Windows 11 Migration Security Checklist
Retrospective: this article looks back at events from October 2025, written in 2026 with the benefit of hindsight.
Use this checklist to plan a Windows 11 migration with security improvements built in.
Readiness
- Hardware readiness assessed (TPM 2.0, supported CPU, Secure Boot capable) using Endpoint analytics or Intune reports.
- Devices that can't upgrade identified, with a replacement plan.
- Application compatibility tested (App Assure can help for some customers).
Security baseline
- Windows 11 security baseline (Intune) applied.
- BitLocker enabled with recovery keys escrowed to Entra ID.
- Virtualization-based security and Credential Guard enabled.
- Microsoft Defender for Endpoint onboarded.
- Attack surface reduction rules configured.
- Local administrator rights removed or managed (Windows LAPS; Endpoint Privilege Management for elevation).
- Windows Hello for Business configured.
Deployment
- Windows Autopilot used for new devices.
- Feature update policies or Windows Autopatch rings defined.
- Pilot group completed before broad rollout.
Identity and access
- Devices Entra-joined (or hybrid-joined during transition).
- Compliance policies require Windows 11 or ESU-enrolled Windows 10.
- Conditional Access requires compliant devices for sensitive apps.
Windows 10 remainder
- ESU purchased for devices that can't upgrade in time.
- Unsupported devices isolated from sensitive data.
- End date for all exceptions.
Measurement
- Weekly upgrade progress report.
- Compliance percentage by department.