{"id":6867,"date":"2021-10-29T07:54:31","date_gmt":"2021-10-29T07:54:31","guid":{"rendered":"https:\/\/www.insentragroup.com\/us\/?p=6867"},"modified":"2022-03-30T08:25:59","modified_gmt":"2022-03-30T08:25:59","slug":"windows-11-is-here-should-you-upgrade-now","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/modern-workplace\/windows-11-is-here-should-you-upgrade-now\/","title":{"rendered":"Windows 11 is here &#8211; should you upgrade now?"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/us\/wp-content\/uploads\/sites\/6\/2021\/10\/aaron_parker_blog_Oct2021_img_1-1024x641.jpg\" alt=\"\" class=\"wp-image-8404\" \/><\/figure>\n\n\n\n<p>Windows 11 introduces&nbsp;some&nbsp;significant changes to&nbsp;hardware requirements and&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/06\/25\/windows-11-enables-security-by-design-from-the-chip-to-the-cloud\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">improvements to security<\/a>.&nbsp;Your organisation&nbsp;will&nbsp;benefit from these changes&nbsp;by&nbsp;improving&nbsp;the security&nbsp;posture of your Windows endpoints,&nbsp;I suspect most organisations will have some work to do&nbsp;before upgrading all devices to Windows 11.&nbsp;<\/p>\n\n\n\n<p>When&nbsp;Microsoft&nbsp;<a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2021\/06\/24\/introducing-windows-11\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">announced&nbsp;Windows 11<\/a>,&nbsp;they&nbsp;also announced&nbsp;the retirement of&nbsp;Windows 10&nbsp;for&nbsp;October 14th, 2025.&nbsp;A migration to Windows 11 for everyone is inevitable; however, should you upgrade your organisation\u2019s devices&nbsp;now&nbsp;or continue with Windows 10&nbsp;until 2025?&nbsp;<\/p>\n\n\n\n<p>Although Windows 11 is available&nbsp;now,&nbsp;<a href=\"https:\/\/blogs.windows.com\/windows-insider\/2021\/10\/21\/preparing-the-windows-10-november-2021-update-for-release\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Windows 10&nbsp;21H2&nbsp;is also ready for release<\/a>.&nbsp;Windows 10 21H2 continues the cumulative update approach Microsoft has taken with Windows 10 2004, 20H2 and 21H1.&nbsp;<\/p>\n\n\n\n<p>Windows 10 21H2 introduces&nbsp;just a&nbsp;few new features &#8211; the most interesting of which, will be the simplification of Windows Hello for Business with a cloud trust model. This will do away with the need to integrate&nbsp;Active Directory Certificate Services, making Windows Hello for Business deployment far simpler. See this article for more details:&nbsp;<a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2021\/07\/15\/introducing-the-next-feature-update-to-windows-10-21h2\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Introducing the next feature update to Windows 10: 21H2<\/a>.&nbsp;<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Are your devices ready for Windows 11?&nbsp;<\/span><\/h3>\n\n\n\n<p>In my experience,&nbsp;many organisations are still having challenges in keeping their Windows&nbsp;endpoints&nbsp;current and it\u2019s common to see devices in the organisation running Windows 10 versions&nbsp;which&nbsp;are out of support. It\u2019s also not uncommon to see Windows 8 and Windows 7 devices still out in the wild.&nbsp;<\/p>\n\n\n\n<p>What&nbsp;is also becoming&nbsp;clear is the number of corporate devices&nbsp;which&nbsp;aren\u2019t ready for Windows 11.&nbsp;Although a small sample size,&nbsp;I have seen devices in client&nbsp;environments&nbsp;which&nbsp;won\u2019t meet Windows 11\u2019s hardware requirements. Issues include&nbsp;Secure Boot not&nbsp;being&nbsp;enabled and devices&nbsp;which&nbsp;don\u2019t&nbsp;meet TPM requirements (TPM not enabled or&nbsp;not TPM 2.0 capable).&nbsp;Resolving these issues&nbsp;would&nbsp;represent a significant amount of work.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Additionally,&nbsp;Windows 11\u2019s&nbsp;minimum CPU&nbsp;requirements&nbsp;will ensure a certain percentage of devices in an organisation&nbsp;won\u2019t&nbsp;be running Windows 11&nbsp;until&nbsp;they are retired and&nbsp;replaced.&nbsp;<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Update to Windows 10 21H2 now&nbsp;<\/span><\/h3>\n\n\n\n<p>Upgrading to Windows 11 for many organisations is going to be&nbsp;a challenge in the short term, so instead,&nbsp;your time would be better spent&nbsp;upgrading devices&nbsp;to Windows 10 21H2.&nbsp;<\/p>\n\n\n\n<p>Windows 10 21H2&nbsp;is a cumulative update for any Windows 10 device on version 2004 or later,&nbsp;which means&nbsp;you will be able to update without delay&nbsp;and&nbsp;have&nbsp;confidence&nbsp;your devices and applications will be compatible.&nbsp;Updating to Windows 10 21H2&nbsp;as soon as possible,&nbsp;will ensure your organisation&nbsp;benefits&nbsp;from&nbsp;extended support,&nbsp;18 months for Windows 10 Pro and&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/lifecycle\/products\/windows-10-enterprise-and-education\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">30 months for Windows 10 Enterprise and Education<\/a>.&nbsp;As Microsoft has not yet made an announcement for Windows 10 releases beyond 21H2, it\u2019s reasonable to assume this version will be supported&nbsp;right up to 2025.&nbsp;<\/p>\n\n\n\n<p>A new Windows 10 21H2 Long-Term Servicing Channel (LTSC) will also be available, allowing all compatible devices to be upgraded to 21H2&nbsp;Semi-annual Channel or LTSC&nbsp;and have&nbsp;those devices supported until 2025.&nbsp;<\/p>\n\n\n\n<p>Read more about&nbsp;<a href=\"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/professional-services\/application-testing-automated-vs-manual\/\" target=\"_blank\" rel=\"noreferrer noopener\">the importance of patching in this blog<\/a>&nbsp;by my colleague Peter Cooney, Global Head of Solutions here at Insentra.&nbsp;&nbsp;<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Report on your device compatibility with Windows 11&nbsp;<\/span><\/h3>\n\n\n\n<p>Microsoft has a few tools you can use&nbsp;to report on Windows 11 compatibility.&nbsp;The preferred approach for reporting on Windows 11 readiness is to use the&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-au\/mem\/analytics\/work-from-anywhere\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Work from anywhere report<\/a>&nbsp;in Endpoint Analytics in the Microsoft Endpoint Manager admin centre.&nbsp;&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/us\/wp-content\/uploads\/sites\/6\/2021\/10\/aaron_parker_blog_Oct2021_img_2-1024x535.jpg\" alt=\"\" class=\"wp-image-8405\" \/><\/figure>\n\n\n\n<p>For environments using Microsoft Intune to manage devices, you will have access to this report now. If you\u2019re using Microsoft Endpoint Configuration Manager to manage your Windows devices, make sure you\u2019ve deployed <a href=\"https:\/\/docs.microsoft.com\/en-us\/mem\/configmgr\/tenant-attach\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">tenant attach<\/a> and co-management so you can take advantage of this report as well.<\/p>\n\n\n\n<p>There are plenty of good reasons to adopt tenant attach and co-management. For most clients, it will provide more insights into your Windows endpoint environment and the opportunity to simplify the management of Windows devices.<\/p>\n\n\n\n<p>For those environments which haven\u2019t yet moved to tenant attach and co-management or can\u2019t (for whatever reason), Microsoft has a hardware readiness script available which can be run via Configuration Manager. For more information see this article: <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-endpoint-manager-blog\/understanding-readiness-for-windows-11-with-microsoft-endpoint\/ba-p\/2770866\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Understanding readiness for Windows 11 with Microsoft Endpoint Manager<\/a>.<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Update devices for Windows 11 compatibility<\/span><\/h3>\n\n\n\n<p>Once you\u2019ve determined Windows 11 readiness in your environment, you will have some work to do updating devices which are not compatible. In real client environments, we are seeing the need to update firmware, configure <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/information-protection\/tpm\/trusted-platform-module-overview\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Trusted Platform Modules<\/a>, enable Secure Boot or upgrade RAM capacity.<\/p>\n\n\n\n<p>With those devices incapable of running Windows 11 at all (typically due to CPU), then updating them to Windows 10 21H2 will ensure the device is running a supported configuration until its end of life. From there you can plan for their retirement and replacement.<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Ensure your device management tools are Windows 11 ready<\/span><\/h3>\n\n\n\n<p>Adding support for Windows 11 in your deployment tools should be an easy task &#8211; upgrade to Configuration Manager 2017 and\/ or wait for Microsoft to include full support for Windows 11 in Intune.<\/p>\n\n\n\n<p>Just like Windows, you should be keeping your Configuration Manager environments current, so upgrading to Configuration Manager 2107 should be part of the standard support lifecycle.<\/p>\n\n\n\n<p>Microsoft has already been updating Microsoft Intune to support Windows 11 with changes in the <a href=\"https:\/\/endpoint.microsoft.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft Endpoint Manager admin center<\/a>.<\/p>\n\n\n\n<p>Capable devices <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/whats-new\/windows-11-prepare\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">won\u2019t automatically update to Windows 11<\/a>. As a Windows administrator, you will have controls in Group Policy, Windows Server Update Services, Configuration Manager and Microsoft Intune to upgrade devices to Windows 11 when you are ready to do so.<\/p>\n\n\n\n<p>Customers using Windows Autopilot should be aware of which version of Windows comes with new devices. Remember Windows 10 is supported until 2025, however &nbsp;well before then device manufacturers will start shipping PCs with Windows 11.<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Validate and pilot Windows 11 now<\/span><\/h3>\n\n\n\n<p>Whether you know it or not, I\u2019ll bet at least one person in your organisation is already testing Windows 11. I have seen this over the past few months in at least four client environments.<\/p>\n\n\n\n<p>It is important to start validating Windows 11 now to determine whether you need to make changes to your deployment methodology. There are no major changes you need to make in the way you manage Windows 10 today to start managing Windows 11; however, there are some key changes and features introduced with Windows 11.<\/p>\n\n\n\n<p>Not least of these changes is the new Start menu, Taskbar and the Settings application. These will be obvious changes to users, thus it\u2019s worth ensuring these new features are well understood before Windows 11 is deployed to your managed endpoints. Additionally, there are changes to the <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/evolving-the-microsoft-store-for-business-and-education\/ba-p\/2569423\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft Store coming with Windows 11<\/a> which could have a big impact on the way some organisations manage applications on their devices.<\/p>\n\n\n\n<p>Start with a small-scale pilot within IT, even if it\u2019s manually updating devices to Windows 11, and validate if the organisation is ready for those important changes coming with this new version of Windows.<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Communicate with your users<\/span><\/h3>\n\n\n\n<p>I highly recommend communicating with user end-users that Windows 11 is on the way, even if it\u2019s just to say, \u201cWindows 11 is coming\u201d.<\/p>\n\n\n\n<p>Changes to the Windows 10 interface since the initial release in 2015 have realistically been minor with iterative updates with each release. Windows 11 introduces major interface changes and while the way you interact with Windows 11 doesn\u2019t fundamentally change, users should have some understanding of the changes they will see when their PC is upgraded.<\/p>\n\n\n\n<h3 style=\"padding-bottom: 15px;margin-bottom: 30px;margin-top: 40px;border-bottom: 1px solid #f16020\"><span>Deploy in 2022<\/span><\/h3>\n\n\n\n<p>Can you believe it\u2019s already October 2021? You\u2019ve probably got plenty to do before the end of the year and for all of us, 2020 and 2021 have been difficult enough. Plan and prepare now, so you\u2019re ready to start deploying Windows 11 in 2022.<\/p>\n\n\n\n<p>We\u2019re here to help, of course. We have developed a robust methodology for modern device management using Microsoft Endpoint Manager which takes you from design right through to production release, providing a framework for a successful deployment and adoption of new technologies introduced in Windows 10 and Windows 11. <\/p>\n\n\n\n<p>Curious about Microsoft Edge? I captured&nbsp; 17 reasons why organisations should standardise on Edge in <a href=\"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/professional-services\/17-reasons-for-microsoft-365-customers-to-standardise-on-microsoft-edge\/\" target=\"_blank\" rel=\"noreferrer noopener\">my previous blog<\/a>.<\/p>\n\n\n\n\n.attachment-large {\n  display: none !important;\n}\n\n","protected":false},"excerpt":{"rendered":"<p>Windows 11 introduces some significant changes to hardware requirements and improvements to security. <\/p>\n","protected":false},"author":65,"featured_media":7147,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[19],"tags":[100,99,95,47,59,60,102,103,73,86,96,98,97,101],"class_list":["post-6867","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-modern-workplace","tag-end-of-life","tag-end-of-support","tag-endpoint-protection","tag-intune","tag-microsoft","tag-microsoft-365","tag-modern-workplace","tag-office-365","tag-patch-management","tag-security","tag-windows-10","tag-windows-11","tag-windows-365","tag-windows-autopilot","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/6867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/comments?post=6867"}],"version-history":[{"count":5,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/6867\/revisions"}],"predecessor-version":[{"id":8913,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/6867\/revisions\/8913"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media\/7147"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media?parent=6867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/categories?post=6867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/tags?post=6867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}