Is Your Workstation Windows 11 Compatible? Model List 2026
Posted by Konstantin Protasov on Apr 7th 2025
The most common question we get about an older workstation is not what it's worth or how fast it is. It's "will it run Windows 11?" — and the answer is more interesting than yes or no, because Microsoft draws its line by processor generation, not by age or capability. A 2017 HP Z240 with TPM 2.0 and Secure Boot fails. A 2017 HP Z4 G4 from the same catalog year passes. A 20-core Z840 with 128 GB of RAM fails, while a four-core Z2 G4 sails through.
The short answer: your workstation needs TPM 2.0, Secure Boot, and a processor on Microsoft's list. Most professional workstations from 2017 onward clear all three: Intel Xeon Scalable (all generations), Xeon W-2100 and every later Xeon W, Xeon E-2100 and newer, Core 8th generation and newer plus the Core X 7000X/9000X/10000X parts, and Threadripper PRO are in. What falls out is the generation just before them — Xeon E5 v3/v4 and 6th/7th-generation Core — which means the HP Z440/Z640/Z840 and Z240, the Dell Precision T5810/T7810/T7910 and 3620, and the Lenovo ThinkStation P510/P710/P910 and P320: some of the most numerous workstations ever sold.
What this guide covers:
- A model-by-model table for HP Z, Dell Precision and Lenovo ThinkStation — supported or not, and why
- What "not supported" actually means in practice, in Microsoft's own words, and what happens if you install anyway
- How to check your own machine in about five minutes
- Whether the TPM 1.2 → 2.0 firmware upgrade on a Z440/Z640/Z840 helps (it does not, and here's why)
- How much time you actually have: Windows 10 support ended in October 2025, but consumer ESU was quietly extended to October 12, 2027
- What to buy if your machine didn't make the list — with current prices
The Four Things Windows 11 Actually Checks
Microsoft's published requirements are short, and three of the four are trivial for any workstation built this decade:
- Processor: 1 GHz or faster, 2+ cores, 64-bit — and on Microsoft's compatible processor list. This is the one that decides it.
- TPM 2.0: a Trusted Platform Module, version 2.0. Many workstations from 2014–2016 shipped with TPM 1.2, which does not qualify.
- UEFI firmware with Secure Boot capability. Note the word capable — Secure Boot has to be supported and the machine has to be booting in UEFI mode, not legacy BIOS/MBR.
- 4 GB RAM, 64 GB storage, DirectX 12 / WDDM 2.0 graphics, 720p display. No workstation fails these.
So in practice the whole question comes down to two things: is your processor on the list, and do you have TPM 2.0 with Secure Boot. Here is how the CPU list reads for workstation silicon, from Microsoft's general Windows 11 supported Intel processors and AMD processors pages — not the per-version pages written for manufacturers, which is where we went wrong before (see the note below the table):
HP Z Workstation Windows 11 Compatibility
Every HP Z model we get asked about, with the verdict and what to do next. "Supported" means the machine's standard processors are on Microsoft's list and the hardware meets the other requirements — the upgrade runs normally from Windows Update or the Installation Assistant.
Dell Precision and Lenovo ThinkStation Compatibility
The same logic, applied to the other two families, and the pattern is the same as HP's: everything from the 2017 Xeon W-2100 / Xeon Scalable / 8th-gen Core wave onward passes, and the Xeon E5 v3/v4 and 6th/7th-gen Core machines immediately before it don't.
If your model isn't listed, the rule of thumb that covers almost every case: a workstation from the 2017 Xeon W-2100 / Xeon Scalable / 8th-generation Core wave or later is supported; anything on Xeon E5 v3/v4 or 6th/7th-generation Core is not, however capable it still is.
What "Not Supported" Actually Means
This is where most articles get vague, so let's be precise. There are three distinct states a machine can be in, and they have very different consequences.
For state 2 and 3, this is what Microsoft puts on screen before you proceed — worth reading once rather than clicking past:
Read that carefully, because the practical meaning is narrower than the wording suggests. In practice, unsupported machines have continued to receive monthly security updates — Microsoft has not switched them off. What you lose is the entitlement: no guarantee for any given month, no promise that the next feature update will install, and an explicit statement that hardware damage from incompatibility isn't a warranty matter. Microsoft's own recommendation, in the same document, is that if an unsupported device has problems after upgrading, you go back to Windows 10.
For a home machine, that's a risk many people accept. For a business running twenty of them, "not entitled to security updates" is a sentence your auditor will want to discuss. That distinction — not the technical possibility — is what should drive the decision.
How to Check Your Own Machine in Five Minutes
Four checks, in the order that saves you the most time — the CPU one first, because it's the one that usually decides the outcome.
- Identify the processor. Press
Win + R, typemsinfo32, press Enter, read the "Processor" line. Then find that family in the table above, or search it directly in Microsoft's general list. An E5-2680 v4 or an i7-7700 tells you the answer immediately. - Check TPM version.
Win + R→tpm.msc. Look at "Specification Version" in the status panel: 2.0 passes, 1.2 doesn't. "Compatible TPM cannot be found" usually means it's disabled in BIOS rather than absent — check the security settings in firmware before concluding anything. - Check Secure Boot and BIOS mode. Still in
msinfo32: "BIOS Mode" must read UEFI, and "Secure Boot State" must read On or Off rather than Unsupported. If BIOS Mode says Legacy, the disk is partitioned MBR and needs converting to GPT (Microsoft'sMBR2GPTtool does this in place) before Secure Boot can be turned on. - Run PC Health Check. Microsoft's tool gives the official verdict and names the specific failing requirement. Use it last — by then you'll already know what it's going to say, and you'll understand its answer instead of just receiving it.
One HP-specific note: on Z-series machines the TPM is often disabled by default in the BIOS security menu, and on some units it ships in "hidden" state, which makes tpm.msc report nothing at all. Enter BIOS (F10 on boot), look under Security → TPM Embedded Security, set the device to available and enabled, save, and re-check before deciding your machine lacks a TPM.
The TPM 1.2 → 2.0 Upgrade on a Z440/Z640/Z840: Does It Help?
This comes up constantly, so here is the straight answer: the upgrade is real, it works, and it does not make your machine Windows 11 compatible.
HP shipped these workstations with an Infineon TPM that can be reflashed between 1.2 and 2.0 firmware using HP's TPM Configuration Utility (SoftPaq SP87753). The SoftPaq's own release notes list the Z240, Z440, Z640 and Z840 among supported models, and the procedure is straightforward: run the SoftPaq, which extracts to C:\SWSetup\SP87753, then run TPMConfig64.exe as administrator. Some units need a BIOS downgrade first, and the utility refuses to run twice without clearing its log file. Afterwards tpm.msc reports 2.0 and BitLocker behaves like a modern machine.
What it doesn't do is put a Xeon E5-2680 v4 on Microsoft's processor list. The CPU check is separate and independent, and no E5 v3 or v4 part appears anywhere in the supported list. So a Z840 with upgraded TPM lands squarely in state 2 above: Windows 11 will install with the documented bypass and run well — these are still capable machines — but it stays formally unsupported forever.
How Much Time Do You Actually Have?
More than most people think, and the reason is a change Microsoft made quietly in the middle of 2026. Windows 10 reached end of support on October 14, 2025. The consumer Extended Security Updates program was originally a single year, ending October 2026 — then in June 2026 Microsoft extended it by another year without an announcement, adding an editor's note to a blog post. Microsoft's ESU page now states plainly that coverage runs "through October 12, 2027" and that already-enrolled devices roll over automatically.
Two things follow. First, nobody has to panic in 2026 — if your machine can't run Windows 11, enrolling in ESU is cheap and buys until late 2027. Second, the arithmetic turns against waiting quickly if you're a business: two years of commercial ESU costs $183 per device, three costs $427, and none of that money buys you a faster machine or a supported one. It buys time on hardware that is already unsupported.
The market has largely made this decision already. Windows 11 passed Windows 10 worldwide in mid-2025 and reached roughly 70% of desktop Windows share by June 2026, with Windows 10 down near 28% (StatCounter) — the steepest annual decline recorded for a Windows version, and one The Register tracked through the year. The remaining Windows 10 installed base skews heavily toward exactly the machines in the "no" rows above.
If Your Machine Didn't Make the List: What to Buy
The replacement question has an unusually clear answer this year, because the used market prices workstations by age and horsepower — not by whether Microsoft happened to list their processor. That mismatch is money on the floor. Prices below are from our inventory on September 5, 2026, and every machine listed runs a processor that is on Microsoft's list.
Two honest caveats on that table. The Z2 G4 at $322 is a four-core machine — it replaces an office PC, not a Z840. And the Xeon Scalable towers, while fully supported, are 2017–2019 hardware: you're buying supported status and core count, not modern single-thread speed.
Which brings up the option nobody sells you: keep the unsupported machine and put Linux on it. A Z440 or Precision T7810 with 20 cores and 128 GB of RAM is a perfectly good Linux workstation or virtualization host in 2026, with no end-of-support clock at all. If the workload doesn't need Windows, that beats both ESU and replacement on cost. We wrote about the same calculus for servers in our Proxmox migration guide.
Not sure which side of the list your machine falls on?
Send us the model and the processor line from msinfo32 and we'll tell you straight — including when the answer is "keep what you have."
Windows 11 Workstation Compatibility: FAQ
Is the HP Z440 compatible with Windows 11?
Not officially. The Z440's Xeon E5-1600/2600 v3 and v4 processors are not on Microsoft's supported list, so the machine fails the CPU check regardless of anything else. Its TPM can be reflashed from 1.2 to 2.0 and Secure Boot works, so Windows 11 will install through the documented registry bypass and run — but the machine stays formally unsupported, with a desktop watermark and no entitlement to updates. The same answer applies to the Z640 and Z840.
Is the HP Z840 compatible with Windows 11?
No, for the same reason as the Z440: Xeon E5 v3/v4 processors aren't on Microsoft's list. A TPM firmware upgrade to 2.0 is possible via HP's TPM Configuration Utility and is worth doing for BitLocker, but it doesn't change the CPU verdict. A dual-socket Z840 remains an excellent Linux or virtualization machine.
Is the HP Z240 compatible with Windows 11?
No. The Z240 has TPM 2.0 and Secure Boot — it passes everything except the processor check, since its 6th and 7th generation Core and Xeon E3-1200 v5/v6 chips sit one generation below Microsoft's 8th-generation cutoff. It's the most frustrating "no" on the list, because the hardware is otherwise ready.
Is the HP Z4 G4 compatible with Windows 11?
Yes. Both processor families HP sold in it are on Microsoft's list: Xeon W-2100/W-2200 (the "Xeon W-2100 Series" and "Xeon W-2200 Series" rows) and Core X (7000X/9000X/10000X). TPM 2.0 is standard, and HP rates the Z4 G4 "Compatible Driver Support" for Windows 11 through 25H2, the same as the Z8 G4. Run PC Health Check to confirm on your unit. Until September 5, 2026 this guide said the Xeon W builds were not supported; that was our error — see the correction at the top.
Is the HP Z420 or Z620 compatible with Windows 11?
No, and these are the hardest cases. Xeon E5 v1/v2 processors aren't listed, and these machines shipped with TPM 1.2 without a 2.0 upgrade path. Installing Windows 11 requires stripping the security checks out of the installer. For business use, treat them as Windows 10 ESU machines or move them to Linux.
Is the Dell Precision 5820 or Lenovo ThinkStation P520 compatible with Windows 11?
Yes, in every configuration they were sold in. Xeon W-2100/W-2200 and, on the 5820, Core X are all on Microsoft's list; Dell lists the Precision 5820 Tower among computers tested for the Windows 11 update, and Lenovo lists the ThinkStation P520 and P520c among devices supported for the upgrade. Check that TPM 2.0 is present and enabled in tpm.msc: it was an option on some 5820 configurations, and P520 units sold in mainland China shipped without it. This guide said the opposite until September 5, 2026 — see the correction at the top.
Which refurbished workstations are officially Windows 11 compatible?
HP Z2 G4/G5/G9, Z1 G5, Z4 G4, Z6 G4, Z8 G4, Z4 G5, Z6 G5, Z8 G5; Dell Precision 3430, 3630, 3640, 3650, 3680, 5820, 7820, 7920, 7865; Lenovo ThinkStation P330, P340, P350, P360, P520, P520c, P620, P720, P920, P5, P7 and P8. In short: any workstation on Xeon Scalable, Xeon W-2100 or newer, Xeon E-2100 or newer, Core 8th generation or newer (Core X included), or Threadripper PRO.
Can I install Windows 11 on an unsupported workstation anyway?
Yes. Microsoft documents a registry route for machines that have TPM 2.0 but an unlisted CPU, and clean-install methods exist for machines without TPM 2.0. Windows 11 then runs normally on most workstation hardware. What you accept is Microsoft's disclaimer: the device is no longer supported, isn't entitled to updates including security updates, and damage caused by incompatibility isn't covered by the manufacturer warranty. A watermark appears on the desktop. In practice these machines have kept receiving monthly updates, but that is Microsoft's discretion, not a commitment.
Does upgrading my TPM to 2.0 make my workstation compatible?
Only if the processor was already on the list and TPM was the sole failure. On a Z440/Z640/Z840 or a Precision T5810/T7810, the CPU is also unlisted, so the TPM upgrade fixes one of two blockers and leaves the machine unsupported.
How long can I keep running Windows 10?
Windows 10 reached end of support on October 14, 2025. Consumer Extended Security Updates now run through October 12, 2027 — Microsoft extended the program by a second year in June 2026 — for $30, covering up to 10 devices, or free via Microsoft Rewards or Windows Backup. Businesses can buy commercial ESU through October 2028 at $61, $122 and $244 per device for years one, two and three. After those dates there is no further paid option.
Is it cheaper to buy ESU or replace the machine?
For a business, replacing usually wins on a two-to-three-year view: three years of commercial ESU is $427 per device, while a fully supported refurbished workstation starts around $322 and comes with warranty, faster storage and a machine you can keep past 2028. For a single home machine, $30 of consumer ESU through October 2027 is the cheaper way to buy thinking time.
The Bottom Line
Windows 11 compatibility on workstations is decided almost entirely by one list, and that list is drawn by processor generation rather than by capability or age. Everything from the 2017 Xeon W-2100 / Xeon Scalable / 8th-gen Core wave onward passes — including the Z4 G4, Precision 5820 and ThinkStation P520 we wrongly marked as failing before September 2026. The generation just before it doesn't: a Z240 with TPM 2.0 and Secure Boot fails on a CPU one generation too old, and a 20-core Z840 fails on Xeon E5 v4 while a bare-bones Z2 G4 sails through.
Practically, that gives you three honest options. If your machine is on the list, upgrade — there's nothing to think about. If it isn't but has TPM 2.0, you can install anyway and accept that Microsoft owes you nothing, which is a reasonable trade for a home machine and a poor one for a fleet. And if it's a pre-2017 dual-socket monster, the best answer is often neither Windows 11 nor ESU, but Linux — those machines have plenty of useful life left in a role that doesn't care what Microsoft's list says.
What you have is time: until October 2027 on consumer ESU, October 2028 on commercial. What you don't have is a version of this that gets cheaper by waiting — ESU pricing doubles annually by design, and the supported used machines that solve the problem outright start at less than two years of it.