Kestro

Windows 11 on an older machine: what does it take?

For individuals and companies4 min readUpdated 2026-08-23

Plenty of machines that run perfectly well are told they cannot update to Windows 11. That is rarely about performance and almost always about three requirements you can check in a couple of minutes.

The three requirements

TPM 2.0 is a security chip. Most business machines from 2016 onwards have it, but it is sometimes switched off in the BIOS from the factory. Secure Boot must be enabled, and the machine has to boot in UEFI mode rather than the old Legacy mode.

The processor also has to be on Microsoft's list. That is the limit that bites hardest, and it cannot be worked around by changing a setting.

Check it yourself

Press the Windows key and R, type tpm.msc and hit enter. The window tells you whether there is a TPM and which version. Type msinfo32 in the same place: it shows both BIOS mode, which should be UEFI, and Secure Boot state.

If the TPM shows as disabled, that is often just a BIOS setting — usually called PTT on Intel and fTPM on AMD.

If the machine cannot come along

There are guides to bypassing the requirements. We do not recommend it on a machine used in a company: Microsoft gives no guarantee of updates afterwards, and a machine without security updates is a problem, not a saving.

The sensible alternative is a used business machine that meets the requirements. There are plenty about, precisely because companies changed fleets for the same reason.

If you would rather have it done

If a whole fleet needs assessing, we can go through the list with you and say which machines can come along and which are better replaced.

Write to us

Let us find the right solution for you

Tell us about your situation and we will come back with a concrete proposal — no obligation and no sales pitch.