How To Bypass Windows 11 TPM Secure Boot Requirements (Easy Step-by-Step)
It can be really frustrating to hit that “This PC can’t run Windows 11” message when you’re excited for an upgrade. Many perfectly capable computers don’t meet Microsoft’s strict hardware criteria, especially regarding TPM 2.0 and Secure Boot. Luckily, there are straightforward ways to bypass these Windows 11 TPM Secure Boot requirements, letting you install the operating system without a hitch.
This guide will walk you through a few methods, from a quick registry tweak during setup to creating a custom USB installer. We’ll show you exactly what to do, step by step. You’ll be enjoying Windows 11 on your machine in no time, even if it’s technically “unsupported.”
Table of Contents
- The Hardware Wall: Why Windows 11 Requires TPM 2.0 and Secure Boot
- Method 1: The Quick Registry Edit During Installation
- Method 2: Create a Custom Bootable USB with Rufus (Highly Recommended)
- Method 3: Bypass for In-Place Upgrades from Windows 10
- Activating Windows 11 on Your “Unsupported” Hardware
- Frequently Asked Questions
The Hardware Wall: Why Windows 11 Requires TPM 2.0 and Secure Boot
Windows 11 introduced some pretty specific hardware demands, and two big ones are the Trusted Platform Module (TPM) version 2.0 and UEFI Secure Boot. TPM is a security chip that handles cryptographic functions, crucial for features like BitLocker encryption and secure credential storage. Microsoft implemented this to beef up security against firmware and boot-level attacks.
Secure Boot, another requirement, ensures that only trusted software loads during startup, preventing malicious code from hijacking your system before Windows even starts. Alongside these, Microsoft also restricted Windows 11 to newer CPU generations, typically 8th Gen Intel or AMD Zen 2 and newer. These stringent checks, while designed for enhanced security, left many users with capable but slightly older hardware feeling left out.
Millions of PCs that run Windows 10 perfectly fine suddenly couldn’t upgrade. Thankfully, Microsoft’s own engineers created some internal workarounds for testing purposes. These “diagnostic override flags” are what we’ll be leveraging to get Windows 11 running on your system.
Method 1: The Quick Registry Edit During Installation
If you’re in the middle of a Windows 11 installation and you’ve hit that dreaded “This PC can’t run Windows 11” message, don’t worry. You don’t have to restart or rebuild your USB. You can perform a simple registry edit right then and there to proceed.
First, you need to open the Command Prompt. On the error screen, press Shift + F10 on your keyboard. Some laptops might require you to press Fn + Shift + F10 to make this work.
Shift + F10
Once the Command Prompt window appears, type regedit and hit Enter to open the Registry Editor. This tool lets you make direct changes to Windows’ configuration.
regedit
In the Registry Editor, navigate to the following path. You can copy and paste this into the address bar at the top of the editor for speed.
HKEY_LOCAL_MACHINE\SYSTEM\Setup
Right-click on the Setup key, then select New > Key. Name this new key LabConfig. This is where we’ll add the bypass entries.
Inside the newly created LabConfig key, right-click on the empty space in the right pane. Choose New > DWORD (32-bit) Value and create four new entries. Make sure to set the Value data of each to 1.
BypassTPMCheck
BypassSecureBootCheck
BypassRAMCheck
BypassCPUCheck
Once all four DWORD values are created and set to 1, close the Registry Editor and then the Command Prompt. Now, click the back arrow in the top-left corner of the Windows 11 setup window. Select your desired Windows edition again and click Next. The setup process will now bypass all those annoying hardware checks.
Method 2: Create a Custom Bootable USB with Rufus (Highly Recommended)
For many users, the easiest and most automated way to install Windows 11 on unsupported hardware is by using a tool called Rufus. This free, open-source utility can create bootable USB drives and conveniently integrates options to strip away the Windows 11 TPM Secure Boot requirements during the process. It’s a fantastic solution if you haven’t started your installation yet.
First, you’ll need the official Windows 11 ISO file. You can download this directly from the Microsoft Software Download page. Choose the “Download Windows 11 Disk Image (ISO)” option.
Next, grab the latest version of Rufus. You can find it on the official Rufus website. It’s a small, portable application, so there’s no complex installation required.
Now, insert a USB flash drive (at least 8GB) into your computer and open Rufus. Make sure your USB drive is selected under “Device.” Click the SELECT button and choose the Windows 11 ISO file you downloaded.
Once the ISO is loaded, click START. A “Windows User Experience” popup window will appear with various customization options. This is where the magic happens for bypassing the Windows 11 TPM Secure Boot requirements.
In this popup, check the box labeled “Remove requirement for 4GB+ RAM, Secure Boot and TPM 2.0”. You might also see other helpful options, like skipping the Microsoft Account requirement for local accounts. Feel free to select those too if you wish.
Click OK to confirm your choices and let Rufus begin writing the customized ISO to your USB drive. This process can take a few minutes, so be patient. Once it’s done, you’ll have a bootable USB installer that completely ignores your PC’s TPM 2.0 and Secure Boot status.
Method 3: Bypass for In-Place Upgrades from Windows 10
If you’re already running Windows 10 on a computer that doesn’t meet Windows 11’s hardware standards, and you want to upgrade without doing a clean installation, this method is for you. It lets you keep all your files, applications, and settings. This approach is similar to the first registry trick, but it’s applied to your active Windows 10 system before starting the upgrade.
First, make sure you’re booted into your Windows 10 operating system. Open the Registry Editor by typing regedit into the Start menu search bar and pressing Enter. Confirm any User Account Control prompts.
Navigate to the following path in the Registry Editor. You can paste this path into the address bar at the top for quick access.
HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup
If the MoSetup key doesn’t exist under Setup, you’ll need to create it. Right-click on Setup, select New > Key, and name it MoSetup. This key is specifically for modifications during the setup process.
Inside the MoSetup key, right-click on the empty space and select New > DWORD (32-bit) Value. Name this new DWORD value AllowUpgradesWithUnsupportedTPMOrCPU. This specific entry tells Windows to ignore the hardware checks during an in-place upgrade.
Double-click on AllowUpgradesWithUnsupportedTPMOrCPU and change its Value data to 1. This activates the bypass. Then, click OK and close the Registry Editor.
[HKEY_LOCAL_MACHINE\SYSTEM\Setup\MoSetup]
"AllowUpgradesWithUnsupportedTPMOrCPU"=dword:00000001
Now, mount your Windows 11 ISO file (you can right-click it and choose “Mount”) and run setup.exe from the virtual drive. The upgrade wizard will now proceed without checking your TPM or Secure Boot status, allowing for a smooth transition to Windows 11 while retaining your data.
Activating Windows 11 on Your “Unsupported” Hardware
It’s important to understand that bypassing the Windows 11 TPM Secure Boot requirements doesn’t affect your ability to activate Windows. Microsoft separates hardware eligibility from product licensing. Once you have Windows 11 installed, whether on supported or unsupported hardware, you still need a valid product key to activate it fully.
To activate your Windows 11 system, follow these simple steps:
- Open the Settings app by pressing Windows key + I.
- Navigate to System, then click on Activation.
- Look for the Change product key option and click it. Enter your genuine Windows 11 product key in the provided field.
- Click Activate. Windows will connect to Microsoft’s activation servers and bind your digital license to your hardware, giving you full access to all features and updates.
Using a legitimate license ensures you receive all crucial security updates and maintain system stability. You can confidently enjoy your bypassed Windows 11 installation, knowing it’s fully activated and secure.
Frequently Asked Questions
Here are some common questions people ask about bypassing the Windows 11 installation restrictions.
Will my unsupported PC still receive Windows 11 updates?
Yes, absolutely! Microsoft continues to deliver all standard quality, security, and feature updates via Windows Update, even on systems where TPM 2.0 or Secure Boot was bypassed. You won’t miss out on anything.
Is bypassing TPM 2.0 and Secure Boot illegal?
No, it’s not illegal. The registry overrides we discussed are built directly into Windows setup by Microsoft’s own engineers for testing purposes. Using these tools to install genuine Windows 11 on your personal hardware doesn’t violate any licensing terms.
Can I play games like Valorant on a bypassed system?
Most games from platforms like Steam or Epic Games Store will run without issue on a bypassed system. However, a small number of games, particularly those with very aggressive kernel-level anti-cheat software like Riot Vanguard (used by Valorant), may still enforce actual TPM 2.0 and Secure Boot at runtime. For these specific titles, you might still encounter problems.







