Fix it now
0xC1900200 is MOSETUP_E_COMPAT_SYSREQ_BLOCK: the system does not pass the minimum requirements to install the update. It is a verdict rather than a fault. Some of what triggers it is a firmware setting you can change in ten minutes; the processor check is not one of those, and no key or setting changes it.
setup.exe /auto upgrade /compat scanonly
- Run PC Health Check as well, which reports the failed requirement in plain language rather than as a code.
- Open
tpm.mscand confirm a TPM is present, reports ready for use, and shows specification version 2.0. Microsoft’s published requirement is TPM 2.0. - Run
msinfo32and read two lines: BIOS Mode should say UEFI, and Secure Boot State should say On. The published firmware requirement is UEFI, Secure Boot capable. - If the TPM is absent, look in firmware for Intel Platform Trust Technology, Intel PTT, AMD fTPM, or an entry called Security Device. Many business machines ship with it switched off.
- If BIOS Mode says Legacy, the disk is on the old partition scheme. Validate a conversion first with
MBR2GPT /validate /disk:0 /allowFullOSbefore changing anything, and suspend BitLocker before you convert. - Check the processor model against Microsoft’s published supported processor list for Windows 11. If it is not on the list, nothing on the machine changes that.
Converting the system disk and changing the firmware boot mode can leave a machine unbootable if the firmware does not pick up the new boot entry. Take a full image backup first and know how to reverse it.
If the compatibility scan now passes, run the upgrade. If the block is the processor or soldered hardware, the next section explains why there is nothing left to change.
Why it happens
Before setup copies anything it runs a compatibility appraisal against the published minimum requirements. 0xC1900200 is that appraisal blocking the install: MOSETUP_E_COMPAT_SYSREQ_BLOCK, the system does not pass the minimum requirements to install the update. Microsoft’s other published wording for the same code is that setup.exe has detected the machine does not meet the minimum system requirements. It is not a fault, a corruption or a download problem.
The other three codes tell you where in that process the refusal happened, and the distinctions are real. 0xC1900202 is MOSETUP_E_COMPAT_DOWNLOADREQ_BLOCK: the system does not pass the minimum requirements to download the update – the check ran before the payload was offered. 0xC1900201 is MOSETUP_E_COMPAT_SYSREQ_CANCEL: the user has chosen to cancel because the system does not pass the minimum requirements to install. That is a person clicking cancel after being told, not a second machine-side refusal.
0xC1900200 – 0x20008 is published in Microsoft’s support tables with its own row: the computer does not meet the minimum requirements to download or upgrade, with the mitigation to check the specifications and review the logs for compatibility information. The extend code decodes as phase 2 SAFE_OS, operation 0x08 PREPARE_SAFE_OS, which tells you where setup was standing when it gave up.
The requirements themselves are published and worth quoting rather than paraphrasing: 1 GHz or faster with two or more cores on a compatible 64-bit processor or system on a chip; 4 GB or greater memory; 64 GB or greater available disk space; a graphics card compatible with DirectX 12 or later with a WDDM 2.0 driver; UEFI, Secure Boot capable system firmware; TPM version 2.0; and a high definition 720p display, 9 inches or greater, with 8 bits per colour channel. Some of those are settings. The processor list is not.
The TPM exists but is switched off in firmware
You have this one if tpm.msc says no compatible TPM was found on a machine of an age where one should be present.
- Restart into firmware setup and look for Intel Platform Trust Technology, Intel PTT, AMD fTPM, or an entry called Security Device or TPM Device.
- Enable it, save and restart into Windows.
- Confirm in
tpm.mscthat a TPM appears and reports specification version 2.0, or withGet-Tpmin elevated PowerShell. - Run the compatibility scan again before starting the upgrade.
Firmware TPMs on both Intel and AMD platforms satisfy the TPM 2.0 requirement. A separate hardware module is not needed.
The machine boots in legacy mode, so Secure Boot cannot be on
You have this one if msinfo32 shows BIOS Mode Legacy and Secure Boot State Unsupported, and the system disk uses MBR.
- Suspend BitLocker:
manage-bde -protectors -disable C: -rebootcount 3, with the recovery key stored off the machine. - Validate the conversion:
MBR2GPT /validate /disk:0 /allowFullOS. It checks the layout before anything is changed and returns an error if the disk is not eligible. - Convert if validation passes:
MBR2GPT /convert /disk:0 /allowFullOS. - Restart into firmware setup, switch from Legacy or CSM to UEFI, and enable Secure Boot.
- Boot into Windows and re-check
msinfo32before running the upgrade.
Run from the full operating system, MBR2GPT cannot reuse the existing MBR system partition, so it creates a new EFI system partition by shrinking the OS partition. The firmware must be switched to UEFI afterwards or the machine will not boot.
The processor is not on the supported list
You have this one if TPM 2.0 is present and enabled, Secure Boot is on, memory and storage are ample, and setup still refuses.
- Get the exact model with
Get-CimInstance Win32_Processor | Select-Object Namein PowerShell. - Check it against Microsoft’s published supported processor list for Windows 11 for that CPU vendor.
- If it is absent, accept the result. There is no setting, driver or update that adds a processor to that list.
- Plan the device out: keep it on a supported release with an appropriate entitlement, or replace it.
Memory, storage or graphics is below the published floor
You have this one if An older or entry-level machine with 2 GB of memory, a 32 GB drive, or no WDDM 2.0 display driver.
- Compare installed memory and free space against the published 4 GB and 64 GB minimums.
- Add memory where the machine allows it, which on many small devices it does not.
- Check the display driver’s WDDM version on the Display tab of
dxdiagagainst the WDDM 2.0 requirement. - Where the hardware is soldered and below the floor, this is a replacement rather than a repair.
A virtual machine has no virtual TPM or Secure Boot
You have this one if The refusal appears on a guest while the host and physical machines pass.
- On Hyper-V, confirm the guest is generation 2, then enable Secure Boot and Trusted Platform Module under the virtual machine’s Security settings.
- On other hypervisors, add a virtual TPM device to the guest, which may first require the VM to be encrypted or a key provider to be configured.
- Start the guest and confirm
tpm.mscsees the device before running the upgrade.
A generation 1 Hyper-V guest cannot be converted in place. It has to be rebuilt as generation 2 or migrated with a conversion tool.
Full reference
The published minimum requirements
| Requirement | Published minimum |
|---|---|
| Processor | 1 GHz or faster with two or more cores on a compatible 64-bit processor or SoC |
| Memory | 4 GB or greater |
| Storage | 64 GB or greater available disk space |
| Graphics card | Compatible with DirectX 12 or later, with a WDDM 2.0 driver |
| System firmware | UEFI, Secure Boot capable |
| TPM | Trusted Platform Module version 2.0 |
| Display | High definition 720p, 9 inches or greater, 8 bits per colour channel |
Which code you got, and what it tells you
| Code | Published meaning |
|---|---|
0xC1900200 |
MOSETUP_E_COMPAT_SYSREQ_BLOCK: does not pass the minimum requirements to install |
0xC1900201 |
MOSETUP_E_COMPAT_SYSREQ_CANCEL: the user cancelled because it does not pass |
0xC1900202 |
MOSETUP_E_COMPAT_DOWNLOADREQ_BLOCK: does not pass the requirements to download |
0xC1900200 - 0x20008 |
Does not meet the minimum requirements to download or upgrade; SAFE_OS / PREPARE_SAFE_OS |
Working out which check failed
| What you find | What it means |
|---|---|
tpm.msc reports a compatible TPM cannot be found |
No TPM is exposed to Windows, usually disabled in firmware |
tpm.msc reports specification version 1.2 |
There is a TPM but not at the version the requirement names |
msinfo32 shows BIOS Mode Legacy |
The machine boots in legacy mode, so Secure Boot cannot be on |
| Everything passes except the processor | The model is not on the published list, and that check cannot be satisfied |
| A virtual machine fails on TPM and Secure Boot | No virtual TPM, or an older VM generation |
What Microsoft says about installing anyway
Microsoft’s published position is that it is not recommended to install Windows 11 on a device that does not meet the requirements, and that if it has been done, Microsoft recommends rolling back to Windows 10 immediately. That is the whole of the published guidance, and it is worth quoting to whoever is asking you to do it. Nothing on this page tells you how to bypass the appraiser, because Microsoft does not publish a supported way to do so.
Validating an MBR to GPT conversion before you commit
MBR2GPT checks the disk before it changes anything: that the disk is currently MBR, that there is room at both ends for the primary and secondary GPTs, that there are at most three primary partitions, that one is active and is the system partition, that there is no extended or logical partition, that the BCD store has a default OS entry pointing at an OS partition, and that volume IDs can be retrieved for every lettered volume. If any check fails the conversion does not proceed and an error is returned – which is exactly why you run /validate first.
When the answer is a different machine
- Confirm the processor verdict yourself rather than taking a tool’s word for it, because that is the one check with no workaround.
- Decide what the device does next: a supported Windows release with an entitlement that covers it, or retirement.
- If several machines share a model, test one properly and apply the answer to the fleet rather than repeating the diagnosis.
- Where the block is firmware settings rather than silicon, a single BIOS change applied across a fleet can move a large number of machines at once, so establish which category each model is in first.
When a licence is the actual fix
If the processor is off Microsoft’s published list, or memory and storage are soldered below the published floor, this device does not become a Windows 11 machine by any supported route. That is a hardware decision rather than a licensing one, and no key changes the appraiser’s verdict – which is worth saying plainly, because it is the most common thing people try. Where a licence does matter is on the replacement: a new machine needs its own Windows entitlement, and for business use that is normally a Windows 11 Pro OEM licence supplied with the device rather than a retail upgrade bought afterwards. Two things to check before you buy anything. First, that the block really is the processor and not a TPM switched off in firmware, because the second costs nothing to fix. Second, whether the existing machine has a role that keeps it useful on a supported release for a while longer, which changes the urgency without changing the eventual answer.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xC1900200 |
MOSETUP_E_COMPAT_SYSREQ_BLOCK: the system does not pass the minimum requirements to install the update | Microsoft Learn |
0xC1900201 |
MOSETUP_E_COMPAT_SYSREQ_CANCEL: the user chose to cancel because the system does not pass the minimum requirements to install | Microsoft Learn |
0xC1900200 - 0x20008 |
The computer does not meet the minimum requirements to download or upgrade; the extend code decodes as SAFE_OS / PREPARE_SAFE_OS | Microsoft Learn |
0xC1900202 |
MOSETUP_E_COMPAT_DOWNLOADREQ_BLOCK: the system does not pass the minimum requirements to download the update | Microsoft Learn |
Confirm the fix worked
tpm.mscreports the TPM ready for use at specification version 2.0.msinfo32reports BIOS Mode UEFI and Secure Boot State On.- The compatibility scan reports no blocking hardware.
- Setup moves past the compatibility stage into the download or copy phase.
- If you converted the disk, the machine boots normally from UEFI and BitLocker protection is back on.
Questions people ask about this
Will buying a Windows 11 licence make my PC compatible?
No. The appraiser checks hardware, not entitlement. A licence changes what you are allowed to install, never what the machine passes.
Can I bypass the check?
Microsoft does not publish a supported way to do so on the pages that cover these codes. Its published position is that installing Windows 11 on a device that does not meet the requirements is not recommended, and that if you have, you should roll back to Windows 10 immediately.
My machine ran Windows 11 before and is now refused. What changed?
Check the firmware first. A cleared CMOS, a firmware update that reset defaults, or a setting changed for another reason can switch off the firmware TPM or return the machine to legacy boot. tpm.msc and msinfo32 answer it in under a minute.
Is TPM 2.0 the same as BitLocker being on?
No. The TPM is hardware that Windows can use; BitLocker is one of the things that uses it. A machine can have TPM 2.0 enabled with BitLocker switched off and pass this check perfectly well.
What is the difference between 0xC1900200 and 0xC1900202?
Which check refused. 0xC1900200 is the requirements block for installing; 0xC1900202 is the requirements block for downloading. The second means the machine failed before the payload was ever offered to it.
