It's borderline, but it's officially out of spec for Microsoft :-(. The 7th generation chips apparently lack a few security features that 8th generation and later have, and they're slightly less susceptible to Meltdown and Spectre vulnerabilities than 7th generation and older models, the big feature being VBS. I suspect that's why Microsoft cut it... Ugh, BIOS patching exists, and any reasonably current machine like Haswell has high-speed patching!!! 1st-gen Core i chips (up to 3rd gen) were decimated by the patches to the point that I completely ignored the BIOS update on my XPS 8500. The 4th-5th generation chips were hit hard, but the 6th-7th generation chips were impacted to a lesser degree, although not as severely as the others. 8th gen and up weren't hurt by the patching much (if at all) because they had hardware mitigations in place by then, and 12th gen is completely protected against Meltdown but not Spectre. I think the 7th-gen cutoff is a cash grab by the OEMs on PCs, given they all pass the "TPM 2.0" test Microsoft is so attached to. As for 6th generation and older, those are a crapshoot in terms of what you get, such as the 6th-gen i3 being available in either 2C/2T or 2C/4T configurations, and the i5 and i7 being quad-core minimum, with some models offering 4C/4T or even 4C/8T; laptops were a complete mess to the point you need to check what yours has if you bypass it - 2C/2T snd 2C/4T 6th gen i3s are asking for trouble in the long run, i5 4C/4T and 4C/8T is (probably) doable but it's more risky then 7th gen. I understand cutting those off, given how many wildcards 6th gen introduced, but 7th gen is a straight cash grab, considering they all have TPM 2.0 and pass every f'n test outside of the CPU.
ANYWAY, I made this: Windows 10/11 - USB Installation Media Creation -- it covers how to bypass their bullshit with borderline PCs. I agree with them on 6th gen and older living through the wildcard that was (and 5th gen and older taking a nasty enough hit from the patches), so I disabled it on my full-fat socketed i7-4800MQ E6540. I even left it at the Spectre/Meltdown early patch BIOS for the rest of its time; it worked and stopped updating it in case Dell blocked rollbacks when the more invasive patches were released. YEP! I did what everyone said not to and was fine.
If you do choose to replace it with a newer machine like a secondhand laptop, any current AMD/Intel model is fine - I have an EliteBook 640 G11 and a 645 G11, and I am happy with modern Ryzen and Intel chips - AMD made a lot of noise with the 5000 series when their performance numbers began competing with Intel to such a degree it genuinely doesn't matter if you go red or blue for your CPU. Intel has 12 cores on the Core Ultra vs AMD's 6 core Ryzen 5 PRO chips (and 8 on the 7 PRO; you lose 4 with Ryzen 7 vs 6 on Ryzen 5, but you pay more for them - your call how much you care -- I have a 5 PRO and it's as fast as my 12 core Intel Ultra 5 640). My experience is the Ultra and Ryzen are both amazing chips and part of that is AMD's cache approach compensating. You can usually get the AMD models cheaper given they were cheaper new vs the Intel models, especially pre Ryzen AI machines. You lose the Windows studio effects unless you get one of the Ryzen AI machines, so I guess if you care about fast AI and Windows Studio effects, it's gotta be Intel or one of the AI AMD EliteBooks for a lot more.
Just for the love of whatever deity you believe in... Secure erase it, reinstall Windows with a Rufus image and check for MDM on your first day with the machine - some companies forget and you risk problems with a machine enrolled in Microsoft Intune Autopilot. It's in the BIOS under hard drive utilities with HP, Dell is under security but I don't know where off the top of my head - you'll see it under "secure erase" or similar terms. Lenovo has the option as of the 9th gen and up CPU series under the app menu when you press F12>ThinkShield secure wipe. It's hidden such you have to intentionally want to do it.
crwdns2934105:0crwdne2934105:0
crwdns2934113:0crwdne2934113:0
crwdns2915270:0crwdne2915270:0
crwdns2889612:0crwdne2889612:0
1