Detection Script to help identify why your PC isn't Windows 11 ready
github.com
github.com
And the text list of what's compatible:
https://www.microsoft.com/en-us/windows/windows-11-specifica...
The two that people are complaining about most are:
- Arbitrary requirement of 8th gen or better for Intel i3/5/7/9[1]. Which seems odd, given that some 2017 era Celerons are on the list.
- TPM 2.0 module
[1] Specific Intel CPUs: https://docs.microsoft.com/en-us/windows-hardware/design/min...
Most motherboards ship with it disabled in the BIOS so you have to find that setting (probably somewhere in the "advanced" settings) and change it.
They also warn that some OEM motherboards have it disabled in the BIOS but do not expose a setting to change it, so with those you might be out of luck if the OEM did not include hardware TPM.
[1] https://arstechnica.com/gadgets/2021/06/heres-what-youll-nee...
You should check and see if the "Firmware TPM"/"fTPM" option is available, because that one will work without the physical add-in card.
Thank you. Yes indeed there is a Firmware option there.
Doesn't work on Domain joined machines. It tells me to contact my IT department (which is me!) and doesn't show anything else.
The tool told me that it's indeed TPM. I didn't even know what it is and my PC is 2 months old ;)
you can also enroll your own key relatively easily using mokutil
if you're building your own kernels it's one command to sign them (sbsign)
The MS link appears to say that you need UEFI that is Secure Boot capable. That includes most implementations.
If you have Bitlocker enabled, all bets are off. Make sure you have a recovery key set up.
I signed linux and it's just fine, debian does it transparently now.
I already know where microsoft is going with this - Xbox-like DRM. In a few years they'll probably release pci-e based "security devices" with full DMA privileges, too.
There's no way Windows _NEEDS_ to be signed to boot. Even macOS doesn't complain that much when booted without Secure Boot. Perhaps someone will find a way to cheat Windows about SecureBoot or TPM by using OpenCore, like the Hackintosh community has been doing for a long time.
We do as well, but since we're using Macs they last so friggin long that some folks are still on 2016 MacBook Pro's. I badly want the new M1 ;)
Yes and no. 3-4 years from when the person got it maybe, which is usually not the manufacture date. And, it's one of those budget items that tends to get pushed out when there's a financial crisis, like now for many Covid affected businesses. I work for a F500, and my laptop was made in 2018, and is a 6th gen Intel.
At the companies I've worked for the programmers generally get new hardware about as often ...but other workers not so much. They are more likely to get the hand-me-down hardware.
My 3 year old top of the line gaming PC won't get Windows 11. It's annoying.
I've read the announcements, but from what I've seen Windows 11 is basically Windows 10 with new UI. And a few small details like widgets and "built-in" Microsoft Teams.
Getting new hardware is easy, getting new software isn't.
https://answers.microsoft.com/en-us/windows/forum/all/forced...
worked on windows 7 to windows 10 for me.
I built my current PC in 2012 and it still works perfectly well - no slowdown at all thanks to SSDs and the end of Moore's law. I can't imagine I'll want to upgrade it within the next 4 years.
But it turned out there was an easy fix. Recent AMD processors have a TPM module built into the processor, and it was just a case of heading into the BIOS and turning it on. Now the PC is compatible with Windows 11.
What changed?
Seriously that’s probably more than half the reason.
Perhaps Windows and MacOS track version numbers the same way as Firefox and Chrome.
I can tell that you don’t work in marketing.
(I personally think we may see MacOS numbers start to move about as fast as iPhone numbers)
I used to use Arch until a libpng upgrade broke everything.
It requires: virtualization instructions enabled and working, legacy bios disabled (not merely just booted with UEFI; workstations that are qualified for this operation usually have the option entirely removed, but simply turning legacy boot off entirely is enough), UEFI on, trusted boot on with Microsoft's keys enrolled, TPM 2.0 on and functioning and the OEM has to physically qualify that no external DMA interfaces can be hacked (ex: my 1660 Super claims it has a USB-C port (due to type-C DP support), the card physically only has DP and HDMI, no type-C, so I have to set a registry key saying "this PCI-E device has been qualified to not be an external concern") (another ex: even with USB3 etc host chips that are qualified (ie, the IOMMU properly sandboxes them), VBS sets the option that disables connecting a USB etc device awhile device is locked; you can only plug in a device while unlocked and have it actually connect).
VBS is for truly secure workstations, the kind that really truly try to defend themselves against all sorts of security issues, including physically there (in concert with Intel vPro deployed correctly for VBS, and AMD's equivalent that I'm blanking on the name for).