Before you start
These steps cover personal Windows 11 computers. Use IT support for an organisation-managed device. If a named setting is missing, search for its name in Start.
Prepare power and a copy of important data. Do not install fixes from pop-up messages. If there are serious signs of an active attack, use the incident steps first.
Install updates
- Open Start → Settings → Windows Update.
- Select Check for updates.
- Choose Download & install if updates are offered.
- Save open documents before a requested restart.
- After restarting, return to Windows Update and check for pending actions.
You’re up to date means no further updates are currently offered. It does not certify that the computer is free from malware.
Check threat protection
Search Start for Windows Security. Open Virus & threat protection, then Quick scan. Review the result and any recommended actions, not just whether the scan finished.
Scan options provides additional checks. Full scan is a broader scan; Microsoft Defender Offline scan requires a restart, so save work first. Available controls also depend on the installed protection. Do not reconnect a computer under active remote control just to perform this check.
Create and verify a backup
- Search Start for Windows Backup.
- Check the personal Microsoft account used for storage.
- Under Folders, select the available folders to back up to OneDrive.
- Start the backup and review the status of each selected item.
- From another trusted device, confirm that an important saved file opens.
Windows Backup is not a complete image of every drive. Check documents outside selected folders and transfer instructions for important apps. See the backup guide for a separate copy. Disconnect a backup drive when finished; do not attach it to a computer showing signs of infection.
If the computer is lost
In advance, search Settings for Find my device and check that it is on. This requires a personal Microsoft account with administrator access and location enabled; work and school accounts do not use this consumer procedure.
If the computer goes missing, enter account.microsoft.com/devices on another trusted device. Choose Find My Device, select the correct computer and choose Find. When Lock is available, complete the process and check its status. The feature must have been prepared before the loss; results depend on device availability.
Locking is not remote erasure. Protect exposed Microsoft and other accounts. Report theft to police; do not give passwords to someone claiming to return the computer.
Erase before selling or giving away
First verify your backup and account access. If the drive is encrypted, obtain your BitLocker recovery key, used to unlock the encrypted drive during recovery. It is not your account password. Disconnect backup drives.
If the key was saved to your Microsoft account, enter aka.ms/myrecoverykey on another trusted device and sign in. Match the Key ID to the ID requested on the recovery screen. If it is missing, check an earlier printout or USB copy, or ask whoever set up encryption. Do not publish the key or erase your only data copy just to get past that screen.
Open Settings → System → Recovery → Reset PC. Keep my files retains personal files and is unsuitable for handoff. For handoff, choose Remove everything and enable Clean data. Check the drive scope and final summary before confirming.
Keep power connected and do not interrupt the reset. Leave the initial setup screen for the next user. This is a consumer process, not certification against business data-destruction requirements. Seek specialist help for those requirements or a faulty drive.
If the device may be compromised
For active remote control, extortion or file encryption, disconnect Wi-Fi and Ethernet. Do not enter new passwords or connect backups. Use another trusted device to follow device recovery. If money is at risk, contact the bank immediately.