Preparing for Insider Preview Builds of Windows 11 - ***UPDATED 6/28***

Anonymous
2021-06-24T16:00:22+00:00

Hello Windows Insiders! Today we announced Windows 11, and we know you are excited to get your hands on it. You can check out all the details on how to prepare for Windows 11 Insider Preview builds on our blog post.

Once you've reviewed the blog, please use this post to ask any related questions you may have.

We are excited to hear your feedback!!

-The Windows Insider Team

***UPDATE***

For users who are receiving the following message in your Windows Insider Settings:

Your PC does not meet the minimum hardware requirements for Windows 11. Your device may continue to receive Insider Preview builds until Windows 11 is generally available, at which time it is recommended to clean install to Windows 10.

We've made an update to Settings to resolve some issues. Please reboot your device to ensure you have the latest update.

Windows Insider program | Windows Insider preview | Install, activate, and Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

2,500 answers

Sort by: Most helpful
  1. Anonymous
    2021-07-04T12:30:23+00:00

    the program is in beta test, it isnt done

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. MartMcd 2,670 Reputation points Volunteer Moderator
    2021-07-04T09:12:02+00:00

    Windows 11 is a very early pre-release version.

    there are significant risks with running any pre-release software.

    you should expect there to be bugs etc some of these bugs could cause data loss or make the system unstable or vulnerable.

    However, to be clear, it is the automatic sample submission that is being erroneously turned off, and not real time protection.

    the automatic sample submission helps Microsoft improve the protection going forward.

    Windows Defender is still offering protection against malware.

    Nobody is being forced to run windows 11 (now or when it is launched) windows 10 will continue to be supported until (at least) 2025.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2021-07-04T08:20:10+00:00

    @Endwar:

    Stop making false claims. I certainly DO NOT use a "pirated" version of Windows 11. I had a licenced version of Windows 10. I was on the Dev channel since long on 24 june, when Insider proposed to upgrade and test Windows 11.

    Windows11 was loaded directly from the regular Windows Update, and it is activated with a genuine licence.

    And yes, Windows 11 does not keep Windows Defender ON: it is always OFF at boot and must be reactivated AFTER boot and logon (really too late), but it runs after that (and will stop running on next reboot.

    This just means that windows 11 DROPS basic security and is LESS protected than windows 10.

    As well VBS, HVCI, MDAG, Credit Guard, Deve Guard, TPM2.0, were working at boot in windows 10 (without the alleged "performance" problems that Microsoft would like to publicly assert (this is false).

    It's just the fact that Microsoft dropped the necesarry components that made all this work correctly, reliably, and even fast in Windows 10 (and still in the latest version of Windows Server), but no longer in Windows 11.

    Such drop of support made Windows 11 no longer respect the specifications. In fact the problem lives in the new *preboot* UEFI loader (loaded even before selecting the OS to boot on or entering into UEFI BIOS parameters): it no longer works. And then the normal boot loader jsut assumes that the preboot environment made the correct settings, but it's wrong! It does no longer respects the UEFI bios settings (including security ones), and does no longer want to work with them: it boots now WITHOUT security (not even basic security), even though the PC was fully capable and had everything OK (as demosntratd in Windows 10 and Windows Server on the same machine).

    What is working in the Server version, and Windows 10 for boot, Microsoft no longer wants to integrate it in Windows 11, for very strange "performance" reasons (not demonstrated at all), and disabling TPM, VHCI, VBS is absolutely not coming from incorrect settings, but just because Micrsosoft made FALSE assumptions by dropping necessary components and thinking that these minimum pieces of software needed for the configuration would no longer be needed at all, just because they were not necessary on newer generations of processors where all is preconfigured. The claim that theise components would have a performance is false: Microsoft compares the performance with or without HVCI/VBS and jsut found that with HVCI/VBS it was running a bit faster (but less securely), and so decided to only run windows 11 for best performance only (undemosntrated claim) ignoring all security considerations (with latest generations the performance claims are reversed: PCs run a bit faster without these components integrated in Windows 10 and Windows Server, but only affect the boot time (but changing it by some milliseconds) and absolutely not at runtime (or it is not visible when running on a PCU with more cores than what is required, more memory than what is required, and faster frquencies than what is required).

    Microsoft jsut does not want to look for alternative solutions, it has just decided to stop any research for them and to ignore the technical specifications to find alternatives: Microsoft jsut chose to support very few options coming from a restricted set of manufacturers that just want to sell more hardware. It's jut a strategy to force users to buy new PCs (and new Windows licences at the same time).

    The performance claims are wrong anyway: Microsoft compares things that are NOT comparable. And has silently decided to longer support the hardwares on which they provided a WHQL certification (which was actually never assessed seriously but just based on what manufacturers claimed in their own selftests: those manufacturers, notably CPU foundries, just did not want to work with Microsoft and support Windows 11 as well). They want jsut users to be sticked on windows 10 or Windows Server and then want Microsoft to claim that these PCs MUST NOT be made compatible with Windows 11. There's NO assesment at all: I've run the latest ADK, and every test demonstrate that the PC has ALL the necessary features. Only manufacturers DO NOT WANT to let us to run Win11 with these CPUs, and they even want Microsoft to make these PCs unprotected: Microsoft listened only manufacturers, not the end users at all, and not any competitor that could propose things that CPU foundries DO NOT want to continue to support in Windows.

    The situation is clear now: users will have to use another hypervisor, and will need to run windows 11 in a VM (have you seen that these new requirements are NOT requirements and that Microsoft will continue supporting Windows 11 in a VM?).

    Here again this is a commercial tactic: Microsoft wants to sell cloud-based solutions (in Azure, or with its partners).

    So what is the alternative: install Windows Server on the same PCs (or vmWare or Citrix or Oracle/Redhat/Ubuntu hypervisors on top of Linux), and have Windows 10 or Windows 11 booting on them. This leaves lot of consumers beside (and with now a premature deadline: those PCs MUST die in 4 years because Microsoft will want to kill Windows 10, without any viable alternative).

    And this is not justified at all by need of security: of course increasing security has some impact on performances, but not at all what Microsoft claimed: msot PCS are largely fast enough to support the features and the impact on performance for the same set of basic features decreases over time, because there are new optimizations, or better programming: the research does not stop there, only the first version implemening these features may be a bit slower. But Microsoft must be ready to listen for alternatives (even those coming from competitors, instead of just focusing on what the original manufacturers want to claim, without providing ANY evidence of an impossibility).

    Lot of companies are working on viortualization, there are many alternatives (and notably many made for use in Linux) and developed by research tems worldwide.

    There are solutions appearing, as demosntrated with what was initially designed to fight the Heartbleed problem (e.G. with the initial "retpoline" mitigation that was developed rapidly and had some noticeable performance problems, only experience on servers, but not really by endusers, an this problem is now over). New security problems will continue to happen and will not be avoided just by these requirements, simply because Microsoft does not really asses it, but just makes assumptions. In reality the "WHQL certification" logo is just fake: manufacturers continue to do what they want, because they want us to buy again new hardwares (at growing prices, because they also do not provide enough quantities: there's a large shortage on these CPUs, chipsets supporting them, suitable RAM modules). This strategy is also WASTEFUL. And it leaves billions of users worldwide without a solution for long. Microsoft will reopen the digital fracture.

    Now it's time for Microsoft to leave other providers build and support Windows on their alternatively hypervisors.

    But for most end users at home or in small business, the only viable strategy is to zap Windows as the core OS and go to Linux (on which they will run Windows in a VM if they still need Windows for their apps). There are already excellent Linux distributions (like Fedora, CentOS, AlmaLinux, OracleLinux), and even for non-geeks like Ubuntu and LinuxMint) which are fully capable of running Windows; more advanced users already use other hypervisors than Hyper-V (including Microsoft itself for its Azure-based farms!).

    And if you don't need the Windows API for apps (because most of your work is done now in a web browser and can be done as well on Android or iOS mobiles, and because you can as well play now many games on Linux if not using game consoles) installing Linux has never been so easy (and it is easier now than Windows, simpler to manage and maintain, and has better long term support). Excellent desktop environments and excellent browsers are available and fully compatible (even Microsoft Edge is available on Linux!) and with much more design options (and better security as well).

    But users that don't want to pay the price required by Microsoft will have several choices: going with Apple (and buy everything at the mximum price every 3 years, like what Microsoft dreams to do), or go with cloud-based solutions (and use basic tablets), or go to Linux. The windows option offers much less alternatives and much less stability (even when compared to Apple offers).

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2021-07-04T07:37:33+00:00

    When you look into the Feedback Hub enough people posted already. Windows Defender is running but there is a problem for many people where on every restart of the system "Automatic transmission of examples" is disabled again, me included.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2021-07-03T19:13:40+00:00

    "Un-allowed DMA capable bus/device(s) detected"

    And of course, this message should explicit which device was detected (if we can unplug it, or disable it at boot time, notably if it is not at all necessary for booting Windows.

    I think this is related to "DDA" specifications (for dynamic allocation of PCI resources using an IOMMU, such as Intel VT-d, that must NOT be disabled in UEFI BIOS parameters)

    Another blocking factor is "Secure MOR" (unexplained by Microsoft: I found that it means that the UEFI BIOS must implement a hardware protection for its firmware, so that it will be protected during boot (including when plugging in a JTAG: windows should not boot, and a new firmware assessment must be provided and certified by a certificate, signed by an endorsed PKI and the Microsoft HQLabs, otherwise the BIOS will be considered "unsafe"). This now blocks HVCI in Windows 11 (not in windows 10 where it was possible to have endorsed exceptions, notably for some BIOS updates made by manufacturers to solve compatibility with some models of CPU or memory banks, or fix energy and performance monitoring settings: this should NOT be blocking anyone if your CPU is not made for being overaccelerated and the CPU already implements hardware limitations of frequencies, and monitors temperature, voltages, and other regulators).

    Note also that CPUs can also include updated microfirmwares (made by Intel, AMD, or Qualcomm) to implement mitigations: these microfirmwares are normally integrated in Windows, but some UEFI BIOS will preload these into the CPU.

    As Windows wants to get full control of the CPU and all buses, if the BIOS properly hands up the lock and surrenders the property to the Microsoft UEFI preboot loader (shipped with the Windows installer), it's up to Microsoft to implement this and perform the necessary check.

    "HSTI" is another limiting factor for the same reason: some *UEFI-COMPLIANT* are NOT required to implement the HSTI tests, if they surrender everything to the UEFI boot loader (e.g. when the BIOS was configured to use UEFI *without* CSM support, and all unnecesary devices (not needed for booting) have been disabled, and all others were correctly configured to use UEFI drivers, and not any legacy BIOS interface.

    Unfortunately, the Windows pre-boot loader ("\EFI\Microsoft\bootloaderfw.efi" in the UEFI partition) makes false assumptions. It expects the UEFI BIOS to do all the job itself, and then provide an assessment (which may be unsafe as it is based only on limited tests made by the motherboard manufacturer just to get the Microsoft WHQL label, that it got successfully even for Windows 10; and there is still no other WHQL test for Windows 11: the WHQL label is fake and not a warranty, and customers are NOT informed and are left with no choice): this is Microsoft's fault, not making the correct assessments certifications, and then Microsoft using FALSE assumptions in its boot loaders for windows or in its FAKE compatibility checker (based only on purely administrative declarations) and not enforcing the rule for manufacturers to pass again the certification when they create BIOS updates.

    In some cases, you'll have to revert the BIOS version to using one that had the correct certification (but expect then that some BIOS settings for performances will no longer work or will crash or "burn" your system, if you do not use the "BIOS defaults" (notably for CPU/GPU/memory timings, voltage and frequency regulation), or your newer CPU model that became usable on your system will no longer work with that BIOS, or you'll need to change your memory banks to those compatible with the older BIOS version.

    If your BIOS was WHQL certified, it should include an HSTI assesment... but this has not always been the case: there's an HSTI declaration, but it is empty! And no normal user have any way to know it (and for many users, it is too late: the manufacturer has stopped servicing their motherboard since too long): this is a real hidden defect (normally not eligible to time limitation, but manufacturers don't care about it: they are in China and bypass the European or American laws, or reject their fault to the seller or importer, that were not informed either of the defect and have NO access to these tricky details).

    And we are back to Microsoft's fault! For failing to provide hardware assesment tools that can be freely used by any customer, and in correct time before the manufacturer stops its support (this happens very soon, sometimes they've stopped their support since many months before you bought your new system, due to import delays or the long time these systems were left in harbours, cargos, or distribution supplies: sometimes more than one year). And Chinese manufacturers don't care: they will sell everything they still have in their depots, even if this hardware is no logner supported by them.

    Law for consumer protection is abused, and Microsoft does not give any help to end users who don't know what they buy, and that will not work even if the hardware had a WHQL certification (which actually did not test all the requirements and settings).

    Now Windows 11 is very extreme: it just says our machines are not compatible, but without saying why: consumers cannot report the issue to a manufacturer, that reject the fault to the consumers or the importers and sellers (which may now be inaccessible; notably for purchases on the web). Go to any real shop: they will also not let you run any compatibility check on their device: you have to trust what their partial specs say (and often don't say), showing only the sticker showing "designed for Windows N" and a licence label (and there are tons of fake labels, including in the most reputable and wellknown distributors and brands, except possibly DELL if you buy directly from them...)

    So please Microsoft: develop a really informative hardware assesment tool that every customer (and resellers) can use, providing detailed logs of causes (missing features, incorrect default settings that may be changed...) and that can perform REAL checks, and not just looking at some declarative statements reported in UEFI data, notably when these declarations were NOT even mandatory to get the logo (Microsoft constantly changes the requirements over time, silently: it just made it a few days ago, including for windows XP, 7, Vista, 8, 8.1 and 10.0, whose online documentation was silently and destructively edited to match the new requiremens for Windows 10; this is a LIE and breach of support contract; the WHQL certification is just FAKE when Microsoft can change the rules at any time, even for existing supported systems)

    Final Note: if your system currently has no TPM, it should be possible to connect one at low cost, and support it at boot time with a UEFI program to install on the system. It should work if your BIOS is UEFI compliant (and almost all of them ARE compliant, even if they don't implement all the new checks or new methods to plug and recognize a TPM in the preboot environment).

    Note as well that this UEFI program support (ar preboot time, before even choosing which OS to boot from and before enumerating devices configurable in the UEFI BIOS) can also be implemented by Microsoft itself, in its "bootloaderfw.efi" installed with Windows. But it has no role after the OS is booting (using "bootloader.efi" in the second phase): at that time, the Windows boot will shutdown the UEFI services, and will use its own drivers, and tools like "tpm.msc": the UEFI surrenders and abandons the full control to Windows, exept for very limited devices (notably security devices implemented in the UEFI BIOS, such as "Intel TXT", supported by Intel and that should be trusted by Microsoft in Windows)

    Note: even if your Windows is booting in UEFI secure mode, you may need to configure other settings in the BIOS:

    * use the WHQL UEFI mode for Windows 8/10, not the legacy mode

    * enable the NX protection (even if the UEFI BIOS may forget to report it in the HSTI assessment, its presence and effectiveness can be tested easily by the Windows boot loader, and then Windows can protect it itself)

    * disable CSM support in EUFI mode

    * disable legacy devices (such as option roms): configure them to use their UEFI ROM only, notably graphic cards, network adapters, storage and RAID devices, unless these devices provide an HSTI asssesment (that Microsoft should detect in its Windows loader).

    * enable hardware virtualization

    * enable the IOMMU (named "VD-d" with Intel motherboard)

    * enable Intel security

    * disable multimedia boot support (e.g. to switch on with a custom media player running only in UEFI or BIOS without any OS, e.g. to play a DVD)

    * disable online services (that could wake up your PC remotely): real working systems like this are not reliable except on very costly servers used in datacenters.

    * disable any device that is not plugged (unused PCI express or SATA slots, or legacy PS/2 mouse/keyboard when you have only USB inputs)

    * check that your GPU firmware is updated (use its drive update tool: it should not only update the Windows driver but also its UEFI firmware if needed).

    * disable the "onboard" display device (notably GPU integrated in old CPU) if you have a better graphics installed on a PCI slot, use it. In some cases, it will be the reverse: remove the extra GPU installed on the PCI device, as it may not have the necessary firmware support for secure boot, that the GPU embedded in the CPU has: you'll need to install another more modern graphics board later.

    * configure the TPM device to use SHA2, not SHA1, if it supports both (but the Windows 11 bootloader has a BUG: it may still attempt to use SHA1, even if it does not support it, and if the TPM was properly configured to use SHA2). The UEFI BIOS may provide hardware assessments in PCR11 in BOTH channels (which one will be used is then dependant of the OS you'll choose to boot with): Windows 11 is inconsistant then reports a "missing" TPM2 module at boot time even if it was present (and correctly reported!), jsut because Windows 11 jut uses the first algorithm found (generally TPM1.2 before TPM2, the UEFI BIOS does not allow to hide TPM1.2 support, even when booting in UEFI WHQL Secure boot mode: this allowed to boot Windows 7/8/8.1 or Windows Server and even Windows 10, but no longer Windows 11) !!!

    However this does not mean that Windows 11 will say your device is compatible: the last FALSE assumptions are those about the processor family (and here you generally cannot do anything as replacement implies changing the motherboard, the CPU, the memory, and this is costly!)

    Sometimes, it is just enough to "restore BIOS defaults" in the UEFI BIOS settings, but some defaults may not be correct for windows if they disable the TPM, or IOMMU, or enable legacy BIOS boot.

    Sometimes you'll need to revert some BIOS updates to a supported version (ignoring some betas that were not necessary for your configuration, such as specific processor or RAM models in specific markets: some of these are "tweaks" made for specific situations, never tested for Windows operation and certification).

    But in some case, you'll need the last version that is the only one to support TPM2 (the last supported version was made for TPM1.2 and was fully compliant with Windows 8/8.1/10 to get the WHQL-certified label!)

    I don't understand why Microsoft insists on TPM2, TPM 1.2 should still be enough !

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments