Restrict clients on a Domain to Windows 11 *24H2) and not allow anything older i.e. Windows 10

Graham Duffy 105 Reputation points
2025-11-10T11:27:40.96+00:00

Is there any way either via Policy or other, to not allow Windows clients older than say Windows 11 24H2 to be used for user to logon to a Domain. i.e. Users need to connect to the domain from devices that are Windows 24H2 or higher ? Thus if a user had a Windows 100 system they cannot logon to the Domain, but if there client system is Windows 11 they can logon to the Domain ?

Windows for business | Windows Client for IT Pros | Directory services | User logon and profiles
0 comments No comments
{count} votes

Answer accepted by question author
  1. Q&A Assist
    2025-11-10T11:28:07.1433333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    To restrict clients on a domain to only allow Windows 11 (version 24H2) or higher, you can utilize Group Policy settings. Specifically, you can implement policies that enforce minimum operating system requirements for domain logon. While the context provided does not specify a direct method for enforcing OS versions for logon, you can achieve similar results by using the following approaches:

    1. Group Policy: You can create a Group Policy Object (GPO) that applies to the organizational unit (OU) containing your user accounts. Within this GPO, you can configure settings that restrict access based on the operating system version.
    2. Device Compliance Policies: If you are using Microsoft Intune or another Mobile Device Management (MDM) solution, you can set compliance policies that require devices to be running Windows 11 (24H2) or later. Non-compliant devices would be blocked from accessing the domain.
    3. Network Access Control: Implementing Network Access Control (NAC) solutions can help enforce device compliance before allowing them to connect to the network.
    4. User Education and Communication: Inform users about the requirement to upgrade their devices to Windows 11 (24H2) or higher to avoid login issues.

    By combining these strategies, you can effectively restrict domain access to only those clients that meet your specified operating system requirements.


    References:


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.