Microsoft 365How-To & HardeningRetrospectives

Windows 11 Migration Security Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2025, written in 2026 with the benefit of hindsight.

Use this checklist to plan a Windows 11 migration with security improvements built in.

Readiness

  • Hardware readiness assessed (TPM 2.0, supported CPU, Secure Boot capable) using Endpoint analytics or Intune reports.
  • Devices that can't upgrade identified, with a replacement plan.
  • Application compatibility tested (App Assure can help for some customers).

Security baseline

  • Windows 11 security baseline (Intune) applied.
  • BitLocker enabled with recovery keys escrowed to Entra ID.
  • Virtualization-based security and Credential Guard enabled.
  • Microsoft Defender for Endpoint onboarded.
  • Attack surface reduction rules configured.
  • Local administrator rights removed or managed (Windows LAPS; Endpoint Privilege Management for elevation).
  • Windows Hello for Business configured.

Deployment

  • Windows Autopilot used for new devices.
  • Feature update policies or Windows Autopatch rings defined.
  • Pilot group completed before broad rollout.

Identity and access

  • Devices Entra-joined (or hybrid-joined during transition).
  • Compliance policies require Windows 11 or ESU-enrolled Windows 10.
  • Conditional Access requires compliant devices for sensitive apps.

Windows 10 remainder

  • ESU purchased for devices that can't upgrade in time.
  • Unsupported devices isolated from sensitive data.
  • End date for all exceptions.

Measurement

  • Weekly upgrade progress report.
  • Compliance percentage by department.
windows 11 migration security checklistWindows 10 end of support2025

More on this story