Checking Windows 11 Compatibility with Intune and then deploying with a feature update

Windows 11 has been out a while now and I’m sure most of you have been testing and are nearing the point of looking at deploying to your userbase.

As we all know, however, the requirements are a lot stricter than they were for Windows 10 (or even 7) so you may find yourselves needing to do some hardware refreshes. But, how do you know which to replace??

Before looking at that, let’s refresh the requirements first:

Whilst most recent machines tick the boxes, the 7th Gen requirement is going to rule out some perfectly capable machines unfortunately and you *can* technically install W11 on these, but it’s totally unsupported.

Detection

Anyway, to find out which, you need to navigate to Report – Endpoint Analytics and then Work from Anywhere

You then want to click on the Windows Tab at the top

This then gives a list of your devices with a heading for Windows 11 Readiness State and another for the reason

As you can see, mine is a VM so not compatible with Win11

You can also sort on the Readiness State or export to CSV to better filter within Excel (and maybe do a nice pie chart to present to whoever holds the budget)

Deployment

First up, create an Azure AD group and populate with the devices exported and marked as compatible:

In Intune, navigate to Devices – Windows Devices

Click the Columns button at the top and select Azure AD Device ID

Now export the list of devices into CSV format.

Once you have the two device lists, get the Device IDs for the compatible devices with some Excel magic (or a VLOOKUP)

Now navigate to Azure AD and create a new AAD Group (Statically Assigned)

Navigate to the new group and select Bulk Actions – Import Members:

Download the Template

Edit the CSV and enter the AAD Device IDs we exported earlier.

Next, in Intune, navigate to Devices – Feature Updates for Windows 10 and Later

Create a new Profile and select Windows 11

If you want to get it done quickly select Make update available as soon as possible, otherwise go for the gradual approach:

Assign this to your Windows 11 group and the machines will start to receive the update

Posted in Intune