Windows 11 on an Unsupported PC: Read the Price First

Your machine works fine. Windows 10 stopped getting security updates last October, and Windows 11 says your PC is not good enough for it.

So you go looking for a way round, and you find one in about ten seconds. What you do not usually find is the paragraph Microsoft makes you agree to. It is not a long read and it is worth your time.

I went and read that paragraph, and then read what Microsoft says afterwards, because it changes whether this is a clever trick or a bad trade.

What Microsoft makes you accept

Its own words, and they are worth reading slowly. Microsoft documents the installation as not recommended, adding that it "may result in compatibility issues."

That is the gentle half. Then the hard half, verbatim. "If you proceed with installing Windows 11, your PC will no longer be supported and won't be entitled to receive updates."

And the money sentence. "Damages to your PC due to lack of compatibility aren't covered under the manufacturer warranty."

Elsewhere on the same page it is put plainly. These devices "aren't guaranteed to receive updates, including but not limited to security updates."

The part that undoes the whole plan

Because the reason you are here is security updates in the first place. You left Windows 10 because it stopped getting them, and Microsoft's lifecycle page is exact. "Windows 10 will reach end of support on October 14, 2025."

An unsupported Windows 11 install is not guaranteed them either. Read those two facts together before you start.

In practice many unsupported machines do keep updating. In practice is not a guarantee, and Microsoft has written down that it is not one. So this buys you a newer Windows, not a promise. Decide with that in front of you.

Microsoft's own advice, which nobody quotes

Short, and it is the opposite of what the how-to pages say.

Straight from Microsoft's page on unsupported installs: "If you installed Windows 11 on a device not meeting Windows 11 system requirements, Microsoft recommends you roll back to Windows 10 immediately."

The rollback window is ten days. After that, in Microsoft's words, "the files needed to perform this function are removed to free up disk space."

Ten days is not long, and a compatibility problem can take a fortnight to surface. The route is Settings, System, Recovery. Learn it before you need it, not after.

The registry key everyone cites is not on Microsoft's page

Worth knowing, because people call it official and it is not quite that. The value that circulates is `AllowUpgradesWithUnsupportedTPMOrCPU`, a DWORD set to 1 under `HKLM\SYSTEM\Setup\MoSetup`.

Reported by an adviser on Microsoft's own Q&A: it "only bypasses the TPM and CPU requirements," and you "still need to set the BIOS boot mode to EUFI to enable the secure boot option." So it is not a master key.

Microsoft's unsupported-install page does not carry it. It publishes the disclaimer and the rollback advice. Not that method. Secure Boot and UEFI still have to be real.

Check your own machine before you do anything

Two readings, and one is easier than the usual advice makes out.

Ours, and it saves an elevated prompt. Secure Boot state sits in the registry at `HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\State`, in a value called `UEFISecureBootEnabled`. This laptop reads 1, meaning on.

That value is readable as a normal user. The usual advice, `Confirm-SecureBootUEFI`, is not: run it here without administrator and it answers "Unable to set proper privileges. Access was denied."

TPM is the other half, and that one does need elevation. `Get-Tpm` returned nothing here as a standard user. Know both answers before you start. No UEFI and no Secure Boot rules the machine out.

What this laptop is, for context

Ours, so you can see what a supported machine looks like. An AMD Ryzen 7 6800H with 15 GB of usable memory. That clears the Windows 11 bar comfortably.

Secure Boot reads enabled, one of the two gates the registry value does not open for you. None of the steps above were performed here. This machine did not need them. Nothing was changed.

Your machine is the one that matters. The requirements themselves are worth reading properly before you decide.

The alternatives worth weighing first

Because bypassing is not the only door. Check whether your PC is actually unsupported. Plenty of machines fail only because TPM or Secure Boot is switched off in firmware, which is a setting rather than a limit.

Turning those on in the firmware makes the machine supported, with no bypass, no disclaimer and no lost warranty cover. A machine with no UEFI or TPM at all is old, and at that point a cheap second-hand replacement is a real option.

And a PC staying on an out-of-support Windows is a security decision, not a neutral one. Keeping the machine you have is fine, but know what is protecting it.

**Status: read on 18 September 2026 from Microsoft's page on installing Windows 11 on devices that do not meet minimum requirements and its Windows 10 lifecycle page, with the Secure Boot and TPM readings taken here on a Home edition running 25H2.

No bypass was performed, no registry value was written and no installation was attempted.**

Can I install Windows 11 on an unsupported PC?

It is possible, and Microsoft publishes a disclaimer you have to accept rather than blocking it outright.

That disclaimer says your PC will no longer be supported and will not be entitled to receive updates, and that damage from incompatibility is not covered by the manufacturer warranty.

Will an unsupported Windows 11 PC still get security updates?

Not guaranteed. Microsoft's wording is that these devices are not guaranteed to receive updates, including but not limited to security updates. Many do in practice, but you are relying on that rather than on anything Microsoft has promised.

Is the AllowUpgradesWithUnsupportedTPMOrCPU registry key official?

It is widely cited, but Microsoft's own page on unsupported installs does not publish it.

An adviser on Microsoft's Q&A said it only bypasses the TPM and CPU checks and that you still need UEFI boot mode with Secure Boot available, so it is not a way round everything.

How do I check Secure Boot without administrator?

Read the registry value UEFISecureBootEnabled under HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot\State. A 1 means it is on.

The usual command, Confirm-SecureBootUEFI, refuses to run without an elevated session and says access was denied.

The Short Version

  • Microsoft's disclaimer says the PC will no longer be supported and will not be entitled to updates.
  • It also says incompatibility damage is not covered under the manufacturer warranty.
  • Unsupported devices are not guaranteed updates, including security updates.
  • Windows 10 support ended on 14 October 2025, which is why people are here.
  • Microsoft's advice after an unsupported install is to roll back to Windows 10 immediately.
  • The rollback window is ten days, then the files are deleted to save space.
  • The famous registry value is not on Microsoft's own page, and it does not bypass Secure Boot.
  • Check Secure Boot from the registry without administrator before you plan anything.

Where to Next

Read the disclaimer before the how-to, because the disclaimer is the part that decides this.

Check whether your machine is genuinely unsupported or just has TPM and Secure Boot switched off in firmware.

If it is the second, turn them on and take the supported route with the warranty and the updates intact.

And if you do go ahead anyway, put a note in your calendar for day nine, because the rollback disappears on day ten.

If your PC failed the check for a reason this does not cover, say which requirement it named in the comments. That is usually the deciding detail.

Leave a Comment