Family owned in Gilbert, AZ · Since 2015
Orca IT Solutions

Windows 11 Support

A Windows 11 rollout nobody complains about

Windows 11 upgrades go badly for predictable reasons: a driver nobody validated, a print stack that broke, a VPN client from 2019, or a user who lost their taskbar habits with no warning. We check the hardware requirements properly, pilot with real users, and roll out in waves with a rollback window that is still open if something surfaces.

🛡 Pilot First Driver Validation💰 Rollback Planned Never Outsourced

Requirements

TPM, Secure Boot and the compatibility check that lies to you

Most machines that fail the readiness check are not actually unqualified. They are just misconfigured in firmware.

Windows 11 has three hardware gates that matter: a TPM 2.0 module, UEFI firmware with Secure Boot capability, and a processor on Microsoft's supported list, which in practice starts around Intel's 8th generation and AMD's Ryzen 2000 series. The frustrating part is that the first two are usually present and switched off. Nearly every business-class machine from the last several years has firmware TPM built into the chipset, Intel calls it Platform Trust Technology, AMD calls it fTPM, and it frequently ships disabled. Turn it on in BIOS and the same machine that failed the check yesterday passes today.

The disk is the other quiet blocker

Secure Boot requires UEFI boot mode, and UEFI requires a GPT-partitioned disk. Plenty of machines were imaged years ago in legacy BIOS mode with an MBR disk and have been running that way ever since. Converting is straightforward with Microsoft's MBR2GPT tool, but it must be done in the right order: validate the disk, convert, then switch firmware from legacy or CSM mode to UEFI. Do it in the wrong order and the machine will not boot, which is why we take an image first on anything that matters.

Our free Windows 11 readiness checker gives you a quick per-machine read on where you stand. For a fleet, we run the same checks centrally and produce a list sorted into upgrade now, upgrade after a firmware change, and replace, which pairs directly with the planning on our Windows 10 migration page.

What actually breaks during upgrades

The operating system upgrade itself is reliable. What breaks is everything around it. Printing is the perennial offender: old Type 3 drivers and vendor print utilities that were already living on borrowed time, plus the tightened security around print spooler behavior. Legacy VPN clients and endpoint agents that predate the release cause boot delays or fail silently. Some line-of-business applications with 16-bit installer components or unsigned drivers simply refuse. Scanner and multifunction software from the mid-2010s is another regular casualty.

There are platform-level considerations too. Virtualisation-based security and memory integrity are on by default on many new machines and carry a measurable performance cost on some workloads and a hard incompatibility with a small number of older drivers, worth knowing before someone blames the upgrade for a slow CAD workstation. Certain older Ryzen platforms had an fTPM-related stutter that was resolved by an AGESA firmware update, which is one more reason we push BIOS updates before the OS upgrade rather than after.

For deployment we use the method that fits the client. In-place upgrades preserve applications, profiles and settings and are right for the majority of business machines; they are quick, they run overnight, and they keep the ten-day rollback window open. Wipe-and-load with a standard image is better where the existing install carries years of accumulated cruft, or where you want to move to a clean managed baseline. New hardware should arrive through Windows Autopilot: the machine ships to the user, they sign in with their work account, and Intune builds it, applications, policies, BitLocker, printers, without a technician touching it. That is also covered on our new computer setup page.

The rollback window deserves emphasis because clients keep discovering it too late. After an in-place upgrade, Windows keeps the previous installation for a limited period, ten days by default, during which you can go back cleanly from Settings. After that window closes, or once someone runs Disk Cleanup and removes the previous installation files, going back means a rebuild from backup. So we schedule pilot upgrades early enough that a full working week passes under real usage before the wider rollout, and we do not clean up the previous installation on production machines until we are past it.

On the business side, edition and configuration matter more than most people assume. Windows 11 Pro joined to Entra ID enables automatic BitLocker with the recovery key escrowed to your tenant, which is one of the cheapest genuine security wins available to a small business. Windows Hello for Business replaces passwords at the device with a hardware-backed credential. Enterprise adds application control and more granular update management for larger fleets. We set these correctly at deployment because retrofitting encryption and identity policy across a fleet later is significantly more work than doing it once, properly, at the start.

Upgrade the firmware before you upgrade the operating system. Every time.Orca IT, Gilbert AZ

Deployment Options

Four ways to get there, and when each fits

There is no single right method. There is a right method for each machine.

In-place

Upgrade over the top

Keeps applications, profiles and settings. Fastest path for healthy machines, and it preserves the rollback window if something surfaces.

Wipe and load

Clean standard image

Best for machines carrying years of accumulated software debt, or when you want the whole fleet on one managed baseline.

Autopilot

Zero-touch new devices

Hardware ships straight to the user. They sign in, Intune configures everything, and no technician ever unboxes it.

Cloud PC

Windows 365 or AVD

Where endpoints are old but workloads are light, a hosted desktop can extend hardware life and centralise management.

Pilot group

Real users first

A representative slice of the business runs Windows 11 for a couple of weeks so problems surface on five machines, not fifty.

Staged waves

Department by department

Rollout scheduled around your busy periods, with each wave validated before the next one starts.

How It Runs

A rollout in four stages

01

Readiness

Central hardware check, firmware and TPM state, disk partitioning, plus an inventory of every application and peripheral in use.

02

Validate

BIOS and driver updates from the vendor catalog, then testing of printing, VPN, scanners and line-of-business software on a reference build.

03

Pilot

A small group of real users across different roles run it for two weeks. We fix what they find before anyone else is affected.

04

Roll out

Waves by department, scheduled outside working hours, with rollback available and the help desk briefed on what changed for users.

Check your fleet in minutes

Our free readiness tool gives you a per-machine answer before we ever speak.

Get a Free Assessment

Windows 11 done once, properly, with encryption and identity set up right.

Deployment across Gilbert, Chandler, Mesa and remote teams nationwide.

Talk to Your Pod

Windows 11 questions

Our machines fail the compatibility check. Now what?

Check firmware first. Most business machines from the last several years have firmware TPM and Secure Boot support that shipped disabled, and enabling them resolves the failure. If the disk is still MBR it also needs converting to GPT. Only after that do you know whether the processor is the real blocker.

How long can we roll back after upgrading?

Ten days by default, using the go back option in Settings, and only while the previous installation files remain on disk. Running Disk Cleanup or letting the automatic cleanup happen closes that door early. We time pilot upgrades so real usage happens inside the window.

Will our printers and scanners still work?

Most will, but this is the area that generates the most tickets. Older Type 3 print drivers and vendor scanning utilities are the usual casualties. We test the actual devices you own against a reference build before rollout and source current drivers or replacements where needed.

Is Windows 11 slower than Windows 10?

On modern hardware, no. On some machines, virtualisation-based security and memory integrity being enabled by default do carry a measurable cost for specific workloads. That is a configuration decision to make deliberately, weighing the security benefit against the performance need, not something to discover by accident.

Do we need Pro or Enterprise?

Pro covers most small businesses, and joined to Entra ID it gives you automatic BitLocker with escrowed recovery keys and Windows Hello for Business. Enterprise makes sense at larger scale or where you need application control and more granular update management. We size it to the fleet rather than upselling.

What is Autopilot and do we need it?

Autopilot lets a new machine ship directly to the user and configure itself when they sign in with their work account, with applications and policy delivered by Intune. If you buy more than a handful of machines a year or have remote staff, it saves real time and produces a consistent build every time.

Can you do this outside business hours?

Yes, and we usually do. In-place upgrades run overnight with the machine left on, and remote users can be scheduled individually. Most people arrive in the morning to a machine that finished, with a short note explaining what changed on screen.

What about the annual feature updates after we are on Windows 11?

We manage them with deferral policies and rings rather than letting them arrive whenever Microsoft decides. A pilot group takes each new version first, we validate line-of-business software against it, and the fleet follows once it is proven.

Talk to Your Pod

Ready to move, or already halfway and regretting it?

We do both: clean rollouts from scratch, and rescuing deployments that stalled partway through.

(602) 677-0779

Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced

Same-day response No long contracts Flat, honest pricing Five-star service

Get your free IT consultation

A few details and your pod gets right back to you, usually the same business day.

Spam-protected with a quick CAPTCHA. Your message goes straight to our team in Gilbert. We only use your details to help with your request. Never sold, never shared.