Windows 11 will install on older hardware, but Microsoft won't support it

Microsoft lists specific hardware requirements for Windows 11 — a processor from 2017 or newer, 4 GB of RAM, 64 GB of storage, and a TPM 2.0 chip. If your computer doesn't have these, Windows 11 will refuse to install through the normal route. You can bypass this refusal by downloading the ISO file directly and using it to create installation media, which skips Microsoft's hardware checks. The installation itself usually works. What changes is what happens after: Microsoft won't send you security updates, won't fix bugs, and won't help you if something breaks.

This matters for security because Windows 11 on unsupported hardware stops receiving patches the moment you install it. When a vulnerability is discovered — in Windows itself, in drivers, or in built-in programs — Microsoft releases a fix for supported machines only. Your unsupported machine stays vulnerable. This is not a theoretical risk. It is the reason security experts recommend against this route unless you have a specific reason and understand the trade-off.

Key Takeaways

  • Downloading Windows 11 directly from Microsoft's website and using it to install on unsupported hardware bypasses the hardware check but leaves you without security updates.
  • Microsoft defines unsupported hardware as machines without TPM 2.0, processors older than 2017, or less than 4 GB of RAM, and these machines will not receive patches after installation.
  • Your computer will function day-to-day, but each month that passes without updates increases the risk that a known vulnerability will be exploited.
  • If your machine is unsupported, upgrading the hardware, staying on Windows 10, or switching to Linux are safer alternatives than installing Windows 11 without support.

How to read and create Windows 11 installation media

Go to microsoft.com/software-read/windows11 in a web browser. You will see a section called "Create Windows 11 Installation Media." Click the "read Now" button under that heading. This downloads a tool called the Windows 11 Installation Assistant, which is about 1 MB in size.

Run the Installation Assistant. It will ask you to accept Microsoft's terms, then offer you two choices: upgrade this PC or create installation media for another PC. Choose "Create installation media for another PC." The tool will then read the full Windows 11 image, which is about 6 GB. This takes 20 to 60 minutes depending on your internet speed. Once the read finishes, the tool will ask you to insert a USB drive (8 GB or larger) or a blank DVD. It will write the Windows 11 image to that media.

If you prefer not to use the Installation Assistant, you can read the ISO file directly from the same page. An ISO is a single file that contains the entire Windows 11 installation. You can then use a tool like Rufus (rufus.ie) or Balena Etcher (balena.io/etcher) to write that ISO to a USB drive yourself. This route gives you more control but requires an extra step.

Installing Windows 11 on a machine that fails the hardware check

Insert the USB drive or DVD you created into the computer where you want to install Windows 11. Restart the computer and boot from that media. On most machines, you hold down F12, F2, Delete, or Esc while the computer is starting up to enter the boot menu. The exact key varies by manufacturer — Dell often uses F12, Lenovo uses F2, HP uses Esc. If you are unsure, restart and watch the first screen; it usually says "Press [key] to enter setup" or "Press [key] to choose boot device."

Once you are in the boot menu, select the USB drive or DVD. The Windows 11 installer will start. Follow the prompts: choose your language, accept the license terms, and select the drive where you want to install Windows 11. When the installer checks your hardware, it will either pass or show an error saying your machine does not meet the requirements. If it passes, proceed normally. If it fails, the installation stops.

To bypass the hardware check, you need to interrupt the installation and edit a configuration file. Press Shift + F10 to open a command prompt. Type regedit and press Enter. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\Setup. Right-click in the empty space, select New, then Key, and name it LabConfig. Inside LabConfig, create two new DWORD values: one named BypassTPMCheck set to 1, and one named BypassRAMCheck set to 1. If your processor is the issue, also create BypassCPUCheck set to 1. Close the registry editor and the command prompt, then continue with the installation. The installer will now proceed without checking your hardware.

What happens to security updates after installation

Once Windows 11 is installed on unsupported hardware, Windows Update will stop offering you patches. You will see "Your device is running the latest version of Windows" even when new security updates have been released for supported machines. This is by design — Microsoft's update system checks your hardware configuration and refuses to send updates to machines it does not support.

This creates a growing gap between your machine and the rest of the Windows 11 ecosystem. When a vulnerability is found in Windows 11 — say, a flaw in how it handles network connections or how it processes files — Microsoft releases a patch. Supported machines get it within days or weeks. Your machine never gets it. If an attacker discovers that vulnerability and writes code to exploit it, your machine is a target.

You can check for updates manually by going to Settings > System > About and clicking "Check for updates," but the result will be the same: no updates available. Some users try to read patches directly from Microsoft's update catalog, but this is unreliable and does not cover all the components that need updating. There is no practical way to keep an unsupported Windows 11 installation find.

Why Microsoft set these hardware requirements

The TPM 2.0 chip, the processor requirement, and the RAM minimum exist because Windows 11 uses security features that older hardware cannot run. TPM 2.0 is a dedicated chip that stores encryption keys and verifies that your system has not been tampered with. Processors from 2017 onward have built-in security features like Control Flow Guard that make certain types of attacks harder. The RAM and storage requirements may support Windows 11 has room to run these security features without slowing to a halt.

When you bypass these checks, Windows 11 still tries to use these features, but the underlying hardware cannot support them properly. This does not always cause crashes — most of the time, Windows 11 runs fine on older machines. But it means the security features that Windows 11 was designed around are either missing or degraded. You are running an operating system in a configuration it was not built for, which is why Microsoft will not support it.

Safer alternatives if your machine is unsupported

If your computer does not meet Windows 11 requirements, you have three realistic options that do not involve running unsupported software.

Stay on Windows 10. Windows 10 will receive security updates until October 2025. If your machine runs Windows 10 well, staying there for another year or two is the simplest choice. You already know how it works, your programs are compatible, and you will continue to get patches. After October 2025, you will need to upgrade your hardware or switch operating systems, but you have time to plan.

Upgrade your hardware. If you want Windows 11, the most reliable path is to upgrade the parts that are holding you back. Adding a TPM 2.0 module costs $20 to $40 and takes 10 minutes if you are comfortable opening your computer. Upgrading RAM is similarly cheap and straightforward. A new processor is more involved and more expensive, but still cheaper than a new computer. If your machine is very old, a used business-class computer from 2018 or later (a Dell Optiplex, Lenovo ThinkCentre, or HP EliteDesk) often costs $200 to $400 and will run Windows 11 with full support.

Switch to Linux. Linux is free and runs on older hardware better than Windows 11 does. Ubuntu, Linux Mint, and Fedora are beginner-friendly distributions that handle most everyday tasks — web browsing, email, document editing, video playback. The learning curve is real, and some programs you use may not be available, but if your machine is too old for Windows 11 and you cannot upgrade, Linux is a legitimate option that will receive security updates indefinitely.

What to do if you have already installed Windows 11 on unsupported hardware

If you have already installed Windows 11 on a machine that does not meet the requirements, you have two paths forward.

The first is to accept the security risk and use the machine for low-stakes tasks only. If you use it to browse the web, check email, and watch videos, and you do not store sensitive information on it, the risk is lower than if you use it for banking, shopping, or work. You can reduce the risk further by using a separate browser just for banking and shopping, keeping that browser up to date (browsers do receive updates even on unsupported Windows), and not installing programs from untrusted sources. This is not a safe long-term strategy, but it is better than pretending the risk does not exist.

The second is to reinstall. Back up your files to an external drive or cloud storage. Then read Windows 10 (microsoft.com/software-read/windows10) or a Linux distribution, create installation media the same way you did for Windows 11, and install the supported operating system instead. This takes a few hours but leaves you with a machine that will receive security updates again.

Frequently Asked Questions

Will Windows 11 run faster on my old computer if I bypass the hardware check?

No. Windows 11 is more demanding than Windows 10, and older hardware will struggle with it regardless of whether you bypass the check. You may see slower performance, longer startup times, and more frequent freezing. The hardware check exists partly to prevent this frustration, not just to enforce support policies.

Can I get security updates if I read them manually from Microsoft?

Microsoft publishes updates to its catalog, but the update system on unsupported Windows 11 machines will not install them. You can read individual patches, but this is time-consuming, incomplete, and straightforward to get wrong. It is not a practical substitute for automatic updates.

What if I only use my computer offline?

Offline machines are safer than connected ones, but not risk-free. Malware can spread through USB drives, external hard drives, and files you read and transfer. If your machine is truly offline and will stay that way, the security risk is lower. But most people use their computers online at least sometimes, so this exception rarely applies.

Is it illegal to install Windows 11 on unsupported hardware?

No. You own the copy of Windows 11 you install, and you can install it where you choose. Microsoft will not support it, but they will not prosecute you. The risk is entirely about security and functionality, not legality.

How do I know if my computer has TPM 2.0?

Open the Run dialog by pressing Windows key + R, type tpm.msc, and press Enter. If TPM 2.0 is present, you will see it listed. If nothing opens or you see an error, your machine does not have TPM 2.0. You can also check in Device Manager: press Windows key + X, select Device Manager, and look for "Trusted Platform Module" in the list. If it is not there, you do not have it.