|
| A “can’t run Windows 11” banner is a summary. TPM, Secure Boot, and the processor are three different answers. |
The line This PC can’t run Windows 11 is not a diagnosis. It is a summary. Windows Update, PC Health Check, and the firmware screen can disagree with each other, and only one of those three is usually telling you the whole story.
That matters more in 2026 than it did in 2021. Regular Windows 10 support ended on October 14, 2025. A free upgrade still exists for a genuine Windows 10 license on hardware that actually qualifies. The cost of believing a single red banner is either staying on an unsupported PC too long, or buying a new laptop you did not need.
This guide is for a home Windows 10 PC. It shows how to find the real blocker — TPM, Secure Boot, processor, storage, or a stale eligibility cache — using official Microsoft tools only. It does not walk through unofficial bypasses, modified ISOs, or registry tricks that disable the hardware checks. A work or school computer is a different case: do not change UEFI settings without IT. Instructions and official sources were reviewed on August 24, 2026.
Quick Answer
Download PC Health Check only from Microsoft and select Check now. Then press Windows key + R, type tpm.msc, and confirm the specification version is 2.0. Open msinfo32 and check that BIOS Mode is UEFI and Secure Boot State is On. If Health Check fails only on TPM or Secure Boot, the chip is often present and switched off in UEFI (Intel PTT or AMD fTPM). If it fails on the processor, that is usually a hardware stop. If Health Check says you pass and Windows Update still says you fail, refresh the Compatibility Appraiser and free disk space before you buy anything. If the PC cannot qualify, enroll in Windows 10 ESU and plan a replacement — do not install an unofficial Windows 11 image.
Key Takeaways
- Windows Update, PC Health Check, and the firmware screen measure different things. Trust the detailed failure line, not the banner.
- A missing Security processor section often means TPM is disabled, not missing. DIY motherboards commonly ship that way.
- TPM 2.0 and Secure Boot are firmware switches on many 2018–2020 PCs. A processor that is off Microsoft’s supported list is not.
- You do not need a Copilot+ PC to leave Windows 10. A normal supported Windows 11 device is enough.
- The free upgrade keeps your genuine Windows 10 license. You are not buying Windows again.
- If Health Check and Windows Update disagree, refresh eligibility with Microsoft’s Compatibility Appraiser before you change hardware.
- Unsupported Windows 11 installs can lose updates and a clean recovery path. ESU plus a planned replacement is the safer pair.
The message is one sentence. The cause is one of three.
Treat every “can’t run Windows 11” screen as belonging to one bucket. The next hour of your life depends on which bucket it is.
| Bucket | What it usually looks like | What actually fixed it |
|---|---|---|
| Firmware no | Health Check fails TPM or Secure Boot. tpm.msc says a compatible TPM cannot be found. |
Turn on Intel PTT or AMD fTPM in UEFI, then re-check. No new parts. |
| Housekeeping no | Health Check says the PC meets requirements. Windows Update still refuses. Disk is nearly full. | Refresh the Compatibility Appraiser, free 20+ GB, then use the official Installation Assistant. |
| Hardware no | Health Check names an unsupported processor, TPM 1.2 only, or a 32-bit PC. | Do not hunt for a bypass. Use ESU on Windows 10 and plan a supported PC. |
Most angry forum threads mix the three buckets into one panic. A 2019 laptop with TPM switched off is not the same machine as a 2014 Core i5 that Microsoft will never put on the CPU list. One is a five-minute firmware visit. The other is a purchasing decision.
What Windows 11 actually requires in 2026
Microsoft’s public minimums have not become exotic. They do lock out a lot of perfectly useful 2014–2017 PCs:
- 64-bit processor, 1 GHz or faster, 2 or more cores, on Microsoft’s supported CPU list
- 4 GB RAM — workable; 8 GB is the realistic floor for a family PC
- 64 GB storage — tight on a small eMMC drive
- UEFI firmware that is Secure Boot capable
- TPM version 2.0
- DirectX 12 / WDDM 2.0 graphics and a 720p screen larger than 9 inches
- Windows 10, version 2004 or later, to take the in-place upgrade
A Copilot+ PC is a separate, more expensive class with a fast NPU, 16 GB RAM, and 256 GB storage. You do not need one to get off Windows 10 safely. Confusing the two is how people get sold a machine they did not come to buy.
The processor list is the quiet killer. A CPU can be 64-bit, dual-core, and faster than 1 GHz, and still be absent from Microsoft’s list. Health Check will say so in plain language. Believe that line.
Health Check also has honest gaps. Microsoft says the app does not evaluate the graphics card or the display, because most PCs that pass the other tests already meet those two. If a machine is a tiny tablet, a very old discrete GPU, or a headless box, do not treat a green Health Check as a guarantee that every visual feature will behave. It answered the upgrade gate, not every hardware trivia question.
Step 1 — Run the official checker, not a random site
Install PC Health Check from Microsoft only
Use aka.ms/GetPCHealthCheckApp. Close any page that offers a “Windows 11 eligibility tool” next to a download button. Those installers are a common way fake antivirus and browser hijackers still arrive.
Select Check now and read the first failed item
The useful output is not the red headline. It is the specific reason: TPM, Secure Boot, processor, RAM, or storage. Write that reason down before you touch BIOS. You are diagnosing one fault, not rebuilding the PC.
Confirm you are on a current Windows 10
Open Settings > System > About. You want version 22H2 on a home PC in 2026. An abandoned 1909 or 20H2 install can fail the upgrade for reasons that have nothing to do with TPM. Finish Windows 10 updates first.
Step 2 — Prove whether TPM 2.0 is missing or merely off
TPM is a small security processor. Windows 11 uses it for Windows Hello and BitLocker. Microsoft’s own support note is blunt: most PCs shipped in recent years can run TPM 2.0, and many — especially retail motherboards in home-built PCs — leave it off at the factory.
Check with tpm.msc
Press Windows key + R, type tpm.msc, press Enter. If you see The TPM is ready for use, look at Specification Version. You need 2.0. Version 1.2 does not meet Windows 11. If you see Compatible TPM cannot be found, do not assume the board has no TPM. Assume it may be disabled.
Cross-check in Windows Security
Go to Settings > Update & Security > Windows Security > Device security. A Security processor section with specification 2.0 confirms the OS can see the chip. No section at all usually matches the “TPM cannot be found” console message.
Turn it on in UEFI if the chip is hiding
On Windows 10: Settings > Update & Security > Recovery > Restart now. Then Troubleshoot > Advanced options > UEFI Firmware Settings > Restart. Look under Advanced, Security, or Trusted Computing. The switch may be named Intel PTT, Intel Platform Trust Technology, AMD fTPM, AMD PSP fTPM, TPM State, or Security Device Support. Enable it, save, and boot back to Windows. Run tpm.msc again before you touch anything else.
Step 3 — Confirm UEFI and Secure Boot
Windows 11 expects UEFI firmware that can do Secure Boot. A PC still running old Legacy BIOS / CSM will fail even if the CPU is modern.
Read System Information
Press Windows key + R, type msinfo32, press Enter. Check BIOS Mode (you want UEFI) and Secure Boot State (you want On). If BIOS Mode is Legacy, converting the disk to GPT and switching firmware is a real operation with a real chance of an unbootable PC. Back up first, or take the machine to someone who does this weekly.
Do not enable Secure Boot on a half-converted disk
If the PC is still MBR + Legacy, flipping Secure Boot on and hoping is how people get a black screen and a weekend of recovery. Firmware changes come after a confirmed backup, not before.
Step 4 — When Health Check says yes and Windows Update says no
This mismatch is common after you enable TPM. It is also common when the PC is eligible but cannot complete an in-place upgrade: not enough free space, a stale update cache, or a safeguard hold on a specific driver.
Refresh Microsoft’s eligibility task
Microsoft documents this when hardware changed and the two screens disagree. Open Task Scheduler, go to Task Scheduler Library > Microsoft > Windows > Application Experience, right-click Microsoft Compatibility Appraiser, and select Run. Or open Command Prompt as administrator and run:
schtasks.exe /Run /TN "\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser"
Wait several minutes, restart, then check Windows Update again. Do not expect the banner to flip in ten seconds.
Free real space, not “Storage Sense theater”
An in-place upgrade wants tens of gigabytes free on the system drive. Empty the Recycle Bin, move videos off the disk, and uninstall giants you do not use. A 64 GB eMMC that is 90 percent full will fail even when every security chip is perfect.
Use the official Installation Assistant if Update stays stubborn
If PC Health Check still says the device meets requirements, download the Windows 11 Installation Assistant from Microsoft’s Windows 11 download page — not from a mirror. That path upgrades in place and keeps files and apps when the hardware is eligible. It is not a bypass. It simply does not wait for Windows Update to change its mind.
RAM and storage: the failures people skip
TPM gets the headlines. Full disks kill more upgrades.
Open Settings > System > About for installed RAM. 4 GB meets Microsoft’s minimum and feels poor in 2026 once the browser and antivirus are open. 8 GB is the practical floor for a shared family PC. Adding RAM, when the laptop allows it, can move you from “minimum” to “usable.” It cannot fix an unsupported CPU.
For storage, open File Explorer, right-click the system drive, and check free space. Microsoft’s 64 GB floor is the size of the drive, not the free space you have today. An in-place upgrade wants a large working area. If the drive is 119 GB and 8 GB free, Health Check may still say the device has enough storage while Setup later fails. Empty first. Upgrade second.
Step 5 — Read a processor failure as a hardware stop
If Health Check names the CPU, stop shopping for registry files. Microsoft publishes a supported processor list. Seventh-generation Intel and first-generation Ryzen machines are the classic heartbreak: they feel fine, they are 64-bit, and they are still off the list.
That is not Microsoft being vague. It is the company refusing to treat that silicon as a Windows 11 baseline. You can argue about it on a forum. You cannot make Windows Update pretend otherwise with a setting that stays supported.
Same verdict if tpm.msc shows specification 1.2 and there is no 2.0 firmware option, or if System type in About says 32-bit. Those PCs have a future. It is not official Windows 11.
What to do in each bucket
| Your result | Do this next | Do not do this |
|---|---|---|
| TPM or Secure Boot was off; now Health Check passes | Back up, then upgrade from Windows Update or the Installation Assistant. | Leave Windows 10 “for a while” out of habit. The hardware argument is over. |
| Health Check passes; Update still refuses | Run the Appraiser, free disk space, then use the official Assistant. | Download a random ISO from a file host because “Update is broken.” |
| Processor or TPM 1.2 fails Health Check | Enroll in consumer ESU if eligible, move banking off the riskiest accounts, budget a supported PC. | Install Windows 11 with a published bypass and hope monthly updates keep coming. |
| Work or school PC | Ask IT about the organization’s Windows 11 or commercial ESU plan. | Change UEFI or run Installation Assistant on a managed device. |
If you will stay on Windows 10 for a while
Staying is only rational when the hardware bucket is real and ESU is on. Consumer Extended Security Updates can cover eligible Windows 10 22H2 PCs through October 12, 2027. ESU is a bridge. It is not a new operating system, and it does not make an old CPU official.
Check enrollment under Settings > Update & Security > Windows Update. If you are not enrolled and this PC holds banking or work email, treat that as urgent — more urgent than arguing with a Health Check screenshot. The full decision tree is in our Windows 10 safety guide linked above.
A 30-minute home checklist
Use this on a Saturday, not at midnight before a flight.
- Install PC Health Check from aka.ms and write down the first failure.
- Run
tpm.mscandmsinfo32. Decide the bucket: firmware, housekeeping, or hardware. - If firmware: enable PTT or fTPM from UEFI Firmware Settings, then re-check.
- If housekeeping: run the Compatibility Appraiser, free space, use the official Assistant.
- If hardware: enroll in ESU the same day and put a replacement date on the calendar.
Frequently asked questions
Is “This PC can’t run Windows 11” always true?
No. It is often true about the current firmware state, not about the silicon. Run PC Health Check and tpm.msc before you accept it as a death sentence.
PC Health Check says I can upgrade. Windows Update says I cannot. Whom do I trust?
Trust Health Check for the hardware question. Then refresh the Compatibility Appraiser and try the official Installation Assistant. Windows Update can lag after you enable TPM.
Do I need to buy a Copilot+ PC?
No. Copilot+ is an extra hardware class for on-device AI features. A supported ordinary Windows 11 PC is enough to leave Windows 10.
Will enabling TPM erase my files?
Enabling TPM does not format the disk. If BitLocker is on, Windows may ask for the recovery key after the firmware change. Have that key before you restart into UEFI.
My CPU is not on Microsoft’s list. Can I still install Windows 11 “for personal use”?
Not through a supported path. Unofficial installs exist. We do not recommend them. Use ESU and replace the PC if you need a supported OS.
Is the Windows 11 upgrade free?
Yes, when the PC is running a genuine qualifying Windows 10 and meets the hardware rules. You are moving the existing license, not purchasing Windows a second time. Metered-internet charges from your ISP are a separate issue.
Should I clean-install or upgrade in place?
If the PC is eligible and reasonably healthy, the in-place upgrade from Windows Update or the Installation Assistant is the calmer path. A clean install is for a machine already full of leftover toolbars, or when you are replacing the drive anyway. Back up first either way.
This is a work laptop. Can I enable TPM myself?
Usually no. Firmware and upgrade policy belong to IT. Consumer steps in this article are for a PC you own.
The honest bottom line
Most “can’t run Windows 11” screens are either a switch that was never flipped, or a processor Microsoft already decided not to carry. Those are different problems. The first one takes an afternoon and a backup. The second one takes money and a calendar.
Run the official checker. Read the first failed line. Fix firmware if the chip is only off. Refresh eligibility if the two Microsoft screens disagree. If the CPU is the blocker, stop looking for a clever ISO and put this PC on ESU until its replacement arrives.
The goal is not to win a hardware argument. The goal is a machine that still gets patches next year.
Sources
- Microsoft, “Windows 11 specs and system requirements.” Microsoft
- Microsoft, PC Health Check app. aka.ms/GetPCHealthCheckApp
- Microsoft, “How to use the PC Health Check app.” Microsoft Support
- Microsoft, “Enable TPM 2.0 on your PC.” Microsoft Support
- Microsoft, “Check if a device meets Windows 11 system requirements after changing device hardware.” Microsoft Support
- Microsoft, Windows 11 download (Installation Assistant). Microsoft
- Microsoft, Windows processor requirements. aka.ms/CPUlist
Comments
Comments
Post a Comment