Windows 11 Security and the Advantages for Test Applications

Contents

How does Windows 11 change the way security works on my test system?

At first glance, Windows 11 looks like Windows 10 with a few cosmetic changes. Under the hood, however, Windows 11 introduced several enhanced security features unavailable with Windows 10. Many of these features are now enforced by default or require specific hardware to function optimally. Here’s a breakdown of the key differences and how these will impact your test systems.

Virtualization-Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI)

Both Windows 10 and Windows 11 support VBS and HVCI, but in Windows 11 these features are more tightly integrated and enabled by default on supported hardware. VBS isolates critical parts of the system to protect against kernel-level exploits, while HVCI ensures only trusted code—signed by the vendor with an approved certificate—and runs in kernel mode.

How VBS and HVCI Impact Test

  • Software packages you buy that are Windows 11 compliant will be more secure.
  • Older unsigned software components may not run in Windows 11 environments. 

Steps to Ensure Compatibility

  • Check with your software suppliers to ensure that critical applications will continue to run after you upgrade to Windows 11.
  • Check the versions of your NI software applications and drivers with the versions listed at NI Product Compatibility for Microsoft Windows 11 to ensure compatibility.

Trusted Platform Module (TPM) 2.0 Requirement

Windows 11 mandates the use of a TPM 2.0 chip, which is optional in Windows 10. TPM chips can be used by the operating system or your test application to store encrypted information. This technology enables features like the following examples: 

  • Secure credential storage (for example, Windows Hello)
  • BitLocker encryption
  • Device encryption
  • Credential binding to hardware

This requirement enables Windows 11 to support passwordless authentication and stronger protection against phishing and credential theft. 

Trusted Platform Module (TPM) 2.0 impact

  • If your computer has no TPM chip, it may work fine with Windows 10—but it will not work with Windows 11. You may need to update your computer systems to incorporate TPM chips. 

Prepare for TPM Requirements

Secure Boot and UEFI

While Secure Boot is available in Windows 10, Windows 11 emphasizes its use more strongly. Secure Boot ensures that only trusted software is loaded during startup, reducing the risk of boot-level malware.

Secure Boot’s Effect on Legacy Software and Multi-OS Systems

  • Older software that worked in Windows 10 may not work in Windows 11 with Secure Boot. You may need to update your software applications when you upgrade your controller to Windows 11.
  • If you dual-boot multiple OSs on the same computer, Secure Boot may make this more difficult. 
  • Secure Boot may falsely flag some of your software applications as malicious and block them from running. If this happens, contact the software provider to find a resolution, which may require an update from the vendor.

Preparing Your Software for Secure Boot

  • Check with your software providers to ensure they have tested for Windows 11 compliance.

BitLocker and Device Encryption

Both OS versions support BitLocker, but Windows 11 leverages TPM more effectively to bind encryption keys to the device, enhancing protection against data theft from lost or stolen devices.

Encryption’s Impact on Data Handling and Performance

  • If you remove hard drives from your test system, they may be encrypted with BitLocker on your Windows 11 system. You will need to devise a strategy for moving hard drives if they are encrypted.
  • If you store critical data you don’t want to lose, store your BitLocker encryption keys in a secure location. If your computer fails and won’t boot, you’ll need the keys to recover your data from the locked drive.
  • Encryption requires extra processing and may slow your data throughput. Test your data system to ensure that it can maintain your data rates after enabling BitLocker encryption. 

Best Practices for Managing Encryption

  • Document encryption in your system and create a strategy for the safe storage of encryption keys. 

Windows Hello and Biometric Authentication

Windows 11 integrates Windows Hello more deeply, using TPM to store biometric credentials securely. This feature makes it easier to deploy passwordless authentication across organizations.

Authentication Changes and Shared Workstation Challenges

  • Test teams will need to consider how to take advantage of passwordless systems, where a token is used to log in rather than a password.
  • Using tokens instead of passwords restricts a computer to a single user. Restricting a station to a single user is an important step in securing a workstation, but this restriction causes problems if your users share a laboratory computer. You may need to configure the system to allow sharing in these situations, and you’ll need to consider the security implications of doing this. 

Updating Login Procedures for Security and Usability

  • Review your test procedures to identify where logins are shared among operators.
  • Update procedures where possible to require each operator log in to the system.

Pluton Security Processor

Pluton is a chip-to-cloud security technology that’s embedded directly into the CPU. It’s designed to provide stronger protection for sensitive data, such as encryption keys, credentials, and personal information, by isolating them from the rest of the system—even from the firmware and operating system. Being built into the CPU (rather than being a separate chip, like TPM) means that it’s even harder to tamper with. A Pluton CPU acts as a TPM 2.0 device.

Security Enhancements with Pluton Integration

  • As an end user, you probably will not be impacted by whether your system is using a TPM chip or a Pluton processor. Your system will be more secure and protected from memory vulnerabilities that use a memory error in one software application to get data from another software application. Pluton helps protect against this. 

Zero Trust Architecture Support

Windows 11 integrates deeper security controls, identity protections, and hardware-based defenses to align with the core principles of Zero Trust: Verify explicitly, use least-privilege access, and assume breach. 

Security Architecture Shifts in Test Environments

  • Zero Trust means that users are verified more often. You will need to architect your test code and test procedures to account for increased scrutiny over who is using the system. 
  • Expect your security team to look deeper at each component in your test system. Zero trust means that you can’t assume that the system is safe; you have to assume someone has broken in and you have to protect each part of the system.  

Adopting Secure Development Practices

  • If you haven’t already done so, adopt a secure development framework to ensure you are implementing best practices in your development process. 

Lifecycle and Support Considerations

Microsoft is ending mainstream support for Windows 10 General Availability Channel (GA) Versions on October 14, 2025, prompting many IT departments to migrate to Windows 11 to maintain security updates and compliance

Windows 10 End-of-Life and Compliance Pressures

  • Moving to Windows 11 may be forced, not a choice. You need to plan for how to update your Windows 10 systems to maintain basic support for those systems.
  • Many customers (including the U.S. government) require that suppliers meet security controls. One of the most important controls is to only use software with support for fixing security issues. After Microsoft discontinues support for Windows 10, you may need to update to comply with this requirement.

Coordinating Upgrade Plans with IT and Security Teams

 

  • Work with your IT team and security team to understand their plans and timelines to roll out Windows 11 to make sure you are ready for the changes.
  • Moving forward, NI software releases will still be officially supported for Long Term Servicing Channel (LTSC) versions of Windows 10. OS Support compatibility is documented for customer on ni.com and will be updated to reflect the Windows 10 version differences here: NI Supported Operating System Roadmap.