Skip to content
Kestro

Lifecycle and replacement

Windows 11 on an older machine: what does it take?

Three things decide it: TPM 2.0, Secure Boot in UEFI mode, and whether the processor is on Microsoft's list. The first two are often just a BIOS setting. The third cannot be worked around — and that is where a machine running perfectly well still has to be replaced.

Alireza Makvandi, Co-founder & Technical Director

Written by Alireza Makvandi · Co-founder & Technical Director

4 min read

Plenty of machines that run perfectly well are told they cannot update to Windows 11. That is rarely about performance and almost always about three requirements you can check in a couple of minutes.

The three requirements

TPM 2.0 is a security chip. Most business machines from 2016 onwards have it, but it is sometimes switched off in the BIOS from the factory. Secure Boot must be enabled, and the machine has to boot in UEFI mode rather than the old Legacy mode.

The processor also has to be on Microsoft's list. That is the limit that bites hardest, and it cannot be worked around by changing a setting.

Check it yourself

Press the Windows key and R, type tpm.msc and hit enter. The window tells you whether there is a TPM and which version. Type msinfo32 in the same place: it shows both BIOS mode, which should be UEFI, and Secure Boot state.

If the TPM shows as disabled, that is often just a BIOS setting — usually called PTT on Intel and fTPM on AMD.

If the machine cannot come along

There are guides to bypassing the requirements. We do not recommend it on a machine used in a company: Microsoft gives no guarantee of updates afterwards, and a machine without security updates is a problem, not a saving.

The sensible alternative is a used business machine that meets the requirements. There are plenty about, precisely because companies changed fleets for the same reason.

If you would rather have it done

If a whole fleet needs assessing, we can go through the list with you and say which machines can come along and which are better replaced.

Write to us

More on lifecycle and replacement

Questions we get about this

What does Windows 11 require of the machine?

TPM 2.0, Secure Boot switched on, and the machine booting in UEFI mode rather than the old legacy mode. On top of that the processor has to be on Microsoft's list, and that is the limit that bites hardest — it cannot be got round by changing a setting.

How do I check whether my machine meets the requirements?

Press the Windows key and R, type tpm.msc and press enter — the window says whether there is a TPM and which version. Type msinfo32 in the same place: it shows both the BIOS mode, which has to be UEFI, and the Secure Boot state.

TPM shows as switched off — can that be changed?

Often yes. It is frequently just a setting in the BIOS, usually called PTT on Intel and fTPM on AMD.

Can the Windows 11 requirements be bypassed?

Guides to doing it exist, but we do not recommend it on a machine that will be used in a company. Microsoft gives no guarantee of updates afterwards, and a machine without security updates is a problem in itself.

Let us find the right solution for you

Tell us about your situation and we will come back with a concrete proposal — no obligation and no sales pitch.

The people you will be talking to

Ismail Masoumabadi, Network Security & International Sales Management

Ismail Masoumabadi

Network Security & International Sales Management

Mehdi, Sales Advisory & Head of Marketing and Sales

Mehdi

Sales Advisory & Head of Marketing and Sales

Meet us