Transitioning to a new operating system is never a trivial task. With Windows 10 reaching end-of-life in October 2025, organisations are under pressure to migrate to Windows 11 24H2. This isn’t just a routine update, it’s a significant shift that requires careful planning, resource allocation, and change management.
Understanding the Scope of Change
Windows 11 24H2 introduces a full operating system upgrade, not just a cumulative update. This means traditional servicing methods won’t suffice. Devices must be running Windows 11 version 22H2 or 23H2 with the May 2024 non-security update installed to proceed with the upgrade. Otherwise, its a full wipe and reinstall.
This change requires organisations to reassess their deployment strategies. Phased rollouts become essential to validate compatibility with existing applications, hardware, and infrastructure. It’s not just about pushing an update; it’s about ensuring business continuity throughout the transition.
Evaluating Device Readiness
Before initiating the migration, it’s crucial to assess whether your current hardware meets Windows 11 requirements, such as TPM 2.0, Secure Boot, and supported processors. Overlooking these prerequisities can lead to deployment failures and increased support calls.
Moreover, consider the user experience. Windows 11 brings a new interface and features that may require user training. Allocating time and resources for training sessions can mitigate resistance and enhance adoption rates.
Security Enhancements
Windows 11 24H2 comes with updated security baselines, including mandatory SMB signing for all connections. While these enhancements bolster security, they may disrupt access to legacy systems or third-party NAS devices that don’t support SMB signing. Here are some of the security enhancements to be aware of:
- Mandatory SMB Signing: Server Message Block (SMB) signing is now required by default for all connections. This ensures the authenticity and integrity of SMB communications, mitigating risks associated with reply attacks and credential theft.
- Removal of NTLMv1 Authentication: Windows 11 24H2 eliminates support for NTLMv1, an outdated authentication protocol. This move strengthens security by enforcing the use of more secure authentication methods.
- Default Activation of LSA Protection: Local Security Authority (LSA) protection is enabled by default, safeguarding credential storage and preventing unauthorised access to sensitive information.
- Default BitLocker Device Encryption: BitLocker encryption is now enabled by default on supported devices, ensuring data at rest and protecting against unauthorised access in case of device loss or theft.
- Modernised Windows Hello with Passkey Support: The Windows Hello authentication system has been updated to support passkeys, offering a more secure and user-friendly sign-in experience.
- Enhanced Virtualisation-Based Security (VBS): VBS is further integrated to protect against sophisticated attacks by isolating critical parts of the operating system, reducing the risk of kernel-level exploits.
- Updated Security Baselines: Microsoft has released new security baselines for Windows 11 24H2, providing recommended configuration settings to enhance device security.
Organisations must audit their network infrastructure to identify potential compatibility issues. Engaging with vendors to update firmware or adjust settings to maintain seamless operations.
Deployment Strategies
Deciding between traditional on-premises and a cloud-first approach is pivotal. On-premises methods offer control but lack scalability. Conversely, leveraging tools like Microsoft Intune can streamline deployments and policy management across diverse environments.
A hybrid approach might offer the best of both worlds, allowing organisations to maintain critical on-premises systems while adopting cloud solutions for flexibility and scalability.
How Novus can Help
At NOVUS, we understand the complexities involved in such a significant transition. Our team offers comprehensive services to support your migration to Windows 11:
- Assessment and Planning: Evaluate your current environment and develop a tailored migration plan.
- Deployment Execution: Implement the chosen deployment strategy with minimal disruption.
- Security Configuration: Apply updated security baselines and ensure compliance.
- Training and Support: Provide user training and ongoing support throughout the transition.
Contact us today to discuss your Windows 11 deployment strategy.
