Blog Post

Microsoft Security Baselines Blog
2 MIN READ

Windows 11, version 26H2 security baseline

Rick_Munck's avatar
Rick_Munck
Icon for Microsoft rankMicrosoft
Sep 29, 2026

Microsoft is pleased to announce the security baseline package for Windows 11, version 26H2!

You can download the baseline package from the Microsoft Security Compliance Toolkit, test the recommended configurations in your environment, and customize / implement them as appropriate.

Summary of Changes

This release includes several changes since the Security baseline for Windows 11, version 25H2 that further strengthen enterprise security and align the baseline with current platform capabilities and industry standards. These changes are summarized in the table below.

Security Policy

Change Summary

Printer\Configure Windows Ready Print driver ranking

Configured as “Enabled” to reduce reliance on third-party print drivers in the stack, narrowing the overall print driver attack surface.

Internet Explorer\Internet Control Panel\Advanced Page\Turn off encryption support

Updated from TLS 1.1 and TLS 1.2 to TLS 1.2 and TLS 1.3 to align with current security standards.

 

Windows Ready Print driver ranking

Configure Windows Ready Print driver ranking" is the newly added setting under Administrative Templates\Printers to control whether Windows prefers the modern inbox IPP class driver over third-party OEM drivers when installing new printers. We recommend enabling this policy to reduce reliance on third-party print drivers in the stack, narrowing the overall print driver attack surface. Note that driver ranking applies when printers are installed via a connection method that supports IPP, such as USB or network multicast discovery. In those cases, if the printer supports IPP, Windows will install using the class driver even if a vendor V3/V4 driver is available. If the printer doesn't support IPP, or is installed directly as a TCP/IP printer, there's no change in behavior.

 

Encryption Support

We have updated the policy "Turn off encryption support" to allow only TLS 1.2 and TLS 1.3. Previous baseline releases permitted TLS 1.1 and TLS 1.2; however, TLS 1.1 is now considered obsolete and is no longer recommended for enterprise environments. This change aligns the security baseline with modern cryptographic standards while maintaining compatibility with widely deployed services that support current TLS versions.

 

Please let us know your thoughts by commenting on this post or through the Security Baseline Community.

Updated Sep 28, 2026
Version 1.0