Support for Windows 10 is ending on October 14, 2025, and you might have started wondering whether your devices are ready for Windows 11. While Microsoft has released new hardware requirements for Windows 11, they are not dramatically different from Windows 10 requirements.

However, here is the critical insight many organizations miss: before you can be Windows 11 ready, you must first be Windows 10 ready.

Check you PC for Windows 11 readiness before upgrading to Windows 11
Check you PC for Windows 11 readiness before upgrading to Windows 11

Windows 11 has specific requirements designed to enhance security and performance. These include:

  • Processors/CPUs (Central Processing Units). At least 1 Ghz. with 2 or more cores and on the list of approved CPUs . The processor in your PC is a key factor for running Windows 11. The clock speed (the minimum of 1 Ghz.) and number of cores (at least 2) are built into the processor as it was made are not considered upgradable components.
  • TPM 2.0. Trusted Platform Module (TPM) is a chip that provides hardware-based security features such as encryption, authentication, and attestation. Windows 11 requires TPM 2.0, which is the latest version of this technology, to enable features such as BitLocker, Device Encryption, Windows Hello, and Measured Boot.
  • UEFI and Secure Boot. Unified Extensible Firmware Interface (UEFI) is a modern replacement for the legacy BIOS that initializes the hardware components and boots the operating system. Secure Boot is a feature of UEFI that ensures that only authorized software can run during the boot process. Windows 11 requires UEFI and Secure Boot to prevent malware and rootkits from compromising the system.
  • BIOS-Level Hardware Virtualization Support. Make sure that your computer supports hardware virtualization. Windows 11 requires virtualization to support Virtualization Based Security (VBS). VBS is a feature of Windows 11 that uses virtualization to create a secure environment where sensitive operations and data can be protected from malicious software. VBS isolates the operating system’s memory, secrets, and critical components from the rest of the system, making it harder for attackers to access or tamper with them. VBS also enables features such as Windows Defender Credential Guard , and Windows Defender System Guard .

The prerequisite: Be Windows 10 ready

Before we dive into the upgrade steps, let me clarify why these requirements matter for your current Windows 10 environment. TPM, UEFI, and virtualization are not optional features you enable at your convenience - they are essential components of Windows 10’s security architecture.

When properly configured, TPM, UEFI, and virtualization enable Windows 10 to:

  • Protect your devices from unauthorized access and data theft by encrypting the hard drive, verifying the identity of users and devices, and preventing spoofing and phishing attacks.
  • Detect and prevent malware and rootkits from compromising the boot process, the operating system, and the critical system components by using secure and measured boot, code integrity policies, and hypervisor-enforced code integrity.
  • Isolate and protect sensitive operations and data from the rest of the system by using virtualization-based security, credential guard, device guard, and system guard.
  • Enhance the performance and reliability of your devices by using modern firmware and hardware technologies that support faster boot times, improved power management, and better error handling.

If you have not enabled TPM, UEFI, and virtualization on your Windows 10 devices, you are not only missing these benefits but also putting your organization at risk of security breaches, data loss, and compliance violations. It is crucial that you check and enable these features on all existing devices and ensure that any new devices you purchase or deploy have these components enabled.

A solid foundation or platform constructed with security building blocks labeled with icons for TPM, UEFI, Secure Boot, and VBS

By addressing these settings now, you accomplish two goals simultaneously:

  1. Strengthen your current security posture - Your Windows 10 environment becomes more secure immediately.
  2. Prepare for Windows 11 - You eliminate the most common blockers for Windows 11 deployment.

5 steps to get ready for Windows 11

If you want to enjoy the new features and benefits of Windows 11, you need to prepare your organization for the upgrade. Here are five steps to get ready for Windows 11 and make the transition smoother.

Step 1: Validate your Windows 10 security posture

Before thinking about Windows 11, ensure your current Windows 10 environment has the foundational security features enabled:

  • Verify TPM is enabled and functional across your device fleet
  • Confirm UEFI mode is active (not legacy BIOS)
  • Ensure Secure Boot is enabled
  • Check that Virtualization Based Security (VBS) is operational

You can use the PC Health Check  tool to assess individual devices, or leverage Microsoft Intune’s hardware readiness reports for fleet-wide visibility.

Step 2: Update and configure device firmware

Firmware updates are often overlooked but critical for both security and compatibility. Ensure device firmware is updated regularly and configured according to best practices:

  • Enable TPM 2.0 - If your devices have configurable TPM settings, ensure TPM 2.0 is selected (not TPM 1.2)
  • Enable Hardware Virtualization - Intel VT-x or AMD-V must be enabled in BIOS/UEFI settings
  • Enable UEFI and Secure Boot - Disable legacy boot options and CSM (Compatibility Support Module)

Consider using Windows Autopilot  with DFCI (Device Firmware Configuration Interface) to manage firmware settings at scale for supported devices.

Step 3: Verify driver compatibility

Applications with hardware-level access - such as endpoint security products, VPN clients, and inventory agents - must use signed drivers that have passed the Windows Hardware Compatibility Program .

How to verify drivers:

  1. Open Device Manager (Win + X, then select Device Manager)
  2. Right-click on the device and select Properties
  3. Navigate to the Driver tab and review the driver version and date
  4. Check for a Digital Signer - it should show a trusted publisher

Step 4: Protect your data

Data loss during upgrades is every organization’s nightmare. Before initiating the upgrade, ensure user data is protected:

  • Enable OneDrive Known Folder Move (KFM) - Automatically sync Desktop, Documents, and Pictures folders to OneDrive for Business. This ensures user data is backed up to the cloud and available on any device.
  • Verify backup solutions - Confirm your enterprise backup solution covers critical data and test restore procedures.
  • Communicate with users - Inform users about what data is protected and remind them to save work before upgrades.

OneDrive KFM can be configured via Microsoft Intune or Group Policy. Learn more: Redirect Known Folders .

Step 5: Plan and execute the upgrade

With the foundation in place, it’s time to plan your deployment strategy:

  • Assess readiness - Use Intune’s Windows 11 readiness reports to identify devices that meet requirements and those that need attention.
  • Pilot first - Deploy to a pilot group of early adopters to identify issues before broad rollout.
  • Use managed deployment - Deploy Windows 11 using Windows Autopatch, Windows Update for Business, or feature update policies in Intune. Avoid manual downloads for enterprise environments.
  • Communicate - Inform your team about the upgrade schedule, expected experience, and where to get support.
  • Monitor and validate - After deployment, verify that all systems are functioning correctly and address any issues promptly.

Frequently asked questions

What if my hardware doesn’t meet the Windows 11 requirements?

If your hardware doesn’t meet the requirements, you have several options:

  • Review the specific blocker - Use PC Health Check to identify exactly which requirement is not met. Sometimes it’s a simple BIOS setting.
  • Check for firmware updates - Some older devices gained TPM 2.0 support through firmware updates.
  • Plan hardware refresh - For devices that genuinely cannot support Windows 11, plan a hardware refresh cycle aligned with the Windows 10 end-of-support date.
  • Extended Security Updates (ESU) - For devices that cannot be upgraded or replaced in time, Microsoft offers paid Extended Security Updates for Windows 10. However, this should be a last resort, not a long-term strategy.
How long does the upgrade process take?

The duration varies depending on several factors:

  • Individual device: Typically 30-60 minutes for the actual upgrade, depending on hardware specifications and data volume.
  • Fleet deployment: For enterprise environments, plan for a phased rollout over weeks or months. Start with pilot groups, then expand to broader deployment rings.
  • Preparation time: The 5 steps outlined above may take several weeks to complete properly, especially firmware updates and driver compatibility verification.
Will my applications work with Windows 11?

Most applications compatible with Windows 10 will work with Windows 11. Microsoft has maintained strong application compatibility between versions. However:

  • Test critical line-of-business applications in a pilot environment before broad deployment.
  • Check with vendors for official Windows 11 support statements, especially for security software and drivers.
  • Use the App Assure program - Microsoft offers free assistance through App Assure  to help resolve application compatibility issues.
Can I bypass the Windows 11 requirements?

While there are workarounds to install Windows 11 on unsupported hardware, this is not recommended for enterprise environments:

  • Unsupported devices may not receive all security updates.
  • You may encounter stability and compatibility issues.
  • Microsoft does not guarantee support for unsupported configurations.
  • Your organization’s security and compliance posture could be compromised.

Instead, focus on properly preparing your device fleet or planning hardware refreshes for non-compliant devices.

When should we start preparing for Windows 11?

Now. With Windows 10 end of support on October 14, 2025, organizations should already be in the planning and preparation phase. A realistic timeline:

  • Now - Q2 2024: Complete Steps 1-4 (validation, firmware, drivers, data protection)
  • Q2 - Q3 2024: Begin pilot deployments
  • Q4 2024 - Q2 2025: Phased production rollout
  • Q3 2025: Final remediation and hardware refresh for remaining devices

Don’t wait until the last minute - unexpected issues always arise during large-scale deployments.

Start your Windows 11 journey today

The clock is ticking toward Windows 10 end of support. But remember - the first step isn’t installing Windows 11. The first step is ensuring your organization is truly Windows 10 ready.

Illustration showing 5 ascending glass steps or platforms leading upward, each step illuminated with a soft blue glow

By following these five steps, you’ll not only prepare for a smooth Windows 11 transition but also strengthen your current security posture. That’s a win-win.

Do you have questions about your Windows 11 readiness journey? Feel free to reach out - I’m always happy to discuss deployment strategies and lessons learned.

Happy upgrading!

–Jesper