Microsoft Entra ID
General

Migrate Microsoft Entra Enterprise State Roaming

In brief

As of July 2026, ESR can no longer be managed in the Microsoft Entra admin center. Administrators must use Windows settings backup and restore policies; the supported settings remain unchanged.

What Entra admins need to know

Review existing ESR use and configure Windows backup and restore policies to maintain settings roaming. Without action, existing controls are honored for one year.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

EnableMigrate Enterprise State Roaming infrom Microsoft Entra ID

Enterprise State Roaming provides(ESR) lets users sync supported Windows settings across devices associated with their Microsoft Entra ID account. ESR management moved from the Microsoft Entra admin center to Windows settings backup and restore in July 2026. IT administrators now configure backup policies by using Microsoft Intune, another mobile device management (MDM) provider, or Group Policy.

The set of ESR settings remains unchanged. Only the management experience has changed. For the current list of supported settings, see the Enterprise State Roaming settings catalog.

ESR is separate from consumer settings sync, which uses a unified experience across their Windows devices and reducespersonal Microsoft account. Before July 2026, a Global Administrator could configure ESR through device settings in the time needed for configuring a new device.Microsoft Entra admin center. That portal management option is no longer available.

Migrate Enterprise State Roaming operates similarmanagement

To migrate ESR management, follow these steps:

  1. Review your current use of ESR and identify the users and devices that need settings backup and roaming.
  2. Confirm that your devices meet the backup requirements and that users have an eligible license. For current requirements and licensing information, see Windows settings backup and restore, the Enterprise State Roaming settings catalog, and the Microsoft Entra product page.
  3. Configure the Enable Windows Backup policy by using Microsoft Intune, the Policy configuration service provider (CSP), or Group Policy.
  4. Assign the policy to the standard consumer settings syncusers or devices that was first introduced in Windows 8. Enterprise State Roamingneed settings backup and roaming.
  5. Verify that the policy applies successfully.

For information about the legacy controls that limit which settings sync, see Group Policy and MDM settings for settings sync.

Backup is available to any organization with asupported for eligible Microsoft Entra ID P1 or P2 or Enterprise Mobility + Security (EMS) license.joined and Microsoft Entra hybrid joined devices. For more information on how to get a Microsoft Entra subscription,current operating system versions and build requirements, see the Microsoft Entra product pageWindows settings backup and restore system requirements.

To enable Enterprise State Roaming

  1. Sign in to the Microsoft Entra admin center as a Global Administrator.
  2. Browse to Entra ID > Devices > Overview > Enterprise State Roaming.
  3. Select Users may

    Microsoft Edge sync settings and app data across devices.is managed separately from ESR. For more information, see how to configure device settingsMicrosoft Edge Sync.

For a Windows 11 or Windows 10, version 21H2 or newer device to use the Enterprise State Roaming service, the device must authenticate using a Microsoft Entra identity. For devices that are joined to Microsoft Entra ID, the user’s primary sign-in identity is their Microsoft Entra identity, so no other configuration is required. For devices that use on-premises Active Directory, the IT admin must Configure Microsoft Entra hybrid joined deviceslegacy ESR diagnostics, see Troubleshoot Enterprise State Roaming.

Data storage and retention

Enterprise State RoamingWindows settings backup and restore treats user-specific settings as personal data is hosted in one or more Azure regions that best align withand stores the country/region value setdata in the Microsoft Entra instance. Enterprise State Roaming data is partitioned based on three major geographic regions: North America, EMEA, and APAC. Enterprise State Roaming data fortenant's region. In the public cloud, the country or region selected when the tenant is locally locatedcreated maps to a geographic location in Exchange Online.

By default, data is retained while it's associated with an active account and device. For current information about storage, encryption, compliance, and retention, see the geographical region, and isn't replicated across regions.Windows settings backup and restore FAQ. For example:

Country/region valuehas their data hosted in
An EMEA country/region such as France or ZambiaOne or more oflegacy ESR-specific questions, see the Azure regions within Europe
A North American country/region such as United States or CanadaOne or more of the Azure regions within the US
An APAC country/region such as Australia or New ZealandOne or more of the Azure regions within Asia
South American and Antarctica regionsOne or more Azure regions within the US

The country/region value is set as part of the Microsoft Entra directory creation process and can’t be modified later.Settings and data roaming FAQ. For general information about cloud locations, see Azure regions. If you need more details on yourhelp determining a data storage location, file a ticket withreview Azure support options or contact Azure support.

Data retention

Data synced to the Microsoft cloud using Enterprise State Roaming is retained until manually deleted or the data is determined to be stale.

Explicit deletion

Explicit deletion is when an administrator deletes a user, directory, or requests explicitly that data is to be deleted.

  • User deletion: When a user is deleted in Microsoft Entra ID, the user account roaming data is deleted after 90 to 180 days.
  • Directory deletion: Deleting an entire directory in Microsoft Entra ID is an immediate operation. All the settings data associated with that directory is deleted after 90 to 180 days.
  • On request deletion: If the Microsoft Entra admin wants to manually delete a specific user’s data or settings data, the admin can file a ticket with Azure support.

Stale data deletion

Data that isn't accessed for one year ("the retention period") is treated as stale and might be deleted from the Microsoft cloud. The retention period is subject to change but isn't less than 90 days. The stale data might be a specific set of Windows/application settings or all settings for a user. For example:

  • If no devices access a particular settings collection like language, then that collection becomes stale after the retention period and might be deleted.
  • If a user turned off settings sync on all their devices, then none of the settings data is accessed. All the settings data for that user will become stale and might be deleted after the retention period.
  • If the Microsoft Entra directory admin turns off Enterprise State Roaming for the entire directory, then all users in that directory stop syncing settings. All settings data for all users will become stale and might be deleted after the retention period.

Deleted data recovery

The data retention policy isn't configurable. Once the data is permanently deleted, it isn't recoverable. However, The settings data is deleted only from the Microsoft cloud, not from the end-user device. If any device later reconnects to the Enterprise State Roaming service, the settings are again synced and stored in the Microsoft cloud.

Next stepsRelated content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…