Blog Post

Microsoft Security Baselines Blog
3 MIN READ

Windows 11, version 26H2 security baseline

Rick_Munck's avatar
Rick_Munck
Icon for Microsoft rankMicrosoft
Sep 29, 2026

Microsoft is pleased to announce the security baseline package for Windows 11, version 26H2!

Update: The Windows 11, version 26H2 security baseline has been updated to reflect the general availability of Administrator protection. An updated v2 package is now available, and organizations should review and test the existing Administrator protection configuration as appropriate for their environment.

 

You can download the baseline package from the Microsoft Security Compliance Toolkit, test the recommended configurations in your environment, and customize / implement them as appropriate.

Summary of Changes

This release includes several changes since the Security baseline for Windows 11, version 25H2 to further strengthen enterprise security and align the baseline with current platform capabilities and industry standards.

Security Policy

Change Summary

Printer\Configure Windows Ready Print driver ranking

Configured as “Enabled” to reduce reliance on third-party print drivers in the stack, narrowing the overall print driver attack surface.

Internet Explorer\Internet Control Panel\Advanced Page\Turn off encryption support

Updated from TLS 1.1 and TLS 1.2 to TLS 1.2 and TLS 1.3 to align with current security standards.

User Account Control: Configure type of Admin Approval Mode (updated)

Configured as “Admin Approval Mode with Administrator protection” to enable Administrator protection.

User Account Control: Behavior of the elevation prompt for administrators running with Administrator protection (updated)

Configured as “Prompt for credentials on the secure desktop” to require credential verification for administrative elevation.

 

Windows Ready Print driver ranking

Configure Windows Ready Print driver ranking" is the newly added setting under Administrative Templates\Printers to control whether Windows prefers the modern inbox IPP class driver over third-party OEM drivers when installing new printers. We recommend enabling this policy to reduce reliance on third-party print drivers in the stack, narrowing the overall print driver attack surface. Note that driver ranking applies when printers are installed via a connection method that supports IPP, such as USB or network multicast discovery. In those cases, if the printer supports IPP, Windows will install using the class driver even if a vendor V3/V4 driver is available. If the printer doesn't support IPP, or is installed directly as a TCP/IP printer, there's no change in behavior.

 

Encryption Support

We have updated the policy "Turn off encryption support" to allow only TLS 1.2 and TLS 1.3. Previous baseline releases permitted TLS 1.1 and TLS 1.2; however, TLS 1.1 is now considered obsolete and is no longer recommended for enterprise environments. This change aligns the security baseline with modern cryptographic standards while maintaining compatibility with widely deployed services that support current TLS versions.

 

Administrator Protection (update)

Administrator protection is now generally available. Organizations can enable it through Microsoft Intune or Group Policy.

Important: Organizations should review and test their existing configuration and adjust these settings as appropriate for their environment. The security baselines for Windows 11, versions 24H2, 25H2, and 26H2 include settings that enable Administrator protection.

The following policies are part of the security baseline:

  • User Account Control: Configure type of Admin Approval Mode
  • User Account Control: Behavior of the elevation prompt for administrators running with Administrator protection

An updated v2 package has been published for Windows 11, version 26H2, to reflect this change.

Please let us know your thoughts by commenting on this post or through the Security Baseline Community.

Updated Oct 08, 2026
Version 2.0