skinny.

Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations

Windows 11 Quietly Mandates Enterprise Hardware Security Module for All

Episode 86 of The Windows Podcast digs into Microsoft's quiet new requirement: every Windows 11 Enterprise device must have a hardware security module (HSM) or a TPM-backed virtual HSM for key storage by the end of 2026. Lucas explains what an HSM is — a tamper-resistant chip that stores encryption keys separately from the CPU — and why Microsoft is now mandating it after years of optional support. He walks through the three key scenarios affected: BitLocker key protection, Windows Hello biometric data, and Azure AD certificate-based authentication. Luna challenges whether this is just…

The skinny

The skinny isn't ready yet — notes appear once the transcript is processed.