In short
- Windows 11 needs TPM 2.0, Secure Boot, and a processor on Microsoft's list (roughly Intel 8th gen or newer, AMD Ryzen 3000 or newer).
- TPM and Secure Boot are often present but switched off. Turning them on in the BIOS fixes a lot of "incompatible" PCs for free.
- The processor rule can't be fixed with a setting or a part. If that's your wall, ESU keeps you safe to October 2027 while you decide.
- Back up before you upgrade, and enroll in ESU first so a rollback lands on a patched system.
Microsoft's PC Health Check is famous for saying "this PC doesn't currently meet Windows 11 system requirements" and stopping there. That one unhelpful sentence is why so many people conclude they need new hardware. Most don't. The requirements are rules about security features, not speed, and two of the three common failures are settings.
What Windows 11 actually requires
| Requirement | What it is | If you fail it |
|---|---|---|
| TPM 2.0 | A security chip, or a firmware feature that does the same job, for storing encryption keys. | Often fixable. Frequently present but switched off in the BIOS. See below. |
| Secure Boot | A firmware feature that only starts signed operating systems. Needs UEFI mode, not Legacy. | Often fixable. Usually a toggle, though Legacy-boot machines need a disk conversion first. |
| Supported processor | Intel 8th generation (late 2017) or newer; AMD Ryzen 3000 (Zen 2) or newer. Microsoft's current list has no 7th-gen exceptions. | Hard block. No setting or add-on part changes this. It's the wall most 2015–2017 PCs hit. |
| 4GB RAM, 64GB storage | Bare minimums. | Fixable. A memory or drive upgrade helps Windows 10 just as much. |
Source: Microsoft Learn, processor requirements. Re-checked September 10, 2026.
Step one: find out which check failed
- Run WhyNotWin11. It's free and open-source, and unlike Microsoft's tool it shows every requirement as its own green or red line. Now you know your actual situation.
- Red on TPM? Restart, press the BIOS key during startup (usually Del or F2), and look for
PTTon Intel systems orfTPMon AMD, often under Security or Advanced. It is frequently disabled from the factory. Switch it on, boot back up, run the checker again. A lot of "incompatible" PCs become compatible right here. - Red on Secure Boot? Also usually a firmware toggle. One caution: if Windows was installed in the old Legacy/MBR style, switching to UEFI boot needs a disk conversion first (Microsoft's
mbr2gpttool does it in place). Read up before flipping the switch. - Red on the processor? That one's real. Skip to the CPU wall.
- Whatever you find, enroll in ESU today. It's free, takes five minutes, and keeps the PC patched while you sort the rest out.
Desktop with no firmware TPM at all?
Some 2015–2018 desktop motherboards have no PTT or fTPM option but do have a TPM header, a small row of pins on the board. Motherboard makers sell plug-in TPM 2.0 modules for those headers. Two warnings before you buy one. First, the pin layout differs between makers and even between board generations, so check your board's own manual and buy the module the manual names; a mismatched module can damage the board. Second, the module only helps if your processor is on the list. A 6th- or 7th-gen Intel desktop with a shiny new TPM is still blocked.
Only after checking the manual
TPM 2.0 add-in module (match your motherboard brand)
For desktops whose motherboard has a TPM header but no firmware TPM option. The pin layout is specific to your motherboard maker, so check the manual first.
See options on Amazon Paid link
Eligible? The boring, correct way to upgrade
The upgrade is free, keeps your files and programs, and mostly just works. These steps are about making it consequence-free.
- Back up first. A full copy of everything you care about, on a drive you then unplug. The 20-minute version is enough.
- Enroll in ESU before you upgrade. It's free, and if you end up rolling back to Windows 10 within the ten-day window, you roll back to a machine that's still patched.
- Settings → Update & Security → Windows Update, and take the upgrade when it's offered.
- Offer never appears despite being eligible? That's usually Microsoft's staged rollout, not your PC. The Windows 11 Installation Assistant from Microsoft's download page starts it on demand. If you'd rather do a clean install, the same page makes a bootable USB stick; you need an 8GB or larger drive.
- Give it an unhurried hour or two and expect a couple of restarts.
For the upgrade
- WD Elements 2TB portable hard driveRoomy, simple backup storage. Amazon
- SanDisk Ultra 32GB USB 3.0 flash driveFor installers and rescue sticks. Amazon
Paid links. Prices change often, so we don't print them; the listing shows the current price. We earn a commission on purchases, at no cost to you.
When the processor really is the wall
If WhyNotWin11 shows red on the processor line, this PC is never getting an official Windows 11 upgrade. Microsoft has held that line since 2021 and there's no sign of it moving. What that does not mean is that you need a new computer this month; that's the version of the story that sells refurbished laptops.
Your actual position: free security updates until October 2027 through ESU, which is more than a year to decide between a Windows 11 machine eventually, Linux on the hardware you already own, or a Mac if you have a positive reason to want one. The path finder walks through which of those fits how you use the machine. If Linux is on the shortlist, the hardware check flags the graphics and Wi-Fi combinations that cause install-day trouble before you commit a weekend.
The unsupported route. Rufus, the free USB tool, can create Windows 11 install media that skips the TPM, Secure Boot and processor checks, and people run it successfully. Know what you're signing up for: Microsoft doesn't support installs done this way, says they may not receive all future updates, and guarantees nothing about stability. The whole point of upgrading is to keep getting updates, and this route puts exactly that in doubt. Fine for a tinkerer with backups and a second machine. Wrong for the family PC. For most people whose processor is blocked, ESU now and an unhurried decision later is the better deal.
Eligible but happy on Windows 10?
Eligible doesn't mean obligated. ESU covers you to October 2027 either way, so a machine that's working well on Windows 10 isn't wrong to stay there for now. The sensible tiebreaker is time: upgrade when you have a free afternoon and a fresh backup, not because a countdown timer told you to.
Product links on this page are affiliate links. If you buy through one, we earn a small commission at no cost to you, and the retailer's cookies apply once you're on their site (we run none). We link only to things that fit the advice above, and we never link to replacement computers as a fix for a working one.