Windows 11 is the next client operating system, and includes features that organizations should know. Windows 11 is built on the same foundation as Windows 10. If you use Windows 10, then Windows 11 is a natural transition and update to what you know, and what you’re familiar with.
It offers innovations focused on enhancing end-user productivity, and is designed to support today’s hybrid work environment.
Your investments in update and device management are carried forward. For example, many of the same apps and tools can be used in Windows 11. Many of the same security settings and policies can be applied to Windows 11 devices, including PCs. You can use Windows Autopilot with a zero touch deployment to enroll your Windows devices in Microsoft Endpoint Manager. You can also use newer features, such as Azure Virtual Desktop and Windows 365 on your Windows 11 devices.
Security and scanning
The security and privacy features in Windows 11 are similar to Windows 10. Security for your devices starts with the hardware, and includes OS security, application security, and user & identity security. There are features available in the Windows OS to help in these areas. This section describes some of these features.
- The Windows Security app is built into the OS. This app is an easy-to-use interface, and combines commonly used security features. For example, your get access to virus & threat protection, firewall & network protection, account protection, and more.
- Security baselines includes security settings that already configured, and ready to be deployed to your devices. If you don’t know where to start, or it’s too time consuming to go through all the settings, then you should look at Security Baselines.
- Microsoft Defender Antivirus is built into Windows, and helps protect devices using next-generation security. When used with Microsoft Defender for Endpoint, your organization gets strong endpoint protection, and advanced endpoint protection & response. If your devices are managed with Endpoint Manager, you can create policies based on threat levels found in Microsoft Defender for Endpoint.
- The Application Security features help prevent unwanted or malicious code from running, isolate untrusted websites & untrusted Office files, protect against phishing or malware websites, and more.
- Windows Hello for Business helps protect users and identities. It replaces passwords, and uses a PIN or biometric that stays locally on the device. Device manufacturers are including more secure hardware features, such as IR cameras and TPM chips. These features are used with Windows Hello for Business to help protect user identities on your organization devices.As an admin, going passwordless help secures user identities. The Windows OS, Azure AD, and Endpoint Manager work together to remove passwords, create more secure policies, and help enforce compliance.
Easier access to new services, and services you already use
- Windows 365 is a desktop operating system that’s also a cloud service. From another internet-connected device, including Android and macOS devices, you can run Windows 365, just like a virtual machine.
- Microsoft Teams is included with the OS, and is automatically available on the taskbar. Users select the chat icon, sign in with their personal Microsoft account, and start a call:This version of Microsoft Teams is for personal accounts. For organization accounts, such as
[email protected], you can deploy the Microsoft Teams app using MDM policy, such as Endpoint Manager. For more information, see:Users can manage preinstalled apps using the Settings app > Apps > Apps & Features. Admins can create a policy that pins apps, or removes the default pinned apps from the Taskbar.
- Power Automate for desktop is included with the OS. Your users can create flows with this low-code app to help them with everyday tasks. For example, users can create flows that save a message to OneNote, notify a team when there’s a new Forms response, get notified when a file is added to SharePoint, and more.Users can manage preinstalled apps using the Settings app > Apps > Apps & Features.
Customize the desktop experience
- Snap Layouts, Snap Groups: When you open an app, hover your mouse over the minimize/maximize option. When you do, you can select a different layout for the app:This feature allows users to customize the sizes of apps on their desktop. And, when you add other apps to the layout, the snapped layout stays in place.When you add your apps in a Snap Layout, that layout is saved in a Snap Group. In the taskbar, when you hover over an app in an existing snap layout, it shows all the apps in that layout. This feature is the Snap Group. You can select the group, and the apps are opened in the same layout. As you add more Snap Groups, you can switch between them just by selecting the Snap Group.Users can manage some snap features using the Settings app > System > Multitasking.You can also add Snap Layouts to apps your organization creates.
- Start menu: The Start menu includes some apps that are pinned by default. You can customize the Start menu layout by pinning (and unpinning) the apps you want. For example, you can pin commonly used apps in your organization, such as Outlook, Microsoft Teams, apps your organization creates, and more.Using policy, you can deploy your customized Start menu layout to devices in your organization.Users can manage some Start menu features using the Settings app > Personalization.
- Taskbar: You can also pin (and unpin) apps on the Taskbar. For example, you can pin commonly used apps in your organization, such as Outlook, Microsoft Teams, apps your organization creates, and more.Using policy, you can deploy your customized Taskbar to devices in your organization.Users can manage some Taskbar features using the Settings app > Personalization. F
- Widgets: Widgets are available on the Taskbar. It includes a personalized feed that could be weather, calendar, stock prices, news, and more:You can enable/disable this feature using the
Computer Configuration\Administrative Templates\Windows Components\widgetsGroup Policy. You can also deploy a customized Taskbar to devices in your organization.
- Virtual desktops: On the Taskbar, you can select the Desktops icon to create a new desktop:Use the desktop to open different apps depending on what you’re doing. For example, you can create a Travel desktop that includes web sites and apps that are focused on travel.
Use your same apps, improved
- Your Windows 10 apps will also work on Windows 11. App Assure is also available if there are some issues.You can continue to use MSIX packages for your UWP, Win32, WPF, and WinForm desktop application files. Continue to use Windows Package Manager to install Windows apps. Use Azure Virtual desktop with MSIX app attach to virtualize desktops and apps.In the Settings app > Apps, users can manage some of the app settings. For example, they can get apps anywhere, but let the user know if there’s a comparable app in the Microsoft Store. They can also choose which apps start when they sign in.
- If you manage devices using Endpoint Manager, then you might be familiar with the Company Portal app. Starting with Windows 11, the Company Portal is your private app repository for your organization apps.For public and retail apps, continue using the Microsoft Store.
- Windows Terminal app: This app is included with the OS. On previous Windows versions, it’s a separate download in the Microsoft Store.This app combines Windows PowerShell, a command prompt, and Azure Cloud Shell all within the same terminal window. You don’t need to open separate apps to use these command-line applications. It has tabs. And when you open a new tab, you can choose your command-line application:If users or groups in your organization do a lot with Windows PowerShell or the command prompt, then use policy to add the Windows Terminal app to the Start menu layout or the Taskbar.Users can also search for the Terminal app, right-select the app, and pin the app to the Start menu and taskbar.
- The Microsoft Store has a new look, and includes more public and retail apps. For more information on the end-user experience, see:
- The Microsoft Edge browser is included with the OS, and is the default browser. Internet Explorer (IE) isn’t available in Windows 11. In Microsoft Edge, you can use IE Mode if a website needs Internet Explorer. Open Microsoft Edge, and enter
edge://settings/defaultBrowserin the URL.To save system resources, Microsoft Edge uses sleeping tabs. Users can configure these settings, and more, in
Deployment and servicing
- Install Windows 11: The same methods you use to install Windows 10 can also be used to install Windows 11. For example, you can deploy Windows to your devices using Windows Autopilot, Microsoft Deployment Toolkit (MDT), Configuration Manager, and more. Windows 11 will be delivered as an upgrade to eligible devices running Windows 10.
- Windows Autopilot: If you’re purchasing new devices, you can use Windows Autopilot to set up and pre-configure the devices. When users get the device, they sign in with their organization account (
[email protected]). In the background, Autopilot gets them ready for use, and deploys any apps or policies you set. You can also use Windows Autopilot to reset, repurpose, and recover devices. Autopilot offers zero touch deployment for admins.If you have a global or remote workforce, then Autopilot might be the right option to install the OS, and get it ready for use.
- Microsoft Endpoint Manager is a mobile application management (MAM) and mobile device management (MDM) provider. It helps manage devices, and manage apps on devices in your organization. You configure policies, and then deploy these policies to users and groups. You can create and deploy policies that install apps, configure device features, enforce PIN requirements, block compromised devices, and more.If you currently use Group Policy to manage your Windows 10 devices, you can also use Group Policy to manage Windows 11 devices. In Endpoint Manager, there are administrative templates and the settings catalog that include many of the same policies. Group Policy analytics analyze your on-premises group policy objects.
- Windows Updates and Delivery optimization helps manage updates, and manage features on your devices. Starting with Windows 11, the OS feature updates are installed annually. FLike Windows 10, Windows 11 will receive monthly quality updates.You have options to install updates on your Windows devices, including Endpoint Manager, Group Policy, Windows Server Update Services (WSUS), and more.Some updates are large, and use bandwidth. Delivery optimization helps reduce bandwidth consumption. It shares the work of downloading the update packages with multiple devices in your deployment. Windows 11 updates are smaller, as they only pull down source files that are different. You can create policies that configure delivery optimization settings. For example, set the maximum upload and download bandwidth, set caching sizes, and more.
- Windows Operating Systems and Microsoft Office Suite are also available in our store. Update your PC with the latest version of Windows 10, or Windows 11 Operating System and install Microsoft Office 2019 Suite or Microsoft Office 2021 Suite to bring the performance of your device to the top.