Emergency server help: get in touch

Windows 11 Compatibility Hold: Avoid 25H2 and 26H1 Upgrade Problems

Understand why Windows Update refuses to offer Windows 11 25H2 or 26H1 to some devices, how safeguard holds work, how to identify the hold ID with Update Compliance or the registry, and when it is safe to override.

Published Updated 5 min read

Windows 11 25H2 (build 10.0.26200) is the mainstream branch in most estates today, and 26H1 (build 10.0.28000) has been shipping since February 2026, initially on new hardware and now offered more broadly. Between the two sits the familiar problem: some machines are offered the new version immediately, others show “This PC doesn’t currently meet the minimum system requirements” or simply never see the offer. Most of the time the cause is a safeguard hold, a targeted block Microsoft applies when a driver, application or firmware combination is known to break after the upgrade. This guide explains how to identify and handle holds on Windows 11 devices managed by Windows Update, Intune or WSUS.

Applies to Windows 11 25H2 and 26H1

Short answer: A compatibility hold is a server-side block keyed on a specific driver, application or hardware ID that stops Windows Update from offering 25H2 or 26H1 to affected devices until the issue is fixed. Find the hold ID through Windows Update for Business reports (the “Safeguard holds” tab) or the GStatus values under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\TargetVersionUpgradeExperienceIndicators, resolve the underlying driver or app, and the offer resumes; override with the DisableWUfBSafeguards policy only on test devices.

How the two releases differ

25H2 shares the servicing branch with 24H2 and is delivered as an enablement package, so a device on 24H2 with current cumulative updates moves to 25H2 with one small download and a single reboot. 26H1 is a new platform release built on a new kernel branch; it arrives through Windows Update as a full feature update, takes longer to install, and has its own hardware baseline. Compatibility holds therefore differ between the two: a hold on 26H1 does not necessarily apply to 25H2, and devices blocked from 26H1 can still receive 25H2 and its monthly updates.

Where holds come from

Microsoft publishes known issues on the Windows release health page with a safeguard ID for each. Categories that have driven holds during 2026 include:

  • Storage and network drivers with kernel changes in 26H1.
  • Anti-cheat and endpoint security drivers that hook undocumented structures.
  • Audio, camera and fingerprint drivers on specific OEM models.
  • Applications with incompatible file-system filters or virtualisation layers.

The hold lifts automatically when Microsoft, the OEM or the vendor ships a fix and the telemetry shows the device has it.

Find the hold on a device

Windows Update for Business reports in Azure Monitor expose the Safeguard holds workbook; it lists devices and the numeric hold IDs. Without that, the device keeps its own record from the last compatibility appraisal:

reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\TargetVersionUpgradeExperienceIndicators" /s

Under the key for the target version (for example NI26H1 or a similar tag), the values GStatus, GatedBlockId and GatedBlockReason describe the state. A GStatus of 2 with a GatedBlockId means a hold is active; the ID matches the one listed on the release health page. RedReason names a hard block such as unsupported CPU or missing TPM 2.0, which is not a safeguard hold and cannot be lifted.

The appraiser runs during the update scan; force a fresh evaluation with:

schtasks /run /tn "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser"

Clear a hold the right way

Resolve the cause. Update the offending driver from the OEM or Windows Update optional drivers, upgrade the flagged application, or remove it if it is no longer needed. Rerun the appraiser and the update scan; the offer normally appears within a day.

For pilot devices where you accept the risk, Intune’s Settings Catalog contains Windows Update for Business » “Disable Safeguards For Feature Updates”, which maps to the registry value:

reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v DisableWUfBSafeguards /t REG_DWORD /d 1 /f

The equivalent GPO lives at Computer Configuration » Policies » Administrative Templates » Windows Components » Windows Update » Manage updates offered from Windows Update » “Disable safeguards for Feature Updates”. This bypasses only safeguard holds, not the hardware requirements, and it only works on Windows Update for Business managed devices, not on WSUS.

Verify

After the fix, check Settings » Windows Update; a device that was held now shows the feature update as available or downloading. From PowerShell confirm the appraiser result:

reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\TargetVersionUpgradeExperienceIndicators" /s | findstr GStatus

A GStatus of 1 with no GatedBlockId means eligible. In Intune, the Feature updates report under Reports » Windows updates lists the device state per policy.

Common pitfall

Teams often reach for the Installation Assistant or a mounted ISO to push past a hold. That works, but it upgrades a device Microsoft has specifically flagged as likely to break, and support for the resulting fault lands on you. Reserve manual upgrades for devices where you have confirmed the flagged driver is already updated but the hold has not yet lifted, and keep a rollback path (the previous installation is retained for ten days by default). For patching context this month see Windows 11 Patch Tuesday September 2026 (KB5124008).

Windows 11 compatibility hold at a glance

Windows 11 Compatibility Hold summary card: A compatibility hold is a server-side block keyed on a specific driver, application or hardware ID that stops Windows…
In short: A compatibility hold is a server-side block keyed on a specific driver, application or hardware ID that stops Windows Update from offering 25H2 or 26H1 to affected devices until the issue is fixed.

Official documentation: Windows client documentation, Windows Server documentation.

Related guides: Configure DHCP failover between two Windows Servers · Disable RDP drive, clipboard and USB redirection with Group Policy · Change a domain controller’s IP address without breaking replication.

Frequently asked questions

Does a safeguard hold also block Windows Server 2025 upgrades?

No. Safeguard holds are a Windows client mechanism tied to Windows Update for Business. Server in-place upgrades run from media and rely on the setup compatibility scan instead, which reports blocking issues in the compatibility report.

How long does a compatibility hold last?

Anywhere from a couple of weeks to several months; holds tied to a single driver often clear within a month once the vendor releases a fix, while holds on discontinued hardware can remain indefinitely. The release health page shows the status of each ID.

Can I undo a 26H1 upgrade that I forced through a hold?

Yes, within the rollback window (10 days by default, extendable to 60 with DISM /Online /Set-OSUninstallWindow /Value:60 before the upgrade) through Settings » System » Recovery » Go back. After that, a clean install of 25H2 is the only route.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
Windows 11 25H2 and 26H1
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.