

- [Enable Windows Backup for Organizations - Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-enrollment/windows/enable-backup-restore)
- [Windows settings backup and restore overview](https://learn.microsoft.com/en-us/windows/configuration/windows-backup/)
- [Windows settings backup and restore settings catalog](https://learn.microsoft.com/en-us/windows/configuration/windows-backup/catalog)
- [Enterprise State Roaming and Windows settings backup and restore](https://learn.microsoft.com/en-us/windows/configuration/windows-backup/catalog-esr)
