An IT professional monitors cloud synchronization, device status, and analytics dashboards across multiple screens.
Microsoft has added a fresh batch of Windows 365 features. Most of them deal with the jobs Cloud PC admins actually spend time on: retiring machines, planning disaster recovery, getting users back into their work after a disconnect, and keeping connections up on poor networks. Petri described the batch as an expansion of recovery, management and connectivity features. Microsoft's own Windows 365 change log supports most of that, with one catch. These features did not ship together, and they are not all at the same stage. Some are generally available, some are in public preview, some are rolling out in phases, and a few of the claims are hard to confirm at all.

Here is what changed, who can use it, and what to check before you turn anything on.

Windows 11 26H2 Cloud PC images arrive​

The most concrete new item is the image gallery. In Microsoft's change log for the week of September 28, 2026, the latest Windows Enterprise 26H2 images are available for provisioning new devices. Admins can update provisioning policies to use one of the following images: Windows 11 Enterprise 26H2, Windows 11 Enterprise + Microsoft Apps 26H2, and Windows 11 Enterprise Developer Configuration + M365 Apps 26H2.

The timing fits the wider Windows schedule. Anoop C. Nair's HTMD blog reports that the Windows 11 26H2 OS itself reached General Availability on September 29, 2026, so Cloud PC images showed up at about the same time the OS did.

The Developer Configuration image has been building up for a while. Microsoft first released a developer-optimized Windows 11 image in preview in June. The change log later shows Intelligent Terminal and Coreutils being added in preview, followed by Microsoft 365 Apps. Endpoint Weekly, writing about the original preview, said the image came with tools such as Visual Studio Code, Git, GitHub CLI, Python and Node.js. It also flagged two limits: "Not for production workloads" applied to the preview, and the preinstalled third-party tools can't be managed through Intune. Your team still has to patch and watch those tools. If you are standardizing on the 26H2 developer image, budget time for that.

Section summary: Three 26H2 gallery images are available for new provisioning. Existing Cloud PCs don't move to them automatically. You have to update your provisioning policies.

Lifecycle management: bulk deprovisioning and Admin Insights​

Bulk deprovisioning during the grace period. When a Cloud PC loses its license, it goes into a seven-day grace period. Before this change, admins either waited the seven days out or ended the grace period on one machine at a time. Microsoft's change log shows the feature first launched in public preview for Windows 365 Enterprise and Frontline Dedicated. A later entry lists bulk deprovisioning as generally available for Windows 365 Enterprise and Windows 365 Flex dedicated Cloud PCs. Microsoft's documentation says it runs through the provisioning policy view and the Intune Bulk Action Wizard.

What it's good for: a wave of offboarding, a project wrapping up, or a license reshuffle. You can clear dozens of idle Cloud PCs at once instead of clicking through them one by one. The flip side is that deprovisioning can't be undone. Check your selection twice before you confirm.

Keep this separate from a different Windows 365 Reserve preview, which lets admins bulk provision and deprovision up to 1,000 Reserve Cloud PCs in a single request. The two features do different jobs.

Admin Insights. Admin Insights started in public preview in May and is now generally available. Microsoft says it gives administrators a prioritized view of important signals across the Cloud PC environment, with links into the related reports and device views. A separate preview adds outlier cards to the Monitor Cloud PCs > Connection health tab, which point out Cloud PCs with high latency or high connection-failure rates. It works as a triage layer on top of your existing monitoring, not a replacement for it.

Local admin via Cloud PC configurations (preview). The existing "Enable local admin" setting can now be set under Devices > Cloud PC Settings > Create > Cloud PC configurations in Intune. This doesn't make local admin a default. It moves an existing setting into the newer configuration model. The security tradeoff hasn't changed: users with local admin rights can install software and change system settings. Windows 11 26H2 also introduces Administrator protection, which Microsoft's Windows IT Pro Blog describes as providing just-in-time administrative privileges and profile separation to help harden Windows against elevation-of-privilege attacks. That makes it worth reviewing your local admin policy alongside your OS upgrade plans.

Section summary: Bulk grace-period deprovisioning and Admin Insights are generally available. Local admin through Cloud PC configurations is still in preview.

Recovery: one setup experience, more region options​

Unified BCDR setup (GA). Setup for Point-in-Time Restore, Cross-region Disaster Recovery and Disaster Recovery Plus is now generally available inside Cloud PC Settings, and all three can be enabled together in one Cloud PC configuration. This combines the setup screens only. The three services still work differently. Point-in-Time Restore rolls a Cloud PC back to an earlier state, while the cross-region options protect against a whole region going down.

Alternate DR regions (public preview). Microsoft's change log says Windows 365 now supports alternate Azure regions for BCDR. This is aimed at geographies with only one Windows 365-supported region. Admins can pick alternate regions for Cross-region Disaster Recovery and DR+, with Australia Southeast and South India given as examples. Microsoft is clear that alternate regions are for disaster recovery only and can't be used to provision Cloud PCs. Petri said Microsoft had "expanded support" here, but in practice the feature is in preview and limited to disaster recovery.

Section summary: BCDR setup is now in one place and generally available. Alternate regions are a preview for DR only, so check current regional eligibility in Microsoft's requirements before you write them into a compliance plan.

Session State Retention for Flex dedicated Cloud PCs​

This one users will feel right away. Microsoft's change log lists Session State Retention as generally available for eligible Windows 365 Flex dedicated Cloud PCs. Normally, once a user has been disconnected for the idle period (two hours by default), the Cloud PC powers off. With this feature, an eligible machine saves the session instead, so when the user reconnects their apps and documents are still open. Microsoft pairs it with Intelligent pre-start, which powers the Cloud PC on ahead of a likely connection.

"Eligible" is doing a lot of work in that sentence. Microsoft's eligibility page lists these requirements:

  • Windows 365 Flex in dedicated mode only
  • Windows 11 24H2 or newer from a Microsoft gallery image. Custom images aren't supported yet.
  • At least 4 vCPU / 16 GB RAM / 128 GB. Two-vCPU sizes are excluded, and retention is "best-effort."
  • Connections through a Windows App client (web, Windows, iOS, macOS or Android). Third-party clients aren't supported.
  • One of a specific list of Azure regions, including Central US, Canada Central, UK South, Japan East and Southeast Asia, among others

The feature relies on hibernation, so typical hardening scripts can quietly turn it off. If it isn't working, check these first:

  1. Power policy: Any custom power policy applied through Group Policy, Intune or local changes excludes the Cloud PC until the policy is removed or set back to defaults.
  2. Hibernation: Scripts that run powercfg /h off, or that set HKLM\SYSTEM\CurrentControlSet\Control\Power\HibernateEnabled to 0, must not apply to these machines.
  3. hiberfil.sys: Cleanup tools, antivirus or DLP software must not delete C:\hiberfil.sys. Microsoft recommends adding an exclusion for it.
  4. Services: CIS, STIG or custom baselines must not disable the Windows Power service or the Hyper-V Guest Shutdown Service (vmicshutdown). Set both to Automatic.
  5. Disk space: You need roughly as much free OS-disk space as the Cloud PC has RAM.
  6. VBS: If VBS, Credential Guard or HVCI is enabled, you need Windows 11 24H2 (build 26100) or later. Guarded Host must be off.

Microsoft also says Azure capacity limits can affect whether retention is available, so don't promise users it will always work.

Reserve, connectivity and peripherals​

Windows 365 Reserve user provisioning (GA). When IT enables it, eligible users can start provisioning a Reserve Cloud PC themselves from Windows App. That's useful when a laptop dies or someone is stuck travelling. The feature is off by default. Admins turn it on through Windows App settings in Intune and limit it to specific Microsoft Entra ID groups, and IT still controls policy and licensing. Separately, Autopilot Device Preparation for Reserve is generally available, so required apps and settings are applied before the user connects.

Connectivity. Microsoft's change log shows RDP Multipath with redundant UDP paths is generally available in Azure Government. A phased GA rollout has also started there for redundant TCP paths and for RDP Shortpath via TURN. Azure Government uses a dedicated 20.140.236.0/22 range for STUN/TURN, so government tenants should update their firewall allow lists. For macOS, the change log notes RDP Shortpath for public networks and RDP Multipath with UDP in the Beta of Windows App for macOS. That is narrower than Petri's description of broad macOS expansion. Microsoft also warns that redundant TCP may not be switched on for every Cloud PC until the rollout finishes.

TWAIN scanner redirection (preview). Supported scanners plugged into a local Windows device can be redirected to a Cloud PC using high-level redirection, which Microsoft describes as a better scanning experience than USB redirection. That should help healthcare, legal and back-office teams that still run on paper. "Supported scanners" means not every scanner will work, so pilot it first.

Identity and Display Protection. Microsoft's change log includes an entry for iOS preview support for in-session passwordless authentication. Petri also reported external identity support on iOS, generally available external identity support on macOS, and a Display Protection preview for protecting sensitive content on screen in Cloud PC sessions. We couldn't confirm the macOS GA claim or the Display Protection details in Microsoft's documentation, so treat those as Petri's reporting until Microsoft publishes them.

The bottom line for admins​

Petri's overall verdict that Windows 365 is becoming more resilient and easier to manage is reasonable. Still, this is a set of separate updates at different stages, not a single release. In practical terms:

  • Generally available: 26H2 gallery images, bulk grace-period deprovisioning, Admin Insights, unified BCDR setup, Session State Retention (for eligible Flex dedicated PCs), Reserve user provisioning, and Reserve Autopilot Device Preparation
  • Preview or beta: alternate DR regions, local admin via Cloud PC configurations, TWAIN redirection, iOS in-session passwordless sign-in, and macOS Shortpath/Multipath
  • Phased rollout: Azure Government TURN and redundant TCP Multipath

Microsoft says monthly Windows 365 updates can take several weeks to reach every tenant, so a feature may not show up in your Intune console straight away. For most teams, a sensible order is to start with the low-risk GA items: switch provisioning policies to 26H2 images, clean up grace-period Cloud PCs in bulk, and check Admin Insights. Then audit your hardening baselines before you count on Session State Retention.

 

References

  1. Microsoft Expands Windows 365 With New Recovery, Management, and Connectivity Features Petri IT Knowledgebase 2026-10-07T16:08:36+00:00
  2. Windows 365 Developer Image: A Pre-Configured Cloud PC… endpointweekly.com
  3. Create A New Windows 11 26H2 Cloud PC Using Intune HTMD Blog anoopcnair.com