How to Clean Install Windows 11: The Complete Walkthrough From a New Jersey Repair Bench
Windows Support Somerville, NJ · 14 min read
A clean install is the single most effective thing you can do for a Windows computer that has years of buildup on it. Not a tune-up utility, not a registry cleaner, not another antivirus scan. Wiping the drive and installing Windows 11 fresh removes every leftover driver, every startup program you forgot about, and every piece of software that hitched a ride over the years. It is how every machine leaves my bench when a reinstall is the right call, and it is completely doable at home if you are careful and you follow the steps in order.
This guide walks you through the entire process the way I would do it in the shop: checking that your computer actually qualifies first, enabling TPM 2.0 and Secure Boot in the BIOS if they are turned off, backing up properly, creating the installation drive with Microsoft's official tool, and getting through every screen of the installer without wiping the wrong drive.
One honest note before we start. A clean install erases everything on the drive you install to. Photos, documents, tax records, saved games, all of it. If any part of the backup section makes you nervous, or the computer holds data you cannot afford to lose, stop and bring it to us instead. Reinstalls with full data transfer are one of the most common jobs on my bench, and our $75 diagnostic is credited toward the work.
What You Will Need
A USB flash drive, 16GB or larger. Microsoft's official minimum is 8GB, but 16GB gives the Media Creation Tool room to work and modern drives barely cost more. Everything on the drive gets erased during creation, so use one that is empty or expendable. Any name-brand USB 3.x drive works. These are the ones I keep in a drawer at the shop because they are reliable and fast enough that the install does not crawl:
- SanDisk Ultra (32GB or 64GB, USB 3.0): the workhorse. Slightly slow to write the media, fast enough to install from.
- Samsung BAR Plus (32GB or 64GB): metal body, quick, nearly indestructible on a keychain.
- Samsung FIT Plus or SanDisk Ultra Fit: the tiny low-profile ones. Handy if you want to leave a recovery drive plugged into the back of a desktop.
- Kingston DataTraveler Exodia or DTX: widely available, does the job.
Skip the no-name multipacks. A flash drive that drops out halfway through writing the installer is a frustrating way to lose an afternoon, and a failed write can look exactly like a failed install.
A second drive for your backup. An external USB hard drive or SSD large enough to hold your files, or a cloud service you already trust with them. This is separate from the flash drive above.
An internet connection and a Microsoft account. Windows 11 setup on Home and Pro requires an internet connection and a Microsoft account sign-in to finish. If you do not have a Microsoft account, create one at account.microsoft.com before you begin. The old tricks for skipping this during setup have been steadily removed by Microsoft, so plan on signing in.
Your product key, maybe. If this computer has run an activated copy of Windows 10 or 11 before, you almost never need a key. Activation is stored as a digital license tied to the hardware, and Windows reactivates itself when it connects to the internet. Choose "I don't have a product key" during setup and let it happen. Only a brand-new build or a drive that never had Windows needs a purchased key.
About an hour of active time. The install itself takes 15 to 30 minutes on an SSD. Updates and drivers afterward take longer, but you do not have to babysit that part.
Step 1: Confirm Your Computer Qualifies
Windows 11 has hardware requirements that Windows 10 did not, and the two that stop people are TPM 2.0 and Secure Boot. Check before you wipe anything.
- On your current Windows installation, press the Windows key + R, type tpm.msc, and press Enter.
- If the window says "The TPM is ready for use" and Specification Version shows 2.0, you are set on TPM. If it says "Compatible TPM cannot be found," the module is probably disabled in the BIOS. Step 2 covers turning it on for every major brand.
- Next, press Windows key + R again, type msinfo32, and press Enter.
- In System Summary, find BIOS Mode and Secure Boot State. You want BIOS Mode: UEFI and Secure Boot State: On. If Secure Boot State says Off, Step 2 covers that too. If BIOS Mode says Legacy, the machine is booting the old-fashioned way and needs to be switched to UEFI, which is also a BIOS setting but comes with a catch I explain below.
- Finally, check the processor. Windows 11 officially supports Intel 8th generation Core chips and newer, and AMD Ryzen 2000 series and newer. Microsoft's free PC Health Check app (search "PC Health Check" at microsoft.com) gives you a plain yes or no on the whole system.
If the processor itself is unsupported, no BIOS setting fixes that. That is the point where the honest conversation is whether the machine is worth carrying forward at all, and it is a conversation we have at the counter every week. Bring it in and we will give you the real math.
Step 2: Enable TPM 2.0 and Secure Boot in the BIOS
This is the step that stops most people, because every manufacturer buries these settings somewhere different and calls them something different. Here is where they live on the brands I see most on the bench. One translation note that helps everywhere: on Intel systems, firmware TPM is called Intel PTT (Platform Trust Technology). On AMD systems it is called AMD fTPM or AMD CPU fTPM. Both count as TPM 2.0. If you see either of those names, that is your switch.
To get into the BIOS on any machine: shut down fully, power on, and immediately start tapping the setup key listed below. If Windows boots instead, restart and try again, tapping earlier. You can also get there from inside Windows: Settings > System > Recovery > Advanced startup > Restart now, then Troubleshoot > Advanced options > UEFI Firmware Settings > Restart.
HP (desktops and laptops)
- Setup key: F10 (tap Esc first if you want the startup menu, then choose F10 for BIOS Setup).
- TPM: go to the Security tab. Look for TPM Embedded Security, TPM Device, or TPM State. Set TPM Device to Available and TPM State to Enabled.
- Secure Boot: go to Advanced (or Boot Options on some models) and open Secure Boot Configuration. Set Secure Boot to Enabled and make sure Legacy Support is Disabled.
- Press F10 again to save and exit. Some HP machines ask you to type a four-digit confirmation code shown on screen before a TPM change takes effect. Type it and press Enter.
Dell (desktops and laptops)
- Setup key: F2 (F12 gives you a one-time boot menu instead, which you will use later).
- TPM: in the left-hand menu, expand Security and click TPM 2.0 Security (some newer models say Firmware TPM). Check TPM On and make sure Enabled is selected.
- Secure Boot: in the same left-hand menu, expand Secure Boot (or Boot Configuration on newer BIOS layouts) and set Secure Boot Enable to On.
- Click Apply, then Exit. Dell layouts vary by generation, but Security and Secure Boot are always top-level categories in the sidebar.
Lenovo (ThinkPad, ThinkCentre, IdeaPad, Legion)
- Setup key: F1 on ThinkPads and ThinkCentres, F2 or Fn+F2 on IdeaPads and Legions. Many Lenovo machines also have a tiny Novo button (a pinhole or small round button on the side) that opens a menu with BIOS Setup on it.
- TPM: go to the Security tab and open Security Chip. Set Security Chip Selection to Intel PTT (Intel) or Firmware TPM/dTPM (AMD or discrete), and Security Chip to Enabled.
- Secure Boot: still under Security, open the Secure Boot submenu and set Secure Boot to Enabled.
- Press F10 to save and exit.
Asus (motherboards and laptops)
- Setup key: Del on desktop motherboards, F2 on laptops.
- Asus boards open in EZ Mode. Press F7 to switch to Advanced Mode, where the real settings live.
- TPM on Intel boards: go to Advanced > PCH-FW Configuration and set PTT to Enable (select PTT when it asks TPM Device Selection).
- TPM on AMD boards: go to Advanced > AMD fTPM configuration and set TPM Device Selection to Firmware TPM.
- Secure Boot: go to the Boot tab, open Secure Boot, and set OS Type to Windows UEFI Mode. If CSM (Compatibility Support Module) is enabled under Boot, disable it, or Secure Boot cannot turn on.
- Press F10 to save and exit.
MSI (motherboards and laptops)
- Setup key: Del.
- MSI's Click BIOS also has an EZ and Advanced view. Press F7 to toggle to Advanced.
- TPM: go to Settings > Security > Trusted Computing and set Security Device Support to Enabled. Below it, select PTT on Intel boards or AMD CPU fTPM on AMD boards.
- Secure Boot: go to Settings > Advanced > Windows OS Configuration. Set BIOS CSM/UEFI Mode to UEFI. The Secure Boot option appears once UEFI mode is set. Open it and set Secure Boot to Enabled.
- Press F10 to save and exit.
Gigabyte and Aorus (motherboards)
- Setup key: Del.
- TPM on Intel boards: go to Settings > Miscellaneous and set Intel Platform Trust Technology (PTT) to Enabled. On some BIOS revisions it lives under Peripherals or under Settings > Trusted Computing instead.
- TPM on AMD boards: go to Settings (or Peripherals on older revisions) and set AMD CPU fTPM to Enabled.
- Secure Boot: go to the Boot section, set CSM Support to Disabled, save and reboot back into the BIOS, then return to Boot and set Secure Boot to Enabled. Gigabyte boards often will not show or allow Secure Boot until CSM is off and you have rebooted once.
- Press F10 to save and exit.
Menu names drift between BIOS versions even within a brand, so if your screen does not match word for word, look for anything that says TPM, PTT, fTPM, Trusted Computing, or Security Device. That is the setting.
The Legacy BIOS catch. If Step 1 showed BIOS Mode: Legacy, your current Windows drive is probably partitioned as MBR, and simply flipping the BIOS to UEFI will make the old installation unbootable. For a clean install this does not matter, because you are erasing that drive anyway: set the BIOS to UEFI mode, disable CSM, and proceed. Just understand there is no booting back into the old system once you flip it, so finish your backup first.
A note on BitLocker. If your current drive is encrypted with BitLocker or Device Encryption, changing TPM settings can trigger a recovery key prompt at boot. Before touching the BIOS, sign in at account.microsoft.com/devices/recoverykey and save your recovery key somewhere off the computer. It takes two minutes and it prevents the single worst surprise in this whole process.
Step 3: Back Up Like You Mean It
Everything on the target drive is about to be erased. Not moved to a recycle bin. Erased.
- Copy your user folders (Documents, Pictures, Desktop, Downloads, Videos, Music) to your external drive or cloud storage.
- Get the hidden stuff: browser bookmarks and saved passwords (sign into a sync account or export them), email files if you use Outlook with POP accounts, QuickBooks or other financial data files, game saves that live outside the cloud, and anything in odd locations like C:\ root folders that installers created.
- Deactivate license-limited software. Some programs, especially older Adobe products and specialty tools, count installations. Sign out or deactivate them first so the license frees up.
- Confirm the backup by opening files from the external drive on another computer if you can. A backup you have not tested is a hope, not a backup.
Data transfer is a big part of what people actually pay us for on reinstall jobs, and this step is why. If the machine will not boot well enough to back itself up, do not guess. That is a bench job.
Step 4: Create the Installation Drive
Microsoft's Media Creation Tool does this in a few clicks, and using the official tool means the drive is built exactly the way the installer expects.
- On any working Windows computer, go to microsoft.com/software-download/windows11.
- Under "Create Windows 11 Installation Media," click Download Now and run the tool. Accept the license terms.
- Confirm the language and edition (the defaults match the computer you are on, which is usually what you want) and click Next.
- Choose USB flash drive and click Next.
- Plug in your flash drive, select it from the list, and double-check you picked the right one, because it gets wiped. Click Next.
- The tool downloads Windows 11 and writes the drive. Depending on your internet speed this takes 15 to 45 minutes. When it says "Your USB flash drive is ready," click Finish.
Step 5: Prepare the Computer
Two things before you boot the installer, and the second one is the most important advice in this entire guide.
- Plug the flash drive into the computer you are installing on. On a desktop, use a rear USB port wired directly to the motherboard rather than a front-panel or hub port.
- Disconnect every storage drive except the one you are installing Windows on. Power the machine off, unplug it, and disconnect the SATA or power cables from any secondary hard drives and SSDs, and unplug external drives, including your backup drive. This makes it physically impossible to wipe the wrong disk on the partition screen, and it prevents the installer from scattering boot files onto a second drive, which causes bizarre problems months later when that drive is removed. I do this on every single reinstall at the shop, no exceptions. If you are on a laptop with one drive, you are already done. Reconnect everything after Windows is installed and running.
Step 6: Boot From the USB Drive and Install
- Power on and tap the one-time boot menu key: F12 on Dell and Lenovo, F9 on HP (tap Esc first if needed), F8 on Asus boards, F11 on MSI, F12 on Gigabyte. Choose the entry that names your flash drive with "UEFI" in front of it.
- The installer loads. Confirm your language and keyboard settings and click Next.
- Choose the setup option that installs Windows 11 and check the box confirming you agree that everything will be deleted, including files, apps, and settings. This wording is the current installer telling you exactly what a clean install is. Click Next.
- On the activation screen, click I don't have a product key if this hardware has run activated Windows before. Enter a key only if this is a new build or a never-activated machine.
- Select your edition (Home or Pro, matching what the machine had before) and accept the license terms.
- If asked to choose an installation type, choose the custom option that installs Windows only. Do not choose Upgrade. Upgrade keeps the old system, which defeats the purpose of everything you have done so far.
- Now the partition screen. Because you disconnected the other drives, you should see exactly one disk, probably listed as Drive 0 with several partitions on it. Select each partition on that disk, one at a time, and click Delete, until the entire disk shows as a single block of Unallocated Space. Do not create partitions or format anything manually. Select the unallocated space and click Next. The installer creates the correct layout itself.
- Windows copies files and restarts a few times. Leave the flash drive alone unless the machine tries to boot back into the installer's first screen, in which case pull the drive and let it restart. Ten to twenty minutes on an SSD.
Step 7: First-Time Setup
The out-of-box experience walks you through configuration. The screens shift slightly as Microsoft updates the installer, but the sequence is stable:
- Confirm your country and keyboard layout.
- Connect to your Wi-Fi network or plug in ethernet. Setup wants this connection to finish.
- Name the PC if asked, then sign in with your Microsoft account. This links your digital license, which is what makes activation automatic on this hardware forever after.
- Create a PIN when prompted. This is just the local sign-in code for this machine.
- If setup offers to restore from a backup of a previous PC, choose to set up as a new PC. Restoring settings onto a clean install drags old configuration back in, which is the opposite of what you wanted.
- The privacy settings page is worth thirty seconds. Every toggle works either way; turn off what you are not comfortable sharing.
- Skip the optional promotions for Office trials, Game Pass, phone linking, and OneDrive backup unless you actually want them. All of it can be set up later.
- Setup finishes with "This might take a few minutes." Let it sit. It can take longer than a few minutes on slower hardware, and interrupting it is the classic way to corrupt a brand-new install.
Step 8: After the Desktop Appears
The install is done, but the machine is not finished. Do these in order:
- Windows Update first. Settings > Windows Update > Check for updates. Install everything, restart, and check again. Repeat until it comes back clean. Windows Update also delivers most of your hardware drivers now, which is why it comes before anything else.
- Confirm activation. Settings > System > Activation should read "Windows is activated with a digital license." If it does not after an hour online, the Activation troubleshooter on that same page fixes most cases, especially with "I changed hardware on this device recently."
- Finish the drivers. Open Device Manager and look for yellow warning marks. For anything left over, get drivers from the manufacturer's support page for your exact model (Dell, HP, and Lenovo all have auto-detect tools), or from the motherboard maker's page for a custom build. Graphics drivers come straight from NVIDIA, AMD, or Intel.
- Shut down and reconnect your other drives, then boot and confirm they all show up in File Explorer.
- Copy your files back from the backup drive, and reinstall programs from their official sources as you need them, not all at once. A clean install stays clean longer when you only put back what you actually use.
- Save your BitLocker recovery key. Windows 11 enables device encryption automatically on most modern hardware when you sign in with a Microsoft account. Go to account.microsoft.com/devices/recoverykey and confirm the new key is saved there. Future you may need it.
When to Bring It to the Shop Instead
A clean install is very safe when the steps are followed, but there are situations where doing it yourself is the wrong call:
- The computer fails the TPM, Secure Boot, or processor checks and you are not sure whether it is a settings problem or a hardware limit. We see machines every week that were declared "not compatible" and just needed one BIOS toggle, and others where an upgrade would be throwing money at hardware that will not carry it.
- The current Windows is too broken to boot, so you cannot back anything up first. Getting data off a failing installation before the wipe is exactly what the bench is for.
- The drive itself is suspect. Installing a fresh Windows onto a dying SSD or hard drive just resets the clock on the same failure. Part of every reinstall we do is testing the drive's health first, and swapping it while the machine is already open costs far less than a second visit.
- BitLocker is prompting for a recovery key you do not have. Stop before making it worse.
We handle Windows 11 clean installs, upgrades from Windows 10, and full data transfers at our Somerville shop, drop-off, usually with quick turnaround. The $75 diagnostic is credited toward the repair, so finding out where your machine actually stands costs you nothing extra if you move forward. Call 908-428-9558 or stop by 75 N Bridge St.
Frequently Asked Questions
Do I need to buy a Windows 11 license if my PC had Windows 10?
No. An activated Windows 10 machine has a digital license that activates Windows 11 of the same edition automatically once the fresh install connects to the internet. Choose "I don't have a product key" during setup.
How big a flash drive do I need?
Microsoft's minimum is 8GB, but buy 16GB or larger. Modern name-brand drives in that range cost very little and remove any chance of the Media Creation Tool running out of space.
Will a clean install make my computer faster?
If the slowdown comes from software buildup, dramatically. If it comes from a failing drive, too little RAM, or an aging processor, no reinstall fixes hardware. Our slow computer guide covers how to tell the difference, and the diagnostic settles it for certain.
Can I keep my files and do a clean install?
Not in the same operation. A clean install erases the drive by definition. Back up first, install, copy back. If you want a refresh that keeps files, Windows has a built-in Reset option, but it does not clean as deeply and it inherits some existing problems.
My PC says it does not meet Windows 11 requirements. Now what?
First check whether TPM 2.0 and Secure Boot are simply disabled, using Step 1 and Step 2 above. That is the fix a surprising amount of the time. If the processor itself is unsupported, the honest options are staying on Windows 10 with extended security updates while they last, or putting the money toward hardware that will carry you forward. Bring it in and we will walk you through the real math for your machine.
How long does the whole process take?
Plan a half day end to end: backup time depends on how much data you have, media creation takes 15 to 45 minutes, the install itself 15 to 30 minutes on an SSD, and updates plus drivers another hour of mostly unattended time.
Rather never do this yourself again? Every custom PC we build in New Jersey leaves the bench with this exact clean install already done, TPM set, drivers current, updates finished.