Skip to main content
< All Topics
Print

How to Set Up a New Windows 11 PC for Business


📄 Windows & Devices
🕑 8 min read
Cybergate IT Team
Setting up a new Windows 11 PC for business
A properly configured Windows 11 business PC takes 1 to 3 hours but protects your data and enables remote management.

Setting up a new Windows 11 PC correctly from the start saves time, prevents security issues and ensures the device is properly managed by your IT team. Skipping steps like Windows Update, BitLocker and RMM enrollment creates security gaps that are expensive to fix later. This guide covers the complete business setup from unboxing to ready-to-use.

Do This Before Handing the PC to the User

Complete all setup steps including Windows Update and antivirus before the user starts working on the machine. Updates often require restarts that disrupt work, and an unprotected PC can be compromised within minutes of connecting to the internet.

Step 1: Complete the Windows 11 Initial Setup (OOBE)

1

Power On and Region Selection

Power on the PC. The Out-of-Box Experience (OOBE) setup wizard will start automatically. Select your Country or Region (Malaysia), Keyboard Layout (US or your preferred layout) and click Yes. Add a second keyboard layout if needed or click Skip.

2

Connect to WiFi

On the network screen, select your office WiFi network and enter the password. If setting up via a wired Ethernet connection, this screen will be skipped automatically. An internet connection is required to complete setup and activate Windows.

Tip

If this is an Azure AD joined device, connect to the internet before proceeding – Windows needs to reach Microsoft servers to complete the Azure AD join.

3

Sign In With Work Account

When prompted to sign in, choose Set up for work or school. Enter your Microsoft 365 work email address. Windows 11 will connect to your organisation’s Azure AD tenant and join the device automatically. If your IT team uses Intune, the device will be enrolled in mobile device management as part of this step.

If the PC should use a local account instead (not recommended for managed environments), click Sign-in options > Domain join instead.

Step 2: Run Windows Update

Settings Windows Update Check for Updates
4

Install All Pending Updates

After the initial setup completes and you reach the desktop, immediately run Windows Update. Go to Settings > Windows Update and click Check for updates. Install all available updates including optional updates.

Pay particular attention to:

  • Cumulative updates for Windows 11 (security patches)
  • Driver updates (especially for network adapters, graphics and storage)
  • Microsoft Defender antivirus definition updates

The PC will likely need to restart once or twice. Keep running Windows Update until it shows You’re up to date.

Windows 11 Update settings screen
Run Windows Update immediately after setup and install all updates including optional ones.

Step 3: Install Microsoft 365 Apps

5

Download and Install Office

Open Microsoft Edge and go to portal.office.com. Sign in with the work Microsoft 365 account. On the home page, click Install apps in the top right corner, then click Microsoft 365 apps.

The installer file (OfficeSetup.exe) will download. Run it and allow the installation to complete. This installs Word, Excel, PowerPoint, Outlook, Teams, OneNote and other Microsoft 365 apps. The installation takes 10 to 20 minutes depending on internet speed.

After installation, open Outlook and sign in with the work email account to configure the mailbox.

Step 4: Enable BitLocker Drive Encryption

Start Menu BitLocker Manage BitLocker
6

Turn On BitLocker

Search for BitLocker in the Start menu and open Manage BitLocker. Click Turn on BitLocker next to the C: drive. Follow the wizard:

  • Choose how to unlock at startup (recommend: Automatically unlock)
  • Choose how to back up the recovery key – select Save to your Microsoft account or Save to a file (save to a USB drive or network location, not on the C: drive)
  • Choose how much of the drive to encrypt – select Encrypt entire drive for existing data or new PCs
  • Choose encryption mode – select New encryption mode (XTS-AES)
  • Click Start encrypting

Encryption runs in the background and takes 30 minutes to several hours depending on drive size. The PC remains usable during encryption.

Save the Recovery Key

Store the BitLocker recovery key in a safe location outside the encrypted PC. Without it, data cannot be recovered if the PC fails or the user forgets their PIN. Save it to your Microsoft account, a USB drive or print it and file it securely.

Step 5: Install Antivirus and Security Software

7

Install and Configure Antivirus

Windows Defender is enabled by default and provides baseline protection. If your organisation uses a third-party antivirus:

  • McAfee Total Protection / McAfee Endpoint Security: Download the installer from the McAfee ePolicy Orchestrator (ePO) server or McAfee portal. Run the installer and the agent will auto-configure from the ePO policy.
  • Kaspersky Endpoint Security: Download from the Kaspersky Security Center console. Deploy via the push installation feature or run the installer manually.
  • Sophos Endpoint: Log into the Sophos Central dashboard and use the Protect Devices link to download the installer. Sophos auto-registers the device with your Central account.

After installation, verify the antivirus is running and definitions are up to date before proceeding.

Step 6: Configure OneDrive Backup

System Tray OneDrive icon Settings Backup Manage backup
8

Enable Folder Backup

Click the OneDrive cloud icon in the system tray (bottom right). If not visible, search for OneDrive in the Start menu and sign in with the work Microsoft 365 account.

Once signed in, click the OneDrive icon > Settings > Backup > Manage backup. Enable backup for Desktop, Documents and Pictures. Click Start backup.

Files in these folders will now sync automatically to OneDrive. If the PC is lost, stolen or damaged, all files are recoverable from any other device signed into the same account.

Step 7: Install the RMM Agent

9

Deploy ManageEngine Endpoint Central Agent

If the PC is managed by Cybergate or an internal IT team using ManageEngine Endpoint Central:

  • Download the agent installer provided by your IT team
  • Run the installer as Administrator (right-click > Run as administrator)
  • The agent installs silently and connects to the ManageEngine console automatically
  • Within 5 minutes, the device will appear in the Endpoint Central console

Once enrolled, the IT team can remotely manage patches, deploy software, access the desktop remotely and monitor device health from the central console.

Setup Complete Checklist

Before handing the PC to the user confirm: Windows is fully updated, Microsoft 365 apps are installed and signed in, BitLocker is enabled and recovery key is saved, antivirus is installed and updated, OneDrive backup is running for Desktop/Documents/Pictures, RMM agent is enrolled and visible in the console.

Need IT Help in Malaysia?

Cybergate provides onsite IT support for businesses across Malaysia. Our team is available Monday to Saturday, 9am to 6pm.

Frequently Asked Questions

For a business PC managed by an IT team, always use a Microsoft 365 work account (Azure AD joined) rather than a personal Microsoft account or local account. This allows central management, Intune enrollment, Conditional Access policies and remote wipe capability.

Initial setup including Windows Update can take 1 to 3 hours depending on internet speed and the number of pending updates. Plan for this when onboarding a new device. The PC may restart several times during the update process.

Windows Defender (Microsoft Defender Antivirus) provides solid baseline protection and is acceptable for many business environments. For higher security requirements or compliance purposes, a dedicated endpoint security solution such as Sophos, Kaspersky or McAfee provides additional features including EDR, web filtering and central management.

Yes. Cybergate provides onsite PC setup and configuration for Malaysian businesses, including Windows configuration, Microsoft 365 deployment, antivirus installation and RMM agent enrollment. Contact us for a quote.

CG
Cybergate IT Team
Managed IT support for Malaysian businesses since 2014. Microsoft Partner · Fortinet Technology Partner. About Us

Related Articles

Table of Contents