Windows

Windows Backup for Organizations with Intune: the complete 2026 guide

Back up and restore users' Windows settings during a PC refresh with Intune: prerequisites, configuration, Autopilot and troubleshooting.

Windows Backup for Organizations with Intune: the complete 2026 guide

🌐 This article was originally written in French and automatically translated. Read the original (FR)

TL;DR

Windows Backup for Organizations (now named Windows settings backup and restore) backs up Microsoft Entra ID users' Windows settings and list of Microsoft Store apps to the cloud, then restores them during the OOBE of a new Microsoft Entra joined PC. In Intune, you need a Settings catalog policy with "Enable Windows Backup" and the tenant-wide "Show restore page" turned on.

Windows Backup for Organizations lets you back up a Microsoft Entra ID user’s Windows settings and list of Microsoft Store apps to the cloud, then automatically restore them during the OOBE of their new PC. In Intune, you turn it on with two settings: a Settings catalog policy for backup, and the tenant-wide “Show restore page” option for restore.

I covered this feature in a video on my YouTube channel. This article walks through the same approach in writing, with the exact prerequisites, the pitfalls I run into with customers and the points to watch on the Autopilot side.

What is Windows Backup for Organizations?

Windows Backup for Organizations is the enterprise flavor of Windows Backup. As I write this, Microsoft is renaming it Windows settings backup and restore, so you’ll see both names in the documentation and consoles for a while.

The goal is simple: when a user changes PCs (hardware refresh, migration from Windows 10 to Windows 11, reset after an incident), they get back their wallpaper, dark mode, accessibility settings, Start menu layout or File Explorer preferences, without the service desk having to step in.

How it works:

  1. The administrator enables the backup policy.
  2. A scheduled task automatically backs up settings every eight days. Users can also start a manual backup from the Windows Backup app (Back up button).
  3. On the new PC, after Entra ID authentication in OOBE, a page offers to restore a backup from a previous device or to set up the PC as new.

Note: Microsoft announced that starting with Windows 11, version 26H2, backup will be enabled by default on eligible devices. Existing administrator-configured policies (enabled or disabled) are still honored, and restore must still be enabled explicitly.

What is backed up… and what isn’t

Microsoft publishes a detailed catalog of supported settings. In short, on Windows 11:

Category Examples backed up and restored Examples not supported
System Night light, notifications, Do not disturb, Snap windows, show file extensions Rename this PC, notification sounds
Personalization Background, colors and mode, themes, lock screen, Start layout, taskbar behaviors Taskbar pinned layout, “most used apps”
Devices Pointer speed, touchpad, pen, AutoPlay, Windows-managed default printer Pen button as right-click
Time & language Time zone, touch keyboard options Language preferences and dictionary
Accessibility Text size, Magnifier, Narrator, color filters, Sticky keys Starting Magnifier or Narrator before sign-in
File Explorer Hidden files, extensions, compact view, check boxes —
Accounts — Accounts, Wi-Fi networks and passwords
Windows Update — No settings

Two points are worth stressing to your users and management:

  • Files are out of scope. The documentation only covers settings and the list of Microsoft Store apps. Documents remain OneDrive’s job.
  • Win32 and LOB apps aren’t restored. Only the Microsoft Store apps in the backup are reinstalled. Your line-of-business apps keep coming through Intune.

On Windows 10, the scope is narrower (for example, no Snap or themes). That makes sense, since Windows 10 is only used to back up before migrating; restore only happens on Windows 11.

Prerequisites

Backup

The user must be signed in with a Microsoft Entra ID account, on a Microsoft Entra joined or hybrid joined device, running at least:

  • Windows 10, version 22H2, build 19045.6216 or later;
  • Windows 11, version 22H2, build 22621.5768 or later;
  • Windows 11, version 23H2, build 22631.5768 or later;
  • Windows 11, version 24H2, build 26100.4946 or later.

Restore during OOBE

  • Microsoft Entra joined device (no hybrid join at this stage).
  • Windows 11 22H2 (22621.3958+), 23H2 (22631.3958+) or 24H2 (26100.4770+ according to the Windows documentation).
  • The user must have at least one backup.
  • If Autopilot is used, the profile must be in user-driven mode.

If your PCs ship with an image older than July 2025, enable the Install Windows quality updates setting in your enrollment status page (ESP) profile so the PC gets the required updates during OOBE.

Restore at first sign-in

Microsoft also documents a restore at first sign-in after enrollment, on Windows 11 24H2 (26100.7922+) or 25H2 (26200.7922+). It accepts Microsoft Entra joined or hybrid joined devices, which opens the door for fleets that aren’t “cloud native” yet.

Roles, licensing and clouds

  • The tenant-wide restore setting requires the Intune Service Administrator role (or Global Administrator).
  • The feature isn’t available in Government clouds (GCC High, sovereign) or in China (21Vianet).
  • For settings roaming (formerly Enterprise State Roaming), Microsoft states that an appropriate license is required, for example Microsoft 365, EMS, Microsoft Entra ID or Windows E3/E5.
  • Windows 11 SE, Holographic, IoT Core and Team (Surface Hub) editions aren’t supported.

Configure backup and restore in Intune

Step 1: enable backup with the Settings catalog

  1. Sign in to the Microsoft Intune admin center (intune.microsoft.com).
  2. Go to Devices > Manage devices > Configuration and create a policy.
  3. Choose the Windows 10 and later platform and the Settings catalog profile type.
  4. In the Administrative Templates\Windows Components\Sync your settings category, add Enable Windows Backup and set it to Enabled.
  5. Assign the policy to a group of users or devices, then save.

If you prefer OMA-URI, the matching CSP is:

./Device/Vendor/MSFT/Policy/Config/SettingsSync/EnableWindowsbackup
Type: string – Value: `<enabled/>`

Don’t mix GPO and CSP for this feature: Microsoft warns that combining both leads to unexpected results.

Step 2: show the restore page

  1. In the Intune admin center, go to Devices > Enrollment, Windows tab.
  2. Under Enrollment options, select Windows Backup and Restore.
  3. For Show restore page, select On.
  4. Select Save.

This setting is tenant-wide: it applies to every Windows device that enrolls, and it’s only delivered at enrollment time. Changing it later has no effect on devices that are already enrolled.

There’s a second option, applied after enrollment: the Enable Windows Restore setting in the Windows Backup And Restore category of the Settings catalog (CSP ./Device/Vendor/MSFT/WindowsBackupAndRestore/EnableWindowsRestore). It follows the normal policy refresh cycle and can be targeted by group.

Step 3: control what users can change

On the device, users manage their options in Settings > Accounts > Windows backup: Remember my preferences and Remember my apps. If you want to lock these choices, the “Do not sync” policies under Sync your settings let you turn off specific groups (accessibility, personalization, language, apps…).

Windows Autopilot: what works and what doesn’t

This is the point that raises the most questions in projects. Restore is not supported with:

  • self-deploying mode;
  • the technician flow of pre-provisioning (Autopilot for pre-provisioned deployment);
  • Autopilot Reset;
  • Microsoft Entra hybrid join in OOBE;
  • manual enrollment through the Settings app, via Group Policy or via Configuration Manager co-management;
  • shared or userless devices.

In practice, the target scenario is Autopilot user-driven mode with Microsoft Entra join: the user authenticates, sees the restore page, picks their old PC, then the ESP continues. For pre-provisioning, the documentation only excludes the technician flow; I recommend validating the user flow on a pilot before rolling out broadly.

The end-user experience in OOBE

Here’s what the user sees on their new PC:

  1. They start the PC, choose their language and network, then sign in with the same work account as on the old device.
  2. A restore page displays their list of backups (one PC per line).
  3. They select the old device and select Continue, or choose to set up the PC as new.
  4. Setup completes and the settings and Store apps are restored automatically.

My field advice: brief users before delivery. A simple message such as “on the restore screen, pick your old PC” saves a lot of clicks on “set up as new”.

Monitoring and troubleshooting

The per-device report

  1. Go to Devices, Windows tab, and open the device.
  2. Select Enrollment.
  3. Find the Windows Backup and Restore profile row.

Possible statuses are: Not Applicable, No policy assigned, Succeeded, Failed, No Backup Profiles and Setup as New PC Selected. “No Backup Profiles” usually means the old PC never backed up.

The causes I see most often

  • Conditional Access: a policy that requires a compliant device can block the token during OOBE (“You can’t get there from here”). Microsoft recommends allowing the service with AppId d32c68ad-72d2-4acb-a0c7-46bb2cf93873.
  • Phishing-resistant MFA: if you enforce a strong authentication strength, the restore experience app (74d197dc-b84d-4d43-a1b2-b5bf3bb91c11) can trigger a security key prompt. On a Hyper-V VM this is blocking: use a Temporary Access Pass.
  • Hardening policies: if EnableActivityFeed, PublishUserActivities, UploadUserActivities, EnableCDP or AllowConnectedDevices are set to Disabled, backup doesn’t happen. A classic on tenants built from older baselines.
  • Build too old: check the exact build number, not just the version.

View or delete backed-up data

Backups can be accessed through the Microsoft Graph beta APIs, or more simply with the PowerShell module published by Microsoft:

Install-Module WindowsBackupAdmin -Scope CurrentUser
Get-WindowsBackup -UserId user@contoso.com
Remove-WindowsBackup -UserId user@contoso.com

Handy for a GDPR request or to clean up the data of a departed employee.

Comparison with Enterprise State Roaming and OneDrive

Windows Backup for Organizations Enterprise State Roaming OneDrive (Known Folder Move)
Scope Windows settings + list of Store apps Roaming of some settings across devices User files (Desktop, Documents, Pictures…)
Timing Backup every 8 days, restore at OOBE or first sign-in Continuous sync Continuous sync
Management Intune / CSP / GPO Now through Windows settings backup and restore policies OneDrive policies

Important: Microsoft has moved Enterprise State Roaming management into Windows settings backup and restore. Management from the Microsoft Entra portal was only planned until the end of June 2026; after that, only policy-based management is supported. If you were using ESR, make sure your Intune policies take over.

The three building blocks are therefore complementary: OneDrive for files, Windows Backup for the Windows environment, Intune for apps and configuration.

My take as a consultant

Windows Backup for Organizations doesn’t replace a migration strategy, but it removes a large part of the friction users feel during a device refresh. My approach:

  1. Enable backup several weeks before the rollout, so every user has at least one recent backup.
  2. Turn on “Show restore page” once your user-driven Autopilot profiles are validated.
  3. Test Conditional Access and MFA on a pilot before opening it to everyone.
  4. Communicate clearly: “your settings come back, your files are in OneDrive, your apps arrive through the Company Portal”.

Well prepared, it’s one of the features that delivers the most perceived value for minimal configuration effort.

Key takeaways

  • Backup works on Microsoft Entra joined or hybrid joined devices; restore during OOBE requires a Microsoft Entra joined device.
  • Two Intune settings are required: "Enable Windows Backup" in the Settings catalog and "Show restore page" under Devices > Enrollment > Windows.
  • With Autopilot, only user-driven mode is supported: not self-deploying mode, not the pre-provisioning technician flow, not Autopilot Reset.
  • Settings and the list of Store apps are restored, not files or Win32 apps: OneDrive and Intune remain essential.
  • When it fails, check Conditional Access, Activity Feed / CDP policies and the device's "Windows Backup and Restore profile" status.

Frequently asked questions

Does Windows Backup for Organizations back up user files?

No. The feature backs up Windows settings and the list of installed Microsoft Store apps. For files, rely on OneDrive and Known Folder Move.

Can a backup be restored on a PC that is hybrid joined to Active Directory?

Not during OOBE: restore at enrollment requires a Microsoft Entra joined device, and hybrid join is listed among the unsupported provisioning methods. Microsoft does document a first sign-in restore, on recent Windows 11 24H2/25H2 builds, which accepts hybrid joined devices.

Does Windows Backup for Organizations work with Autopilot self-deploying mode?

No. Microsoft states that the Autopilot profile must use user-driven mode. Self-deploying mode, the pre-provisioning technician flow and Autopilot Reset aren't supported.

Which role is required to turn on the restore page in Intune?

The "Show restore page" setting is a tenant-wide setting that requires the Intune Service Administrator role (or Global Administrator). It applies to all Windows devices that enroll.

Sources and documentation

#Windows Backup for Organizations#Microsoft Intune#Windows Autopilot#Windows 11#Microsoft Entra ID