ASD's Blueprint for Secure Cloud

Hardware Requirements

This section describes the design decisions associated with hardware requirements for Windows 10 and 11 endpoints configured according to guidance in ASD's Blueprint for Secure Cloud.

Estimated reading time: 2 minutes

The hardware platform chosen to support the SOE is key to its stability and provides the components that can be configured by the operating system and applications.

The selected processor architecture and associated firmware capability directly influence the supportability of applications and security features of an operating system. The minimum hardware requirements listed below will ensure that the system runs reliably and is supported by the vendor, Microsoft.

Organisations should select a reputable hardware platform that supports enterprise features, such as having an interface to provision zero-touch UEFI configuration and updates.

Minimum physical hardware configuration for the Windows 10 SOE applicable to all organisations and implementation types.

Architecturex64Required to Support more than 4GB RAM.
ProcessorAt least 4 logical processors, VT-x (Intel) or AMD-V CPU extensions, 2 GHz or higher with Second Level Address Translation (SLAT) supportSLAT is required to support Windows Defender Application Guard.
RAM8GBTo meet design specifications.
Graphics CardDirectX 9 WDDM 1.0To meet design specifications. Integrated or dedicated.
Input Device(s)Keyboard
Multi-touch display screen to enable Windows 10 touch screen features (optional)
Keyboard and mouse may be built into a laptop, but touch screens are optional.
Minimum HDD Space128GBTo meet design specifications.
MicrophoneRequired for speech recognition (optional)Speech recognition is not required to be enabled but may be needed for organisations with accessibility requirements.
BIOSMinimum UEFI 2.3.1Required to support Secure Boot, Windows Defender Device Guard, Windows Defender Credential Guard, Windows Defender Exploit Guard and Kernel DMA Protection.
TPMMinimum version 2.0 (with device attestation preferred)Required to support Microsoft Intune Windows Autopilot and MECM. Note: TPM device attestation is preferred to enable Windows Autopilot Self-deploying mode.

In addition for Windows 11 SOEs, the processor must be selected from the supported list for Windows Processor Requirements.

Security & Governance

  • None identified


  • None identified


  • None identified


  • None identified

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra